LEGAL / PRIVACY
Privacy Policy
This Privacy Policy explains how SkimZero Vault handles your information. In short: your entire vault is encrypted on your device, the browser uses local content blocking, and we have no way to read it.
Effective date: July 28, 2026
Who we are
SkimZero Vault ("the App", "we", "us") is developed by SkimZero Lab (sole proprietor: Damaso Sanchez Cervantes). Contact: support@skimzerolab.com.
Our core promise
We cannot read your vault. All vault content (photos, videos, notes, passwords, TOTP codes) is encrypted on your device using Argon2id + AES-256-GCM before it is ever stored. We have no key, no back door, and no way to decrypt your data. No vault content leaves your device under any circumstance.
Data stored on your device
The following data is stored locally on your iPhone, encrypted at rest. It never leaves your device and we cannot access it:
- Photos, videos, and documents you import into the vault
- Secure notes
- Password entries
- TOTP secrets and authenticator codes
- Audio recordings
- Intruder selfie photos (captured on failed unlock attempts)
- Security event log
- Browser bookmarks
Optional recovery backend
The backup and cloud-assisted recovery feature is entirely optional. If you use it, our recovery backend (Cloudflare Workers, hosted in the EU/US) processes only the data listed below. It NEVER receives your vault PIN, vault key, vault content, passwords, notes, or photos — the backup factor is a random value unrelated to your vault. You can delete your recovery account anytime from Settings → Recovery Account → Delete Account, which permanently removes your email and all associated data.
- Email address — send OTP codes and identify your recovery account; kept until you delete the account.
- Encrypted backup factor — a random 32-byte key stored as AES-256-GCM ciphertext to help re-derive your vault key on restore; kept until revoked or deleted.
- IP address — stored only as an HMAC-SHA256 hash for rate limiting; deleted after 1 hour.
- OTP request metadata — request ID, email hash, and expiry for rate limiting; auto-deleted after the code expires or is used.
- Audit events — security log linked to your account ID (not raw email); kept until the account is deleted.
Device permissions
All permission requests are optional; the App remains functional at a reduced level if you deny them:
- Camera — document scanner and intruder selfie on failed unlock.
- Microphone — in-vault audio recorder.
- Face ID / Touch ID — first factor of the two-factor vault unlock.
- Speech Recognition — transcription for recorded audio and scanned documents.
Analytics, advertising & tracking
We collect zero analytics, diagnostics, or usage data. We run no advertising SDK, share no data with third parties for marketing, and use no tracking pixels, fingerprinting, or cross-app tracking.
Third-party services
These services are used only for the optional features noted; no data flows to them during normal vault use:
- Cloudflare Workers & D1 — powers the optional recovery backend (cloudflare.com/privacypolicy).
- Resend — transactional email for OTP codes; only your email and the OTP body are sent (resend.com/legal/privacy-policy).
- Have I Been Pwned — optional breach check when you set a vault password; only the first 5 characters of a SHA-1 hash are sent (k-anonymity), never your full password (haveibeenpwned.com/Privacy).
Data security
Vault data is encrypted with Argon2id (key derivation) and AES-256-GCM using keys that never leave your device. The vault key is wrapped with a KEK derived from your PIN and a device-bound secret stored in the iOS Keychain with Secure Enclave backing. Data in transit to the recovery backend is protected by TLS 1.3.
Children's privacy
SkimZero Vault is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently received such information, contact us and we will delete it promptly.
Your rights (GDPR / CCPA)
If you use the optional recovery feature, you have the right to access, correct, or delete the data we hold about you. You can exercise these rights by deleting your recovery account in the app (Settings → Recovery Account → Delete Account), which triggers immediate deletion of all server-side data. For other requests, contact privacy@skimzerolab.com.
Changes to this policy
If we make material changes, we will update the effective date and notify users via an in-app notice or App Store release notes. Continued use of the App after changes constitutes acceptance.
Contact
SkimZero Lab · privacy@skimzerolab.com · vault.skimzerolab.com