Effective date: August 1, 2026
This Privacy Policy explains how First Vault ("we", "us", "our") collects, uses, and protects your information. First Vault is provided by Namrata Pithva, an individual developer trading as Namrix Tech, based in Ahmedabad, Gujarat, India, who acts as the data controller for the purposes of this policy.
This policy applies to users worldwide, including specific rights for users in the European Economic Area (GDPR), California (CCPA/CPRA), and India (Digital Personal Data Protection Act, 2023), described in Section 7 below.
Account information. When you sign up using Google, Sign in with Apple, or email and password, we collect your email address, display name, and — for Google accounts only — a profile photo, if you've set one. Apple does not provide a profile photo by design.
Vault content. Passwords, payment card details, and Wi-Fi credentials you save are stored on your device. If cloud sync is enabled for your account, encrypted vault data is also stored on our backend infrastructure (Supabase) so it can be available across your devices.
We want to be transparent about the current state of this: as of this version, First Vault's cloud sync does not yet use a separate master passphrase known only to you (a "zero-knowledge" architecture). This means that, technically, our infrastructure provider processes your encrypted vault data server-side, and in principle it is not architecturally impossible for the data to be accessed at the infrastructure level. We do not access, view, sell, or use your vault content for any purpose — including advertising or profiling — under any circumstances. A fully zero-knowledge encryption upgrade, where even we could not technically access your data, is planned for a future release.
Breach Watch data. When you use Breach Watch, First Vault checks your saved passwords against a public database of known breaches using a privacy-preserving method (k-anonymity): only a short, partial hash of your password is sent, never the password itself, and never in a form that could be reversed to reveal it.
Backup files. Encrypted backup files you export are created and stored by you, on your own device or wherever you choose to save them — we do not receive or store copies of your backups. Starting with backups created after mid-2026, a backup file includes your account email in plain text solely so the app can warn you if you try to restore a backup created by a different account; this label never leaves your device and is not transmitted to us.
Biometric data. Face ID/Touch ID authentication is handled entirely by your device's operating system. First Vault never receives, transmits, or stores your biometric data — we only receive a yes/no result from the OS indicating whether authentication succeeded.
Subscription and billing data. If you purchase Premium, your subscription status is managed through Apple's App Store or Google Play, using RevenueCat as our subscription-management provider. We receive your subscription/entitlement status only — we never receive or store your card number or other payment details, which are handled entirely by Apple or Google.
Crash and diagnostic data. We use Sentry to detect and diagnose app crashes and errors. This may include device model, OS version, and the technical details of an error. We deliberately do not collect console logs, network request bodies, screenshots, or session recordings, and any field that looks like a password, card number, PIN, or similar secret is automatically redacted before it ever leaves your device. Diagnostic data collection is disabled in development builds and only active in the released App Store/Play Store version.
We use the information above to: provide and maintain the Service, including cross-device sync where enabled; authenticate you and secure your account; detect breached passwords through Breach Watch; process and manage subscriptions; diagnose and fix crashes and bugs; and communicate with you about your account or the Service when necessary.
We do not sell your personal information, and we do not use your data for advertising or third-party profiling.
We share limited information with the following service providers, solely to operate First Vault:
We do not sell, rent, or otherwise disclose your personal information to advertisers or data brokers.
We retain your account and vault data for as long as your account remains active. If you delete your account, we delete your associated account and vault data from our systems within a reasonable period, except where retention is required by law. Backup files exist only on your own device or storage location and are retained (or deleted) entirely at your discretion.
We use industry-standard measures to protect your data, including encrypted storage on your device, encrypted backup files (AES-256 with PBKDF2 key derivation), and encrypted transmission (TLS) between the app and our service providers. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security, but we work to apply appropriate safeguards throughout the app.
First Vault is not directed at children, and we do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
You may access, correct, or request deletion of your personal information at any time by contacting us at the email below. Where in-app self-service isn't yet available for a specific request, we will process it manually upon request.
If you are in the European Economic Area or UK (GDPR): you have the right to access, rectify, erase, or restrict processing of your personal data, the right to data portability, the right to object to processing, and the right to withdraw consent at any time. Our legal basis for processing is primarily the necessity of performing our contract with you (providing the Service) and, where applicable, your consent. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information — though we do not sell or share your personal information as defined under California law, so no opt-out action is needed. We do not discriminate against you for exercising these rights.
If you are in India (Digital Personal Data Protection Act, 2023): you have the right to access a summary of your personal data and its processing, the right to correction and erasure, the right to grievance redressal, and the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Account deletion: at the time of writing, First Vault does not yet offer a fully self-service, in-app "Delete Account" option. To request deletion of your account and associated data, email us at the address below and we will process the request. An in-app deletion option is planned ahead of general release.
Depending on your location and the infrastructure regions used by our service providers (Supabase, Sentry, RevenueCat), your data may be processed in a country other than your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for such transfers.
We may update this Privacy Policy from time to time. We will update the "Effective date" above when changes are made, and we will highlight material changes in-app or by email where practical.
For any privacy questions, requests, or concerns, contact: hello@namrixtech.com