Vaulto
Security & privacy

Your family's information, protected.

Vaulto holds sensitive details — what you own, where it is, the documents that prove it. We treat that responsibility seriously. Here's exactly how we protect it, in plain language.

How we protect your data

Encrypted in transit.

Every connection to Vaulto uses TLS (HTTPS) — the same padlock-icon encryption you see on banking and shopping sites. Your data is scrambled while it travels between you and us, so no one in between can read it.

Encrypted at rest.

Your records and uploaded files are encrypted at rest — "at rest" simply means while they're stored, not while they're moving. They sit on professionally managed, secured servers, and Vaulto seals the sensitive parts again inside the app itself before they're written: item names, descriptions, locations and notes, the photos and scans you upload, and exact valuations are encrypted with keys managed in Google Cloud KMS rather than kept beside the data. The block below sets out which fields are sealed and which stay readable.

Passwords never stored plainly.

We "hash" your password with a strong, modern method called scrypt — a hash is a one-way scramble that can't be turned back into your password. Even we can't read it.

Short-lived sessions.

The sign-in "token" that proves it's you expires quickly and is kept in memory. The token that keeps you signed in lives in a secure, script-proof cookie — a small browser file that harmful scripts on a page can't read or steal.

Protected against abuse.

We limit how many times sign-in and other sensitive actions can be tried in a row — this is called "rate-limiting." It blocks the fast, repeated guessing that automated attacks rely on.

Access controls.

Each person's vault is isolated from other users.

Our privacy promises

We never sell your data.

Full stop.

We don't share to advertise.

Your information isn't handed to third parties to market to you.

You're in control.

You decide what you add — and what you remove.

Your data is yours

Your data is yours — export a complete, machine-readable copy of your records (JSON, CSV, or PDF) anytime, from Settings. Machine-readable means a standard file another app or spreadsheet can open and re-use — not a locked PDF. No lock-in, no waiting on us. (You can also export a ZIP archive that includes your original uploaded photos and scans alongside the structured record.) This supports your right to data portability under GDPR — the EU privacy law (Article 20) that lets you take your data with you.

Plain-language, no overclaim. We describe only what's true today: encryption in transit, encryption at rest applied by the app itself with keys managed in Google Cloud KMS, files kept in private storage, hashed passwords, strict access control. We deliberately do not claim "end-to-end" or "zero-knowledge" encryption: we hold the keys, so we can decrypt your records to run the service and the AI features you ask for. Nor do we claim "bank-level" or any certification we haven't earned. Here is what is sealed and what is not. Encrypted: the item names, descriptions, locations and notes you write, the exact valuations, and the files you upload. Readable to our servers: the structured fields around them, so your vault can still be sorted without opening the sealed parts — things like category, dates and tags, currency, country, an institution or serial number, purchase price, who an item belongs to, and a coarse value band. Data export is live (above). When we add a formal third-party audit, where an independent security firm reviews us, this page will say so. For privacy or security questions, contact privacy@myvaulto.com.

Private from the first thing you add.

Start free — your vault is yours alone, and you can export or delete it whenever you want.

Get started free