๐Ÿ”

VaultChat Privacy Policy

Effective Date: May 10, 2026 ยท Last Updated: May 11, 2026

Plain-English Summary

VaultChat is end-to-end encrypted. We can't read your messages, listen to your calls, or watch your video. The math doesn't allow it โ€” your private key never leaves your device, and the encrypted blobs that pass through our servers are useless without it.

What we do collect, briefly:

  • An email address or phone number for sign-up & verification
  • A handle and (optional) display name and avatar so people can find you
  • Encrypted message ciphertext, so we can deliver it to your contacts
  • Minimal account metadata (online status timestamps, push tokens for incoming calls, IAP subscription records)

We don't sell your data. We don't currently show third-party ads in any tier. We don't profile you. The full details follow below.

1. Who We Are

VaultChat is operated by AUXXILUS MEDIA LLC, a New Jersey limited liability company headquartered in Glassboro, New Jersey, United States.

For privacy questions, contact privacy@vaultchat.co. For general support, contact support@vaultchat.co.

This Privacy Policy describes how we collect, use, share, and protect personal information when you use the VaultChat mobile app (the "Service"). It applies to everyone who uses VaultChat, anywhere in the world.

2. What We Collect โ€” and What We Don't

Information you provide at sign-up

  • Email address (or phone number) โ€” to create your account and verify it's you
  • Handle (e.g. @yourname) โ€” your unique public identifier within VaultChat
  • Display name and avatar (optional) โ€” what other users see when you message them
  • Password โ€” never stored in cleartext; we store only a one-way hash that we cannot reverse

Information stored only on your device

The following are stored locally on your phone, never transmitted to our servers:

  • Your NaCl private key โ€” the secret half of the encryption keypair that decrypts messages addressed to you. If you lose it (e.g., you uninstall the app without backing it up), prior messages cannot be decrypted, even by us.
  • Your Real PIN, Decoy PIN, and Vault PIN
  • Your cached message history (stored encrypted at rest by iOS Data Protection)
  • Your chat folder definitions, contact name overrides, theme preference, and other UI preferences
  • Your blocked users list (mirrored from our server for offline filtering)

Information we receive when you use VaultChat

CategoryWhy we have it
Encrypted message ciphertext (text, photos, videos, voice notes, files) To deliver the message to its recipient. We see only the encrypted blob and the sender / recipient identifiers โ€” we cannot decrypt it.
Public encryption key So your contacts can encrypt messages to you.
Online presence + last-seen timestamps To show your contacts when you're online (subject to your privacy settings).
PushKit (VoIP) device tokens To wake your phone and ring CallKit when someone calls you, even if VaultChat has been killed by iOS. The token is provided by Apple and is meaningless outside of APNs.
Group membership and group metadata (name, description, photo) So group messages route correctly. Group names and descriptions are not encrypted.
Reports of policy-violating content So our safety team can review reports and take action. See "User reports" below.
Subscription receipts (if you purchase Premium) To verify your subscription status with Apple and unlock paid features. We store the receipt, the product ID, the transaction ID, and the expiration date โ€” never your payment method.
WebRTC signaling messages To set up direct phone-to-phone connections for voice and video calls. The actual call audio and video flow peer-to-peer (or via TURN relay if peer-to-peer fails) โ€” they never reach our application servers.

What we do not collect

  • The plaintext contents of any message, photo, video, voice note, file, or call
  • Your phone's contact list (we never upload your address book โ€” see "Contact discovery" below)
  • Your location (unless you choose to share a location pin in a message)
  • Browsing history, web tracking data, or behavioral profiles
  • Advertising identifiers (currently). If we add advertising to the free tier in the future, this section will be updated and users notified.
  • Biometric data (Face ID / Touch ID happens on your device; we never see the result)

Diagnostic information (optional)

If the app crashes or hits a serious error, iOS may offer to share an anonymous crash report with us. You can disable this in iOS Settings โ†’ Privacy & Security โ†’ Analytics & Improvements. We use crash data only to fix bugs.

3. Contact Discovery

To help you find friends already on VaultChat, we offer optional contact sync. Here's exactly how it works:

  • VaultChat asks for permission to read your phone contacts. You can decline โ€” the app still works.
  • If you grant permission, VaultChat normalizes each phone number on your device into E.164 format and computes a one-way SHA-256 hash of each one.
  • Only the hashes are sent to our server, where we check whether any of them match the hashed phone numbers of registered VaultChat users.
  • We return only the matches. We do not store the unmatched hashes. We never see the actual phone numbers from your address book, and we never see the names you have for them.
  • You can disable contact sync at any time and revoke iOS permission in Settings โ†’ VaultChat โ†’ Contacts.

4. End-to-End Encryption

VaultChat uses the NaCl (TweetNaCl) public-key authenticated encryption primitive โ€” specifically crypto_box_curve25519xsalsa20poly1305 โ€” for one-to-one and group messages. When you send a message:

  • Your device fetches the recipient's public key from our key directory.
  • Your device combines that public key with your own private key to derive a shared secret.
  • Your device encrypts the plaintext with that shared secret and a random nonce.
  • Only the ciphertext, the nonce, and the sender / recipient identifiers travel to our server.
  • The recipient's device performs the inverse operation to recover the plaintext.

Because the shared secret is derived locally on each device using each party's private key, the server has no way to derive that secret and cannot decrypt the ciphertext. This is mathematically true, not policy-true โ€” it does not rely on us promising not to look.

For voice and video calls, audio and video stream peer-to-peer over WebRTC with mandatory DTLS-SRTP encryption. Where direct peer-to-peer fails (typically because both parties are behind restrictive NATs), traffic is relayed through a TURN server but stays encrypted end-to-end โ€” the relay sees only encrypted UDP packets.

The limits of end-to-end encryption you should understand:

  • Group names, group descriptions, your handle, your display name, and your avatar are not encrypted. They need to be readable for the service to function.
  • Online presence and last-seen timestamps are not encrypted.
  • If you choose to forward a copy of a message in a Report, that forwarded copy arrives unencrypted to our safety team โ€” by your explicit consent.
  • If your device is unlocked and in someone else's hands, they can read your messages. Encryption protects content in transit and at rest on our servers; it cannot protect content from a person physically using your unlocked phone.

5. How We Use Your Information

We use the information described above to:

  • Operate the service โ€” deliver messages, place calls, register your account, send verification emails
  • Keep VaultChat safe โ€” review reports, enforce our Community Guidelines and Child Safety Policy, detect abuse and ban evasion
  • Provide customer support โ€” respond to support emails and account inquiries
  • Process subscriptions โ€” verify Apple receipts, unlock Premium features, send renewal reminders
  • Comply with legal obligations โ€” respond to lawful law-enforcement requests, report apparent CSAM to NCMEC under 18 U.S.C. ยง 2258A, retain records as required by law
  • Improve the service โ€” diagnose bugs from crash reports, plan capacity

We do not use your information to:

  • Train AI or machine-learning models on your messages
  • Target you with third-party advertising (currently โ€” see notice at top of this policy regarding future changes)
  • Build behavioral profiles
  • Sell or rent your data to anyone, ever

6. Who We Share Information With

We share personal information only with the service providers we need to operate VaultChat, with law enforcement when legally required, and in the limited safety scenarios described in our Child Safety Policy. We do not share your data with advertisers, data brokers, or analytics companies under our current configuration. If we add a third-party advertising network in the future, that network will be listed in our Third-Party Services section and disclosed before any data sharing begins.

Service providers (sub-processors)

ProviderRoleData they touch
Supabase Authentication + database hosting Account records, encrypted message ciphertext, push tokens, subscription records
Railway Realtime signaling server (Node.js + socket.io) Live socket sessions, WebRTC signaling messages (offer/answer/ICE candidates), in-flight encrypted messages. Nothing is persisted beyond the active session.
Apple App Store, In-App Purchase, Apple Push Notification service (APNs / PushKit), CallKit Subscription receipts, push tokens, the existence and timing of incoming calls
Resend Transactional email (verification, password reset) Email addresses and message bodies for verification messages
Twilio SMS verification (toll-free +1 (866) 496-1347) Phone numbers and verification codes โ€” used only for sending the SMS, not stored beyond delivery
National Center for Missing & Exploited Children (NCMEC) CyberTipline reports of apparent child sexual abuse material The contents of any CSAM report we receive, plus the relevant account metadata, as required by 18 U.S.C. ยง 2258A

Law enforcement

We respond to lawful preservation requests, subpoenas, court orders, and search warrants from law enforcement agencies that comply with applicable law. We do not voluntarily disclose user information except in the narrow circumstances permitted by law (e.g., emergency disclosure under 18 U.S.C. ยง 2702(b)(8)).

Because the contents of your messages are end-to-end encrypted, the data we can produce in response to a lawful request is limited to the information described in Section 2 โ€” primarily account metadata, subscription history, encrypted blobs we cannot decrypt, and (where applicable) any content a user explicitly forwarded to us through the in-app Report flow.

Business transfers

If AUXXILUS MEDIA LLC is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may transfer to the successor entity. We will notify you (by email or in-app) before your information becomes subject to a different privacy policy.

7. International Data Transfers

VaultChat is operated from the United States. If you use VaultChat from outside the U.S., your information will be transferred to and processed in the U.S. The U.S. has data-protection laws that differ from those of your country and may not provide the same level of protection.

If you are in the European Economic Area, the United Kingdom, or Switzerland, transfers of your personal information to the U.S. and to our sub-processors are made on the basis of (a) the European Commission's Standard Contractual Clauses, (b) sub-processor self-certification under the EUโ€“U.S. Data Privacy Framework, or (c) your consent.

8. Data Retention

We retain personal information for as long as your account is active, plus the additional periods described below, after which we delete or anonymize it.

  • Encrypted message ciphertext โ€” retained on our server in an in-memory rolling buffer of the most recent 500 messages per chat. Older messages exist only on your device.
  • Account record โ€” retained while your account is active. On account deletion, the record is removed within 30 days, except as noted below.
  • Handle reservation โ€” your handle is held for 30 days after account deletion, then released for reuse.
  • Reports โ€” retained for the period necessary to investigate, enforce against repeat offenders, and meet legal obligations. Reports involving apparent CSAM are retained for the period required by 18 U.S.C. ยง 2258A (currently 90 days, extendable on request from law enforcement).
  • Banned-account records โ€” retained indefinitely so that re-registration attempts can be detected and blocked.
  • Subscription receipts โ€” retained for as long as required for tax, audit, and dispute-resolution purposes (typically 7 years).
  • Backups โ€” backups containing your data may persist for up to 35 days after deletion before they are overwritten on the normal rotation.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and associated personal information (Settings โ†’ Privacy โ†’ Delete Account)
  • Port a copy of your account data in a structured, commonly-used format
  • Object to or restrict certain processing
  • Withdraw consent for processing that is based on consent (e.g., contact sync)
  • Lodge a complaint with your local data-protection authority

To exercise any of these rights, email privacy@vaultchat.co from the address associated with your account. We will verify your identity before acting on your request and respond within the timeframe required by applicable law (generally 30 days).

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act gives you the rights described in Section 9 above, plus:

  • The right to know the categories of personal information we collect, the sources, the business purposes, and the categories of third parties we share it with โ€” all of which is disclosed throughout this Privacy Policy.
  • The right to opt out of the "sale" or "sharing" of your personal information. VaultChat does not currently sell or share your personal information for cross-context behavioral advertising. If we add advertising in the future, we will provide a Do Not Sell or Share My Personal Information mechanism in the app at that time.
  • The right not to be discriminated against for exercising your privacy rights.

To exercise California rights, email privacy@vaultchat.co. You may designate an authorized agent to make a request on your behalf.

11. European / UK Privacy Rights (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, our lawful bases for processing your personal information are:

  • Performance of a contract โ€” to deliver the messaging service you asked for when you created your account
  • Legitimate interests โ€” to keep VaultChat safe, secure, and free of abuse, and to defend our legal rights
  • Legal obligation โ€” to comply with applicable law, including child-safety reporting under 18 U.S.C. ยง 2258A
  • Consent โ€” for processing that requires it, such as contact sync or sending a forwarded copy of content with a Report. You may withdraw consent at any time.

If you have a complaint, you may contact your national data-protection authority. We will work with you to resolve any dispute first, and we encourage you to do so by emailing privacy@vaultchat.co.

12. Children's Privacy

VaultChat is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to VaultChat, contact us at privacy@vaultchat.co and we will promptly delete the account.

For users aged 13โ€“17, parental or guardian consent is required, as described in our Terms of Service.

13. Security

We protect your personal information through:

  • End-to-end encryption of message contents (NaCl box) and call media (DTLS-SRTP), as described in Section 4
  • TLS 1.2+ for every connection between the app and our servers, even though the payload is already separately encrypted
  • Hashed PINs stored only in iOS Secure Enclave / Keychain
  • Row-level security (RLS) on every database table, enforced by Postgres before any query result is returned
  • Least-privilege access โ€” only a small number of named individuals at AUXXILUS MEDIA LLC have administrative access, and access is logged
  • Service-provider vetting โ€” every sub-processor listed in Section 6 has signed a data-processing agreement with us

No system is perfectly secure. If you become aware of a security issue affecting VaultChat, please report it responsibly to security@vaultchat.co.

14. Changes to This Policy

We may update this Privacy Policy as VaultChat evolves and as the law changes. Material changes will be reflected in the "Last Updated" date at the top of this page. For changes that meaningfully expand the categories of data we collect or the purposes for which we use it, we will notify you by email or in-app before the change takes effect.

15. Contact

  • Email: privacy@vaultchat.co
  • Website: vaultchat.co
  • Address: AUXXILUS MEDIA LLC, 11 Hetton Court, Glassboro, NJ 08028
ยฉ 2026 AUXXILUS MEDIA LLC. All rights reserved.
Terms ยท Community Guidelines ยท Child Safety Policy ยท Support