VaultKeep home

Privacy Policy

Last updated 24 September 2026

Overview

VaultKeep is a zero-knowledge password manager operated for the VaultKeep service at vaultkeep.name.ng. This policy explains what information we process when you use the website, browser extension, and mobile apps.

Encryption happens on your device. Your master password and vault decryption keys never leave your device. The server stores ciphertext and account metadata it needs to run the service. It cannot read your vault contents.

What we can see, and what we cannot

  • We cannot see: your master password, recovery kit words, passkey secrets, vault keys, or the plaintext of logins, authenticator secrets, notes, or other vault items.
  • We can see: your email address, optional display name, encrypted blobs you sync, and technical account records needed for sign-in, sync, organizations, and support emails.

Information we process

Account

  • Email address (required to create and recover an account)
  • Optional full name
  • Authentication proofs derived on your device (for example an auth hash of your master password). We store a one-way hash of that proof. We never receive your master password.
  • Key-derivation parameters and salts needed so your clients can unlock the vault
  • Encrypted wraps of your vault key (under your master password, recovery kit, and passkeys)
  • Passkey credential identifiers and related encrypted wraps, when you register a passkey
  • Session access tokens for signed-in clients

Vault and sync

  • Encrypted vault items (ciphertext and initialization vectors). Item types may include logins, authenticator entries, and related data. Contents are encrypted before upload.
  • Organization membership, encrypted organization and folder key wraps, and invites you send or receive, when you use family or business features.
  • Device login records when you approve a website or extension sign-in from a trusted phone (device labels, request metadata, and sealed keys for that session).

Browser extension

  • The extension runs autofill and capture on websites you visit after you unlock. Matching and filling happen locally in the browser when the vault is unlocked.
  • Account sign-in and vault sync use the same VaultKeep API as the website. Encrypted vault data and account credentials are sent to our servers over HTTPS.
  • We do not sell browsing history or inject advertising into pages.

Email

We send transactional email related to your account, such as welcome messages, password reset notices, recovery verification codes, and organization invites. We use an email delivery provider to send those messages.

SpamGuard (optional product)

If you use SpamGuard, we process the phone numbers and related block-list data you sync with that product, tied to your VaultKeep account, so the list can update across devices.

Technical logs

Our hosts may automatically process standard server logs (for example IP address, timestamps, and request paths) to operate, secure, and debug the service. We do not use those logs to read vault contents.

How we use information

  • Provide sign-in, sync, recovery, passkeys, and organization features
  • Deliver transactional email you request or that security events require
  • Maintain security, prevent abuse, and keep the service reliable
  • Respond to support requests you send us

We do not sell your personal information. We do not use vault contents for advertising.

Sharing

We share information only as needed to run VaultKeep:

  • Infrastructure and database providers that host the API and encrypted data
  • Email delivery providers that send transactional messages
  • Organization members you explicitly invite, for shared vault material they are allowed to decrypt
  • Authorities when required by law, or to protect users and the service against abuse

Service providers process data on our instructions. They do not receive your master password or vault keys.

Retention

We keep account and encrypted vault data while your account exists. If you ask us to delete your account, we remove account records and associated vault ciphertext from our primary systems, subject to short backup retention windows and any legal hold we cannot avoid. Access tokens end when you sign out or they expire.

Your choices

  • You can update account details and vault data from the apps.
  • You can remove passkeys, leave organizations, and sign out of sessions.
  • You can export personal vault data from Settings where that feature is available, then delete items or stop using the service.
  • To request account deletion or a privacy question, email rnwonder@gmail.com.

Security

Clients encrypt vault data with AES-256-GCM before upload. Authentication uses proofs derived on device. Transport uses HTTPS. No security practice is perfect. Protect your master password and recovery kit. Anyone with those can unlock your vault on a client.

Children

VaultKeep is not directed at children under 16. Do not create an account for a child under that age.

International processing

We may process and store information on servers in regions where our providers operate. If you use VaultKeep from another country, your information may be transferred to those regions under this policy.

Changes

We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.

Contact

Privacy questions: rnwonder@gmail.com
Website: https://www.vaultkeep.name.ng