Vault Wulvix Privacy Policy
At Vault Wulvix, privacy is not a policy statement—it is a mathematical guarantee. Our entire software architecture is engineered around the principle of zero-knowledge cryptography: your vault contents are encrypted on your local device before touching our network.
Zero Plaintext Access
We never hold your master password or encryption keys. Plaintext vault data is never transmitted to our servers.
Client-Side AES-256
Data is locked using authenticated AES-256-GCM directly within your device CPU before synchronization.
Zero Data Broking
We never sell, rent, monetize, or feed your personal data into public advertising or third-party marketing networks.
1-Click Purge
You maintain full data sovereignty. Triggering vault deletion permanently destroys all encrypted blobs and account metadata.
1. Zero-Knowledge Architecture
Vault Wulvix is architected with a fundamental security invariant: Zero-Knowledge Encryption. When you register an account and initialize your vault, an asymmetric cryptographic keypair and symmetric AES-256 data encryption keys are derived locally in your browser or application runtime from your master password using memory-hard key derivation algorithms (Argon2id and PBKDF2 with high iteration counts).
Your master password and raw cryptographic encryption keys never leave your device. We store only encrypted ciphertext blobs (payloads). Even our database engineers, systems architects, and executive officers cannot decrypt or read your vault entries.
2. Information We Never Collect or Store in Plaintext
Because of our cryptographic design, Vault Wulvix has no technical ability to access, record, or disclose:
- Master Passwords & Passphrases: We never transmit, log, or store your master password.
- Vault Content Plaintext: Stored passwords, usernames, TOTP secrets, notes, bank accounts, credit card numbers, tax IDs, and confidential documents.
- Document Files & Attachments: Scanned passports, national IDs, property deeds, and confidential PDFs remain opaque encrypted blobs (AES-256-GCM) on MinIO/S3 object storage.
- OCR & Document Parsing Results: Document text recognized through optical character recognition is performed on your device or in zero-retention memory buffers.
3. Information We Collect & Why
To operate our secure cloud synchronization and prevent platform abuse, we collect minimal operational metadata:
A. Account Registration Credentials
We collect your permanent email address, an optional user display name, and a cryptographic authentication verifier (derived separately from your vault encryption key). We reject temporary and disposable email providers to maintain platform integrity and mitigate automated abuse.
B. Session Telemetry & Threat Prevention
When you sign in, our backend logs the requesting IP address, user agent, timestamp, and device fingerprint. This data is exclusively utilized to detect credential stuffing, enforce rate limiting, alert you to unauthorized login attempts, and display active session revocation controls in your Security Settings.
C. Subscription Billing Details
Payment transactions are processed by certified PCI-DSS Level 1 compliant gateways (such as Stripe). Vault Wulvix never stores raw credit card numbers or security CVV codes on our servers. We only retain subscription tier identifiers, expiration dates, and transaction receipts.
4. Client-Side Cryptographic Standards
Every byte of vault data is secured using military-grade cryptography implemented via standardized Web Cryptography APIs (SubtleCrypto):
- AES-256-GCM: Symmetric authenticated encryption with unique 96-bit initialization vectors (IVs) per item preventing replay and ciphertext tampering.
- Key Derivation: Master passphrases undergo 600,000 PBKDF2-HMAC-SHA256 iterations or Argon2id key stretching with distinct client salt to defeat offline dictionary attacks.
- Cryptographic Randomness: All cryptographic nonces and random seeds are generated using cryptographically secure pseudorandom number generators (
crypto.getRandomValues).
5. AI Search & OCR Processing Privacy
Vault Wulvix features local document search and intelligent categorization. To uphold our privacy standard:
Unlike traditional cloud document managers that send entire unencrypted PDFs to cloud servers for indexing, Vault Wulvix analyzes document structures locally on your device CPU. When you execute an AI vault query, only temporary, synthesized contextual vectors are queried. We maintain contractual data protection agreements with enterprise AI infrastructure providers guaranteeing that your data is never used to train machine learning models.
6. Emergency Legacy Access Privacy Protocol
Our digital legacy feature allows you to nominate trusted emergency contacts to access your vault in unforeseen circumstances:
- End-to-End Key Wrapping: Your vault decryption keys are shared using public-key cryptography (RSA-OAEP or ECDH) directly to your designated recipient.
- Mandatory Owner Veto Period: Any emergency claim initiates an immediate security countdown (e.g. 7, 14, or 30 days) accompanied by urgent email and push alerts. The vault owner retains an absolute 1-click veto to cancel access if active.
- Zero Plaintext Escrow: Vault Wulvix never holds the unsealed keys during the waiting period.
8. Sub-processors & Infrastructure
To provide high availability and encrypted file storage, we partner with industry-leading infrastructure providers under strict Data Processing Addendums (DPAs):
High-durability S3/MinIO compatible object stores holding exclusively AES-256 encrypted payloads.
Secure SMTP transport gateways (Resend / AWS SES) for delivering verification and emergency alerts.
9. Data Retention & The Right to Cryptographic Erasure
You retain complete control of your data life cycle. When you choose to delete your account or any vault item:
All associated encrypted vault records, ciphertext blobs, file attachments, and relational database records are permanently purged from active databases and object buckets. Because the encryption keys exist only in your memory and on your device, deleting the ciphertext guarantees mathematical unrecoverability.
10. GDPR, CCPA/CPRA & International Rights
Regardless of your country of residence, Vault Wulvix extends privacy rights globally consistent with the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):
- Right of Access & Portability: You may export your entire vault into an unencrypted or encrypted standard JSON/CSV file at any time directly through your dashboard.
- Right to Rectification: You may edit your email address and personal preferences at any time.
- Right to Erasure ("Right to be Forgotten"): 1-click self-service account deletion in your profile settings.
- No Sale of Personal Data: We do not sell personal data as defined by the CCPA/CPRA.
11. Modifications to This Policy
We may update this Privacy Policy from time to time to reflect enhancements to our cryptographic architecture or legal requirements. Material updates will be announced via in-app notifications and email to registered account holders at least 30 days prior to taking effect.
12. Contact the Security & Privacy Team
If you have questions regarding this Privacy Policy, our zero-knowledge implementation, or wish to exercise your statutory data privacy rights, please reach out directly: