Nothing leaves your machine
Last updated: July 7, 2026 · Vault X by Hemant Suthar
Vault X ("the App") is a local-first encrypted file and note vault for Windows. Protecting your privacy is the App's core purpose. This policy explains what data the App does, and does not, collect.
Vault X does not collect, store, or transmit any personal data. The App runs entirely offline on your device. There are no accounts, no sign-ups, no telemetry, no analytics SDKs, no crash reporters, and no third-party tracking of any kind.
All files, photos, notes, and metadata you store in the App are encrypted with AES-256-GCM and remain on your local machine. They are never sent over the network. To hide, lock, and restore files at the locations you choose (for example a document on any drive), the App requests broad file-system access; it uses this only to act on the specific files and folders you select, and never scans, reads, or transmits your files in the background.
Vault X uses envelope encryption with the following layers:
Your PIN, password, and recovery phrase are never stored on disk in plaintext. Only wrapped (encrypted) key material is persisted.
The App can make one optional network request:
No other network requests are made. The App requires no internet connection to function.
If you enable Windows Hello (fingerprint, facial recognition, or Windows Hello PIN), the App stores an opaque encrypted blob on disk that can only be decrypted by your device's Trusted Platform Module (TPM) after a successful Hello gesture. This blob contains the wrapped Data Encryption Key, never your PIN or recovery phrase. Windows Hello biometric data never leaves your device and is managed entirely by Windows.
The App stores data only in the following locations under
%LOCALAPPDATA%\Vault\:
All stored data is encrypted at rest with keys derived from your PIN or recovery phrase. No unencrypted file content is ever written to disk.
The App uses no third-party analytics, advertising, crash reporting, or tracking services. The only external service ever contacted is the Have I Been Pwned API (described in Section 3), and only with your explicit, opt-in action.
You are always in control of your data and can erase it completely:
%LOCALAPPDATA%\Vault\ folder to erase everything immediately.The App is not directed at children under the age of 13. It does not collect any personal information from any user, including children.
If this policy changes in the future, the "Last updated" date at the top will be revised. Since the App does not collect data and cannot notify users of changes, you are encouraged to review this page periodically.
If you have questions about this privacy policy or the App's data practices, please contact:
Hemant Suthar
Email: hemantsuthar2810@gmail.com
Microsoft Store Publisher: Hemant Suthar