Privacy Policy — Vault by AutomateX

Effective date: 2026-08-10
App: Vault by AutomateX (Android) ·Package: pk.privacyvault.app
Contact: [email protected]

Summary

Vault creates an encrypted private space on your Android device. Recovery email, a verified-email account, encrypted cloud backup, and notifications are optional and begin only when you choose the corresponding feature.

Vault does not sell user data and contains no advertising, behavioral analytics, or profiling SDK. Vault content is encrypted before an enabled backup can upload it.

Data kept by the Android app

  • Encrypted photos, videos, audio, documents, notes, thumbnails, and optional intruder photos.
  • App-private Vault, album, settings, lockout, encrypted metadata, recovery, and backup-state records.
  • Versioned PIN verifiers, per-item keys, account tokens, recovery-email bindings, and installation secrets protected by Android app storage and SecureStore/Keystore.
  • Protected verifiers for optional recovery phrases and security-question answers; plaintext answers are not stored.

Temporary decrypted files remain in app-private cache only while required for an explicit action and are cleared on lock or background. Android system backup is disabled. Sensitive screens use Android secure-window protection.

Optional recovery email

If selected, the service receives the submitted email address, a random installation binding, verification challenges, recovery-operation timestamps, and security audit records. The service does not receive the Vault PIN, recovery phrase, security questions or answers, Vault names, filenames, plaintext keys, or Vault content.

Configured PIN recovery becomes eligible after a server-controlled 24-hour security hold and expires at 48 hours. The device clock cannot shorten this hold.

Optional account and encrypted backup

If an account is created or used, the service receives the verified email address, optional display name, opaque account ID, salted password verifier, authentication and verification records, quota usage, and session/security records. Plaintext passwords are not stored or logged.

If backup is enabled, the service receives opaque encrypted files, encrypted metadata envelopes, random object identifiers, integrity values, and quota information. Eligible accounts receive 5 GB of encrypted backup space. Backup failure, sign-out, quota exhaustion, remote-backup removal, and account deletion never delete content from the Vault on the device.

Optional notifications

If enabled, the notification provider and AutomateX service may receive a notification token and account association. Notification text is generic and never contains filenames, Vault names, notes, media, recovery secrets, or hidden-Vault information.

Data sharing and service providers

AutomateX does not sell user data. Infrastructure, email-verification, encrypted-storage, and notification providers may process data only to operate an optional feature selected by the user. Data is not shared for advertising or behavioral profiling.

Permissions

PermissionPurpose
CameraUser-initiated private capture and optional encrypted intruder capture.
BiometricsAndroid-managed unlock for one explicitly eligible Vault.
Photos and videosAndroid system picker and scoped media access for selected imports and verified original deletion.
NotificationsOptional generic account, backup, recovery, and security alerts.
Internet / network stateOptional recovery verification, account access, encrypted backup, and queue handling.

The app does not request broad all-files access. It does not read media outside the items selected by the user or the narrowly scoped MediaStore records needed to complete a verified delete-originals operation.

Security

  • Private media is encrypted and decrypt/read verified before it becomes a committed Vault item.
  • A source original is considered for deletion only after the encrypted Vault copy exists, is non-empty, and passes verification.
  • Encrypted notes use authenticated encryption.
  • Optional backup content is encrypted before upload and transported over HTTPS.
  • Sensitive windows block screenshots, screen recording, and app-switcher previews.
  • Vaults lock and private cache is cleared when the app backgrounds.
  • PINs, recovery phrases, security answers, account passwords, and plaintext keys are never logged.

Retention and account deletion

Vault data remains in the app until the user deletes it, clears app storage, or uninstalls. Items in Deleted Files remain until restored or permanently deleted. Optional account and encrypted-backup records remain while the account or backup is active.

You can delete your account and associated remote data fromSettings → Account & Cloud → Account controls → Delete remote account data. If you no longer have app access, email[email protected]from the account email address and request Vault account deletion. Include only the account email address; never send a PIN, recovery phrase, security answer, verification code, or password. We may verify account ownership before processing the request.

Account deletion removes account sessions, account records, registered notification tokens, remote backup objects, and remote recovery envelopes. It does not delete Vault content stored in the Android app. Security records may be retained only as necessary to prevent abuse or satisfy legal obligations and are not used for advertising.

Children's privacy

The app is not directed to children under 13.

Changes and contact

Material changes will be reflected here before the affected release is distributed.

Questions and deletion requests:[email protected]