๐Ÿ”’ Privacy Policy

SnapVault

Effective Date: April 1, 2026  ยท  Last Updated: April 1, 2026

1. Introduction

Welcome to SnapVault, a private photo, video, and document vault developed by SAS Labs ("we", "us", or "our"). We are committed to protecting your personal data and your right to privacy.

This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it. It applies to all users of the SnapVault iOS application ("App").

๐Ÿ“Œ Short version: Your private media never leaves your device unencrypted. We do not sell your data or use it for advertising.

2. Encryption & Security Architecture

SnapVault is built with a security-first architecture. All user content is encrypted before it is written to local storage or transmitted to cloud servers.

๐Ÿ” Encryption Specification

  • Algorithm: AES-256-GCM (Advanced Encryption Standard, 256-bit key, Galois/Counter Mode)
  • Key Size: 256 bits (32 bytes)
  • Mode: GCM โ€” provides both confidentiality and authenticated integrity (tamper detection)
  • Key Storage: Encryption keys are stored exclusively in the Apple Keychain with kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly protection class
  • Encryption Library: Apple CryptoKit (AES.GCM) โ€” Apple's on-device, FIPS-validated cryptographic framework
  • Thumbnail Cache: Decrypted thumbnail cache files are also AES-256-GCM encrypted at rest using the same key
  • Transport: All network traffic uses TLS 1.2+ (enforced via App Transport Security; no arbitrary loads are permitted)

Authentication

3. Information We Collect

3.1 Information You Provide

DataPurposeLinked to You
Google Account email & display nameAuthentication, account creationYes
Photos, videos, documents, text notesCore vault functionality (encrypted)No โ€” encrypted
In-app purchase historySubscription status verificationYes
PIN (SHA-256 hash only)Album and app lock securityNo

3.2 Information Collected Automatically

DataPurposeTracking
Device model, OS version, app versionAnalytics & crash diagnosticsNo
Anonymous usage events (screen views, feature usage)Product improvement analyticsNo
Break-in alert photo (front camera)Captured locally when wrong PIN is entered; stored in your vaultNo โ€” on-device only
Firebase anonymous installation IDAnalytics session associationNo

๐Ÿšซ We do not collect advertising identifiers (IDFA), use cross-app tracking, or share any data with advertising networks. NSPrivacyTracking is set to false.

4. How We Use Your Information

5. Third-Party Services

SnapVault uses the following third-party services. Each operates under its own privacy policy.

ServiceProviderPurposePrivacy Policy
Firebase AuthenticationGoogle LLCSign-in via Google accountfirebase.google.com/support/privacy
Firebase FirestoreGoogle LLCEncrypted cloud metadata storagefirebase.google.com/support/privacy
Firebase StorageGoogle LLCEncrypted media file cloud backupfirebase.google.com/support/privacy
Firebase AnalyticsGoogle LLCAnonymous usage analyticsfirebase.google.com/support/privacy
Google Sign-InGoogle LLCOAuth 2.0 authenticationpolicies.google.com/privacy
Apple StoreKit 2Apple Inc.In-app purchase processingapple.com/legal/privacy

All media files uploaded to Firebase Storage are encrypted with AES-256-GCM on-device before transmission. Firebase only stores ciphertext and cannot read your content.

6. Device Permissions

PermissionWhen RequestedWhy It's Needed
CameraWhen using in-app cameraCapture photos/videos directly into the encrypted vault
Photo Library (read)When importing photos/videosSelect media to import and encrypt
Photo Library (write/delete)When "Delete Originals" is enabledRemove originals from Camera Roll after secure import
MicrophoneWhen recording videoRecord audio for video files
Face IDWhen enabling biometric lockUnlock the vault via Face ID / Touch ID (data stays in Secure Enclave)

You can revoke any permission at any time in Settings โ†’ Privacy & Security on your device.

7. Data Retention & Deletion

Local Data

Encrypted media files and thumbnails are stored in the app's sandboxed container. They are automatically removed when you delete the app, or you can manually delete individual items or entire albums within the app.

Cloud Data

If cloud sync is enabled, encrypted files are stored in Firebase Storage and metadata in Firebase Firestore under your user account. You can:

Account deletion permanently removes all data from our servers within 30 days.

8. Children's Privacy

SnapVault is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

9. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any right, contact us at saslabs.corp@gmail.com. We will respond within 30 days.

California residents may exercise rights under CCPA. EEA/UK residents may exercise rights under GDPR/UK GDPR. We do not sell personal information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, through an in-app notification. Your continued use of SnapVault after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: