Back to Home
Effective 06 September 2026

Terms & Conditions

The Vault is engineered to prioritize self-custody, privacy, and security. Please review our terms governing use of the application.

01Overview & Acceptance of Terms

These Terms & Conditions ("Terms") constitute a legally binding contract between you ("User", "You", or "Your") and po8o labs llp ("po8o labs", "we", "us", or "our") governing your access to and use of The Vault mobile application, websites, and associated services (collectively, the "App"), accessible at https://thevault.po8olabs.com. By downloading, accessing, installing, or using the App, you explicitly acknowledge that you have read, understood, and agree to be bound by these Terms and our Privacy Policy.

The Vault is an offline-first personal credential and payment card manager engineered to organize and protect your digital secrets locally on your hardware. We operate on a strict zero-knowledge paradigm. po8o labs is solely a software developer and does not provide financial services; po8o labs is not a bank, credit union, depository institution, payment processor, credit card issuer, money services business, or debt collector.

02Zero-Knowledge Cryptographic Architecture & Local Custody

Privacy and self-custody are mathematically guaranteed through our zero-knowledge architecture. All sensitive financial records, card numbers (PANs), CVVs, credentials, and secure notes entered into the App are encrypted locally on your device hardware using authenticated AES-256-GCM encryption with cryptographic keys derived directly from your master password using strong on-device key derivation functions.

Because encryption and decryption occur solely in your device's local memory, po8o labs never receives, transmits, or possesses your unencrypted vault records or master encryption keys. We cannot, under any circumstances, view, extract, decrypt, or recover your master password or the contents of your vault.

Biometric authentication (e.g., Face ID, Touch ID, Android BiometricPrompt) utilizes your device's native hardware Secure Enclave or Trusted Execution Environment (TEE). The App never receives or stores your biometric templates; it receives only a cryptographic verification signal from your operating system.

03User Responsibilities & Master Password Security

You bear sole and exclusive responsibility for maintaining the physical security of your device and the absolute confidentiality of your master password. Because po8o labs operates a zero-knowledge architecture, we have no technical backdoor, bypass, or recovery mechanism.

IN THE EVENT THAT YOU FORGET, MISPLACE, OR LOSE YOUR MASTER PASSWORD, YOUR ENCRYPTED VAULT DATA WILL REMAIN PERMANENTLY INACCESSIBLE. PO8O LABS CANNOT RESET YOUR PASSWORD OR RECOVER YOUR DATA. Resetting the App or clearing local application storage will permanently and irreversibly destroy all local vault data and encryption keys.

04Cloud Synchronization & Backups (Google OAuth 2.0 & Apple iCloud)

The App provides an optional cloud synchronization and backup feature that enables you to store and restore encrypted backup archives across devices. Enabling cloud synchronization is completely voluntary and under your sole discretion.

A.Client-Side Encryption Guarantee:

  • All vault backups are fully encrypted with your master password on your physical device using AES-256-GCM prior to transmission. Third-party cloud storage providers receive only an opaque ciphertext blob and have no technical ability to decrypt, read, or inspect your vault contents.

B.Google Drive Integration & Google OAuth 2.0:

  • When you connect Google Drive for cloud synchronization, The Vault authenticates using the industry-standard Google OAuth 2.0 protocol.
  • The Vault requests minimal access strictly to its own dedicated application data folder (via the 'https://www.googleapis.com/auth/drive.appdata' or 'drive.file' scope). The Vault CANNOT and DOES NOT access, view, read, or modify any other files, folders, documents, or photos in your Google Drive.
  • Google API Services User Data Policy Compliance: The Vault's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never use it to train artificial intelligence (AI) models.
  • You may revoke The Vault's access to your Google account at any time via Google Account Security Permissions.

C.Apple iCloud Integration:

  • Apple iOS users may optionally sync encrypted backups to their personal Apple iCloud account using Apple's native CloudKit framework. Authentication is handled directly by Apple operating system services.

D.Third-Party Cloud Terms & Outages:

  • Engaging cloud backup features requires compliance with the respective provider's terms of service and privacy policies. po8o labs disclaims all liability for third-party cloud service disruptions, account suspensions, synchronization latency, or unauthorized access to your cloud account resulting from compromised third-party account credentials.

05Smart Scan Feature & AI-Powered Field Extraction

The App offers an optional "Smart Scan" feature that utilizes artificial intelligence (AI) to help you rapidly capture payment card details and credentials from physical documents or photographs.

A.Ephemeral Processing & Zero Data Retention:

  • When you initiate Smart Scan, the image is encrypted in transit using TLS 1.3 and transmitted securely to our cloud infrastructure for ephemeral AI text and structured field extraction.
  • Zero Data Retention: Scanned images and extracted text are processed transiently in memory and are NEVER stored, persisted, or cached on remote servers or durable storage.
  • Immediate Purging: Temporary processing data is immediately purged upon returning the extracted fields to your device.
  • No AI Model Training: Customer image inputs and completions are NEVER used to train, retrain, fine-tune, or improve any artificial intelligence or machine learning models.

B.User Verification Duty & Disclaimer of AI Extraction Accuracy:

  • SMART SCAN IS AN AUTOMATED ASSISTIVE FEATURE. ARTIFICIAL INTELLIGENCE AND EXTRACTION ALGORITHMS MAY PRODUCE INACCURACIES, MISINTERPRET CHARACTERS, OR OMIT INFORMATION.
  • YOU HAVE A STRICT, AFFIRMATIVE DUTY TO INSPECT, VERIFY, AND CONFIRM ALL AUTO-POPULATED DATA FIELDS (INCLUDING CARD NUMBERS, EXPIRATION DATES, CVVS, CARDHOLDER NAMES, USERNAMES, AND PASSWORDS) BEFORE SAVING THEM TO YOUR VAULT.
  • PO8O LABS DISCLAIMS ALL LIABILITY FOR ANY INACCURACIES, EXTRACTION ERRORS, TYPOGRAPHICAL DISCREPANCIES, FINANCIAL CHARGES, TRANSACTION REJECTIONS, OR LOSSES ARISING DIRECTLY OR INDIRECTLY FROM AUTOMATED SMART SCAN AI EXTRACTION.

06Application Telemetry, Google Analytics & Onboarding Opt-Out

To monitor application stability, diagnose crashes, and optimize responsiveness, The App may incorporate Google Analytics (Google Analytics for Mobile / Firebase Analytics SDK).

A.Contractual Right to Opt-Out During Sign-Up:

  • Google Analytics is entirely non-essential. You have the contractual right and technical capability to disable Google Analytics directly in the App during the initial sign-up and onboarding process.
  • You may also toggle Google Analytics on or off at any subsequent time by navigating to Settings > Privacy & Diagnostics within the App.

B.Scope of Diagnostics & Absolute Vault Isolation:

  • Telemetry is strictly limited to pseudonymous technical metrics (such as OS version, device model, crash stack traces, and session latency).
  • Google Analytics is mathematically and architecturally prohibited from accessing your encrypted vault database, master password, encryption keys, payment card numbers, credentials, secure notes, or Smart Scan images.

07European Union (EU) & UK Specific Provisions (GDPR / UK GDPR)

For users residing in the European Economic Area (EEA) and the United Kingdom, we adhere to Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 through "Privacy by Design and Privacy by Default".

Because your vault credentials and payment cards are encrypted locally on your hardware and never reach po8o labs servers in unencrypted form, po8o labs does not act as a Data Controller or Data Processor for your vault contents.

You retain full legal authority to exercise your Right to Erasure, Right to Data Portability, and Right to Rectification at any time by managing your local vault items, exporting your encrypted database, or deleting the App.

08United States Specific Provisions (CCPA/CPRA, COPPA & Binding Arbitration)

California Residents (CCPA/CPRA): We do not "sell" or "share" personal information or vault data. Sensitive credentials never reach our servers, and telemetry can be disabled during onboarding or in Settings.

COPPA Compliance: The App is intended strictly for individuals legally permitted to possess payment cards and financial credentials. The App is not directed to children under 13 years of age.

MANDATORY BINDING ARBITRATION AND CLASS ACTION WAIVER: Any dispute, claim, or controversy arising out of or relating to these Terms or the App shall be resolved exclusively through final and binding individual arbitration administered by the American Arbitration Association (AAA) rather than in court. You and po8o labs each agree to waive any right to a jury trial or to participate as a plaintiff or class member in any class, collective, or representative proceeding.

09India Specific Provisions (DPDP Act, 2023 & IT Act, 2000)

For users residing in India, these Terms comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

We do not intercept, collect, or store any Sensitive Personal Data or Information (SPDI) on po8o labs servers. All financial cards and passwords remain client-side encrypted on your personal hardware. Cloud synchronization and Smart Scan are triggered solely by voluntary user action, and Google Analytics may be opted out during sign-up.

Grievance Redressal: In compliance with the IT Act and DPDP Act, any concerns or grievances regarding the App's terms or operation may be directed to our designated Grievance Officer at privacy@po8olabs.com.

10Disclaimer of Warranties

THE APP IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

WE DO NOT WARRANT THAT THE APP WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF VULNERABILITIES. WE EXPRESSLY DISCLAIM ALL LIABILITY FOR: (A) COMPROMISE OF YOUR DEVICE RESULTING FROM MALWARE, OPERATING SYSTEM EXPLOITS, ROOTING, JAILBREAKING, OR LOSS OF PHYSICAL DEVICE CONTROL; (B) SERVICE OUTAGES, DATA LOSS, OR UNAUTHORIZED ACCESS OCCURRING ON THIRD-PARTY CLOUD PROVIDERS (INCLUDING GOOGLE DRIVE AND APPLE ICLOUD); AND (C) ANY ERRORS, INACCURACIES, OR OMISSIONS PRODUCED BY THE SMART SCAN ARTIFICIAL INTELLIGENCE FEATURE OR THIRD-PARTY SERVICE PROVIDERS.

11Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL PO8O LABS LLP, ITS MEMBERS, DIRECTORS, OFFICERS, EMPLOYEES, AFFILIATES, OR AGENTS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, NOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR OTHER INTANGIBLE LOSSES ARISING OUT OF OR IN CONNECTION WITH YOUR ACCESS TO, USE OF, OR INABILITY TO USE THE APP.

IN NO EVENT SHALL OUR TOTAL CUMULATIVE LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE APP EXCEED THE TOTAL AMOUNT ACTUALLY PAID BY YOU TO PO8O LABS FOR THE APP IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR ZERO DOLLARS ($0.00 USD) IF NO SUCH PAYMENT OCCURRED.

12Modifications & Contact Information

We reserve the right to modify these Terms at our discretion. Any revisions will be reflected with an updated "Effective Date" at the top of this document. Your continued use of The Vault after any revisions constitutes your binding acceptance of the amended Terms.

If you have any questions or legal inquiries regarding these Terms, please contact us at support@po8olabs.com or privacy@po8olabs.com, or visit our official website at https://thevault.po8olabs.com.