Privacy
Your vault contents never leave your device. We only hold what is needed to sign you in and to pass an encrypted share between two people for a short time.
What stays on your device
- Every login, note, card, API key, and authenticator code.
- Your master PIN and every key derived from it.
- The trusted contacts you have verified.
What the server holds
- Your email and account status, so we can sign you in.
- One-way hashes of sign-in tokens, never the tokens themselves.
- Your public identity keys, so other people can encrypt a share to you.
- An encrypted share, for at most 24 hours, until the recipient opens it or the link expires. We cannot read it.
- Which version of the terms and of the no-backup notice you accepted, and when. We keep this so that if you ever ask what you agreed to, there is an honest answer.
Backups you make yourself
There is no copy of your vault on our servers, so the app lets you export an encrypted backup file. You choose where it goes, and it never passes through our infrastructure. We never see it, and we cannot open it.
Email we send you
We email you to verify your address, to deliver one-time sign-in codes, and to tell you when your account moves to a different phone. That last one carries a link that ends every session, in case the move was not you. We send no marketing email.
What we never do
- No analytics, attribution, or crash-reporter tools.
- No third-party trackers.
- No selling your data. There is nothing useful to sell.
Delete your data
Use Settings then Wipe vault to destroy local data and release the server-side device binding. To remove your account on the server, email privacy@kaizenstudio.tech.
Questions: hello@kaizenstudio.tech