Home/Legal/Privacy Policy
Mathematical Zero-Knowledge Privacy Guarantee

Vault Wulvix Privacy Policy

At Vault Wulvix, privacy is not a policy statement—it is a mathematical guarantee. Our entire software architecture is engineered around the principle of zero-knowledge cryptography: your vault contents are encrypted on your local device before touching our network.

Effective Date: January 1, 2026•Last Updated: September 23, 2026•Version 2.4 (Active)

Zero Plaintext Access

We never hold your master password or encryption keys. Plaintext vault data is never transmitted to our servers.

Client-Side AES-256

Data is locked using authenticated AES-256-GCM directly within your device CPU before synchronization.

Zero Data Broking

We never sell, rent, monetize, or feed your personal data into public advertising or third-party marketing networks.

1-Click Purge

You maintain full data sovereignty. Triggering vault deletion permanently destroys all encrypted blobs and account metadata.

1. Zero-Knowledge Architecture

Vault Wulvix is architected with a fundamental security invariant: Zero-Knowledge Encryption. When you register an account and initialize your vault, an asymmetric cryptographic keypair and symmetric AES-256 data encryption keys are derived locally in your browser or application runtime from your master password using memory-hard key derivation algorithms (Argon2id and PBKDF2 with high iteration counts).

The Fundamental Security Rule

Your master password and raw cryptographic encryption keys never leave your device. We store only encrypted ciphertext blobs (payloads). Even our database engineers, systems architects, and executive officers cannot decrypt or read your vault entries.

2. Information We Never Collect or Store in Plaintext

Because of our cryptographic design, Vault Wulvix has no technical ability to access, record, or disclose:

  • Master Passwords & Passphrases: We never transmit, log, or store your master password.
  • Vault Content Plaintext: Stored passwords, usernames, TOTP secrets, notes, bank accounts, credit card numbers, tax IDs, and confidential documents.
  • Document Files & Attachments: Scanned passports, national IDs, property deeds, and confidential PDFs remain opaque encrypted blobs (AES-256-GCM) on MinIO/S3 object storage.
  • OCR & Document Parsing Results: Document text recognized through optical character recognition is performed on your device or in zero-retention memory buffers.

3. Information We Collect & Why

To operate our secure cloud synchronization and prevent platform abuse, we collect minimal operational metadata:

A. Account Registration Credentials

We collect your permanent email address, an optional user display name, and a cryptographic authentication verifier (derived separately from your vault encryption key). We reject temporary and disposable email providers to maintain platform integrity and mitigate automated abuse.

B. Session Telemetry & Threat Prevention

When you sign in, our backend logs the requesting IP address, user agent, timestamp, and device fingerprint. This data is exclusively utilized to detect credential stuffing, enforce rate limiting, alert you to unauthorized login attempts, and display active session revocation controls in your Security Settings.

C. Subscription Billing Details

Payment transactions are processed by certified PCI-DSS Level 1 compliant gateways (such as Stripe). Vault Wulvix never stores raw credit card numbers or security CVV codes on our servers. We only retain subscription tier identifiers, expiration dates, and transaction receipts.

4. Client-Side Cryptographic Standards

Every byte of vault data is secured using military-grade cryptography implemented via standardized Web Cryptography APIs (SubtleCrypto):

  • AES-256-GCM: Symmetric authenticated encryption with unique 96-bit initialization vectors (IVs) per item preventing replay and ciphertext tampering.
  • Key Derivation: Master passphrases undergo 600,000 PBKDF2-HMAC-SHA256 iterations or Argon2id key stretching with distinct client salt to defeat offline dictionary attacks.
  • Cryptographic Randomness: All cryptographic nonces and random seeds are generated using cryptographically secure pseudorandom number generators (crypto.getRandomValues).

5. AI Search & OCR Processing Privacy

Vault Wulvix features local document search and intelligent categorization. To uphold our privacy standard:

On-Device Parsing & Ephemeral Context

Unlike traditional cloud document managers that send entire unencrypted PDFs to cloud servers for indexing, Vault Wulvix analyzes document structures locally on your device CPU. When you execute an AI vault query, only temporary, synthesized contextual vectors are queried. We maintain contractual data protection agreements with enterprise AI infrastructure providers guaranteeing that your data is never used to train machine learning models.

6. Emergency Legacy Access Privacy Protocol

Our digital legacy feature allows you to nominate trusted emergency contacts to access your vault in unforeseen circumstances:

  • End-to-End Key Wrapping: Your vault decryption keys are shared using public-key cryptography (RSA-OAEP or ECDH) directly to your designated recipient.
  • Mandatory Owner Veto Period: Any emergency claim initiates an immediate security countdown (e.g. 7, 14, or 30 days) accompanied by urgent email and push alerts. The vault owner retains an absolute 1-click veto to cancel access if active.
  • Zero Plaintext Escrow: Vault Wulvix never holds the unsealed keys during the waiting period.

7. Cookies & Local Web Storage

We do not use tracking pixels, cross-site beacons, Google Analytics, or third-party marketing cookies.

We utilize only essential, privacy-preserving storage mechanisms:

  • HTTP-Only Secure Cookies: To securely store encrypted session tokens (refreshToken) with SameSite=Strict and Secure flags.
  • Local Session Storage: Temporary short-lived client state (such as UI theme preferences and active search filters) cleared when closing your tab.

8. Sub-processors & Infrastructure

To provide high availability and encrypted file storage, we partner with industry-leading infrastructure providers under strict Data Processing Addendums (DPAs):

Encrypted Blob Storage

High-durability S3/MinIO compatible object stores holding exclusively AES-256 encrypted payloads.

Transactional Email Delivery

Secure SMTP transport gateways (Resend / AWS SES) for delivering verification and emergency alerts.

9. Data Retention & The Right to Cryptographic Erasure

You retain complete control of your data life cycle. When you choose to delete your account or any vault item:

Immediate Irreversible Destruction

All associated encrypted vault records, ciphertext blobs, file attachments, and relational database records are permanently purged from active databases and object buckets. Because the encryption keys exist only in your memory and on your device, deleting the ciphertext guarantees mathematical unrecoverability.

10. GDPR, CCPA/CPRA & International Rights

Regardless of your country of residence, Vault Wulvix extends privacy rights globally consistent with the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):

  • Right of Access & Portability: You may export your entire vault into an unencrypted or encrypted standard JSON/CSV file at any time directly through your dashboard.
  • Right to Rectification: You may edit your email address and personal preferences at any time.
  • Right to Erasure ("Right to be Forgotten"): 1-click self-service account deletion in your profile settings.
  • No Sale of Personal Data: We do not sell personal data as defined by the CCPA/CPRA.

11. Modifications to This Policy

We may update this Privacy Policy from time to time to reflect enhancements to our cryptographic architecture or legal requirements. Material updates will be announced via in-app notifications and email to registered account holders at least 30 days prior to taking effect.

12. Contact the Security & Privacy Team

If you have questions regarding this Privacy Policy, our zero-knowledge implementation, or wish to exercise your statutory data privacy rights, please reach out directly:

Vault Wulvix Data Protection Office