Dotvault
Features Pricing Blog
Download Open Web App
Legal

Privacy Policy

Last updated: July 20, 2026

1. Our commitment to privacy

At Dotvault, we believe your secrets are yours alone. Our core philosophy is built on the principle of zero-knowledge: we design our systems so that it is mathematically impossible for us to access, read, or leak the contents of your vault. This policy explains what we actually collect — which is deliberately as little as possible — and how it's used.

2. How the zero-knowledge architecture works

Dotvault does not use a central password database. Instead, it employs the following security model:

  • Client-side encryption: All encryption and decryption happen exclusively on your device. Your data is encrypted using AES-256-GCM before it ever touches a storage medium.
  • Master password security: Your master password is used to derive an encryption key via Argon2id. This password never leaves your machine and is never transmitted to our servers.
  • No backdoors: We do not have a "recovery key" or "master override." If you lose your master password, your data is permanently inaccessible. This is a deliberate design choice to ensure total privacy.

3. Information we collect

What we collect depends entirely on which parts of Dotvault you use:

  • Desktop app (free, local-only): Collects nothing. Your vault database lives entirely on your filesystem and never touches our servers.
  • Web account (Pro): To create an account we store your email address and an authentication hash — never your master password or your plaintext vault key.
  • Synced vault data (Pro): We store an encrypted blob. We do not store the master password, the encryption key, or any plaintext version of your secrets. To us, your synced data is an opaque, undecipherable string of bytes.
  • Billing information (Pro): Payment details are collected and processed directly by Stripe. We receive only what's needed to manage your subscription — your email, subscription status, and a Stripe customer reference. We never see or store your card number.
  • Website analytics: When you visit dotvault.app, Google Analytics (GA4) collects standard usage data — pages viewed, approximate location derived from IP address, device and browser type, and referral source. This is aggregated traffic data, not tied to your Dotvault account. See our Cookie Policy for the specific cookies involved and how to opt out.

4. How we use information

We use the limited data described above only to:

  • Operate and maintain the web app and encrypted sync service.
  • Process payments and manage Pro subscriptions.
  • Send essential account and billing emails (we don't send marketing email today; if that changes, it will be opt-in).
  • Understand aggregate site traffic so we can improve the product.

We do not sell your data, and we do not use it to build advertising profiles.

5. Data retention

Your local vault exists only on your device and is retained for as long as you keep it there — we have no visibility into it. For Pro accounts, we retain your encrypted synced blob and account details for as long as your account is active. If you delete your account, we delete your account record and encrypted data within 30 days, except where we're required to retain billing records for tax or accounting purposes (typically up to 7 years, held by Stripe under their own retention policy).

6. Third-party services

We use a limited number of third-party services to operate the platform, each receiving only what they need to do their job:

  • Vercel: Hosts the web application and marketing site.
  • Stripe: Processes payments for Pro subscriptions. Stripe receives billing information directly — see Stripe's privacy policy.
  • Google Analytics: Provides aggregate website traffic analytics. See Google's privacy policy.

7. International data transfers

Our service providers (Vercel, Stripe, Google) may process data on servers located outside your country of residence, including in the United States. Where this involves transferring personal data out of the UK or EEA, we rely on those providers' standard contractual clauses and other legally recognised safeguards.

8. Your rights

Depending on your jurisdiction (e.g., GDPR in the UK/EU, CCPA in California), you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Since we store virtually no personal data beyond an email address and billing reference, most of these rights are exercised simply by deleting your local vault (desktop) or contacting us to close your account and erase your synced data (Pro). We do not sell personal data, so there is nothing to opt out of under CCPA's "right to opt out of sale."

9. Children's privacy

Dotvault is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.

10. Changes to this policy

We may update this policy as the product changes. Material changes will be reflected by updating the "Last updated" date above; if a change meaningfully affects how we handle your data, we'll make a reasonable effort to notify Pro account holders by email.

Questions about this policy or your data? Email us at hello@dotvault.app.

Dotvault

The developer workspace for API keys, environment variables, SSH keys, tokens, logins and .env files.

Product

  • Features
  • Pricing
  • Blog

Get Started

  • Download
  • Open Web App

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
© 2026 Dotvault
Terms Privacy Cookies
AES-256-GCM · Argon2id · Local-first