Privacy Policy
The short version. Your documents, passwords, cards and notes are stored on your phone and are never sent to us. We do not have a server that holds your data, we do not have accounts, and we cannot see anything in your vault. The only personal information that ever leaves your device is nothing at all: there is no analytics, no tracking and no advertising in the app.
1. Who we are
Hasp Vault is an offline personal vault app. In this policy, "we" means the developer of Hasp Vault and "you" means the person using the app. Contact details are in section 11.
2. What stays on your device
Everything you put into the vault is stored locally in the app's private storage, which other apps on your phone cannot read:
- Passwords, bank cards, notes and document details — held in a database encrypted with AES-256. The encryption key is generated on your device and kept in the Android Keystore.
- Document files (scans, photos, PDFs) — stored in the app's private storage area.
- Your PIN — never stored. We keep only a salted PBKDF2-SHA256 hash, which cannot be turned back into your PIN.
- Break-in photos, if you switch that feature on — taken by the front camera after three wrong PIN attempts and saved into the same encrypted database. They stay on your phone.
None of the above is transmitted to us or to anyone else. We have no ability to access, recover or reset it.
3. What leaves your device, and when
Advertising — none today
Hasp Vault currently contains no advertising of any kind. There is no advertising SDK in the app, it does not read your device's Advertising ID, and no advertising data leaves your phone — because there is nothing in the app that would send any.
Adverts may be introduced in a future version. If that ever happens, this section will be rewritten to say exactly what is collected and by whom before that version is released, and the app's Play Data Safety declaration will be updated to match. Any advertising would be optional and would never appear beside your documents, cards or passwords. Your vault contents would not be shared with an advertiser under any circumstances.
If you are in the EEA, the UK or Switzerland, you are asked for consent before any ad is requested, using Google's certified consent mechanism. You can change that choice at any time from Settings → Ad privacy choices in the app.
Backups — only when you create one
Exporting a backup produces a single encrypted .avault file,
protected by a passphrase you choose. You decide where it goes. It is never
uploaded anywhere by the app. We cannot open it, and neither can anyone
without your passphrase — so if you forget it, that backup cannot be
recovered.
Phone-to-phone transfer — only when you start one
This feature sends your vault directly to another handset across your own Wi-Fi or hotspot. The data is encrypted before it leaves, the receiving phone is reached by its local network address only, and nothing passes through any server of ours or anyone else's. The transfer window closes after one delivery or three minutes, whichever comes first.
4. What we never collect
- No account, sign-up, email address or phone number.
- No analytics or usage tracking. We do not know how you use the app.
- No crash reporting that includes your content.
- No contacts, no calendar, no precise GPS location.
- No copies of your documents, passwords, cards or notes — ever.
5. Permissions, and why
| Permission | Why the app asks |
|---|---|
| Camera | Scanning documents, and the optional break-in photo. Images are saved to your vault only. |
| Photos / media | Importing pictures and PDFs you already have. Only files you pick are read. |
| Biometrics | Unlocking with your fingerprint or Face ID. It never leaves the phone's secure hardware and is never seen by the app. |
| Notifications | Optional expiry reminders for documents you have given an expiry date. The reminder is scheduled on your phone; nothing is sent from a server. |
| Internet | One thing only: the local socket used for phone-to-phone transfer, over your own Wi-Fi. The app contacts no server of ours, because there isn't one. |
6. Children
Hasp Vault is not directed at children under 13, and we do not knowingly collect information from them.
7. How long your data is kept
For as long as you keep the app installed, and no longer. There is no server-side copy with its own retention period.
Uninstalling the app permanently deletes your vault. There is no cloud backup, no recovery code and no way for us to restore it. If you are changing phones, export a backup first.
8. Your choices
- Delete everything — Settings → Erase vault destroys all content and the encryption keys, returning the app to a fresh state. Uninstalling has the same effect.
- Turn off expiry reminders — remove the expiry date from a document, or switch notifications off for the app in your phone's system settings.
Because your data never reaches us, requests to access, correct or delete it are things only you can carry out, from inside the app.
9. Security
The vault database is encrypted with AES-256 using a key held in the Android Keystore. Your PIN is stored only as a salted PBKDF2-SHA256 hash, and repeated wrong attempts trigger increasing lockout delays. The app hides its contents in the app switcher and blocks screenshots while unlocked, and locks itself after a period of inactivity.
No system is perfect, and a phone that is compromised at the operating-system level cannot be protected by any app. Keep your device updated and your screen lock enabled.
10. Changes to this policy
If this policy changes, the date at the top of this page changes with it, and the current version will always be published here. Material changes affecting how data is handled will also be noted in the app's release notes.
11. Contact
Questions about this policy, or about privacy in the app: alwinpatel3@gmail.com