This explains what AEVORIS CLOUD LLP ("we", operating Vault For Us) can and can't see about you, and what we do with it. We try to say this as plainly as the topic allows. See also Security for the technical version.
What we can never see (we call it Tier-1)
Your documents and the passwords you save in Passwords are locked on your own device before upload, with keys created from your master password and passkey: keys we never receive or store. We structurally cannot read this content, hand it over on request, or use it for anything.
What we can see about your account (Tier-2)
To run the service (enforce plan limits, bill correctly, keep backups, and provide support), we hold details about your account that aren't themselves the content of your vault:
- Family and member names as you set them, and member count
- Storage used (byte counts) and item counts (documents, saved logins), never the content
- Document titles, categories and dates — they power search and reminders; the contents stay locked
- Plan, billing status, and billing email (see below)
- If you pay in rupees, the Indian state you choose at checkout. GST law needs it on your tax invoice to decide which tax applies. We never ask for your street address
- Per-member personal email addresses, if a member chooses to add one for reminder and notification emails (see below)
- Per-member mobile numbers, only for members who choose to receive notifications on WhatsApp and confirm the number with a code (see below)
- Push notification subscriptions for devices where a member turns notifications on
- Device and passkey metadata needed for authentication (not passkey private keys, which never leave your device)
- Timestamps: when things were created, changed, or accessed
- The IP address your requests come from, recorded with sign-ins in our audit log and used for rate limiting. We do not look up a location from it automatically: there is no geolocation database in Vault For Us and your address is never sent to a lookup service. Your country is the one you told us at signup, and your currency follows from that. Where there is a specific reason to think a declared country was chosen to get a cheaper price, a member of our team may read those recorded addresses by hand as part of checking — a person decides, never an automated rule, and travelling or living abroad is not itself a problem. See Terms for what happens if a country needs correcting
- The pass/fail results of the invisible checks that stop bots creating vaults — no puzzles for you, and never the content of anything you typed (the technical names are proof-of-work and device attestation)
- An audit log of account-level actions (e.g. "a member added a device"), never vault contents
- Support requests you send us (the name, contact email, and message you type into the contact or support form)
- Anything you upload to our public marketing site (images, videos, captions) if you are an operator with website access. This is deliberately not encrypted — it is material meant for the public internet — and it is operator content, never family content.
- Bug reports and feature requests you file from inside the app: the title and description you write, which part of VFU it's about, and three technical values — app version, device family (“iPhone”, “Windows”), and window size. The form shows you that exact list before you send it. These are readable by us by design — we can't act on a bug report we can't read — and they are included in your data export.
- A public testimonial, if you choose to offer one from You → Feedback & your stories. Nothing here is automatic: you write it, you pick how you're credited (first name, a description of yourself, or anonymous), and you tick which of three places we may use it — our website, our own social accounts, our ads. None are pre-selected. We record exactly what you ticked, against the exact version of the wording you were shown and the time you agreed. You can withdraw it at any time from one button; it comes off our website within a minute and we stop using it in any new post or ad, though copies already published on a social platform or in an advert that already ran may continue to exist. We publish what you wrote word for word or not at all. If you record a video story, that video is deliberately not end-to-end encrypted — a person here has to be able to watch it to review it, and its purpose is to be shown to strangers. Approved stories add a small amount of credit to your family wallet, and the page they appear on says so.
- A log of the service emails we've sent you (recipient, type, and time, not vault content)
A small support team can view these account details (Tier-2) when you ask for help, through an internal console where every access is scoped to your family, individually approved, and recorded in a tamper-evident audit chain. Support staff can never view Tier-1 content: the encryption makes that impossible, not just against policy.
We never claim "zero knowledge" in an absolute sense: this metadata is real, and this section says exactly what it is. The honesty is the point: what we can't see (Tier-1) is unreadable by design, and what we can see (Tier-2) is listed above in full.
Billing email
A billing email is required at signup. We use it for a fixed, narrow set of notices: payment receipts, renewal and trial-ending reminders, failed-payment and account-deletion warnings, account-security alerts (a new, approved, or rescued device, or a Recovery Kit being used), notices about changes to our terms or this policy, and occasional replies from our support team. It is never used for account sign-in, password reset, or any authentication purpose, and never for marketing. Vault For Us has no email-based login of any kind; a lost password is recovered only via your Recovery Kit, never by email.
Member emails and notifications
Separately from the billing email, each member can optionally add a personal email address in their profile settings. It is used only to deliver the reminders that member subscribes to, notifications when they are tagged on something (a document, note, task, event, or similar), and a one-off test email the member can send themselves while setting the address up to confirm it works (its body is fixed and carries nothing personal), and it carries the same guarantee: never sign-in, never password reset, never authentication. Notification emails and push messages are deliberately generic; they never contain the encrypted titles or contents of what they refer to. If a member enables push notifications, the push message transits their browser vendor's push service (Apple, Google, or Mozilla) in the form that vendor requires; those payloads likewise never contain vault content. Members can send a document to another member's email; that sending happens at the member's explicit request and only to email addresses already saved on member profiles.
WhatsApp. A member may also choose to receive notifications on WhatsApp. This is off unless they turn it on: they add their own mobile number, confirm it with a code we send to it, and can remove it at any time — at which point the messages stop immediately. That code confirms the number and nothing else. It is never a way to sign in, never a way to recover an account, and the number is never read by any sign-in or recovery process.
Because WhatsApp delivers these messages, Meta Platforms receives the mobile number, the pre-approved message template used, the words filled into it, and delivery and read timestamps. It receives none of your family's encrypted content. As with email and push, the messages are deliberately generic: they say something happened and to open the app, never what the thing contains. Members choose which apps and which kinds of notification may use each channel, and can set quiet hours during which nothing is sent on any channel — anything that arises waits and is delivered when the window ends rather than being dropped.
Children
Vault For Us is a family product, and members can include children. A family vault can only be created by an adult (18 or older), and that account holder, as the child's parent or guardian, is the one who adds a child member and consents to the small amount of personal data we hold about them: at minimum a display name, and optionally a personal email for reminders, added by the parent. A child's profile has no login and no passkey: children never sign in. Everything else about a child (documents, health records, milestones, dates of birth) lives in Tier-1 encrypted content we cannot read. We never knowingly let a child create an account, never communicate with child members directly except notifications their parent configured, and never use any member's data for advertising, profiling, or tracking: there is no behavioural processing for a child to be protected from here.
Cookies
Every cookie we set is either strictly necessary for signing in and using Vault For Us(session, passkey-challenge, and unlock tokens) or a plain functional preference (your theme and appearance choices), never analytics, never advertising, never a third party of any kind. The complete list you can encounter as a family user:
- vfu_theme — your light/dark theme choice — functional preference
- vfu_appearance — your theme pack, accent, and background choices, mirrored so the page paints correctly on first load — functional preference
- vfu_access / vfu_refresh — keeping you signed in — essential, first-party
- vfu_challenge / vfu_recover_challenge — one-time passkey sign-in and account-recovery challenges — essential, first-party
- vfu_signup_reservation — keeps the Recovery Kit you wrote during setup valid if setup takes a while; it expires with your setup link and is removed when setup finishes — essential, first-party
- vfu_dek / vfu_vault — short-lived vault-unlock tokens — essential, first-party
None of these is used for tracking, none carries an advertising identifier, and there are no third-party cookies anywhere on the site or app. On that basis, we believe none of them requires consent under GDPR/ePrivacy, the UK PECR, or India's DPDP Act, which is why no cookie consent banner is shown: we'd rather explain that reasoning plainly than force a banner on you for effect.
Who processes your data (subprocessors)
Processors acting on our instructions. These providers handle data only to run the service for us, never for their own purposes:
- Cloudflare R2: encrypted blob storage for families without a connected Google Drive
- Google (Drive API): encrypted blob storage, only for families who connect their own Google Drive
- Oracle Cloud Infrastructure (Oracle Corporation): hosting of the application servers and the database
- Google Workspace (Google LLC): delivery of the billing, security, reminder, and notification emails described in the Privacy Policy
- Apple, Google, and Mozilla push services: delivery of push notifications to devices where a member enables them
- Meta Platforms (WhatsApp Business Platform): delivery of WhatsApp notifications, only for members who add and confirm a mobile number. Meta receives that number, the template used and its variables, and delivery/read timestamps — never any content from your vault
Independent controllers. Our payment providers are not processors: they are independent controllers of the payment data you give them, handled under their own privacy policies as payment regulation requires:
- Razorpay: payment processing for India-region checkout
- Paddle: merchant of record for international checkout
Payment details are only ever entered into those providers' own checkout forms, which open on our separate payment page and send what you type straight to the provider, never through Vault For Us: a payment method is linked there at signup, before your account opens, and for recurring terms the first charge happens only when the 7-day trial ends. We never see or store card details; what we receive back is the payment status and reference we need to run your subscription.
None of these providers can read your Tier-1 vault content: encryption happens before it reaches any of them.
If there is a breach
If a security incident affects your personal data, we will notify the affected families without undue delay, and in any case within 72 hours of becoming aware of it, saying what happened, what data was involved, and what we are doing about it. We will also notify regulators where the law requires it: in India, CERT-In within 6 hours of becoming aware of it, where Indian law requires it, and the Data Protection Board of India once the DPDP Act's breach-notice provisions are in force; where the EU or UK GDPR applies, the relevant supervisory authority within 72 hours. Because Tier-1 content is end-to-end encrypted with keys we never hold, a server compromise would not expose your documents or saved passwords in readable form.
Your rights where you live
Find your country below — the rights are the same in spirit everywhere, only the law's name differs. If your country isn't listed, the tools and contact channels at the end of this page still apply to you.
Your rights in India (IT Act, 2000 and DPDP Act, 2023)
The data-protection law in force in India today is section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Under them you can review and correct the information you gave us, and raise a grievance with our Grievance Officer.
India's Digital Personal Data Protection Act, 2023 adds, once its rights provisions are in force (currently scheduled for 13 May 2027), the right as a data principal to access, correct, and request erasure of your personal data, to raise a grievance if you believe we've mishandled it, and to nominate another person to exercise these rights on your behalf if you die or are incapacitated. We honour all of these now, without waiting for that date. To exercise any of them, or to register a nomination, see the Grievance Officer page. We acknowledge grievances within 24 hours and resolve them within 15 days. Separately, Vault For Us's Legacy Handbook lets you write down the contacts and instructions the people you trust would need. It is a place to record that information, not a mechanism that grants anyone access to your account — because your data is end-to-end encrypted, no one can be given access to it without a device you have enrolled or your Recovery Kit. Once the Act's complaint provisions are in force, you may escalate a grievance our response did not resolve to the Data Protection Board of India.
Your rights outside India (GDPR)
For users outside India, AEVORIS CLOUD LLP acts as the data controller for Tier-2 metadata described above. You have the right to access, rectify, erase, restrict, or port your personal data, and to object to its processing, under the EU/UK GDPR. Contact us to exercise any of these rights.
Our legal bases under the GDPR are: performance of a contract (providing the service you signed up for), legitimate interests (keeping the service secure and preventing abuse — the rate limiting, audit logging, and signup checks described above), and consent where we ask for it (for example, a public testimonial). Our application servers and database run on infrastructure we control, hosted by Oracle Cloud in India, and encrypted files are kept with the storage providers listed above. EU and UK personal data is therefore processed in India, outside the EU and UK; where it is, we rely on appropriate safeguards such as standard contractual clauses. You also have the right to lodge a complaint with your supervisory authority.
California and other US residents (CCPA/CPRA and state privacy laws)
We currently operate below the thresholds that trigger CCPA/CPRA obligations, and honor the underlying rights anyway rather than waiting for a threshold: you can access, correct, or delete your data, and you can request an export, using the tools below. We do not sell or share personal information and run no advertising or tracking technology, so there is nothing to opt out of: no "Do Not Sell or Share My Personal Information" link is needed because the practice it targets doesn't happen here. If you're a resident of a state with its own comprehensive privacy law (Virginia, Colorado, Connecticut, and others), the same rights and the same answer apply.
On the CCPA's "categories disclosed" disclosure specifically: in the preceding twelve months we disclosed no category of personal information to any third party for monetary or other valuable consideration, and we disclosed no category for cross-context behavioural advertising. The only third parties that ever receive anything are those listed above: the processors (hosting, email delivery, push, and WhatsApp delivery for members who enable it) receive it to run the service on our instructions, not for their own purposes, and the payment providers (Razorpay, Paddle) receive the payment data you give them in their checkout forms as independent controllers under their own policies.
United Kingdom (UK GDPR)
The same rights and obligations described above under GDPR apply if you're in the UK, under the UK GDPR and Data Protection Act 2018, including the right to access, rectify, erase, restrict, or port your data, and to object to its processing. The UK's Privacy and Electronic Communications Regulations (PECR) govern cookies here too. See "Cookies" above for why no consent banner is shown.
Australia (Privacy Act 1988)
We handle health information, so Australia's small-business exemption doesn't apply to us regardless of size. Under the Australian Privacy Principles you have the right to know what we hold and why, to access and correct it, and to be told if a data breach is likely to cause you serious harm (the Notifiable Data Breaches scheme). Because Tier-1 content is end-to-end encrypted, a server compromise would not expose your documents or saved passwords in readable form. See Security for how that works.
United Arab Emirates (PDPL)
If you're in the UAE, the Federal Personal Data Protection Law (Decree-Law 45/2021) gives you the right to access, correct, erase, and port your data, to object to its processing, and to be notified of a breach affecting you. The same tools and contact channel below apply.
Canada (PIPEDA and provincial law)
Canadian residents have rights of access and correction under the federal Personal Information Protection and Electronic Documents Act, and, for Quebec residents, under Law 25, including a privacy-impact assessment for any cross-border transfer of your data. Contact us using the channels below to exercise any of these rights, in English or French.
Brazil (LGPD)
Under Brazil's Lei Geral de Proteção de Dados, you have the right to confirmation, access, correction, anonymization, portability, and deletion of your personal data, and to information about who we share it with (see "subprocessors" above). Contact us using the channels below, in English or Portuguese.
Exercising any of these rights
For account details (everything this page describes we can see), a primary member can self-serve an export any time from You → Backup & export: no waiting, no email round-trip. Correction is just editing the relevant field in the app. For erasure, You → Billing → "Close account" starts a 7-day reversible window before your content and account details are permanently deleted. For anything these self-service tools don't cover, including a request made under a specific law above, contact us using the details below or see the Grievance Officer page; we acknowledge within 24 hours and aim to resolve within 15 days, whichever law applies. See also Accessibility if the barrier you're reporting is about using the site or app itself rather than your data.
Data retention and erasure
Cancelling a plan, or simply having a payment fail, is not destructive by itself: reading and exporting what you've stored always keeps working, including while an account is read-only for unresolved billing. If a failed payment is never fixed and the account is never closed, we permanently delete the account's data 90 days after it first became read-only for non-payment, with a warning notice sent beforehand; renewing at any point before that cancels the deletion. See Refunds for the full policy.
Closing your account (You → Billing → Close account) deletes your encrypted files and tenant data at the end of the 7-day window described above. A narrow set of billing and audit records is retained afterward, never your Tier-1 content: billing records only as far and as long as tax and accounting law requires, and the audit trail because it is structured so closing one family's account can never silently orphan it. Specifically, that retained set is: billing ledger entries and payment events (kept for eight years, the period Indian tax and accounting law requires), the log of service emails we sent (recipient, type, and time), records of any formal data-subject request you made, and the account-level audit chain. The billing email you signed up with is also kept, unused, for 180 days after closure, because India's IT Rules 2021 require it, and then erased. Nothing else survives closure in our live systems.
One thing we want to be precise about, because “deleted” should mean what it says: our disaster-recovery backups are written to storage that is deliberately immutable for 90 days, so that neither an attacker nor we can destroy or rewrite them. A backup taken before you closed your account therefore still contains your data until that window expires, after which it ages out permanently and is never restored to live systems. Those backups are encrypted, and the copy of your Tier-1 content inside them stays end-to-end encrypted with keys we do not hold — so it is unreadable to us there, exactly as it is everywhere else.
Changes to this policy
We may update this policy as the service changes. Material changes will be reflected here with an updated date.
Contact
Questions or requests about your data: Contact or support@aevoriscloud.com. For a formal grievance, see the Grievance Officer page.