Legal

Privacy Policy

Last updated: July 2, 2026

In short: Your vault, passwords, cards, notes, 2FA, lives on your device, encrypted with AES-256, and is never sent to us. Optional cloud backup stores an encrypted copy in your own Google Drive, which we cannot read. We do collect a small amount of account data (your Google sign-in email, a random install ID, and your subscription status) to manage subscriptions and app access. No ads, no vault access, no selling your data.

01 Data Controller

RakulAgn is the data controller responsible for OneVault. If you have any questions about this policy or your data, contact rakul0agn@gmail.com.

02 What OneVault Stores on Your Device

Everything you save is stored locally on your device in an encrypted database using AES-256-GCM. This includes:

  • Passwords, usernames, URLs, notes, and category labels
  • Credit card details
  • Secure notes and TOTP (two-factor) secrets
  • Emergency-access contacts
  • Your master password, stored only as a salted hash, never in plain text
  • App settings and preferences

The encryption key is generated on your device the first time you launch the app and is stored in your operating system's secure keystore (Keychain / Keystore).

03 Account & Usage Data We Collect

To manage subscriptions and run the app, we store a small amount of account/usage data on our backend (Supabase). This is never your vault contents, only:

  • A random install identifier generated on your device
  • Your Google account email, only after you sign in for cloud backup
  • Your subscription / paid status and plan
  • App version and platform (Android / iOS)
  • When the app was first seen and last opened

We use this to activate your subscription and free-access period, understand our install base, and support you. There is no traditional sign-up, and this data is never sold or used for advertising.

We still do not collect: advertising identifiers, location, your contacts, device-fingerprinting data, third-party analytics SDKs, or any server-side copy of your vault.

04 Optional Cloud Backup (Google Drive & WebDAV)

Cloud backup is off by default. When you turn it on, OneVault encrypts your vault locally before anything is uploaded, and wraps the encryption key under a key derived from your master password using Argon2id.

The encrypted backup is stored in the private appDataFolder of your own Google Drive, or on any WebDAV server you configure. For Google Drive, OneVault requests only the drive.appdata OAuth scope, which limits it to its own hidden folder, it cannot see or touch the rest of your Drive. We never receive a copy, and without your master password no one, including us, can decrypt the backup.

05 Breach Monitoring (HaveIBeenPwned)

The breach check is optional and runs only when you start it. When you do, your password is hashed with SHA-1 on your device and only the first 5 characters of that hash are sent to the HaveIBeenPwned range API (a technique called k-anonymity). Your actual password never leaves your device.

06 In-App Purchases (Google Play & RevenueCat)

Premium features are sold through Google Play Billing, Google processes all payments, and we never see your payment method, card number, or billing address. We use RevenueCat to manage subscription status, keyed to your Google account email; RevenueCat receives your purchase records and that email, never your vault.

07 Permissions We Request

OneVault asks only for permissions that power a feature you use:

  • Biometric authentication, to unlock your vault with your fingerprint or face
  • Camera, to scan QR codes for two-factor codes and to scan a card when adding one (processed on your device; images are never uploaded)
  • Notifications, for password-expiry reminders
  • Autofill, to fill logins into other apps and the browser
  • Internet, used only for Google Sign-In, Drive and WebDAV backup, HIBP breach checks, and Play Store billing

08 Children's Privacy

OneVault is not directed at children under 13, and we do not knowingly collect any data from them.

09 Your Rights (GDPR, CCPA, and Similar Laws)

You have the right to access, correct, delete, and object to the processing of your data, and to withdraw consent. These rights are simple to exercise:

  • Delete your on-device vault by uninstalling the app
  • Revoke Google Drive access at any time at myaccount.google.com/permissions
  • Request deletion of the account record (section 03) by emailing us

For any request, contact rakul0agn@gmail.com.

10 International Users

The limited account data in section 03 is stored on Supabase, which may process it on servers outside your country. Your vault contents are never transferred, they stay on your device and, if you enable backup, in your own Google Drive.

11 Data Retention

Uninstalling the app wipes the local vault from your device, and you can delete the encrypted backup from your own Google Drive at any time. The account record in section 03 is retained to manage your subscription, email rakul0agn@gmail.com to have it deleted.

12 Third Parties

The limited data described above is shared only with: Google (Sign-In, Drive, Play Billing), Supabase (the account record in section 03), RevenueCat (subscription management), and HaveIBeenPwned (optional breach checks), each only for its specific feature. Your use of those services is also subject to their own terms.

13 Changes to This Policy

We may update this policy from time to time. Material changes will be announced in the Play Store release notes. Continued use of the app after an update constitutes acceptance of the revised policy.

14 Contact

Questions about this policy or your privacy: rakul0agn@gmail.com.

© 2026 RakulAgn. OneVault is an independent project and is not affiliated with Google, Apple, or HaveIBeenPwned.