NullVault is built around data minimization. Local vault use does not require a NullVault account. NullVault does not receive your vault pattern, recovery phrase, local encryption keys, or local vault contents during ordinary local use.
This policy applies to the NullVault website and mobile apps published by NullVault. This policy will be updated if production data practices change.
The short version: Your protected content is stored locally unless you deliberately use an export, purchase, support, backup, or sharing feature. Features that use an app store or cloud provider are described below. Optional iOS backup and sharing send encrypted application data through Apple CloudKit. Android does not include cloud backup or sharing at launch. NullVault does not sell personal information or use it for advertising.
At a glance
| Data or activity | Where it is handled | Why |
|---|---|---|
| Vault content, patterns, phrases, and local keys | On your device during ordinary local use | To create, encrypt, open, organize, and recover vaults |
| Selected cloud backup or sharing data | Encrypted by NullVault, then handled by the provider identified for that feature | To provide an optional feature you enable |
| Purchase and entitlement information | The applicable app store; limited entitlement state may be available to NullVault | To complete, unlock, and restore purchases |
| Support email | NullVault and its email provider | To answer your request and prevent abuse |
| Website analytics, after you allow it | Google Analytics | To understand aggregate website use and improve public content |
Website analytics
For visitors in the European Union and United Kingdom, Google Analytics remains off until Allow analytics is selected. Elsewhere it loads without displaying the consent prompt. If it runs, Google receives website interaction and technical information such as pages viewed, approximate location derived from network information, device and browser characteristics, referrer, and visit timing. NullVault disables Google signals and advertising-personalization signals in its tag configuration and does not send vault contents, patterns, phrases, local filenames, or data processed by the browser tools. Google Analytics does not run on /tools/* pages.
Google Analytics uses first-party identifiers to distinguish visits. You can change your choice at any time using Analytics choices in the website footer. Rejecting or withdrawing disables further Analytics collection, removes the site's Google Analytics identifiers where the browser permits, and prevents the script from loading on later page views; clearing site data also clears the saved choice. The site uses Cloudflare's same-origin country signal to decide whether to display the EU/UK prompt. Google processes Analytics data under its own terms and privacy documentation.
Information you provide for support
If you email support@nullvault.app, we receive the address, message, routing information, and attachments you choose to send. We use that information to respond, investigate issues, prevent abuse, and maintain a support record where needed.
Never email a vault pattern, recovery phrase, sharing phrase, private file, payment-card detail, or account password. We do not need those secrets to provide support.
Information handled by the apps
Local vault content
Photos, videos, files, notes, app-managed metadata, patterns, and local vault keys are intended to remain within NullVault's protected local storage during ordinary local use. NullVault does not operate a custom server that receives local vault keys or plaintext merely because you create or open a local vault.
The operating-system platform still processes data needed to run the app. Device backups, crash reporting, diagnostics, notifications, accessibility services, keyboards, screen capture, and other system functions depend on your platform settings and the release configuration.
Optional cloud features
Cloud features differ by platform and release. If you enable an iOS CloudKit feature, encrypted application payloads are sent through Apple's iCloud infrastructure. Apple processes the iCloud account, device, network, storage, timing, participant, and service metadata needed to operate CloudKit. Android does not include cloud backup or sharing at launch; if that changes, this policy will be updated before the feature is made available.
NullVault's design keeps vault content, filenames, patterns, recovery phrases, sharing phrases, and keys out of plaintext CloudKit application records. Apple still processes service metadata needed to run iCloud. Phrase-based sharing is not anonymous to Apple: iCloud associates the owner and claiming recipient with their accounts. A recipient may retain content they are permitted to view or export.
Purchases
The applicable app store—Apple's App Store on iOS or Google Play on Android—will process app purchases, subscriptions, trial eligibility, payment information, tax, and store account history under its own terms. NullVault may receive transaction status, product entitlement, region, or pseudonymous purchase identifiers needed to provide and restore purchased access. NullVault does not collect payment-card details directly.
Device permissions and diagnostics
When you choose a related feature, NullVault may ask the operating system for access to the camera, selected photos, or selected files. That access is used to capture or import the item you requested. You can change app permissions in your device settings, although disabling a permission may stop the related feature from working.
Apple or Google may make crash and diagnostic information available according to your device, app-store, and platform settings. If NullVault receives such information, it is used to diagnose reliability and security issues, not for advertising or tracking. Do not include vault secrets in a diagnostic or support report.
How we use limited information
We use information when necessary to:
- deliver, secure, and troubleshoot the apps;
- answer support and security reports;
- provide or restore purchased features;
- prevent fraud, spam, or abuse;
- comply with legal obligations and protect users, rights, and services.
Where law requires a legal basis, it may be performance of a requested service, legitimate interests in operating and securing NullVault, compliance with law, or consent for a clearly optional function.
When information is shared
We do not sell personal information and do not share it for cross-context behavioral advertising. Limited information may be processed by:
- our email provider for messages sent to support;
- Apple for App Store, iOS, iCloud, and CloudKit functions, and Google for Google Play and Android platform functions;
- professional advisers or authorities when legally required or necessary to protect rights and safety;
- a successor responsible for NullVault if the product or business is reorganized, subject to applicable safeguards.
Providers that process personal information for NullVault are expected to protect it consistently with this policy and applicable law. Apple, Google, and destinations you independently choose may also act under their own terms and privacy policies.
External services and destination apps have their own privacy practices. An intentional export leaves NullVault's managed storage boundary.
Retention
Local vault data remains on your device until you delete it or remove the app, subject to device storage behavior and any copies outside NullVault. Deleting the app can make local encrypted data unrecoverable. Confirm your recovery and backup plan before deletion.
Encrypted cloud data remains until removed through the supported NullVault flow, your provider controls, or the provider's applicable retention process. Exported items and copies retained by a sharing recipient must be deleted at their destination. Store transaction records are retained by the applicable app store under its rules.
We keep support correspondence and operational records only as long as reasonably needed for the request, security, legal compliance, dispute handling, or product improvement.
Security
We use technical and organizational controls appropriate to the information we process. No app, device, cloud provider, network, or storage system can promise absolute security. Review NullVault security and security limitations before relying on the product for a high-risk situation.
Your choices and rights
You can choose not to allow website analytics, not to email us, not to enable optional cloud features, not to export content, and not to make an in-app purchase. Use Analytics choices in the website footer to change the choice saved in your browser. Platform settings provide controls for permissions, supported cloud services, subscriptions, shared data, diagnostics, and app deletion. You may withdraw a permission in device settings and stop using an optional feature at any time.
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about personal data we control. Email support@nullvault.app. We may need to verify that a request concerns you, and some information may be retained when legally required.
We cannot retrieve, inspect, correct, or delete local encrypted content that we do not possess. Delete local items through the app where available. Cloud and store data may also need to be managed through Apple or Google, depending on the platform and feature. NullVault has no conventional user account to delete for ordinary local use.
Children
NullVault is a general-audience privacy product and is not directed to children who cannot legally consent to the relevant data processing in their location. We do not knowingly collect children's personal information through the apps. A parent or guardian who believes a child sent information to support can contact us.
International processing
Infrastructure and service providers may process information in countries other than your own. Where required, we and our providers use contractual or legal safeguards for those transfers.
Changes to this policy
We may update this policy as the apps, providers, or law change. The updated date at the top identifies the current version. Material changes will be communicated through an appropriate app or store notice where required.
Questions people ask
Does NullVault sell personal information?
No. NullVault does not sell personal information or use it for behavioral advertising.
Can NullVault see my local vault content?
Not through ordinary local use. Vault content and keys are intended to remain in protected app storage. Content you deliberately email, export, share, or back up enters the selected destination's boundary.
How do I make a privacy request?
Email support@nullvault.app with “Privacy request” in the subject. Do not include a vault secret or private content.
Contact
Questions or privacy requests can be sent to support@nullvault.app. Put “Privacy request” in the subject and do not include a vault pattern, phrase, key, or private file.
Privacy Policy effective 29 August 2026.