Privacy Policy

Last updated: February 2026

The short version

  • Your vault data is encrypted at rest (L1) and in transit (TLS).
  • L2 data is encrypted client-side with WebAuthn PRF. We cannot decrypt it. Ever.
  • No analytics. No tracking pixels. No third-party scripts.
  • We don't sell, share, or rent your data. To anyone. For any reason.
  • You can delete your account and all data at any time.

What this policy covers

This privacy policy applies to the hosted Vault1984 service at vault1984.com. If you self-host Vault1984, your data never touches our servers and this policy doesn't apply to you — your privacy is entirely in your own hands.

Data we store

When you use hosted Vault1984, we store:

  • Account information: email address and authentication credentials
  • L1 vault data: encrypted at rest with AES-256-GCM using your vault key
  • L2 vault data: encrypted client-side with WebAuthn PRF before reaching our servers — stored as ciphertext we cannot decrypt
  • Metadata: entry creation and modification timestamps, entry titles (L1)

Data we don't store

  • IP address logs (not stored beyond immediate request processing)
  • Usage analytics or telemetry
  • Browser fingerprints
  • Cookies beyond session authentication

L2 encryption guarantee

Fields marked as L2 are encrypted in your browser using a key derived from your WebAuthn authenticator (Touch ID, Windows Hello, or a hardware security key) via the PRF extension. The encryption key never leaves your device. Our servers store only the resulting ciphertext. We cannot decrypt L2 fields, and no future policy change, acquisition, or legal order can change this — the mathematical reality is that we don't have the key.

Data residency

When you create a hosted vault, you choose a region. All infrastructure is Hostkey TIER III.

  • US East (New York) — data stored in the United States
  • EU West (Amsterdam) — data stored in the European Union
  • EU Central (Frankfurt) — data stored in the European Union
  • EU North (Helsinki) — data stored in the European Union (coming soon)

EU data stays on EU servers. US data stays on US servers. We don't replicate across regions unless you explicitly request it.

Third parties

We use infrastructure providers (cloud hosting, DNS) to run the service. These providers process encrypted data in transit but do not have access to your vault contents. We do not use any analytics services, advertising networks, or data brokers.

Law enforcement

If compelled by valid legal process, we can only provide: your email address, account creation date, and encrypted vault data. L1 data is encrypted with your vault key (which we do not store). L2 data is encrypted client-side. In practice, we have very little useful information to provide.

Account deletion

You can delete your account and all associated data at any time from the web interface. Deletion is immediate and irreversible. Backups containing your data are rotated out within 30 days.

Changes to this policy

We'll notify registered users by email before making material changes to this policy. The current version is always available at this URL.

Contact

Questions about this policy? Email privacy@vault1984.com.