PocketVault Privacy Policy

Last Updated: August 6, 2026

Introduction

PocketVault is a local password manager. The app does not request Android Internet permission and contains no analytics, advertising, telemetry, or crash-reporting SDK. It does not operate an account system or a remote server.

Your vault is processed on your device. Data leaves the app only when you explicitly use an export or share action and choose a destination.

1. Data Collection and Use

PocketVault does not collect or transmit personal data. In particular, the developer does not receive:

The app stores its encrypted vault and preferences in its private application storage. It does not include Firebase, Google Analytics, an advertising SDK, or another remote reporting service.

2. App Permissions

PocketVault does not request Internet or broad storage permission. It uses the following device capabilities:

3. User-Initiated Export and Sharing

You can export or share a backup through Android's file picker or share sheet. PocketVault does not choose or contact a destination automatically. If you send a backup to cloud storage, email, messaging, or another app, that recipient's privacy and security practices apply.

A backup contains encrypted vault content and readable configuration metadata. The readable metadata includes the password hint, salt, key-derivation parameters, and an encrypted keyset. Anyone who obtains the backup can read this metadata, although the encrypted vault content still requires the master password. Do not put sensitive information in the password hint, and store backup files securely.

4. Data Security

PocketVault uses the following protections:

No software can guarantee absolute security. Device compromise, malicious keyboards or accessibility services, weak master passwords, insecurely stored backups, and undiscovered implementation or dependency vulnerabilities may still expose data. PocketVault has not undergone an independent professional security audit.

5. Data Backup and Restoration

You are responsible for protecting exported backups and remembering the applicable master password. PocketVault has no account, recovery service, escrow key, or master-password reset mechanism. Losing the master password can make the encrypted vault permanently inaccessible.

Changing the master password does not rewrite backups you exported earlier. An older backup must be opened with the password that protected it when it was created.

Version 2.5.1 can authenticate and normalize early V2 vaults and backups. For an installed legacy V2 vault, the app verifies the data, creates an automatic encrypted backup, and atomically activates the current format. V1 remains unsupported. PocketVault does not transmit the vault or backup during this local process.

6. Data Retention and Deletion

Vault data and automatic backup history remain in the app's private storage until you delete app data or uninstall PocketVault. Exported backups are outside the app's control and must be deleted separately from every location to which you saved or shared them.

7. Open Source

PocketVault's source code is available under the Apache License 2.0. Source availability allows independent inspection, but it is not itself a guarantee that the software is free of vulnerabilities. Verify download sources, release hashes, and signing certificates where provided.

8. Changes to This Privacy Policy

This policy may be updated when app behavior or legal requirements change. The revision date above identifies the current version.

9. Contact Us

For privacy questions, contact:

Email: richonenight@gmail.com