Your privacy, in plain English
File Vault is built so we can’t read your files. This page explains what little we do keep, why we keep it, and what that means for you.
Last updated: August 9, 2026
- Your files stay locked. Titles, names, tags, and contents are scrambled on your device before upload. We host the scrambled bits — we don’t get a readable copy. How that works.
- Your password never comes to us. It stays in your browser. We only store proof that you know it, plus a locked copy of your vault key.
- We need a little account info to run the service. Things like your email, plan, how much storage you use, and basic technical logs (for example to stop abuse and keep the site working).
- We don’t sell your data. No selling mailing lists. No ads built from your vault. We’re not in the business of reading or monetizing what’s inside your files — and we can’t.
- You’re in control of the keys. Guard your password and backup key. If both are gone, nobody — including us — can open your files.
- The grown-up details are below. The short version is the spirit; the fine print covers what we collect, cookies, how long we keep data, and your rights (including under GDPR Article 13).
The fine print Full privacy policy — what we collect and why
This privacy policy describes how File Vault (“we”, “us”) handles information when you use the service. By creating an account or using the service, you acknowledge this policy. It should be read together with our Terms of use.
1. Who this applies to
This policy covers people who visit the website, create an account, or use File Vault to store encrypted personal files.
2. The short version on file contents
File Vault is designed as a zero-knowledge personal vault. File contents and most file metadata (such as title, description, tags, folder names, and original filename) are encrypted in your browser before they are sent to us. We store ciphertext. We do not have your password, and we cannot decrypt your vault contents.
Learn more on How your files stay private.
3. Information we collect
3.1 Account and billing-related data
- Email address — to create your account, confirm signup with a one-time code, let you log in, and contact you about the service if needed.
- Password-derived login material — we store a verifier derived from your password so we can check logins. Your password itself is not sent to or stored by us.
- Wrapped vault key — a copy of your vault key that only your password (or backup key, via recovery) can unlock. We cannot open it.
- Backup-key fingerprint — a one-way fingerprint used to check a recovery key is correct. We do not store the backup key itself.
- Plan and quota data — free/Pro status and storage usage totals so we can enforce plan limits.
3.2 Encrypted vault data
- Encrypted files — ciphertext blobs you upload.
- Encrypted metadata — scrambled titles, descriptions, tags, filenames, and folder names.
- Operational file facts we can see — approximate size of stored ciphertext, when a file was added or updated, and which account it belongs to. These help us run storage quotas and the library. They do not reveal file contents.
3.3 Technical and security data
- Session information — so you stay logged in while using the site.
- IP address, browser/user-agent, and similar request metadata — may appear in server or rate-limit logs to operate, secure, and debug the service and to reduce abuse.
- Timestamps of account and storage activity — for example sign-up time or last login where recorded.
3.4 Information we do not collect by design
- Your plaintext password.
- Readable contents of your uploaded files.
- Readable titles, tags, descriptions, folder names, or original filenames (these are client-encrypted).
- Advertising profiles built from your vault contents (we cannot read those contents).
4. How we use information
We use the information above to:
- Provide, maintain, and secure the service (accounts, uploads, downloads, quotas).
- Authenticate you and prevent unauthorized access or abuse (including rate limiting).
- Communicate about the service when necessary (for example account or security notices).
- Enforce our Terms of use and comply with legal obligations.
- Understand and fix technical problems using operational logs.
We do not sell your personal information. We do not use the contents of your encrypted files for advertising — we cannot read them.
5. Cookies and on-device storage
When you visit File Vault, we use a small number of strictly necessary cookies and similar technologies so the site can function. We do not use advertising or tracking cookies. A short notice about this appears on first visit; more detail is below and in GDPR Article 13 information.
| Name / type | What it does | How long | Why (legal basis) |
|---|---|---|---|
| Session cookie (login) | Keeps you signed in while you use the site | Until you log out or the session expires | Necessary for the service (contract / legitimate interests in securing access) |
| Browser session storage (vault key) | Keeps your vault unlocked in this browser tab after you enter your password | Until the tab/window is closed | Necessary to open your files in the browser (contract) |
| Local preferences | Remembers simple display choices (for example library layout) | Until you clear site data | Legitimate interests in a usable interface; stays on your device |
| Cookie-notice preference | Remembers that you dismissed the cookies & privacy notice | Until you clear site data | Legitimate interests in not repeating the same notice every page load |
Because these technologies are needed to provide the service (or to remember that you saw this notice), we do not offer an “opt out of all cookies” control that would break login or vault unlock. You can clear cookies and site storage in your browser at any time; you may need to log in and unlock again.
6. Sharing and processors
We do not sell your personal information. We may share limited account or technical data with service providers who help us run File Vault (for example hosting, storage, email delivery, or payment processing if Pro billing is enabled), only as needed to provide the service and under obligations to protect the data.
We may also disclose information if required by law, regulation, legal process, or to protect the rights, safety, or integrity of the service and its users — noting that we still cannot decrypt your file contents.
7. Retention
- Account and vault data — kept while your account is active so the service can work.
- After account closure or deletion — encrypted files and account records are removed according to our operational practices; residual backups or logs may persist for a limited time for security and recovery of the infrastructure.
- Security and rate-limit logs — kept only as long as reasonably needed for abuse prevention and troubleshooting.
8. Security
We use encryption in transit (HTTPS), client-side encryption for vault contents, and server-side measures appropriate to a small personal-vault service (access controls, hashed login verifiers, and similar). No method of transmission or storage is perfectly secure. You are responsible for protecting your password, backup key, and the devices/browsers you use to unlock your vault.
9. International users
We may host the service in a different country from where you live. If you use File Vault, we may process your account and technical data where our hosting is located. Client-encrypted file contents remain ciphertext wherever they are stored.
10. Children
File Vault is not directed at children under the age of digital consent in their jurisdiction (for example under 13 in the United States, or 16 in some other places). We do not knowingly create accounts for children below that age. If you believe a child has provided personal information, please contact us so we can remove the account.
11. Your choices and rights
- Access and correction — you can view and update account details available in the app (for example changing your password via Account).
- Deletion — you may delete files you no longer want. To close your account and request deletion of remaining account data, contact us (see below).
- Export / portability — you can download your files while your vault is unlocked. We cannot provide a plaintext export of encrypted vault contents from our servers.
- Marketing — we do not run advertising based on vault contents. If we ever send optional product email beyond essential service notices, you will be able to opt out where required.
If the GDPR or similar laws apply to you, you may also have the rights described in section 14 below.
12. Changes to this policy
We may update this privacy policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be posted on this page. Continued use after changes means you accept the updated policy, except where local law requires a different process.
13. Contact
Questions about privacy or this policy? Contact us using the email or contact details we publish for File Vault.
This page is our privacy notice for the service — not personalized legal advice. If you need advice for your situation, please consult a qualified professional.
14. Information under GDPR Article 13
Where the EU General Data Protection Regulation (GDPR) applies, the following summarizes the information we must provide when personal data are collected from you (Article 13). It does not replace the rest of this policy.
- Controller — We (the people who run File Vault) are the data controller for the account and technical personal data described here. You can reach us using the contact details we publish for File Vault.
- Data Protection Officer — We have not appointed a DPO unless we tell you otherwise. For privacy requests, contact us as above.
- Categories of data — Account data (email, plan, quota), authentication material (not your password in plaintext), encrypted vault ciphertext and related operational facts (sizes, timestamps), session/cookie identifiers, and limited technical logs (such as IP address and user-agent) as described above. Readable file contents and client-encrypted metadata are not available to us.
- Purposes — Providing the vault service; authentication and security; enforcing quotas and terms; service communications; abuse prevention; and legal compliance.
- Legal bases (Art. 6 GDPR) — Contract (Art. 6(1)(b)) for account creation, login, storage, and unlock features you request; Legitimate interests (Art. 6(1)(f)) for securing the service, preventing abuse, basic logging, and remembering that you saw the cookie/privacy notice, balanced against your rights; Legal obligation (Art. 6(1)(c)) where we must retain or disclose data under applicable law. We do not rely on consent for the strictly necessary cookies described above.
- Recipients — Hosting and infrastructure providers acting as processors; payment providers if you purchase Pro; and authorities where legally required. See section 6.
- International transfers — Data may be processed where the service is hosted. Where required, we rely on appropriate safeguards (for example standard contractual clauses) or an adequacy decision for transfers outside the EEA/UK.
- Retention — Account and vault data while the account is active; logs for a limited operational period; session cookies until logout/expiry; on-device vault key until the tab closes. See section 7 and the cookie table.
- Your rights — Where GDPR applies, you may have the right to access, rectify, erase, restrict, or object to certain processing, and the right to data portability for data you provided that we process by automated means on the basis of contract (account data we can identify — not ciphertext we cannot decrypt). You may lodge a complaint with a supervisory authority in your EU/EEA member state or place of work/residence.
- Requirement to provide data — Email and authentication material are required to create and use an account. Without them we cannot provide the service. Optional preferences (display settings) are not required.
- Automated decision-making — We do not use profiling or automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 GDPR.
- Source of data — Data are collected from you (and your device/browser) when you visit the site, create an account, log in, unlock your vault, or upload/manage files.