DigiVault is a private, encrypted vault for photos, videos and documents. It is built so that your files stay on your phone. This page explains, plainly, what the app does with your data and what it does not.
Everything you put in a vault is encrypted with AES-256-GCM using a key derived from your vault password (PBKDF2-HMAC-SHA256, 120,000 iterations). The password itself is never stored. Your vault database, thumbnails and media files exist only inside the app's private storage on your device. If you forget your password and do not have your recovery key, the contents cannot be recovered – by you or by anyone else.
Photos you import keep the information already inside them, including any location tag the camera added. That information is encrypted along with the photo and is never read or sent by the app.
You can share a vault by link, or keep a vault in sync with another person's phone. In both cases:
Sharing and sync only happen when you start them. If you never share, the app never connects to anything.
| Permission | Why the app asks for it |
|---|---|
| Photos and videos | To show your gallery so you can choose what to import into a vault, including whole albums. Nothing is read until you pick it. |
| Media location | So an imported photo keeps its original location tag inside the vault, exactly as the camera saved it. It is encrypted with the photo and never sent anywhere. |
| Camera | Only to scan the pairing code shown on the other person's screen when you set up sync. No image is saved. |
| Internet and network state | For share links and sync, and to reconnect promptly when your network comes back. Nothing is sent unless you share or sync. |
| Foreground service and notifications | To keep a share link streaming while your screen is off. The notification shows only that the app is open – never a count, a name or any content. |
| Wake lock | To keep the screen on while a sync is running so a transfer is not cut off. |
| Receive boot completed | Declared by the foreground-service library the app uses. DigiVault does not start itself at boot and cannot: a vault only opens when you type its password. |
You can export an encrypted backup of a vault to a location you choose. The backup is encrypted exactly like the vault and can only be opened with that vault's password or recovery key. Recovery keys are shown to you once and are never stored in readable form.
Purchases are handled by Google Play. The app never sees or stores your card or payment details.
None. The app does not transmit any information about you or your device to us. There is nothing for us to sell, share or lose.
Delete a vault inside the app, or uninstall the app. Because nothing is stored anywhere else, that is the whole process. There is no server-side copy to request deletion of.
DigiVault is not directed at children and does not knowingly collect information from anyone, of any age.
If this policy changes, the new version will be published at this address with a new effective date.
Questions about this policy: dudhaiya@gmail.com