How The Sealed Vault LLC collects, uses, and protects your information.
When you create an account and use the Service, we collect:
We are committed to data minimisation. The following data is never collected:
We do not sell, rent or trade your personal information to third parties for marketing purposes — ever.
If you are located in the European Economic Area, our legal bases for processing your personal data are:
The Sealed Vault uses the following third-party services to operate:
Authentication, Firestore database, Cloud Storage and Hosting. Firebase stores your account data and encrypted vault data on Google's servers. Firebase is subject to Google's Privacy Policy and Terms of Service.
Used to send email notifications. Email subject lines and recipient addresses are processed through Google's mail infrastructure.
Payment processing for paid subscriptions. Stripe receives your email address and payment details (which we never see or store on our servers) to process subscription payments on our behalf. Stripe may offer Stripe Link, a feature that lets customers save payment details for faster checkout across merchants that use Stripe. If you opt in to Link, your saved payment information is managed by Stripe under Stripe's own Link Terms and Privacy Policy — receipts and payment confirmations may reference "Link" as the payment method even when a credit or debit card was used. Stripe is subject to Stripe's Privacy Policy at stripe.com/privacy.
A separate Data Processing Agreement document is provided which links directly to Google's own DPA. Please refer to the standalone DPA document for full details.
Your encrypted vault data is stored in Google Firebase data centres. Data may be replicated to other regions for redundancy as per Firebase's infrastructure policies.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at contact@sealed-vault.com. We will respond within 30 days. Note that because your vault contents are encrypted and we cannot access them, we cannot provide copies of vault contents — only you can access them with your passphrase.
We do not use advertising cookies or third-party tracking for marketing purposes. You can control cookies through your browser settings, though disabling essential cookies may impair the functionality of the Service.
The Sealed Vault is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take immediate steps to delete that information. If you believe a child under 18 has registered for the Service, please contact us immediately.
The Sealed Vault offers two methods for accessing your account. The authentication method you choose does not affect the zero-knowledge encryption of your vault contents.
When you create an account with email and password authentication, we store:
When you create an account or sign in with Google, we receive from Google:
Google retains records of your sign-in activity with The Sealed Vault in accordance with Google's own privacy policies, which we do not control. Users seeking maximum privacy regarding their account access patterns may prefer email and password authentication.
Your vault contents are encrypted on your device using AES-256-GCM with a key derived from a passphrase that only you know. This passphrase:
Authentication grants access to your account; the passphrase grants access to your vault contents. These are independent. Compromising your authentication credentials would grant access to your account, but not to the encrypted contents of your vaults, which remain protected by your passphrase.
Despite these measures, no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law within 72 hours of discovery.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, and the right to opt-out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at contact@sealed-vault.com.
Your data may be transferred to and stored in countries outside your own, including the United States where Google Firebase's primary servers are located. These countries may have different data protection laws than your country. By using the Service, you consent to this transfer. We take steps to ensure adequate protections are in place through Google's standard contractual clauses and other appropriate safeguards.
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the changes take effect. The updated Policy will be posted on our website with a new effective date. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
For privacy-related enquiries, requests to exercise your rights, or to report a privacy concern, please contact our Privacy Officer:
The Sealed Vault LLC — Privacy Officer
Email: contact@sealed-vault.com
Website: https://sealed-vault.com
Response time: Within 30 days of receipt
If you are located in the EU and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.