Privacy Policy
Last updated: August 12, 2026
Overview
Vaultaire is a local-first private photo vault. Your files are encrypted on your device under a random master key, which is wrapped by a key derived from your pattern. Wraxle does not operate a service that receives a readable copy of your vault contents, pattern, or decryption keys.
Data We Do Not Collect
- Your photos, videos, or files — all data is encrypted on-device and never leaves your phone unencrypted.
- Your pattern or encryption keys — pattern derivation and AES-GCM operations run locally. Lock paths discard active key state and key wrappers clear owned buffers on deallocation, but Vaultaire does not claim that Swift and iOS provably overwrite every transient memory copy.
- Your recovery phrase — stored with legacy pattern fields in an AES-GCM-encrypted recovery database in Keychain. A separate random Keychain item protects that database so the phrase can be shown later in vault settings.
- Your name, email, or account information — Vaultaire requires no account to use.
App analytics (off by default)
Vaultaire does not ask for analytics permission during onboarding. In-app analytics and crash diagnostics remain off unless you turn on Help improve Vaultaire in Settings. Before that opt-in, the app does not start PostHog or queue analytics events for later delivery.
- PostHog receives coarse product events, performance data, and handled errors. Vault contents, patterns, recovery phrases, structured filenames and file types, share IDs, vault IDs, raw StoreKit product IDs, transaction IDs, and receipts are excluded. PostHog's privacy policy.
- Apple Ads attribution uses Apple's AdServices token to learn whether an install came from an Apple ad and, when available, the campaign, ad group, keyword, country, conversion type, claim type, and placement. Vaultaire creates a random install UUID only after consent. Our first-party function sends the token to Apple, hashes the UUID before sending the coarse result to PostHog, and does not retain the raw token or UUID. StoreKit receives that UUID as an app account token on purchases so future first-party Apple server notifications can use the same pseudonymous key.
Turning the setting off disables product analytics, crash reporting, Apple Ads attribution, and the analytics-only StoreKit join key. The app does not use IDFA, request tracking permission, or send app-open advertising conversion events.
Website analytics
The Vaultaire website (vaultaire.app) uses PostHog for first-party website analytics. PostHog stores an anonymous random identifier in your browser's localStorage so we can count unique visitors and measure session lengths without using cookies or cross-site tracking. Website and in-app analytics use separate identifiers.
To attribute visits from ChatGPT ads, the website also uses the OpenAI Ads Measurement Pixel. It can store a privacy-preserving ad-click reference in the first-party __oppref cookie and sends an app_store_clicked event when you select a Vaultaire App Store link. We do not send names, email addresses, account IDs, or app content. The event opts out of future user-level personalization, and the pixel does not load when your browser sends Global Privacy Control.
iCloud Backup
If you enable iCloud Backup in settings, Vaultaire derives a separate device-independent backup key from your pattern and uploads padded AES-GCM-encrypted records to your private CloudKit database. Phrase-based restore also stores an encrypted recovery manifest. Wraxle does not receive your iCloud credentials or readable vault contents. Apple’s iCloud terms apply to this storage.
Vault Sharing
When you share a vault via link, the encrypted data is transmitted through Apple's CloudKit infrastructure. The share link contains the decryption phrase in the URL fragment (after the #), which never reaches our servers. Only the intended recipient with the full link can decrypt the shared vault.
In-App Purchases
Vaultaire offers a premium subscription through Apple's App Store. All purchase transactions are handled by Apple. We do not collect or store your payment information. Apple's terms and privacy policy govern these transactions.
Third-Party Services
- Apple CloudKit — used for vault sharing and iCloud backup (encrypted data only)
- Apple StoreKit — used for in-app purchase processing
- Apple AdServices — opt-in Apple Ads install attribution
- PostHog — coarse in-app product analytics and crash diagnostics, plus separate first-party website analytics
- OpenAI Ads Measurement Pixel and Conversions API: website-only ChatGPT ad attribution using the first-party __oppref cookie and an App Store link-click event
Children's Privacy
Vaultaire does not knowingly collect personal information from children under 13. The app requires no account. Optional analytics are off by default and are not intended for use by children under 13.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date.
Contact
If you have questions about this privacy policy, contact us through the support form.