Back to Home
Effective 06 September 2026

Privacy Policy

Zero-knowledge, offline-first security. Here is our comprehensive disclosure of our local processing, client-side encryption, and transparent Google API Services practices.

01Executive Summary & Zero-Knowledge Commitment

The Vault is an enterprise-grade, offline-first personal credential and payment card management application developed and operated by po8o labs llp ("po8o labs", "we", "us", or "our"), accessible at https://thevault.po8olabs.com. The foundational architecture of The Vault is built on the principle of "Zero-Knowledge Privacy by Design."

The Vault securely stores, organizes, and protects your confidential payment cards, login credentials, passwords, cryptographic seeds, and secure digital records. All sensitive vault data is encrypted on your local device before being written to persistent storage. Under our zero-knowledge paradigm, we do not operate centralized database servers that host your vault records, we have no knowledge of or access to your master password, and we have no cryptographic mechanism to decrypt or inspect your confidential information.

We unequivocally do not sell, rent, monetize, or disclose your personal records, credentials, or vault data to any commercial third parties, advertisers, or data brokers.

02Data Processed Locally on Your Device Hardware

To provide core password and payment card management capabilities, The Vault processes the following categories of information strictly on your physical device:

  • Payment Card Information: Primary Account Numbers (PANs), cardholder names, expiration dates, Card Verification Values (CVVs), card nicknames, issuing banks, billing addresses, and associated user notes.
  • Account Credentials: Usernames, email addresses, complex passwords, multi-factor authentication (MFA/TOTP) seed secrets, and associated service URLs.
  • Secure Attachments: Optional photographic captures or digital document attachments imported from your device camera or photo library.
  • Local Application Configuration: Security and usability preferences, including biometric unlock flags, clipboard auto-clear intervals, auto-lock timeouts, and backup preferences.

All vault data is encrypted using industry-standard AES-256-GCM (Galois/Counter Mode) authenticated encryption. Cryptographic keys are derived directly on your device from your master password using strong cryptographic key derivation functions paired with unique salts. Because encryption and decryption occur exclusively in your device's local memory, po8o labs never receives, transmits, or possesses your unencrypted vault records or master encryption keys.

03Google API Services & Google OAuth 2.0 Disclosures (Cloud Sync)

The Vault provides an optional cloud synchronization and backup feature that integrates with Google Drive. If you choose to enable Google Drive backups, our application interacts with Google APIs using the industry-standard Google OAuth 2.0 protocol. This section outlines our strict adherence to Google's API policies and user data protections.

A.Google User Data Accessed by The Vault:

  • Google Account Profile Information: When you authenticate via Google OAuth 2.0 (Google Identity Services), The Vault requests basic OpenID Connect identity scopes ('openid', 'email', 'profile'). This access token is used solely to authenticate your identity and display your connected Google email address within the app's backup management interface.
  • Google Drive Application Data Scope: The Vault requests access to the dedicated application data folder using the 'https://www.googleapis.com/auth/drive.appdata' or 'https://www.googleapis.com/auth/drive.file' scope. This permission is strictly restricted to creating, uploading, listing, downloading, and deleting The Vault's own encrypted backup files.
  • Strict Scope Boundary: The Vault ONLY accesses, reads, and modifies files and folders that are created directly by The Vault. The Vault CANNOT and DOES NOT access, view, scan, modify, or delete your personal Google Drive documents, spreadsheets, slides, photos, videos, or folders stored elsewhere in your Google account.

B.Client-Side Encryption Before Cloud Transmission:

  • Before any backup file is uploaded to your Google Drive, it is completely encrypted locally on your device using AES-256-GCM with your master password.
  • Google receives only an opaque, encrypted binary blob. Google does not hold your decryption key and cannot read, inspect, or decrypt the contents of your vault backups.

C.How The Vault Uses Google User Data:

  • Google user data is used EXCLUSIVELY to authenticate your identity and provide user-facing cloud backup and cross-device restoration features.

D.Prohibited Uses of Google User Data:

  • We DO NOT use Google user data for advertising, including personalized, contextual, retargeted, or interest-based advertising.
  • We DO NOT sell, rent, license, or monetize Google user data to data brokers, information resellers, or any commercial third parties.
  • We DO NOT use Google user data to assess creditworthiness, eligibility for financial products, or for lending purposes.
  • We DO NOT use Google user data or Google Workspace APIs to train, develop, fine-tune, or improve generalized, non-personalized artificial intelligence (AI) or machine learning (ML) models.

E.Third-Party Disclosures & Security in Transit:

  • The Vault does NOT transfer, share, or disclose your Google user data to any external third parties or remote analytics servers.
  • All communication occurs directly and securely between The Vault app on your device and Google's official API endpoints over encrypted HTTPS/TLS 1.3 connections.
  • No po8o labs employees, contractors, or human reviewers have access to your Google user data or encrypted backup archives.

F.Google API Services User Data Policy Compliance (Limited Use):

  • The Vault's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

04Apple iCloud Synchronization & Third-Party Cloud Providers

In addition to Google Drive, users on iOS and Apple platforms may optionally choose to synchronize or back up their encrypted database to their personal Apple iCloud account using Apple's native CloudKit framework.

Identical to Google Drive sync, all vault records are encrypted on your local device with AES-256-GCM using your master password before being transmitted to Apple iCloud. Authentication is handled directly by Apple's operating system identity framework. Neither po8o labs nor Apple possesses the technical capability to decrypt your vault contents.

Enabling third-party cloud synchronization remains completely optional and under your exclusive control. Your use of third-party cloud storage is subject to the respective provider's privacy policy and terms of service.

05Application Diagnostics, Telemetry & Google Analytics (User Opt-Out During Sign-Up)

To ensure operational stability, diagnose technical errors, and optimize application performance, The Vault may utilize Google Analytics (specifically Google Analytics for Mobile / Firebase Analytics SDK). We maintain strict privacy boundaries regarding what telemetry is captured and provide full user control over analytics collection.

A.User Choice & Opt-Out During Sign-Up:

  • Google Analytics is completely optional and non-essential for vault operation. You can disable Google Analytics directly in the application during the initial sign-up and onboarding process.
  • You also retain the right to toggle Google Analytics on or off at any subsequent time by navigating to the application's Settings > Privacy & Diagnostics menu.

B.Categories of Diagnostic Telemetry Collected:

  • When enabled, Google Analytics collects pseudonymous, aggregated technical telemetry, including application version, operating system release, hardware device model, crash stack traces, feature engagement counts, and network latency metrics.
  • This diagnostic data is utilized strictly to identify crashes, diagnose performance regressions, and improve app stability.

C.Strict Data Boundaries — Absolute Exclusion of Vault Records:

  • Google Analytics is strictly isolated from your vault database. Google Analytics NEVER collects, intercepts, logs, or transmits master passwords, cryptographic keys, payment card details (PANs, CVVs, expiration dates), account usernames, passwords, secure notes, biometric signatures, or image uploads.
  • Telemetry data cannot be correlated with your confidential vault records or your decrypted credentials.

06Smart Scan Feature & AI-Powered Field Extraction

The Vault includes an optional "Smart Scan" artificial intelligence (AI) feature designed to help you quickly digitize and populate payment card details and credentials by scanning a physical card, document, or image using your device camera or photo library.

A.Ephemeral Transmission & Processing:

  • When you initiate a Smart Scan, the captured image is encrypted in transit using modern Transport Layer Security (TLS 1.3) and transmitted securely to our cloud processing infrastructure strictly for AI-assisted text and structured field extraction.

B.Zero Data Retention (ZDR):

  • 1. No Persistent Storage: Scanned images and extracted text are processed transiently in memory and are NEVER written to disk, stored, persisted, or cached on remote servers or durable cloud storage.
  • 2. Immediate Purging: Once AI extraction is completed and the structured data is securely returned to your device, all temporary compute buffers are immediately destroyed and purged.
  • 3. No Artificial Intelligence or Machine Learning Model Training: Your images, documents, and extracted text are strictly prohibited from being used by po8o labs or any cloud service providers to train, retrain, fine-tune, or improve any generalized artificial intelligence or machine learning models.

C.Operational Telemetry Minimization:

  • To ensure infrastructure availability and service reliability, system logs capture strictly non-identifying, aggregated operational telemetry (such as aggregate request volume and technical status codes).
  • Zero User Data Logged: No user identifiers, account credentials, raw images, or extracted text are ever logged, captured, or retained.

D.Local Client-Side Verification:

  • Once structured fields are returned to your device, they are loaded into local memory for your inspection. No data is committed to your encrypted vault until you verify, edit if necessary, and explicitly tap "Save" on your device.

07Device Permissions & Biometric Hardware Enclave

The Vault requests specific operating system permissions strictly when necessary to execute actions you initiate:

  • Biometric Sensors (Face ID, Touch ID, Android BiometricPrompt): Allows rapid, secure unlocking without typing your master password. Biometric matching is handled entirely by your device's native hardware Secure Enclave / Trusted Execution Environment (TEE). The Vault never accesses, collects, or transmits your biometric templates; it receives only a cryptographically signed verification signal from the operating system.
  • Camera & Photo Library: Utilized strictly when you take a photo of a payment card for encrypted attachment storage or when utilizing the optional Smart Scan feature (processed with zero data retention as detailed in Section 6). Photos are never stored on any centralized company database.
  • Near Field Communication (NFC): If supported by your hardware and initiated by you, NFC is used to read contactless payment card parameters directly into the app. Captured NFC signals are processed in local volatile memory and never transmitted externally.
  • Network Access: Utilized strictly to synchronize encrypted backup files with Google Drive or Apple iCloud (when initiated by you), to transmit ephemeral images for Smart Scan under zero data retention, or to send anonymous diagnostic telemetry if Google Analytics is enabled.

08Data Security & Cryptographic Protection Standards

We implement defense-in-depth, industry-standard cryptographic architectures to safeguard your information:

  • Authenticated Encryption at Rest: All vault records, payment card numbers, CVVs, credentials, and attachments are encrypted using AES-256-GCM authenticated encryption. This provides both confidentiality and cryptographic integrity verification against tampering.
  • Hardened Key Derivation: Master encryption keys are derived on-device using strong cryptographic key derivation functions combined with unique per-vault cryptographic salts, resisting brute-force attacks.
  • Zero Remote Exposure: Decryption keys exist only in volatile device RAM while the vault is actively unlocked and are cryptographically wiped upon auto-lock or app termination.
  • Encryption in Transit: All network communications—including Google OAuth 2.0 handshakes, Google Drive and iCloud backup sync, and ephemeral Smart Scan requests—strictly enforce modern TLS 1.3 encryption in transit with certificate validation to prevent eavesdropping and man-in-the-middle attacks.

09Data Retention, Deletion, and Revocation of Access

You maintain absolute, autonomous authority over your data retention, deletion, and third-party authorizations at all times:

A.Local Device Deletion & Cryptographic Shredding:

  • You can modify or delete individual payment cards, passwords, or attachments at any time within the app.
  • The app provides a "Reset Vault" security feature that immediately and cryptographically shreds all local databases, salts, and derived encryption keys.
  • Uninstalling The Vault permanently deletes all locally stored vault databases and encryption keys from your device.

B.Cloud Backup Deletion:

  • You can delete your cloud backup archives at any time directly through The Vault's cloud backup settings interface.
  • For Google Drive, you can also delete backup files directly via the Google Drive web interface (Settings > Manage Apps > The Vault > Delete hidden app data).
  • For Apple iCloud, you can remove stored data via your device's iOS Settings > Apple Account > iCloud > Manage Storage.

C.Revoking Google Account Permissions:

  • You can revoke The Vault's access to your Google account at any time by visiting Google Account Security Permissions.
  • Once revoked, The Vault will immediately lose all authorization to interact with your Google account or Google Drive.

D.Managing Diagnostic Telemetry:

  • You can opt out of Google Analytics during the sign-up process or toggle it off at any time under Settings > Privacy & Diagnostics.

E.Zero Server-Side Residual Data:

  • Because po8o labs does not store your vault data, payment credentials, or Google profile data on centralized company servers, and because Smart Scan operates under zero data retention, there is no residual user data retained on our servers when you delete your local vault or backups.

10European Union (EU) & UK Specific Provisions (GDPR / UK GDPR)

For individuals residing within the European Economic Area (EEA) and the United Kingdom, we comply with Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 under the core tenet of "Privacy by Design and Privacy by Default":

  • Data Controller & Processor Status: Because The Vault operates on a zero-knowledge local architecture and po8o labs does not receive, view, or store your unencrypted vault records, po8o labs does not act as a Data Controller or Data Processor for your vault contents.
  • Legal Bases for Processing: To the extent any data is processed: (a) Local vault processing is performed solely to fulfill our contractual obligations to you; (b) Cloud sync (Google Drive / iCloud) and Smart Scan AI extraction are executed strictly upon your explicit user consent and initiation; (c) Performance telemetry via Google Analytics is processed pursuant to your consent, which may be withheld during sign-up or revoked anytime in Settings.
  • Data Subject Rights: You possess the Right of Access, Right to Rectification, Right to Erasure ('Right to be Forgotten'), Right to Restriction of Processing, and Right to Data Portability. Because your data is stored locally and encrypted with your key, you can exercise these rights directly and autonomously at any time within the app.
  • Inquiries: Contact our Data Protection representative at privacy@po8olabs.com.

11United States Specific Provisions (CCPA / CPRA & COPPA)

  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA): We do not "sell" your personal information, nor do we "share" your personal information for cross-context behavioral advertising. Vault credentials, payment cards, and scanned images never reach po8o labs servers. Google Analytics telemetry is pseudonymous and can be disabled during onboarding or in Settings.
  • Children's Online Privacy Protection Act (COPPA): The Vault is intended strictly for individuals legally eligible to possess payment cards and digital credentials. We do not knowingly collect, solicit, or maintain personal information from individuals under 13 years of age. If you believe a minor has provided personal information, please notify us immediately at privacy@po8olabs.com.

12India Specific Provisions (DPDP Act, 2023 & IT Act, 2000)

For users residing in India, The Vault complies with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules):

  • Protection of Sensitive Personal Data: Payment card details, passwords, cryptographic keys, and biometric authentication signals are recognized as Sensitive Personal Data or Information (SPDI). Through client-side zero-knowledge AES-256 encryption, all SPDI remains strictly on your personal hardware and is never intercepted, stored, or centralized on po8o labs servers.
  • Telemetry & Cloud Consent: Cloud synchronization (Google Drive / iCloud) and Smart Scan AI extraction are triggered strictly upon voluntary user initiation. Google Analytics is entirely optional and may be disabled during the initial sign-up flow.
  • Grievance Officer: In accordance with the IT Act and DPDP Act, any questions, grievances, or concerns may be addressed to our designated Grievance Officer at privacy@po8olabs.com.

13Amendments & Policy Updates

We may update this Privacy Policy periodically to reflect technological advancements, enhancements to The Vault, or evolving legal and regulatory standards (including updates to Google API policies or cloud provider frameworks).

Any modifications will be published on this page with an updated "Effective Date" at the top. We encourage users to periodically review this Privacy Policy to stay informed of our data protection commitments.

14Contact Us & Data Protection Inquiries

If you have questions, feedback, or legal inquiries regarding this Privacy Policy or our security infrastructure, please contact us:

We are committed to addressing all verified privacy inquiries and requests promptly within thirty (30) calendar days.