Private beta · Version 2026-10-01-beta1
Your privacy
in Vault.
Vault has no advertising or marketing analytics. Operating encrypted messaging still requires account, delivery and security information.
Effective October 1, 2026. This notice covers Vault’s private beta, support website and support correspondence.
Who is responsible
The individual developer identified for Vault in Apple’s App Store or TestFlight distribution information accompanying your app is responsible for the processing described here. Vault Support is that developer’s contact name, not a separate company.
Contact privacy@vaultmsg.ch about personal data or support@vaultmsg.ch for app support. You do not need to give Vault your legal name, postal address or identity document to register; a display name may be a nickname.
Accounts & contacts
Vault processes an account identifier, your registration phone number or eligible username, display name, public identity and device keys, device authorization, recovery verifiers, profile and entitlement information. These records support sign-in, account recovery, contact discovery and secure connections; they are not all end-to-end encrypted.
Phone registration uses Google Firebase to send a verification SMS. Google also receives and stores authentication phone numbers for spam and abuse prevention across its services, as explained in its phone authentication information. Your carrier’s messaging charges may apply.
With Contacts permission, Vault reads contact phone numbers into a local cache. It does not bulk-upload your address book. Looking up a particular phone number sends that normalized number to the Firebase directory; username lookup similarly queries a username. Contact requests, public profile information and connection permissions are processed to let people connect. Sharing a profile with a contact is separate from reading your address book.
Messages & notifications
Message and attachment payloads are encrypted before transmission. Local history is stored encrypted. Participating phones and the central relay may hold encrypted delivery payloads for eligible delivery modes. Strict conversations do not use those payload mailboxes.
Relay records also include an owner account identifier, device certificate, public keys, signatures, timestamps, expiry and an opaque message identifier. They do not contain plaintext message contents or chat and group names. Infrastructure and connected peers can process network addresses, connection timing, size and routing information. Encryption of content does not make all technical data anonymous.
Apple Push Notification service and Google Firebase Cloud Messaging process notification tokens and routing information. Vault sends generic alerts with event and routing identifiers, sometimes a sender account identifier; its push payloads do not include message text, attachments or message keys. Notification permission and device settings affect delivery.
Diagnostics & support
Vault does not use advertising identifiers, advertising SDKs or marketing analytics. Technical processing remains: backend logs can contain account, device, request and routing identifiers, a partial token hash, event types, timing and errors. Abuse controls use counters derived from account identifiers or network addresses. These support delivery, troubleshooting and service security.
The app keeps local technical diagnostics, including a rolling diagnostic log and encrypted delivery-event records. These are not automatically attached to bug reports. An optional in-app report sends the text you enter, category, platform and app version. The stored report includes its submission day and handling status, without an account-ID field. Authentication is checked separately and daily salted account counters limit abuse; a report is not anonymous to every network or infrastructure provider.
Email sent to our support or privacy addresses is forwarded through Cloudflare Email Routing to Microsoft Outlook. The sender and recipient addresses, message, headers and attachments are processed to handle your request. Ordinary email is separate from Vault’s encrypted messaging. Avoid sending private messages, passwords, recovery secrets or unnecessary personal details.
Providers & locations
- Google/Firebase: authentication, account and routing records, backend functions and Android push. The configured database is in the European
eur3region; Firebase Authentication and our backend functions run in the United States. See Firebase privacy information. - Cloudflare: the website, DNS, public relay connection and email forwarding. It processes requests and network information through its infrastructure. Website requests include technical information such as network address and browser headers. The site has no advertising or analytics scripts.
- Microsoft: Outlook receives forwarded support and privacy correspondence.
- Apple: iOS push and app distribution. TestFlight automatically shares installation, usage and crash information with the developer and also shares feedback you submit. Email invitations may identify you; joining solely through a public link hides your name and email from the developer. We use this information for beta testing and troubleshooting. See Apple’s TestFlight privacy information.
- Vault’s central relay and participating devices: hold eligible encrypted delivery data and process the metadata needed to deliver it. A configured connectivity relay can also process connection information.
Processing is not confined to Switzerland. Providers may process data in Europe, the United States and other countries where they operate; legal protections can differ. Provider terms and international-transfer arrangements apply to their services. You can contact us for information about the providers and arrangements relevant to your data.
We use information to provide the requested service, protect it, respond to voluntary requests and meet applicable legal obligations. Where applicable law requires a legal basis, these purposes rely on providing the service, legitimate operational and security interests, legal obligations or consent where required. Optional permissions are not blanket consent to unrelated uses. Purchases are disabled for this beta; it does not process payments through the future billing integrations.
Retention & deletion
- Account and profile data: used while the account operates. In-app deletion removes active account and directory records and local account data; authentication and some connection cleanup may finish through backend retries.
- Encrypted central delivery records: expire no later than 30 days after their record timestamp. Expired records cannot be retrieved and are removed by housekeeping. Local history, independent recipient copies and backups have separate lifecycles.
- Notifications: backend wake requests expire after 24 hours, with processed requests eligible for cleanup after 15 minutes; bounded cleanup runs hourly. Apple or Google may hold message and media notification requests for up to 72 hours.
- Optional bug reports: become eligible for deletion around 90 days after submission. Daily abuse counters and salts expire at the start of the second following UTC day.
- Local diagnostics: the rolling log is size-limited to approximately 512 KiB. Ordinary delivery diagnostics are capped at 2,000 entries and 14 days; outstanding operational retry records are separate.
- Acceptance and security records: policy receipts contain account ID, account generation, version, document URLs and acceptance time. These and deletion/security markers are not automatically erased on account deletion and currently have no fixed automatic expiry. Their purposes are to record the applicable agreement, reject obsolete credentials and handle security or legal issues.
Automatic expiry does not guarantee immediate erasure from every backup or provider system. Google states that Firebase Authentication deletion from live and backup systems can take up to 180 days after account deletion is requested. Apple retains TestFlight feedback for one year and may retain crash and usage information until bugs are resolved, as described in the provider information linked above.
For correspondence, technical logs, backups and records without a fixed expiry, retention depends on resolving the request, investigating incidents, preventing replay or abuse, applicable legal needs and provider retention settings. Contact us to request a review or deletion of information no longer needed for those purposes.
Test accounts and beta data may be reset before public launch. A reset or account deletion does not erase copies already received by other people or promise that every retained record disappears simultaneously.
Your choices & rights
You can manage optional device permissions in your phone’s settings and choose whether to send reports or email. Some features require their associated account or connection information to work. This notice does not require an additional personal-information form.
To delete an account, use Settings → Account management → Delete account and all local data, complete both confirmations and keep the app connected until it finishes. Uninstalling alone does not delete backend records. Contact privacy@vaultmsg.ch if you cannot use the app.
Depending on applicable law, you may request access, correction, deletion or a copy of your data, object to or restrict processing, and withdraw consent for optional processing. We may need proportionate proof that a request concerns your account; do not send passwords or recovery secrets. You may also complain to your competent data-protection authority. These rights are not reduced by accepting the beta terms.
Material changes to this notice will receive a new version and be communicated through the app, support site or distribution notes as appropriate. This version remains available at its dated address.