# Steel Vault — Privacy Policy


**Last updated:** October 2026  

**App:** Steel Vault (Android package `com.steelvault.lclabs`)  

**Developer:** LC Labs ("we", "us", "our")  

**Contact / Support:** appstorecontact007@gmail.com  


Steel Vault is a private, hardware-encrypted vault for your files, passwords, notes, and sensitive credentials. This policy explains what data the app handles, what leaves your device, and the choices you have. We built Steel Vault to be **zero-knowledge**: your files, your passphrase, and your encryption keys never leave your device in a form anyone else can read.


---


## 1. Zero-Knowledge Architecture & Local Storage

**Steel Vault** operates under a strict **Zero-Knowledge** security model. All files, passwords, secure notes, photos, and biometric credentials are encrypted directly on your device using hardware-backed **XChaCha20-Poly1305** authenticated encryption with **Argon2id** key derivation. Your unencrypted data, master passphrase, PIN, and cryptographic private keys are never transmitted to our servers, and we have no mathematical or technical ability to decrypt or access your vault contents.


- **Your files stay on your device**, encrypted. We cannot see, decrypt, or recover them.

- **We never receive your PIN, password, passphrase, biometrics, or encryption keys.**

- We do **not** sell your data, show ads, or use third-party advertising/tracking SDKs.

- The only data our servers process is the minimum needed to run optional features (device security/kill-switch, subscription verification, and ephemeral share links) — and even then it is either random identifiers or data that is **already encrypted on your device**.


---


## 2. Information We Do NOT Collect

We believe privacy is a fundamental human right. **Steel Vault does not collect, log, sell, or monetize any personal information.** Specifically:

- We do **not** collect your name, email address, phone number, or physical address.

- We do **not** collect device location data, browsing history, or contact lists.

- We do **not** use third-party tracking cookies, analytics trackers, or advertising SDKs.

- We do **not** inspect, access, or log file contents, filenames, or encryption keys.


---


## 3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication:

- **Google Drive (`drive.file` scope):** Grants the app access only to the specific `.svbak` backup files it creates inside your own Google Drive.

- **Microsoft OneDrive (`Files.ReadWrite.AppFolder`):** Stores encrypted backup archives in your private OneDrive root without accessing your other personal files.

- **End-to-End Encryption:** Only encrypted `.svbak` ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

- **Credential Security:** Cloud authentication tokens are stored exclusively in your device's hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.


---


## 4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

- **Camera:** Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

- **Biometrics (Fingerprint / Face ID):** Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device's Secure Enclave and are never accessible to the app.

- **NFC:** Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

- **Storage / Photo Library:** Used only to import files you choose to store or to save encrypted backup archives.

Denying an optional permission simply disables that specific feature; the rest of the app continues working normally.


---


## 5. Ephemeral Encrypted Share Links (Optional)

If you choose to create a share link, the file is **encrypted on your device first**. Our server stores only:

- the resulting **ciphertext** (which our servers cannot decrypt),

- a public cryptographic salt and an access token derived from your passphrase (which reveal nothing about the passphrase or content),

- basic metadata (file name, type, expiry time, view-once flag).


Share data is **temporary**: it is automatically deleted when the link expires or, for view-once links, immediately after it is opened. You can revoke a link at any time.


---


## 6. Data Retention, Deletion & User Control

You maintain complete ownership and control of your data at all times:

- Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

- Uninstalling the app permanently erases all local encryption keys and stored vault data.

- You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.


---


## 7. Security & Cryptographic Standards

We apply strong, modern cryptography on-device and least-privilege access:

- **AEAD Encryption:** XChaCha20-Poly1305 / AES-256-GCM.

- **Key Derivation:** Argon2id / scrypt with high memory-cost parameters.

- **Post-Quantum Cryptography:** Hybrid ML-KEM (Kyber-768) + X25519 for long-term quantum resistance.

- **Secure Storage:** Hardware-backed Android Keystore and iOS Keychain with BiometricPrompt authorization.


---


## 8. Children's Privacy

Steel Vault is not directed to children under 13 (or the minimum age of digital consent in your country) and we do not knowingly collect personal data from children.


---


## 9. Contact & Support

For questions, privacy inquiries, or data requests, please contact our support team:  

**appstorecontact007@gmail.com**  

LC Labs Vault — Privacy Policy


**Last updated:** 16 June 2026

**App:** Steel Vault (Android package `com.steelvault.lclabs`)

**Developer:** LC Labs ("we", "us", "our")

**Contact:** appstorecontact007@gmail.com


Steel Vault is a private, encrypted vault for your files. This policy explains what

data the app handles, what leaves your device, and the choices you have. We built

Steel Vault to be **zero‑knowledge**: your files, your passphrase, and your

encryption keys never leave your device in a form we can read.


---


## 1. The short version

- **Your files stay on your device**, encrypted. We cannot see, decrypt, or recover them.

- **We never receive your PIN, password, passphrase, biometrics, or encryption keys.**

- We do **not** sell your data, show ads, or use third‑party advertising/tracking SDKs.

- The only data our servers receive is the minimum needed to run optional features

  (device security/kill‑switch, subscription verification, and share links) — and even

  then it is either random identifiers or data that is **already encrypted on your device 

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.come

7. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

8. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

9. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

10. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

11. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

12. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

13. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

14. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

15. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

16. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

17. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

18. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

19. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

2. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

20. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

21. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

22. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

23. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

24. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

25. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

26. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

27. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

28. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

2. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

29. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

30. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

31. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

32. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

33. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

2. Information We Do NOT Collect

We believe privacy is a fundamental right. Steel Vault does not collect, log, sell, or monetize any personal information. Specifically:

We do not collect your name, email address, phone number, or physical address.

We do not collect device location data or contact lists.

We do not use third-party tracking cookies, analytics trackers, or advertising SDKs.

We do not inspect or log file contents, metadata, or encryption keys.

3. Optional Cloud Backups (Google Drive, Microsoft OneDrive, WebDAV, & S3)

If you choose to enable cloud backups, Steel Vault connects directly from your device to your personal cloud storage account using standard OAuth 2.0 PKCE authentication.

Google Drive (drive.file scope): Grants the app access only to the specific .svbak backup files it creates inside your own Google Drive.

End-to-End Encryption: Only encrypted .svbak ciphertext is uploaded. Neither Google, Microsoft, your cloud provider, nor the Steel Vault developers can read the contents of your cloud backup files without your device-held decryption key.

Credential Security: Cloud authentication tokens are stored exclusively in your device’s hardware-backed secure storage (Android Keystore / iOS Keychain) and are never routed through or stored on our servers.

4. Device Permissions & Purpose

Steel Vault requests device permissions strictly to operate user-selected features locally:

Camera: Used solely for capturing photos/videos directly into the encrypted vault, scanning optical cold-storage QR barcodes, or capturing local decoy intruder selfies. Camera data never leaves your device unencrypted.

Biometrics (Fingerprint / Face ID): Used solely to trigger the operating system's local secure authentication prompt. Raw biometric templates remain locked inside your device’s Secure Enclave and are never accessible to the app.

NFC: Used optionally to read physical NFC security tags as a hardware second-factor unlock key.

Storage / Photo Library: Used only to import files you choose to store or to save encrypted backup archives.

5. Data Retention & User Control

You maintain complete ownership and control of your data at all times:

Deleting an item inside Steel Vault permanently overwrites and removes it from local memory.

Uninstalling the app permanently erases all local encryption keys and stored vault data.

You may disconnect cloud sync or delete remote backups at any time directly through the app or your cloud provider's account dashboard.

6. Support & Contact

For questions, privacy inquiries, or technical support, contact our team at:

appstorecontact007@gmail.com

---


## 2. Data stored on your device (never sent to us)

The following stay **only** on your device and, where supported, are protected by the

Android Keystore / hardware secure element:

- Your encrypted files and their encrypted index.

- Your vault settings, decoy/duress configuration, and any local backups you create.

- Your encryption keys and unlock secrets (PIN, password, biometric templates are handled

  by the operating system and are never transmitted to us).


Encryption uses **XChaCha20‑Poly1305** authenticated encryption with keys derived via

**scrypt** and **HKDF‑SHA256**. Because encryption and decryption happen entirely on your

device with keys only you control, we have **no ability to access your content**.


---


## 3. Data our servers process (the minimum, for specific features)


### a) Device security & remote kill‑switch

To protect a lost or compromised device we process:

- a **random device identifier** we generate (not your name, email, phone number, IMEI, or

  advertising ID);

- your device **platform, model, and app version**;

- **security signals** (e.g., whether the device appears rooted, is an emulator, has a

  debugger attached, or could block screenshots) used to compute an access policy.


We use this only to return a security policy to your app (e.g., allow/deny decryption, or

apply a kill‑switch you activate). We do not build advertising or marketing profiles.


### b) Subscription verification (if you purchase premium)

If you buy a subscription, purchases are processed by **Google Play Billing**. To confirm

your entitlement we process the **purchase token**, **product ID**, and your random device

identifier. We do not receive your card or payment details — Google handles payment.


### c) Encrypted share links (only if you create one)

If you create a share link, the file is **encrypted on your device first**. Our server

stores only:

- the resulting **ciphertext** (which we cannot decrypt),

- a public cryptographic salt and an access token derived from your passphrase (which reveal

  nothing about the passphrase or content),

- basic metadata (file name, type, expiry time, view‑once flag).


Share data is **temporary**: it is automatically deleted when the link expires or, for

view‑once links, immediately after it is opened. You can revoke a link at any time.


We do **not** collect analytics, crash telemetry with personal content, location data,

contacts, or your file contents.


---


## 4. Permissions we request (and why)

We request permissions only when you use the related feature, and only for that purpose:

- **Camera** — to capture photos/video directly into your encrypted vault.

- **Biometrics (fingerprint/face)** — to unlock your vault locally (handled by the OS).

- **NFC** — optional physical access key to unlock your vault.

- **Photos/Media/Files** — to let you import items you choose into the vault.

Denying a permission simply disables that feature; the rest of the app keeps working.


---


## 5. How your information is used

We use the limited data above solely to:

- provide vault security, the remote kill‑switch, and threat signals you can see;

- verify subscriptions and unlock premium features;

- operate encrypted share links you choose to create.

We do **not** use it for advertising, profiling, or resale.


---


## 6. Service providers

We use **Google Cloud Platform / Firebase** to host our backend, database, and the

temporary encrypted share storage, and **Google Play Billing** to process purchases. These

providers process data on our behalf under their own security and privacy terms. No other

third parties receive your data.


---


## 7. Data retention & deletion

- **On‑device data** is kept until you delete it or uninstall the app.

- **Random device identifier & security records** are retained while your app is active and

  removed after a period of inactivity.

- **Share link data** is deleted automatically on expiry or first view, or when you revoke it.

- **Subscription records** are kept as required for entitlement and legal/tax purposes.

- To request deletion of server‑side records associated with your device identifier, contact

  us at the email above; because we hold no account or personal identifiers, we may ask you

  to provide your device identifier from within the app.


---


## 8. Security

We apply strong, modern cryptography on‑device and least‑privilege access on the server.

No system is perfectly secure, but by design our servers never hold anything they can

decrypt or tie to your real‑world identity.


---


## 9. Children's privacy

Steel Vault is not directed to children under 13 (or the minimum age of digital consent in

your country) and we do not knowingly collect their data.


---


## 10. International data transfers

Our infrastructure runs on Google Cloud, which may process data in data centers outside your

country. Data we handle is either random identifiers or content already encrypted on your

device.


---


## 11. Your rights

Depending on your region (e.g., GDPR, CCPA), you may have rights to access, correct, delete,

or restrict processing of personal data. Because Steel Vault is designed to minimize and

encrypt data, the personal data we hold is very limited. Contact us to exercise any rights.


---


## 12. Changes to this policy

We may update this policy as the app evolves. We will update the "Last updated" date above

and, for material changes, provide notice in the app.


---


## 13. Contact

Questions or requests: appstorecontact007@gmail.com

LC Labs