Vault: Cloud Storage
Last updated: 26 September 2026
This policy explains what information Vault: Cloud Storage ("Vault", "we", "us") collects, why, where it is kept, who helps us process it, how long we keep it, and the choices and rights you have. It applies to the Vault app and the services behind it.
Vault is provided by Cognify Technologies (SMC-Private) Limited, a company registered in Pakistan. We are responsible for (the "controller" of) the personal information described in this policy.
Contact for anything in this policy, including privacy requests: info@cognify.ltd
The app may for a time be published on Google Play under the developer account of our founder while our company developer account is set up. Cognify Technologies (SMC-Private) Limited provides the service and is responsible for your information either way.
You can use Vault without an account. A guest cloud gets 5 GB of free storage.
If you sign in with Google, we receive your Google account ID and your email address. We do not receive your name, photo or contacts from Google.
Your files are stored privately in the United States. They are encrypted while they travel and while they are stored. They are not end-to-end encrypted, so we could technically access them. We do not look at or scan them, and we never use them for advertising or to train AI.
We do not sell your information, show ads, or use advertising or marketing trackers.
Release versions of the app send crash reports to Google Firebase Crashlytics so we can fix bugs.
You can delete your cloud and everything in it from the app at any time.
When you choose to upload files, such as photos, videos, documents, audio or other files, we store them together with the information needed to show and manage them:
the file name, size, type (for example "image/jpeg"), and a checksum used to check that the upload arrived intact;
the folder it is in, folder names you create, and when it was added, moved to Trash or deleted;
a small preview image (thumbnail) for photos and videos. The app makes this on your phone and uploads it with the file.
Vault uploads only what you choose. It does not back up your phone, camera roll or contacts automatically.
Your files can contain personal information, including information about other people (for example people in your photos). We store these files on your behalf so that you can reach them later. We do not read, analyse or scan their contents.
If you use "Contacts" in the upload menu, Vault asks for permission to read your contacts. It uses that permission to show your contact list on your phone. Only the contacts you select are converted into contact card files (.vcf) and uploaded to your cloud, where they are stored like any other file. Contacts you don't select never leave your phone, and we don't use contact information for any other purpose.
When you start without an account, our server creates a guest cloud. It is identified by random identifiers and a secret credential that only your phone holds; our server keeps just a scrambled (hashed) copy of the credential. We do not store your name, email address, phone number, device details or IP address for a guest.
To prevent abuse, the app sends an app installation identifier and your platform (Android) when a guest cloud is created. Our server uses them for that request only and does not store them.
If you choose to sign in with Google, Google tells us your Google account identifier and your email address (only when Google has verified it). We use these to create your account, sign you in on other phones, and contact you about your account if needed. We don't receive your Google password, and we don't receive or store your name or profile photo.
If you sign in while using a guest cloud, your guest files move into your account.
To keep you signed in, we issue short-lived access tokens (valid for 15 minutes) and refresh tokens (valid for 30 days). The server stores only hashed copies of refresh tokens, plus records made of random identifiers that link a sign-in session to your cloud.
We store your plan (currently the free plan), how much storage you use, and how many files you have, so that we can enforce limits and show your usage.
When a release version of the app crashes, it sends a crash report to Google Firebase Crashlytics. A report contains technical information: what the app was doing when it crashed (the stack trace), the app version, your device model, operating system version, the time, and a random installation identifier that Crashlytics creates. It does not contain your files, file names, contacts or email address. We use crash reports only to find and fix problems.
Like any internet service, our servers necessarily see your IP address and basic request information in order to answer the app. Our own logs record only the kind of request, its result, and error codes. They do not record IP addresses, file names or email addresses. They are kept for about one month. Our hosting provider's security systems (for example rate limiting) may process IP addresses briefly to protect the service from abuse.
We don't collect your precise or approximate location, your browsing history, your photo library as a whole, or payment details. We don't use advertising identifiers, and the app contains no advertising or analytics SDKs.
To work offline and quickly, the app keeps the following on your phone, in storage private to the app:
your sign-in credentials and tokens, encrypted with a key held in your phone's secure hardware keystore (Android Keystore);
your account email (if you signed in), settings, and a list of your cloud files and folders;
files you opened or downloaded, and preview images, kept in the app's cache. Your phone may clear the cache when it needs space;
temporary copies of files waiting to upload, deleted once the upload finishes or is cancelled.
Vault turns off Android app backup, so this information is not copied into your phone's backups. If you uninstall the app, it is removed from your phone. If you are using Vault as a guest and uninstall the app or lose your phone, you lose access to your guest cloud, because only that phone holds its credential. Sign in with Google to keep access.
Vault asks only for the permissions it needs, and most only when you use the related feature:
Internet and network state: to talk to our servers and to wait for Wi-Fi when you choose Wi-Fi-only uploads.
All files access (Android 11 and later) or storage (Android 10 and earlier): only if you use "Phone folders" to browse and pick files from your phone's storage. Vault reads only the files you select to upload and never changes or deletes files on your phone. You can use the system photo and file pickers instead without this permission.
Contacts: only when you open "Contacts" in the upload menu (see 3.2).
Notifications: to show upload progress.
Background work (user-initiated data transfer jobs and a data-sync foreground service): so that uploads you started can finish when you leave the app. You'll always see a notification while this is happening.
Camera: Vault doesn't hold camera permission. "Camera" opens your phone's camera app, and only the photo you take is returned to Vault.
You can withdraw permissions at any time in your phone's settings.
We use the information above to:
provide Vault: store, sync, show and deliver your files, and keep you signed in;
enforce storage and file limits, prevent abuse, and keep the service secure;
find and fix crashes and errors;
respond to your requests and messages;
comply with the law and enforce our Terms of Service.
We don't use your information for advertising, profiling, or selling, and we don't use your files to train artificial intelligence.
Contract: storing and delivering your files and running your guest cloud or account.
Legitimate interests: keeping the service secure, preventing abuse, and fixing crashes, all in ways that don't override your rights.
Legal obligation: where we must keep or disclose information by law.
Consent: where the law requires it, for example for app permissions you grant. You can withdraw consent at any time in your phone's settings.
We don't sell or rent personal information, and we don't share it for advertising. We use a small number of service providers that process information only on our instructions:
Amazon Web Services (AWS) in the United States (Northern Virginia, us-east-1): runs our servers and database.
Backblaze in the United States (US East): stores your files and preview images.
Google Firebase Crashlytics: receives crash reports from release versions of the app.
Google Sign-In: used only if you choose to sign in with Google. Google's own privacy policy covers the information Google processes when you use it.
Google Play: distributes the app. If paid plans are added in future, payments will be handled by Google Play, and we won't receive your card details.
We may also disclose information if the law requires it, for example in response to a valid legal request. We may disclose it to protect the rights, safety or property of our users, the public or us, or as part of a merger or sale of our business. In that last case this policy would continue to apply to your information.
Your files and account information are stored in the United States. We are based in Pakistan. If you use Vault from another country, including the UK or the EU/EEA, your information is transferred to and processed in the United States.
Where the law requires safeguards for such transfers, we rely on the data processing terms our providers offer, including the European Commission's Standard Contractual Clauses (and the UK addendum) where applicable.
Everything moves between the app and our services over encrypted connections (HTTPS/TLS).
Files are stored in a private storage bucket with encryption at rest, and our database is encrypted at rest.
The app never receives broad storage credentials. Each upload or download uses a short-lived, signed link that works for one file only, after our server checks that the file is yours.
Guest credentials and refresh tokens are stored on our server only in hashed form, and sign-in sessions are rotated and can be revoked.
On your phone, credentials are encrypted with a hardware-backed key.
Vault does not offer end-to-end encryption. Our systems hold the keys needed to operate the service, so authorised staff could technically access stored files. We don't access your files except when you ask us to (for example to help with a problem), when the law requires it, or to investigate a serious breach of our Terms reported to us.
No method of storage or transmission is completely secure, and we can't guarantee absolute security. If a security incident affects your personal information, we will notify you and the authorities where the law requires it.
Your files stay until you delete them, delete your cloud, or your cloud is removed under the rules below.
Trash: files you delete go to Trash and are permanently deleted after 7 days, or sooner if you empty Trash.
Recovery copies: after a file is permanently deleted, our storage keeps a hidden recovery copy for up to 7 days. It is then destroyed. This protects against accidental or malicious deletion.
Database backups: our database keeps rolling backups for up to 35 days, after which older copies are overwritten.
Inactive guest clouds: a guest cloud has no account behind it, so we can't contact its owner. We may delete a guest cloud, with all its files, if it hasn't been used for 180 days in a row. Signed-in accounts are not deleted for inactivity.
Sign-in tokens expire (refresh tokens after 30 days) and are removed about a week after they expire.
Server logs are kept for about one month.
Crash reports are kept by Firebase Crashlytics for up to 90 days.
Deletion records: when a cloud is deleted, we keep a minimal record that a cloud with a given random identifier was deleted and when. This ensures the deletion completes and the cloud is never restored. It contains no email address, name, file names or files.
In the app: open the Account tab, tap Delete my cloud and files, and type DELETE to confirm. This works for both guests and signed-in accounts:
your guest credential or account, sign-in identity and email address are removed immediately, and you are signed out;
your files, preview images, folders and file information are deleted, usually within an hour;
recovery copies are destroyed within 7 days, and remaining database backups are overwritten within 35 days.
Without the app: if you signed in with Google, email info@cognify.ltd from the email address on your account with the subject "Delete my Vault account". We'll confirm and delete your account and all its files as described above, usually within 30 days. Because guest clouds are not linked to any email or identity, we can't identify a guest cloud from a request by email. Please delete a guest cloud in the app, or it will be removed under the inactivity rule above.
Uninstalling the app does not delete your cloud.
Depending on where you live, you may have the right to:
access the personal information we hold about you, and receive a copy;
correct inaccurate information;
delete your information (see section 11);
download your files, which you can do at any time in the app (data portability);
object to or restrict certain processing, and withdraw consent where we rely on it;
complain to your data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EU/EEA it is your local supervisory authority.
To make a request, email info@cognify.ltd. We may need to confirm that the request comes from the owner of the account. We will respond within the time the law requires, normally within one month. We won't treat you differently for exercising your rights.
California and other US state residents: we do not sell or share personal information for cross-context behavioural advertising, and we don't use sensitive personal information to infer characteristics about you. You may request access to or deletion of your information as described above.
Vault is not directed at children under 13, and you must be at least 13 years old (or the minimum age required in your country, if higher) to use it. We don't knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, contact info@cognify.ltd and we will delete it.
We may update this policy as Vault changes, for example if we add paid plans or new sign-in options. We'll post the new version at this page and change the "Last updated" date above. If a change materially affects how we use your information, we'll also tell you in the app before it takes effect.
Cognify Technologies (SMC-Private) Limited
Email: info@cognify.ltd