# Privacy Policy — Trust Vault **Effective date:** 2 July 2026 **Last updated:** 2 July 2026 Trust Vault ("the app", "we", "us") is a zero-knowledge, end-to-end encrypted vault for passwords, notes, cards, wallets, identity details, and files, plus a trusted-identity verification and secure-sharing feature. This policy explains what the app does and does not do with your data. Our core principle: **your data is encrypted on your device and only you can decrypt it.** We cannot read your vault contents, and we cannot recover them for you. --- ## 1. Summary - All vault content is encrypted **on your device** with AES-256-GCM before it is stored or transmitted. - Your **master password never leaves your device** and is never sent to us. The encryption key is derived from it locally (PBKDF2). - Our servers only ever store **encrypted ciphertext** and a random **sync token** identifier. We cannot decrypt your data. - We do **not** sell your data, do **not** show ads, and do **not** use third-party analytics or advertising trackers. - Losing your sync token **and** master password means your data cannot be recovered — not even by us. --- ## 2. Information we process ### a) Data you create (encrypted, we can't read it) Passwords, secure notes, cards, crypto wallets, identity records, custom items, and any files you choose to encrypt. This content is encrypted locally and stored on your device. If you use cloud sync, only the **encrypted ciphertext** is uploaded. ### b) Account / sync data - **Sync token:** a randomly generated identifier used to associate your encrypted blobs with your account so you can restore them on another device. It is not derived from, and does not reveal, your identity. - **Authentication tokens:** short-lived tokens used to keep your sync session active. ### c) Trusted-identity data When you pair with or verify another person, a shared secret is generated and **stored encrypted on your device**. During a verification, only an HMAC (a one-way cryptographic proof), never the secret itself, is exchanged. ### d) Device permissions - **Internet:** to sync your encrypted data and to exchange verification links. - **Camera:** to scan pairing / verification QR codes. Camera images are used only in-app for scanning and are **not stored or transmitted**. - **Biometrics (fingerprint / face):** used locally by your device's operating system to unlock the app. We never receive or store biometric data. ### e) What we do NOT collect We do not collect your name, email, phone number, contacts, location, advertising ID, or usage analytics. We do not profile you and do not use tracking SDKs. --- ## 3. How your data is protected - **Encryption at rest:** AES-256-GCM, with keys derived from your master password via PBKDF2. Encrypted data is stored locally; secrets and metadata are held in the platform secure storage / keystore. - **Zero-knowledge sync:** the server stores only ciphertext it cannot decrypt. - **In transit:** all network communication uses HTTPS/TLS. - **Secure sharing:** shared files (.svc) are encrypted with a fresh per-file key so the same secret never produces identical ciphertext twice. Only the intended trusted contact can decrypt them. --- ## 4. Data sharing and disclosure We do not sell, rent, or share your data with third parties for marketing. Because your content is stored only as ciphertext we cannot decrypt, we are unable to disclose readable vault contents to anyone, including in response to a legal request. We may share the limited, non-decryptable account data described above only where required by applicable law. --- ## 5. Data retention and deletion - Data stored locally is removed when you delete an item, reset the app, or uninstall it. - Encrypted data synced to the server is retained so you can restore it. Using the in-app **Reset All Data** removes local data and signs you out; your encrypted cloud copy remains restorable with your sync token until deleted. - To request deletion of your synced encrypted data, contact us at the address below with your sync token. --- ## 6. Children's privacy Trust Vault is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction), and we do not knowingly collect data from them. --- ## 7. International users Your encrypted data may be processed and stored on servers located in other countries. Because it is stored only as ciphertext we cannot decrypt, its confidentiality does not depend on the jurisdiction in which it is held. --- ## 8. Changes to this policy We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date, and, where appropriate, an in-app notice. --- ## 9. Contact Questions or data requests: **Email:** mhuob7470@gmail.com