Privacy Policy
Last updated: September 20, 2026
Vault Pro is a password manager run by Abdul Hannan as an independent project. This page explains what information the service handles and why. Questions: ah0720493@gmail.com.
1. The short version
- Your saved passwords, usernames, notes and website names are encrypted before they are stored. We do not store your Master PIN or the key made from it.
- We do not show ads, sell your data, or run analytics or advertising trackers.
- You can delete your account and your data yourself, at any time, in Settings.
2. Information we handle
Account information
- Your email address and display name.
- Your login password, stored only as a salted hash. We cannot read it.
- If you use Google sign-in: your Google account ID, name, email address and profile picture link, as provided by Google.
- If you upload a profile picture: a resized copy, stored in our database.
- Your settings, such as appearance and auto-lock time.
Your vault
- Each saved account is encrypted before it is stored: its name, website, username, password, notes and category. The service operator cannot read them from the database.
- What is not hidden: that you have a vault, how many accounts it holds, and when each was created or changed.
- Encryption key material: a random vault key that is itself locked with your Master PIN (and with your recovery key, if you made one). We store the locked copies and the salts used, never the PIN, the recovery key or the plain vault key.
- While your vault is unlocked, the vault key is held in the server's memory for a short time and is removed when the vault locks or times out.
- If you add a passkey (fingerprint, Face ID or Windows Hello): its public key, its identifier, the name you gave the device, and a copy of the vault key locked with a secret that only that passkey can produce. Your fingerprint or face is never sent to us.
Google Drive backup (optional)
- If you connect Google Drive, we ask for permission to use the hidden application-data folder of your Drive. That permission lets Vault Pro create, read, update and delete only its own backup file there. It does not let us see any of your other Drive files.
- The backup file holds encrypted data only. It cannot be opened without your Master PIN.
- We store an access token for your Drive, encrypted, so backups can happen automatically. You can disconnect at any time.
Cookies and similar data
- A session cookie keeps you logged in, and a security cookie protects forms. Both are needed for the site to work.
- A "remembered account" cookie (your name, email and photo link) lets the login page offer "Continue as ...". It lasts up to 180 days and you can remove it with "Not you?" on the login page.
- Your browser may keep a copy of static files (styles, scripts, icons) for the installable app. It never stores your vault or pages with your data.
Technical data
- To limit password guessing, short-lived counters kept in memory use a scrambled form of your network address for about 15 minutes.
- Our hosting provider may keep ordinary server logs (for example network address and requested page).
3. How we use it
- To create your account, keep you signed in and run the vault.
- To send you the emails you ask for: address verification and password reset.
- To keep the service secure and prevent abuse.
We do not sell or rent your information and we do not use it for advertising.
4. Google user data
Vault Pro uses Google sign-in to learn your name, email address and profile picture, and (only if you choose it) the application-data folder of your Google Drive to store your encrypted backup. We use this information only to provide those features. We do not share it with other parties except the service providers listed below, and we do not use it for advertising.
Vault Pro's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Services that help us run Vault Pro
- Google: sign-in, and Drive if you connect it. Google's own privacy policy applies to what Google handles.
- Brevo: sends our emails. It receives your email address and the message.
- Render: hosts the application.
- Neon: hosts the database, which holds the data described above.
- Google Fonts and jsDelivr: your browser loads fonts, icons and style files from them, so they can see your network address as they do for any website.
6. Keeping and deleting your data
- We keep your data while your account exists.
- In Settings → Delete my account you can remove your account, vault, passkeys and profile. You can choose to delete your Google Drive backup at the same time, and we revoke our access to your Drive.
- Our hosting and database providers may keep backup copies for a limited time after deletion.
- You can also remove Vault Pro's access at any time from your Google Account's security settings.
7. Security, and your part in it
We use HTTPS, encrypt your vault, lock accounts after repeated wrong attempts and lock the vault when you are away. No system is perfect. Keep your Master PIN and recovery key private. If you forget the PIN and have no recovery key, your vault cannot be recovered by anyone, including us.
8. Children
Vault Pro is not directed at children under 13, and we do not knowingly collect their information.
9. Changes
If this policy changes, we will update the date above. Continuing to use Vault Pro after a change means you accept it.