← Back to Vaultlix
Vaultlix

Privacy Policy

Effective date: 16 September 2026 · vaultlix.com
The short version: We don't ask for your public identity, and we can't read your conversations. When a conversation is erased, its live contents and access are removed — see below for exactly what that covers.

What we collect

Vaultlix requires no email address, phone number, or real name. Accounts use a system-generated Vaultlix private number and your chosen username. Adding a profile image is optional.

What exists on our servers is:

  • The encrypted content of messages, retained so it can be delivered to the other person for the conversation's lifetime; see "How long things last" below
  • The display name each person chooses for their Vaultlix identity
  • An optional profile image, if you add one. It is shown to people who use your exact Private Number or connect with you, and is removed when you remove it or delete your account.
  • If notifications are enabled, a Web Push subscription (an endpoint address tied to your device, provided by Apple's or Google's push service) so a message or call can wake the app
  • Memory-hard authentication verifiers for identity sign-in — never the password itself
  • Standard server access logs generated by Railway (our hosting provider) which may include IP addresses and request timestamps
  • Anonymous, aggregate usage counts (for example, how many conversations are active) — never linked to a readable conversation, private number, or message
  • Your system-generated Private Number, chosen display name, optional profile image, encrypted key wrappers, active-session verifiers, and an opaque encrypted account bundle containing conversation credentials. We do not receive the password, recovery code, readable conversation list, access tokens, or private keys.

A conversation access token is created after a connection is accepted and kept on your device so the app can restore your conversations and route notifications correctly. It proves access to that conversation without being a real-world identity. Active encrypted state and access tokens are checkpointed to restricted persistent storage so the service can survive failures and backup restoration.

How messages work

All messages are end-to-end encrypted using AES-256-GCM with keys generated in your browser. The server never sees your message content — only encrypted ciphertext that it cannot read.

Encrypted conversation ciphertext, participant access data, chosen display names, notification routing details and access tokens are written to restricted persistent storage. Encrypted image and file payloads are kept in private object storage; the conversation database retains only opaque storage references and delivery metadata. This lets conversations survive service failures and planned deployments. Infrastructure backups may retain an encrypted copy until the backup expires or is deleted; Vaultlix still cannot decrypt message or attachment ciphertext. Account records—including opaque encrypted account bundles and authentication verifiers—persist so a user can restore access after reinstalling.

How long things last

A conversation and its live message state are deleted immediately if either person uses "Close & erase." Established private-number connections remain available until someone closes them. Older encrypted infrastructure backups remain subject to the provider's configured retention period.

Disappearing-message timers, when enabled, delete an individual message from live storage as soon as its timer expires.

File attachments

Files are encrypted on your device before upload to private object storage and can only be decrypted by participants in that conversation. Access links are short-lived and require current conversation membership. Files follow the same conversation retention controls described above.

Voice and video calls

Call signaling is encrypted with the conversation's end-to-end encryption key. WebRTC then encrypts audio and video between participant devices using DTLS-SRTP. To prevent either participant from learning the other's IP address, Vaultlix routes call traffic through Cloudflare's TURN service. Cloudflare relays encrypted media packets and processes the connection metadata required to operate that relay, but cannot decrypt call audio or video. Vaultlix does not record or store call media.

Cookies and tracking

Vaultlix does not use cookies, analytics trackers, or advertising pixels, and does not use Google Analytics or an equivalent analytics service. Optional GIF search is provided by KLIPY as described below.

Third-party services

Vaultlix is hosted on Railway (railway.app). Railway may collect standard infrastructure logs including IP addresses. Please review Railway's privacy policy for details. We use Google Fonts for typography — fonts are loaded from Google's servers. Voice and video calls use Cloudflare's TURN service, which relays DTLS-SRTP-encrypted media packets and processes the connection metadata required to operate the relay but cannot decrypt call audio or video. Push notifications are delivered through Apple's and Google's respective push notification services, which see that a notification was sent to your device but not its content.

If you open the GIF picker, your device sends searches, language/region settings, and ordinary network information such as your IP address directly to KLIPY. When a GIF is displayed, the recipient's device loads it directly from KLIPY. The selected GIF reference is included inside the end-to-end encrypted Vaultlix message, but the GIF file itself is delivered by KLIPY and is not end-to-end encrypted by Vaultlix. Vaultlix does not send your private number to KLIPY or proxy, cache, or re-host KLIPY media.

If you expressly use Daily Look, the photo you select is sent to OpenAI to create the requested image. Vaultlix does not keep the selected source photo after that request. OpenAI may retain API inputs and outputs for abuse monitoring under its API data controls; API data is not used to train OpenAI models by default. The created image remains on your device unless you choose to use it as your Vaultlix profile image.

Content safety and reports

Safety checks run on your device before sending text and when displaying incoming content; ordinary message plaintext is not sent to a moderation service. These checks detect some abusive, threatening and exploitative language, but are not comprehensive and do not classify the contents of every image, recording or document. On supported iOS and Android builds, a bundled model checks photos and profile images for possible nudity on your device before sharing or display. Photos and classification results are not sent to a screening provider. Flagged images are withheld; failed checks can be retried. These checks can make mistakes and do not cover video, audio, documents or every form of harmful content. Incoming attachments also require an explicit reveal. Use Report and Block for content the checks miss, or contact legal@vaultlix.com if a photo is incorrectly blocked.

When you submit a report, we receive its category, your written details, the reporting and reported account identifiers, and the conversation reference. Up to five recent text messages are shared with our reviewer only if you explicitly select the message-sharing option. Reports are reviewed by the operator within 24 hours. Unresolved reports remain available until handled; resolved reports and review notes are removed 90 days after their last review update. Account-level block records remain while needed to enforce your block. A reviewer may close a reported conversation and suspend an account from new connections; restrictions can be reviewed on appeal. Contact privacy@vaultlix.com for follow-up or an appeal.

Profile photos and display names are linked to your Vaultlix account and shown to people who know your exact private number or connect with you. Daily Look requests are authenticated to that account to enforce usage limits. Photos, report details and voluntarily shared report messages are therefore linked to account identity; end-to-end encryption of ordinary messages does not make these account features anonymous.

Children's privacy

Vaultlix is not intended for use by anyone under the age of 18. We do not knowingly collect information from minors.

International users

Vaultlix is operated from India and this policy is governed by Indian law, as stated below. If you access Vaultlix from another country, you do so on the understanding that your data may be handled under Indian law; where the law of your own country grants you additional rights that cannot be waived, this policy does not limit those rights.

Legal requests and abuse reports

If we receive a valid legal request under applicable Indian law, we will review it and respond as required. What we can provide is limited to records that exist at that time, including encrypted conversation content, identity profile data and infrastructure logs. We cannot decrypt message content ourselves.

You can use Report and block in Conversation Safety, or contact legal@vaultlix.com. Report contents, access controls, retention and response commitments are described in Content safety and reports above.

Changes to this policy

We may update this policy from time to time. Updates will be reflected on this page with a revised effective date.

Governing law

This policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023.

Questions? Contact us at privacy@vaultlix.com