1. Plain-language summary
NexusVault is designed to minimize what the server can see. Sensitive vault content is encrypted in your browser before it is sent to the server.
We can see some information needed to operate the service, such as your email address, session metadata, and technical security data. We should not be able to read your passwords, secure notes, or cards in plaintext.
2. Account data we collect
We collect information you provide when creating and using your account: name, email address, language preference, theme, profile picture if you add one, and email verification status.
If you use OAuth, we receive the necessary information from the provider you choose, such as the OAuth identifier, name, and email address linked to that account. If you use a passkey, we store public verification data, never your biometric data.
3. Vault data
Vault items are stored in encrypted form. This may include encrypted blobs, cryptographic salts, encrypted keys, encrypted share payloads, and metadata needed for synchronization.
The server may process metadata such as the existence of an item, a share recipient, an acceptance status, or an update time. The zero-knowledge model is designed to prevent the server from reading the secret content of the item.
4. Technical data and logs
To protect the service, diagnose errors, and prevent abuse, we may process IP addresses, browser information, timestamps, requested routes, application errors, and session information.
This data should be used for security, maintenance, fraud prevention, or legal compliance, not for selling your advertising profile.
5. Providers and processors
NexusVault may use providers for hosting, email delivery, DNS/CDN, OAuth authentication, and technical infrastructure. Examples include a VPS host, a transactional email service, and the OAuth providers you choose.
These providers do not receive your plaintext vault password from us. OAuth providers may apply their own privacy policies when you use their sign-in button.
6. Retention, deletion, and recovery
We keep account and vault data while your account exists or while it is needed to provide the service, secure the platform, or comply with the law.
When you delete your account, NexusVault deletes associated data where reasonably possible. Some technical logs may be retained temporarily for security, backups, or legal obligations.
7. Your choices
You can update your profile, change language, manage sessions, delete passkeys, remove vault items, revoke shares, and delete your account from the application.
You can also ask privacy questions or report an issue at privacy@nexusvault.dev.
8. Security incidents
If a security incident affects personal information, we will investigate, take mitigation steps, and communicate with affected people when the situation requires it.