← Back to DNanoVault

Privacy Policy

Last updated: [DATE]

Template notice: this document was drafted to reflect DNanoVault's actual architecture as a starting point — it is not legal advice. Replace every bracketed placeholder and have it reviewed by a lawyer familiar with your jurisdiction (and, if you have users in the EU/UK, California, or elsewhere with specific data-protection statutes) before relying on it.

What we can't see

DNanoVault is built so the contents of your vault — notes, passwords, files, and folder names — are encrypted inside your browser before they ever reach our servers, using a key derived from your passphrase. We store only ciphertext. We do not have your passphrase, we do not have your encryption key, and we have no technical means to decrypt your vault contents, recover a lost passphrase, or read your data on request — including by law enforcement request, since we have nothing readable to hand over.

What we do collect

Because encryption happens client-side, everything below is either necessary to run the service or explicitly outside the encryption boundary:

What we never collect

How we use what we collect

To operate the service (authenticate you, store and return your encrypted data, run imports you request), to prevent abuse (rate limiting, bot detection), to communicate service-related notices to [CONTACT EMAIL] if you provide one, and to meet legal obligations where applicable. We do not sell personal data, and we do not use vault metadata to build advertising profiles.

Third-party services

Google, GitHub, Dropbox, Notion, and Slack each operate under their own privacy policies and terms, which govern how they handle data on their end once you connect an account. Disconnecting a provider in Settings removes our copy of that provider's access token; it does not revoke the authorization on the provider's side — do that from the provider's own account settings for a full revoke.

Data retention and deletion

Your data is retained until you delete individual items, delete your account, or [RETENTION POLICY, e.g. "an account is inactive for N months"]. Account deletion (available in Settings) permanently removes your vault items, salt, folders, profile data, and any connected third-party tokens. This action cannot be undone, for the same reason a lost passphrase can't be recovered: we don't keep a side copy.

Children's privacy

DNanoVault is not directed at children under [13 / 16, depending on jurisdiction] and we do not knowingly collect data from them. Contact us at [CONTACT EMAIL] if you believe a child has created an account.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Account deletion is self-service; for anything else, contact [CONTACT EMAIL]. [Add specifics here for GDPR/CCPA/other applicable regimes — e.g., a designated Data Protection Officer, EU representative, or complaint-authority contact, if required for your user base.]

Changes to this policy

We'll update the date at the top of this page when this policy changes, and — for material changes — provide more prominent notice, such as an in-app banner.

Contact

[CONTACT EMAIL OR ADDRESS]