Legal

Privacy Policy

Last updated: 11 August 2026

Summary

Weave Vault is a local encrypted vault. Your photos, videos, files, pattern, and recovery phrase stay on your device. There are no user accounts, and we do not collect analytics, crash reports, or usage telemetry.

With every optional feature switched off, the app makes no network requests at all. Two features are exceptions, both opt-in, and both are described in full below: encrypted backup, which sends encrypted data to a cloud account you control, and secure sharing, which sends encrypted data to Apple and a small amount of non-content bookkeeping to a service we operate. Even then, your files and your keys remain unreadable to us.

What we collect

We do not collect your photos, videos, files, metadata, thumbnails, pattern, or recovery phrase. There is no sign-up, no login, no account identifier, and no device fingerprint. We run no analytics, no crash reporting, and no advertising or attribution SDKs, in the app or on this website.

The single exception is the sharing gate described under Secure sharing. If you never create a share, we hold no records about you of any kind.

What stays on your device

The following is created and stored only on your device, inside the app’s encrypted storage:

Your unlock pattern is never stored — not as a file and not as a hash. It is used only to derive a key in memory during unlock and is discarded immediately afterwards.

Your recovery phrase is shown once, when you create a vault. Recording and storing it safely is your responsibility. We do not keep a copy. If you lose both your pattern and your recovery phrase, that vault cannot be recovered by anyone, including us.

Vault storage is excluded from your device’s ordinary cloud backup and device-transfer paths, so a routine backup of your phone does not contain your vault.

Optional features that use the network

Encrypted backup

Backup is off by default and must be turned on explicitly. When enabled, the app uploads a copy of your vault storage to a cloud account you control — your private iCloud database on iPhone and iPad, or the hidden application folder of your Google Drive on Android.

What is uploaded is the same ciphertext held on your device. No vault key and no plaintext ever leaves the device. Apple or Google therefore store data they cannot read, under their own privacy policies and your existing relationship with them. We are not a party to this transfer — the data goes from your device to your cloud account, and we neither receive it, see it, nor hold credentials for it.

Turning backup off deletes the copy from your cloud account. You can also remove it yourself through Apple’s or Google’s own storage-management tools.

Secure sharing

Sharing is off unless you create a share. When you do, the app uploads a re-encrypted, point-in-time copy of that vault to Apple’s public CloudKit database, and registers the share with a gate service we operate on Cloudflare.

The decryption key is split. One half derives from the one-time phrase shown to you and never leaves your device or the recipient’s. The other half is held by the gate and released only when a recipient opens a share that has not expired and has not been revoked. Neither half decrypts anything alone, which is what allows expiry and revocation to be enforced rather than merely promised.

For each share you create, the gate stores only:

The gate never receives your files, your phrase, your pattern, your vault keys, your name, your email, or a device identifier. It cannot decrypt anything, because it holds only one half of a split key and never sees the other.

Retention. Share records are deleted automatically when the share expires or is revoked, and the encrypted contents are removed from Apple’s servers at the same time. Rate-limiting records are transient and expire on their own. IP addresses are used only for rate limiting; we do not build profiles from them, and they are not associated with share contents or with any identity.

If you never create a share, none of the above applies to you and no record about you exists.

Device permissions we request

Weave Vault asks the operating system for the following, only when you start an action that needs them:

We do not request location, contacts, or microphone access. Originals you import from your photo library or files app remain there unless you delete them yourself.

Third parties

Apple. The App Store and StoreKit handle distribution and in-app purchases on iOS. If you enable backup, your encrypted vault data is stored in your own private iCloud database. If you create a share, the encrypted share contents are stored in Apple’s CloudKit service. Apple’s handling is governed by Apple’s Privacy Policy.

Google. Google Play and Google Play Billing handle distribution and in-app purchases on Android. If you enable backup, your encrypted vault data is stored in the hidden application folder of your own Google Drive, governed by Google’s Privacy Policy.

Cloudflare. The sharing gate described above runs on Cloudflare’s infrastructure, which processes the requests on our behalf as a service provider. This site is also hosted on Cloudflare Pages; Cloudflare may process standard request information such as IP addresses for security and delivery purposes as part of serving it.

From Apple and Google we receive only entitlement status — whether a subscription or purchase is active. We do not receive your name, email, payment details, or any other personal information. No analytics, crash reporting, advertising, or attribution services are integrated anywhere.

Subscriptions and purchases

Weave Vault Pro is available as a monthly subscription, an annual subscription with a 7-day free trial, or a one-time lifetime purchase. Payments are processed by Apple on iOS and Google Play on Android. Cancel at any time in Settings → [your name] → Subscriptions on iOS or Google Play Store → Subscriptions on Android. Refunds are handled by the relevant store under its own policy.

Children’s privacy

Weave Vault is rated for general audiences and does not knowingly collect personal information from children. Because the app collects no personal information from anyone, this holds regardless of the user’s age.

Your rights

Privacy laws including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and India’s Digital Personal Data Protection Act (DPDP) give you rights of access, correction, deletion, and portability over personal data held about you.

We hold no personal data about you. The only records we hold at all are the per-share bookkeeping described above, which contains no identifier tied to you and is deleted automatically at expiry — and which you can delete at any time by revoking the share in the app. Everything else lives on your device: delete a vault from inside the app, or uninstall the app, and it is gone.

If you have a question about any of this, write to us at the address below and we will answer it.

Changes to this policy

If we materially change this policy we will update the date above and, where appropriate, note it in an app update’s release notes. Continued use after a change indicates acceptance.

Contact

Questions about this policy: privacy@weavevault.app.

General support: support@weavevault.app.