Privacy Policy
Last updated: January 2025
Overview
TrustVault is designed with privacy at its core. We don't require accounts, emails, or any personal information. This policy explains exactly what data we handle and how we protect your privacy.
What we do NOT collect
- Email addresses
- Names or real-world identities
- Phone numbers
- IP addresses (not stored or logged)
- Tracking cookies or advertising pixels
- Your vault keywords (they are hashed client-side)
What we do collect
- Hashed vault identifier — a one-way hash of your 3 keywords, used to locate your vault. We cannot reverse this hash to learn your keywords.
- Files and notes — content you upload or create inside your vault. Stored on our servers (or AWS S3) until you delete it.
- Basic server logs — standard HTTP request metadata retained briefly for operational monitoring. These do not contain vault content or keywords.
How your data is protected
- All connections use HTTPS/TLS encryption in transit.
- Keywords are hashed with SHA-256 on your device before being transmitted.
- Sessions expire automatically after 60 minutes of inactivity.
- Share links have configurable expiry (1h, 6h, 12h, or 24h) and are permanently deleted after expiration.
Third-party services
TrustVault may use the following third-party services:
- Amazon Web Services (S3) — for file storage when S3 mode is enabled. Files are stored in a private bucket.
- Cloudflare — for DNS and DDoS protection. Cloudflare may process connection metadata per their own privacy policy.
Data retention
Your vault data (files and notes) is retained as long as your vault exists. You can delete individual files and notes at any time from within your vault. Shared links are automatically deleted when they expire.
Children's privacy
TrustVault does not knowingly collect data from children under 13. Since we don't collect personal information at all, there is no mechanism to identify any user's age.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
Contact
If you have questions about this privacy policy, please reach out via our contact page.