← CJ Designs
My Secure Vault — Privacy Policy
Effective 11 July 2026
My Secure Vault is a password manager made by CJ Designs, built on a zero-knowledge architecture: your master password, and the vault data it protects, never leave your device in a form that we — or anyone else — can read.
We never see your master password, and we never see your vault in the clear. Everything is encrypted on your own device, using a key derived from your master password, before anything is ever sent anywhere. If you enable optional cloud sync, our backend only ever stores and transmits opaque encrypted data it cannot decrypt.
What we collect
- Encrypted vault data (only if you enable optional cloud sync) — the titles, usernames, passwords, notes, URLs, categories and tags for every item you save, all encrypted on your device before being sent. We cannot decrypt this data ourselves.
- Account details (only if you enable optional cloud sync) — an email address and password, or a Google/Apple sign-in identity, used solely to identify which account your encrypted vault data belongs to.
- Anonymous device security diagnostics — to help detect tampering, rooted/jailbroken devices, or known malicious apps that could put your vault at risk, we use a third-party security library (Talsec's freeRASP). This library sends anonymous technical diagnostics — an anonymous app-instance ID and device identifier, never your vault contents, master password, or personal information — to Talsec's servers for security reporting and product improvement. See Talsec's own data policy for details.
What we don't collect
- We never see your master password, in any form.
- We never see the plaintext contents of your vault — even with cloud sync enabled, everything is encrypted on your device first.
- No advertising identifiers, no ads, and no analytics or tracking beyond the anonymous security diagnostics described above.
- No access to your photo library, files, or contacts beyond what you explicitly choose to attach as a Secure Document or export as an encrypted backup.
How your data is used
Encrypted vault data exists solely so your vault can sync between your own devices — since we cannot read it, we cannot use it for anything else. Account details are used only to sign you in. We do not sell, rent, or share your data with third parties for advertising or marketing.
Where it's stored and how it's protected
On your device, your vault is stored in a SQLCipher-encrypted local database, with an additional layer of AES-256 encryption on your passwords and notes. The encryption key is derived from your master password using Argon2id and is never stored anywhere — including by us. If you enable cloud sync, your already-encrypted vault data and account details are stored via our backend provider, Supabase.
Encrypted backups
If you export an encrypted backup of your vault, the file is created and encrypted on your device, and saved wherever you choose (your device's storage, a cloud drive, etc.). We never receive a copy of it.
Permissions the app asks for
- Face ID / Touch ID / biometrics — used only to unlock your vault on your own device. Biometric data is handled entirely by your device's operating system and never reaches us.
- Photo library — only used if you choose to attach a photo as a Secure Document, which is then encrypted and stored in your vault.
- Files — used only when you choose to import a Secure Document, or to save/open an encrypted backup file you export or restore.
Data retention and deletion
If you use cloud sync, your encrypted vault data and account details are kept for as long as your account exists. To delete your account and all associated data, email support@cjdesigns.app from your registered email address and we will remove it.
Children
My Secure Vault is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new effective date.
Contact
CJ Designs — support@cjdesigns.app