1. Overview & Commitment to Privacy
Welcome to AES Vault, developed by Cipher Deck. Your privacy is our highest priority. AES Vault is designed with a strict Offline-First & Zero-Knowledge Architecture. Your personal notes, passwords, encryption keys, media files, steganographic images, and vault database remain strictly private on your device and are never transmitted to external cloud servers.
✓ Zero-Knowledge Protection: Your plaintexts, master passwords, encryption keys, steganographic media, and files are processed exclusively on your device hardware and are never collected, stored, or transmitted by Cipher Deck.
2. Local Data Processing & Cryptographic Security
AES Vault operates locally on your physical hardware. Here is how your data is processed across all modules:
- Text & File Encryption: Cryptographic operations (AES-256-GCM encryption, decryption, Argon2id & PBKDF2 key derivation) occur entirely in local device memory. Plaintext inputs and keys are wiped from RAM immediately after processing and are never transmitted over any network.
- Image Steganography: Hiding secret text or files inside cover image photos is executed 100% locally on device pixels. Cover images and hidden payloads are never uploaded to any remote server or cloud service.
- X25519 Key Exchange: Elliptic Curve X25519 key pair generation, key agreement, and fingerprint calculations are processed exclusively on-device.
- Encrypted Local Vault Storage: Saved vault items reside locally on your device in secure app storage, encrypted via Android KeyStore / TEE master keys (AES-256-GCM). Data never leaves your device unless you manually export an encrypted backup file.
- Master Password & Local Authentication: Master Passwords and Biometric Locks (Fingerprint/Face Unlock) are verified locally by the Android Operating System using hardware-backed security. AES Vault never collects or stores raw biometric data.
- Screen Security: The app enforces screen capture protection (
FLAG_SECURE) to prevent unauthorized screenshots or task switcher previews.
3. Third-Party Services & SDK Disclosures
To support app functionality, secure in-app purchases, and optional stability diagnostics, AES Vault integrates the following trusted third-party services:
Google Play Billing & RevenueCat
Used to validate in-app purchases and manage Pro feature lifetime access state securely. Transaction receipts and anonymous app user IDs are processed strictly for purchase verification. We do not collect or store credit card or payment details. For more information, visit
RevenueCat Privacy Policy and
Google Privacy Policy.
Google Play Integrity API
Used solely for anti-tamper verification and app attestation checks to ensure application integrity on Android devices.
Google Firebase Crashlytics & Analytics (Optional & Opt-In)
Used for optional, anonymous crash reporting and performance diagnostics to help improve app stability across device models. This service is strictly opt-in and can be enabled or disabled anytime in Settings → Diagnostics. Diagnostic reports contain only anonymous system data (app version, OS version, device model, redacted stack traces). Advertising IDs and ad personalization tracking are completely disabled. Disabling diagnostics in Settings immediately halts reporting and erases pending diagnostic logs from your device.
4. Application Permissions
AES Vault requests only standard Android permissions required to provide its core utility features:
Camera Permission (android.permission.CAMERA)
Used solely for live QR code cipher scanning. Camera access is requested runtime-only when you open the scanner. No camera feeds, photos, or videos are recorded, saved, or uploaded.
Internet Access (android.permission.INTERNET)
Used strictly for Google Play In-App Updates, RevenueCat purchase validation, optional anonymous crash diagnostics, and opening external web links in your browser. Vault data, plaintext, and keys are never transmitted over network connections. Unencrypted HTTP traffic is permanently blocked.
Foreground Service & Notifications (FOREGROUND_SERVICE_DATA_SYNC)
Used strictly during file encryption or decryption tasks to allow processing of large files to finish reliably in the background while displaying real-time progress in your notification bar.
Biometric Authentication (USE_BIOMETRIC)
Used solely to prompt local Android OS authentication when unlocking the app or auto-filling saved passwords.
File Access (Storage Access Framework)
File selection is handled via Android's native Storage Access Framework. The app only accesses specific files you explicitly select for encryption, steganography, or backup export/import.
5. Data Retention & Deletion
Because all data is stored locally on your device, you have complete control over retention:
- You can edit or delete individual vault items, notes, or files directly in the app at any time.
- Uninstalling AES Vault permanently removes all local application data, vault files, and settings from your device.
- Note: Due to our Zero-Knowledge security model, if you lose your Master Password or encryption keys, we cannot recover your encrypted data.
6. Children's Privacy
AES Vault is a general-audience utility tool and does not knowingly collect personal information from children under the age of 13.
7. Policy Updates & Contact
We may update this Privacy Policy periodically to reflect app updates or Google Play policy requirements. Any changes will be posted on this page with an updated effective date.
If you have any questions or feedback regarding this Privacy Policy, please reach out to us: