Vault X
← Back to the vault

Nothing leaves your machine

Privacy Policy

Last updated: July 7, 2026 · Vault X by Hemant Suthar

Vault X ("the App") is a local-first encrypted file and note vault for Windows. Protecting your privacy is the App's core purpose. This policy explains what data the App does, and does not, collect.

1. No Data Collection

Vault X does not collect, store, or transmit any personal data. The App runs entirely offline on your device. There are no accounts, no sign-ups, no telemetry, no analytics SDKs, no crash reporters, and no third-party tracking of any kind.

All files, photos, notes, and metadata you store in the App are encrypted with AES-256-GCM and remain on your local machine. They are never sent over the network. To hide, lock, and restore files at the locations you choose (for example a document on any drive), the App requests broad file-system access; it uses this only to act on the specific files and folders you select, and never scans, reads, or transmits your files in the background.

2. Encryption

Vault X uses envelope encryption with the following layers:

Your PIN, password, and recovery phrase are never stored on disk in plaintext. Only wrapped (encrypted) key material is persisted.

3. Network Access

The App can make one optional network request:

No other network requests are made. The App requires no internet connection to function.

4. Windows Hello

If you enable Windows Hello (fingerprint, facial recognition, or Windows Hello PIN), the App stores an opaque encrypted blob on disk that can only be decrypted by your device's Trusted Platform Module (TPM) after a successful Hello gesture. This blob contains the wrapped Data Encryption Key, never your PIN or recovery phrase. Windows Hello biometric data never leaves your device and is managed entirely by Windows.

5. Local Storage

The App stores data only in the following locations under %LOCALAPPDATA%\Vault\:

All stored data is encrypted at rest with keys derived from your PIN or recovery phrase. No unencrypted file content is ever written to disk.

6. Third-Party Services

The App uses no third-party analytics, advertising, crash reporting, or tracking services. The only external service ever contacted is the Have I Been Pwned API (described in Section 3), and only with your explicit, opt-in action.

7. Data Deletion

You are always in control of your data and can erase it completely:

8. Children's Privacy

The App is not directed at children under the age of 13. It does not collect any personal information from any user, including children.

9. Changes to This Policy

If this policy changes in the future, the "Last updated" date at the top will be revised. Since the App does not collect data and cannot notify users of changes, you are encouraged to review this page periodically.

10. Contact

If you have questions about this privacy policy or the App's data practices, please contact:

Hemant Suthar
Email: hemantsuthar2810@gmail.com
Microsoft Store Publisher: Hemant Suthar

In short: Vault X is a local, offline, encrypted vault. It collects nothing. Your files stay your files. Your secrets stay your secrets.