Privacy Policy
Last updated 5 August 2026
The short version: Vaultly collects nothing. There is no account, no server and no analytics SDK. Your photos, your videos and your passcode never leave your device, so there is nothing for us to see, sell, lose or hand over.
1. What we collect
Nothing. Vaultly does not collect, transmit, store or process any personal data on our systems, because Vaultly has no systems. The app ships without networking code.
Specifically, we do not collect:
- Your photos, videos or any file you add to the vault
- Your passcode, passphrase or biometric data
- Your name, email address, phone number or any account identifier
- Your location, contacts, calendar or health data
- Device identifiers, advertising identifiers or usage analytics
- Crash reports containing your content
2. No ads and no tracking
Vaultly contains no advertising SDKs and no tracking SDKs of any kind. We do not use the App Tracking Transparency framework because there is nothing to track. Your activity in Vaultly is never linked to you or to any other app, service or data broker.
We will not add advertising to Vaultly. An ad SDK would undermine the only promise this app makes.
3. Where your data lives
Every photo and video you add is encrypted with AES-256-GCM and written to your device's private app storage. The encryption key is a random 256-bit key held in the iOS keychain, protected by your passcode and, if you enable it, Face ID or Touch ID.
Your passcode is never stored anywhere. It is used to derive a key that unwraps the encryption key, using PBKDF2-HMAC-SHA256. This means:
- We cannot read your photos
- We cannot reset your passcode
- If you forget your passcode, your content cannot be recovered by anyone, including us
That is not a limitation we plan to remove. It is the property that makes the encryption meaningful.
4. Permissions the app requests
| Permission | Why | Leaves device? |
|---|---|---|
| Photo Library | To import the photos and videos you select into the vault, and to save items back out if you choose to export them. | No |
| Camera | Only if you enable break-in alerts. Used to capture a photo after repeated wrong passcode entries. The image is encrypted and stored on your device. | No |
| Face ID / Touch ID | To unlock the vault without typing your passcode. Biometric data is handled entirely by iOS in the Secure Enclave and is never exposed to the app. | No |
Every permission is optional. Declining any of them leaves the rest of the app fully functional.
5. Backups you create
If you export an encrypted backup, that file is created on your device and encrypted with a passphrase you choose. Where it goes next is entirely your decision — Files, iCloud Drive, a computer, or another device. We never receive it and have no way to decrypt it.
If you save a backup to iCloud Drive, Apple's terms and privacy policy apply to that storage. The file remains encrypted with your passphrase.
6. Purchases
Vaultly Pro is sold through Apple's In-App Purchase system. Apple processes the payment and we never see your payment details. The app checks your subscription status directly with the App Store on your device. We do not operate a receipt validation server.
7. Children
Vaultly is not directed at children under 13 and collects no data from anyone, including children.
8. Your rights
Regulations such as the GDPR and CCPA grant rights to access, correct, export and delete personal data held about you. We hold no personal data about you, so there is nothing for us to produce or erase. You can delete everything Vaultly holds at any time by using Erase vault and reset in the app, or by deleting the app.
9. Changes to this policy
If this policy ever changes, the updated version will be posted here with a new date. If Vaultly were ever to begin collecting data — which is not planned — we would say so plainly and before it happened, not in a quiet edit to this page.
10. Contact
Questions about this policy: support@photovaultly.com