Last Updated: August 6, 2026
PocketVault is a local password manager. The app does not request Android Internet permission and contains no analytics, advertising, telemetry, or crash-reporting SDK. It does not operate an account system or a remote server.
Your vault is processed on your device. Data leaves the app only when you explicitly use an export or share action and choose a destination.
PocketVault does not collect or transmit personal data. In particular, the developer does not receive:
The app stores its encrypted vault and preferences in its private application storage. It does not include Firebase, Google Analytics, an advertising SDK, or another remote reporting service.
PocketVault does not request Internet or broad storage permission. It uses the following device capabilities:
You can export or share a backup through Android's file picker or share sheet. PocketVault does not choose or contact a destination automatically. If you send a backup to cloud storage, email, messaging, or another app, that recipient's privacy and security practices apply.
A backup contains encrypted vault content and readable configuration metadata. The readable metadata includes the password hint, salt, key-derivation parameters, and an encrypted keyset. Anyone who obtains the backup can read this metadata, although the encrypted vault content still requires the master password. Do not put sensitive information in the password hint, and store backup files securely.
PocketVault uses the following protections:
No software can guarantee absolute security. Device compromise, malicious keyboards or accessibility services, weak master passwords, insecurely stored backups, and undiscovered implementation or dependency vulnerabilities may still expose data. PocketVault has not undergone an independent professional security audit.
You are responsible for protecting exported backups and remembering the applicable master password. PocketVault has no account, recovery service, escrow key, or master-password reset mechanism. Losing the master password can make the encrypted vault permanently inaccessible.
Changing the master password does not rewrite backups you exported earlier. An older backup must be opened with the password that protected it when it was created.
Version 2.5.1 can authenticate and normalize early V2 vaults and backups. For an installed legacy V2 vault, the app verifies the data, creates an automatic encrypted backup, and atomically activates the current format. V1 remains unsupported. PocketVault does not transmit the vault or backup during this local process.
Vault data and automatic backup history remain in the app's private storage until you delete app data or uninstall PocketVault. Exported backups are outside the app's control and must be deleted separately from every location to which you saved or shared them.
PocketVault's source code is available under the Apache License 2.0. Source availability allows independent inspection, but it is not itself a guarantee that the software is free of vulnerabilities. Verify download sources, release hashes, and signing certificates where provided.
This policy may be updated when app behavior or legal requirements change. The revision date above identifies the current version.
For privacy questions, contact:
Email: richonenight@gmail.com