SysFenix Vault — Privacy Policy

Last updated: August 9, 2026

SysFenix Vault is an Android app that stores your photos and videos in an encrypted vault on your device. This policy describes what the app does with your data. The short version: your media never reaches us, we collect nothing, and we could not read your data even if we wanted to.

Your media is encrypted on your device

Everything you put in the vault is encrypted on your phone with AES-256, using keys derived from your password with Argon2id. The password never leaves your device and is not stored anywhere. We operate no server, receive no copy of your media, and hold no key that could decrypt it.

When you import a photo or video, the app removes the original from the phone's gallery (with your confirmation through the Android system dialog), so your media exists only inside the encrypted vault.

We collect nothing

The app has no user accounts, no analytics, no telemetry, no crash reporting, no advertising and no tracking of any kind. It makes no network connections at all, with one exception: the optional cloud backup described below, which only ever happens because you set it up.

Optional cloud backup, to storage you own

You can connect the app to your own Google Drive or Dropbox account to back up the vault. What is uploaded is the encrypted data only — the same ciphertext that sits on your device. Your password and decryption keys are never uploaded, so the backup is as unreadable to Google, Dropbox or anyone who obtains it as it is to us.

Backups go to app-scoped storage inside your own account (Google Drive's app data folder, or a dedicated Dropbox app folder). Sign-in happens directly with Google or Dropbox on your device; those services are governed by their own privacy policies. SysFenix Vault's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: the only Google user data the app touches is the encrypted vault content it stores in, and restores from, your Drive app data folder.

There is no password recovery

This is by design. Because we hold no copy of your password and no key, nobody — including us — can recover your data if you forget your password. There is no reset email, no support backdoor, and no way for anyone who takes your phone or your backup to bypass the encryption.

Camera permission and intruder detection

The app has an optional, off-by-default intruder detection feature: if someone enters a wrong password, the app records the time and can take a photo with the front camera. Enabling it is what triggers the Android camera permission request. Those photos are stored only on your device, are never uploaded anywhere (they are not part of the cloud backup), and can be viewed and deleted in the app's security log. If you never enable the feature, the camera is never used.

Deleting your data

Deleting an item in the app permanently removes it from the vault, and the deletion is applied to your cloud backup as well the next time the app syncs. Uninstalling the app removes all of its local data. If you used cloud backup, you can remove the backup from inside the app or directly from your own Google Drive or Dropbox account settings, where app-scoped data can be deleted per app.

Changes to this policy

If the app's behavior ever changes in a way that affects this policy, we will update this page and its date before the change ships.

Contact

Questions about this policy or the app? Email javi@moralesf.com.