Privacy Policy
Your privacy is the foundation of AcroVault. This policy explains exactly how we collect, use, and protect your information - with complete transparency.
1. Introduction
This Privacy Policy explains how Acrolyze ("we," "us," or "our") collects, uses, stores, shares, and protects your personal information when you use AcroVault ("the Service"). We are committed to protecting your privacy and being transparent about our data practices. This policy complies with global privacy standards including GDPR, CCPA, and similar regulations.
2. Information We Collect
2.1 Account Information
When you register, we collect your full name, email address, and a cryptographically hashed version of your password. We never store your actual password - only a bcrypt/argon2 hash.
2.2 Vault Data (Zero-Knowledge)
All passwords, documents, notes, financial records, and other vault items you store are encrypted on your device using AES-256 encryption before being transmitted to our servers. We cannot access, read, or decrypt your vault data under any circumstances.
2.3 Recovery Email (Optional)
If you add a recovery email in Settings, it is stored and used only for account recovery purposes.
2.4 Payment Information
All payments are processed by PayPal. We do not receive, store, or have access to your credit card numbers, bank account details, or PayPal credentials.
2.5 Usage Data
We collect anonymous, aggregate usage statistics (features accessed, error rates) to improve the Service. This data cannot be linked to individual vault contents.
2.6 Communication Data
When you contact support, we retain your messages and our responses for quality assurance and reference.
3. How We Use Your Information
- To create, manage, and secure your account
- To send essential service communications (verification codes, password reset OTPs, 2FA codes, expiry reminders, legacy access notifications)
- To process payments and manage subscriptions
- To detect, prevent, and respond to fraud, abuse, security incidents, and Terms violations
- To improve Service performance, reliability, and user experience based on aggregate data
- To comply with applicable legal obligations and respond to lawful requests
4. Zero-Knowledge Architecture
This is not a marketing claim - it is a technical guarantee:
- Encryption and decryption happen exclusively on your device
- Your encryption keys are derived from your password and never transmitted to our servers in plaintext
- We cannot view, access, search, or decrypt your vault contents
- If we receive a legal order to disclose data, we can only provide encrypted ciphertext - which is mathematically unreadable without your password
- Our support team cannot view your vault - only you hold the keys
5. Data Sharing & Disclosure
We do not sell, rent, trade, or monetize your personal information. We share data only in these strictly limited circumstances:
- Service Providers: Essential third parties (hosting, email delivery, payment processing) under binding confidentiality agreements
- Legal Compliance: If required by valid subpoena, court order, or law - we will notify you unless legally prohibited
- Business Transfer: In merger or acquisition, your encrypted data transfers with the business, subject to this Privacy Policy
- With Your Consent: With your explicit permission for any other purpose
6. Data Retention
- Active Accounts: Vault data retained as long as your account is active
- Deleted Accounts: 30-day grace period for recovery. After 30 days, all data is permanently and irreversibly deleted
- Audit Logs: 90 days (Free), 14 months (Premium)
- Trash: Deleted items recoverable for 30 days
- Backups: Encrypted backups cycled regularly. All copies are encrypted at rest
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your vault data in a portable format (ZIP with CSV)
- Lodge a complaint with your local data protection authority
To exercise these rights, email connect@acrolyze.com or use the built-in tools in Settings. We respond within 30 days.
8. Cookies
We use only essential cookies:
- Session cookie: Required for authentication and security (CSRF protection)
- Theme preference cookie: Remembers your light/dark mode choice
We do not use tracking cookies, advertising cookies, analytics cookies, or third-party cookies of any kind.
9. Children's Privacy
The Service is not intended for individuals under 13 years of age. We do not knowingly collect personal information from children under 13.
10. Security Breach Notification
In the event of a confirmed data breach, we will notify affected users via email within 72 hours. Due to our zero-knowledge encryption, a database breach alone does not expose your vault contents - attackers would only obtain encrypted data.
11. Changes to Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email at least 30 days before taking effect. Continued use after changes constitutes acceptance.
12. Contact
For privacy-related inquiries or to exercise your data rights, contact our Data Protection Officer at:
๐ง Email: connect@acrolyze.com