TL;DR: We can't read your files. Your data is encrypted before it reaches us. We collect minimal metadata. We don't sell data. We're committed to your privacy.

At PrivVault, privacy isn't just a feature—it's our foundation. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

1. Information We Collect

1.1 Information You Cannot Hide From Us

Due to the nature of internet technology, some information is necessarily visible to us:

1.2 Information We CANNOT See

Thanks to zero-knowledge encryption, we cannot access:

Important: We mathematically cannot decrypt your files. Even if compelled by law, we cannot provide plaintext access to your data.

2. How We Use Your Information

We use the minimal information we collect for:

2.1 Service Delivery

2.2 Service Improvement

2.3 Security and Fraud Prevention

2.4 Legal Compliance

3. Our Zero-Knowledge Encryption

Zero-knowledge encryption means we have zero knowledge of your data:

3.1 How It Works

  1. Client-Side Encryption: Files are encrypted in your browser/app before upload
  2. Key Derivation: Your password derives encryption keys using Argon2id (memory-hard algorithm)
  3. No Key Storage: We never receive, store, or have access to your encryption keys
  4. Post-Quantum Layer: Additional Kyber-768 encryption for future-proofing

3.2 What This Means for You

4. Data Sharing and Disclosure

4.1 We Do NOT Sell Your Data

We do not and will never sell, rent, or trade your personal information or metadata to third parties for marketing purposes. Period.

4.2 Service Providers

We share minimal data with trusted service providers:

4.3 Legal Requirements

We may disclose metadata (not file contents) if required by valid legal process:

We publish transparency reports detailing legal requests. We challenge overbroad requests and notify users when legally permitted.

5. Your Privacy Rights

5.1 Access and Portability

5.2 Deletion Rights

5.3 GDPR Rights (EU Users)

5.4 CCPA Rights (California Users)

6. Data Retention

7. International Data Transfers

Your encrypted data may be stored in multiple jurisdictions based on your settings. You can choose specific regions or let our AI optimize placement. All transfers comply with applicable data protection laws.

8. Children's Privacy

PrivVault is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us with information, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy. We'll notify you of significant changes via email or prominent notice in the app. Continued use after changes constitutes acceptance.

10. Security Measures

Contact Us About Privacy

If you have questions about this Privacy Policy or want to exercise your rights:

  • Email: privacy@privvault.com
  • Data Protection Officer: dpo@privvault.com
  • Mail: PrivVault Privacy Team, [Address]

We aim to respond to all privacy requests within 30 days.