Privacy Policy

Last updated: August 2026

What Vault is

Vault is a self-hosted, client-encrypted password manager. This policy explains exactly what data is collected, how it is used, and — just as importantly — what is never collected.

Data we collect

  • Email address — used solely to create and authenticate your account (sign-in, password reset). We do not use it for marketing and do not share it with third parties.
  • Encrypted vault items — every password, username, and note you save is encrypted (AES-256-GCM) on your device before it is ever sent to our servers. We store only the resulting ciphertext — we cannot read, and do not have access to, the contents of your vault.
  • A non-secret salt — a random value used to derive your encryption key from your master password. The salt is not sensitive on its own and cannot be used to recover your master password or your data.

What we never see or store

  • Your master password — it never leaves your device.
  • The plaintext contents of any saved password, username, URL, or note.

Where data is stored

Application data is stored with Supabase, our database and authentication provider. We do not use any advertising, analytics, or tracking services, and we do not sell or share your data with third parties.

Master password resets

Because your vault is encrypted with a key derived from your master password, resetting a forgotten master password makes any previously saved vault items permanently unreadable — they are deleted as part of the reset so the vault remains usable going forward. This is a limitation of client-side encryption, not a data-retention choice: we have no way to recover data encrypted under a password you no longer have.

Deleting your data

You can delete individual vault items at any time from within the app. To delete your account and all associated data entirely, contact us at the address below.

Changes to this policy

If this policy changes, the “Last updated” date above will change accordingly.

Contact

Questions about this policy or your data can be sent to yasin.adnan@mynexsystems.com.

← Back to Vault