Create your identity
Choose the name or pseudonym people will see. Vaultlix gives you a permanent private number.
Create a permanent Vaultlix private number, share it only with people you choose, and start encrypted one-to-one conversations.
With many messaging apps, deleted messages may remain recoverable from backups, stored copies, or device data.
Vaultlix minimizes retained message data and uses encryption and expiry controls so erased conversations are designed to remain inaccessible.
Vaultlix replaces invitation codes and manual room setup with a familiar, direct connection flow.
Choose the name or pseudonym people will see. Vaultlix gives you a permanent private number.
Share only your Vaultlix private number. Your phone number, email, and contacts stay private.
Enter the other person's number and send a request. A conversation appears after they accept.
Communicate inside an encrypted one-to-one space created automatically in the background.
Vaultlix separates the conversation from the identifiers that ordinary messengers often require. The security claims below describe the system precisely.
Vaultlix is a private one-to-one messenger. It does not require your phone number, email address, contact list, or real name.
A permanent, system-generated Vaultlix private number and the name or pseudonym you choose. The number is not a cellular number and cannot receive SMS or ordinary calls.
Exchange Vaultlix private numbers, enter their exact number, and send a connection request. Once accepted, Vaultlix creates the encrypted conversation automatically.
Yes. Messages are encrypted with keys held by the participants. Voice and video calls are encrypted between participant devices with DTLS-SRTP. A TURN service may relay encrypted call packets but cannot decrypt the call media.
No. Vaultlix does not search contacts or suggest people. Someone needs your exact private number before they can send a connection request.
No. Vaultlix is designed exclusively for private, one-to-one communication.
Create your Vaultlix identity, share only what you choose, and connect privately.
Nothing that identifies you in real life. Vaultlix requires no email address, phone number, or real name. Accounts use a system-generated Vaultlix private number and your chosen name or pseudonym.
What exists on our servers is:
Your session token is created by the server when you open or join a vault, then kept on your device too — in your browser's own localStorage, so the app can restore your open vaults if you reload or reopen it, and in IndexedDB if notifications are enabled, so a push notification can be matched to the right vault without a browser tab needing to be open. It travels with each request to prove you belong to that vault. It isn't a real-world identity and stops working when the vault closes. While a vault is open, its encrypted state and access tokens are periodically checkpointed to restricted persistent storage so it can survive service failures and backup restoration.
All messages are end-to-end encrypted using AES-256-GCM with keys generated in your browser. The server never sees your message content — only encrypted ciphertext that it cannot read.
Encrypted conversation ciphertext, vault membership data, chosen display names, notification routing details and access tokens are held in memory and periodically written as an atomic checkpoint to restricted persistent storage. This lets active vaults survive service failures, planned deployments and volume-backup restoration. Railway volume backups may retain a checkpoint until that backup expires or is deleted. Vaultlix still cannot decrypt message ciphertext. Closing or expiring a vault removes it from the live checkpoint; older backup copies remain subject to Railway's configured backup-retention period. Optional anonymous-account records—including opaque encrypted vault bundles and authentication verifiers—also persist so a user can restore access after reinstalling. Vaultlix cannot decrypt those bundles.
A vault and everything in it (messages, member names, subscriptions) is deleted immediately if either person uses "Close & erase." Otherwise, a temporary vault is automatically and permanently deleted after 24 hours of inactivity, measured from the last activity in that vault, not from when it was created. Simply closing your browser tab does not immediately delete a vault; the idle timer above is what eventually does. A permanent vault does not have an inactivity timer at all — it stays available indefinitely until someone uses "Close & erase" or revokes it from within the app, at which point it and everything in it are deleted the same way.
Disappearing-message timers, when enabled, delete an individual message from the server as soon as its timer expires, independent of the vault's own lifetime.
Files are encrypted in your browser before upload, transmitted as encrypted data, and delivered directly to the recipient. Files are not stored on our servers beyond the same vault lifetime described above.
Call signaling is encrypted with the vault's end-to-end encryption key. WebRTC then encrypts audio and video between the participants' devices using DTLS-SRTP. To prevent either participant from learning the other's IP address, Vaultlix routes call traffic through Cloudflare's TURN service instead of using a direct peer-to-peer network path. Cloudflare relays the already-encrypted media packets and processes the connection metadata required to operate that relay, but it cannot decrypt the call audio or video. Vaultlix does not record or store call media.
Vaultlix does not use cookies, analytics trackers, or advertising pixels, and does not use Google Analytics or an equivalent analytics service. Optional GIF search is provided by KLIPY as described below.
Vaultlix is hosted on Railway (railway.app). Railway may collect standard infrastructure logs including IP addresses. Please review Railway's privacy policy for details. We use Google Fonts for typography — fonts are loaded from Google's servers. Voice and video calls use Cloudflare's TURN service, which relays DTLS-SRTP-encrypted media packets and processes the connection metadata required to operate the relay but cannot decrypt call audio or video. Push notifications are delivered through Apple's and Google's respective push notification services, which see that a notification was sent to your device but not its content.
If you open the GIF picker, your device sends searches, language/region settings, and ordinary network information such as your IP address directly to KLIPY. When a GIF is displayed, the recipient's device loads it directly from KLIPY. The selected GIF reference is included inside the end-to-end encrypted Vaultlix message, but the GIF file itself is delivered by KLIPY and is not end-to-end encrypted by Vaultlix. Vaultlix does not send your private number to KLIPY or proxy, cache, or re-host KLIPY media.
Vaultlix is not intended for use by anyone under the age of 18. We do not knowingly collect information from minors.
Vaultlix is operated from India and this policy is governed by Indian law, as stated below. If you access Vaultlix from another country, you do so on the understanding that your data may be handled under Indian law; where the law of your own country grants you additional rights that cannot be waived, this policy does not limit those rights.
If we receive a valid legal request — a court order or a request from law enforcement made under applicable Indian law — we will review it and respond as required by law. What we can actually provide is limited by how Vaultlix is built: we can only disclose what exists in server memory at the moment the request is received (the encrypted content of an active vault, the display names in it, and whatever standard access logs Railway retains) — we cannot decrypt message content ourselves, and we cannot produce anything for a vault that has already been closed or has already expired, because nothing remains anywhere once that happens.
You can use Report and block in a vault's Safety settings, or contact legal@vaultlix.com, to report abuse, suspected illegal content, or a violation of our Terms of Service. An in-app report contains the selected reason, optional details, the report time, and one-way identifiers for the vault and reporter. Vaultlix cannot read encrypted conversations. Up to five recent decrypted text messages are included only when you expressly select that option; the confirmation explains that their plaintext will be shared with Vaultlix safety staff. Reports are access-restricted and automatically deleted after 90 days unless they must be retained longer to investigate an active safety matter or comply with law. We may act on a credible report by disabling or deleting the vault in question.
We may update this policy from time to time. Updates will be reflected on this page with a revised effective date.
This policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023.
Vaultlix is an anonymous, encrypted messaging, voice, and video-calling service. It allows two people to communicate privately without accounts or stored data. Vaults are temporary: they are deleted immediately when either person uses "Close & erase," and otherwise expire automatically after a period of inactivity, as described in our Privacy Policy.
You may use Vaultlix for any lawful purpose. You may not use Vaultlix to:
Vaultlix is provided "as is" without warranties of any kind. We do not guarantee that the service will be available, error-free, or suitable for your specific needs.
To the fullest extent permitted by law, Vaultlix and its operators shall not be liable for any direct, indirect, incidental, or consequential damages arising from your use of the service.
Your use of Vaultlix is also governed by our Privacy Policy.
We reserve the right to terminate or restrict access to Vaultlix at any time, for any reason, without notice.
To report suspected illegal activity, abuse, or a violation of the Acceptable use section above, contact legal@vaultlix.com. We may suspend, disable, or delete any vault without notice if we believe it violates these terms.
We will cooperate with valid legal process to the extent legally required. Because Vaultlix is deliberately built to retain as little as possible, what we're actually able to provide is limited to whatever exists in server memory at the time a request is received — see the Privacy Policy for exactly what that is, and what it no longer includes once a vault has closed or expired.
These terms are governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of courts in Chennai, Tamil Nadu.
For any questions regarding these terms, contact us at legal@vaultlix.com
A private chat app for two people — no phone number or email required, nothing we can read. Your system-generated Vaultlix private number preserves encrypted vault access across devices.
No. Vaultlix does not require a phone number, email or real name. It gives you a system-generated Private Number for sign-in, recovery and exact-number connections.
Vaultlix uses a system-generated Private Number and an opaque encrypted vault bundle; no phone number, email or real name is collected. The Private Number is not a cellular number and cannot receive SMS or ordinary calls.
Yes. Messages are end-to-end encrypted with keys held by the participants. WebRTC call audio and video is encrypted between participant devices with DTLS-SRTP. Cloudflare TURN relays the encrypted packets to hide participants' IP addresses from each other, but cannot decrypt the call media. In guest mode private keys remain local. If encrypted sync is enabled, vault credentials are wrapped inside a separate client-encrypted account bundle before upload; Vaultlix cannot decrypt that bundle.
It's deleted immediately, for both people, along with everything inside it. Not archived, not hidden — gone.
A temporary vault is for one conversation and expires within a day. A permanent vault never expires — reopen it anytime with the same code.
No — Vaultlix is built for one-to-one conversations only.