Privacy Policy
Last updated: January 2026
At PhoneVault, privacy isn't a feature — it's the product. This Privacy Policy explains what we collect, how we use it, and the strong protections we apply by default.
1. Zero-knowledge architecture
Your vault data (passwords, 2FA codes, notes) is encrypted on your device with your master key before syncing. We cannot read it, and we never receive your master key.
2. Information we collect
- Account information — email address and billing details to manage your subscription.
- Encrypted vault data — stored only in encrypted form we cannot decrypt.
- Limited diagnostics — aggregated, non-identifying data to keep the service reliable.
3. VPN no-logs policy
We do not log, monitor, or store your browsing activity, DNS queries, or connection content when using our VPN.
4. How we use information
- To operate and improve the service.
- To process payments and send service notices.
- To provide customer support.
- To protect against fraud and abuse.
5. Data sharing
We do not sell your data. We share only with essential providers (payments, infrastructure) under strict confidentiality, and only as required to operate the service or by law.
6. Security
We use AES-256 encryption, secure infrastructure, and independent audits. While no system is perfectly secure, we apply industry best practices throughout.
7. Your rights
You may access, export, or delete your account data at any time. Contact us to exercise your rights under applicable laws such as GDPR and CCPA.
8. Changes
We may update this policy and will post changes here with a revised date.
9. Contact
Reach us at privacy@phonevault.app or via our contact page.