Privacy

Privacy and demo terms

Short and plain: what Secure Vault keeps, what it can never see, and why real secrets belong on your own server.

The public demo is for trying things out

The public demo runs the same code as a self-hosted Secure Vault. Anyone can create an account, so treat everything you put in it as temporary. Accounts and data may be deleted at any time without notice, for example when the demo is reset.

Never store real credentials, customer data or anything confidential in the demo. For real use, run Secure Vault on your own server.

What is stored

  • Your name, email address and an Argon2id hash of your login password (or your Google account id if you sign in with Google).
  • Workspaces, projects, memberships, roles, invitations and notifications.
  • Normal documents in readable form, because the server needs to show them to everyone with access.
  • Secure documents only as ciphertext, together with your public key, your private key encrypted by your vault password, and project keys sealed to each member. The server can't decrypt any of it.
  • An audit log with the IP address and browser of each recorded action, and active sessions.

What is never stored

  • Your vault password, your recovery key, your private key or any project key in readable form.
  • The contents of secure documents.
  • Analytics, advertising or tracking data. The site loads no third-party scripts, fonts or trackers.

Cookies

Secure Vault uses a session cookie to keep you signed in and a cookie that protects forms against cross-site request forgery. Both are first-party and strictly necessary. Your theme and auto-lock preferences are kept in your browser's local storage.

Email

The app sends email only for your account and your team: verification, password resets, invitations and security alerts. There is no newsletter.

Self-hosted instances

When you self-host Secure Vault, you are the operator: your server holds your data, and your own policies apply. Nothing is sent to the authors of Secure Vault.

Questions

Open an issue on GitHub. Please don't post personal data there.