Calculator Vault
Privacy Policy
Effective date: July 9, 2026
This policy explains every material category of information Calculator Vault processes, what stays on your device, what technical data may be sent to service providers, how it is used, and the choices available to you.
Calculator Vault does not require an account. We do not upload your vault photos, videos, documents, saved passwords, notes, PIN, or intruder-capture photos to our servers or to Firebase.
1. Scope
This Privacy Policy applies to the Calculator Vault iOS app and this support website. In this policy, “we,” “us,” and “our” refer to the developer of Calculator Vault. We act as the controller of information we decide to process. Google and Apple may act as processors or independent controllers under their own terms, depending on the service.
2. Information Processed on Your Device
The following information is processed locally to provide the app’s features and is not collected by us:
- Vault content: photos, videos, documents, notes, saved password entries such as username, password, website and notes, item titles, item type, creation date, and internal file metadata that you choose to add.
- Security information: a cryptographic salt and PIN verifier stored in the iOS Keychain, plus an on-device recovery envelope containing the vault key encrypted by the unique 20-digit recovery code shown to you. The current recovery code is retained in protected iOS Keychain storage so it can be viewed only after the vault is normally unlocked. The app does not store your PIN or derived vault master key. If you enable the Pro Face ID second step, the app stores only the local on/off preference and asks iOS to verify Face ID after the correct PIN.
- Intruder log: if you explicitly enable Intruder Capture, a front-camera photo and timestamp may be saved after a failed PIN attempt.
- Calculator information: calculator expressions, results, calculation history, angle mode, sound and haptic preferences.
- Preferences: onboarding state, installation marker, app icon choice, auto-lock timing, and whether Intruder Capture, decoy mode, Face ID second step, or other optional settings are enabled.
- Temporary viewing data: a video may be decrypted to a protected temporary file while it is viewed. The app removes that temporary file when the viewer closes.
Vault files, the vault index, and intruder-capture images are encrypted on the device using AES-256-GCM. Calculator history and ordinary preferences are stored locally outside the encrypted vault and should not be used for sensitive information. Encryption reduces risk but no device or software can be guaranteed completely secure.
Depending on your iOS and Apple device-backup settings, Apple may include the app’s encrypted container in an iCloud or computer device backup. This is an Apple device service, not a Calculator Vault cloud-vault service, and is governed by Apple’s terms.
3. Information Collected Off Device
| Category | Examples | Purpose |
|---|---|---|
| App interactions | App launch, screen/session lifecycle, onboarding completion, vault creation, lock or unlock outcome, failed-attempt count, import source and item count/type, paywall views, purchase-button taps, and other events listed below | Understand feature use, diagnose problems, and improve the app |
| Identifiers and app information | Analytics app-instance ID, Firebase installation ID, app identifier, bundle identifier, app version, Firebase/Analytics SDK version, and developer platform | Operate Firebase services, distinguish app installations, and diagnose releases |
| Device and general environment | Device model or class, operating-system version, language, country code, time zone, general region derived from a masked IP address, and IP address associated with service requests | Deliver Remote Config values, maintain security, and diagnose compatibility |
| Crash and diagnostic data | Crash stack traces, relevant application state, device and OS information, non-fatal errors, SDK transport performance metadata, and developer-defined diagnostic logs | Find crashes, investigate failures, and improve reliability |
| Support communications | Your email address, email headers, and any device details, screenshots, or other information you voluntarily include when contacting support | Respond to your request and maintain support records |
| Advertising and purchase service data | Ad request, impression, click, product identifier, offering, entitlement, purchase status, restore status, and related device or app metadata processed by Google Mobile Ads, RevenueCat, and Apple | Show ads to non-premium users, remove ads for active Pro users, complete purchases, restore purchases, and measure service reliability |
Diagnostic events are designed not to contain vault files, PIN values, biometric identifiers, saved passwords, usernames, website fields, note text, document contents, media contents, calculation expressions, or user-entered vault titles. An event may reveal that an import involved a category such as photo, video, document, password, or note, but not the content itself. Do not include sensitive vault content when emailing support.
4. Firebase Services
We use the following Google Firebase services as processors:
- Firebase Analytics for app interaction and usage measurement when Analytics is enabled for the Firebase project. Google Analytics automatically assigns an app-instance ID and may automatically measure first open, sessions, screen views, app lifecycle, and, if StoreKit transactions occur, product ID, product name, price, purchase, and subscription events. General location may be derived from masked IP addresses; the app does not request Apple Location Services for Analytics.
- Firebase Crashlytics for crash reports, non-fatal errors, stack traces, relevant app state, device and operating-system information, and diagnostic logs associated with app events preceding a failure. Crashlytics may receive Analytics breadcrumb events and active Remote Config rollout metadata when those integrations apply.
- Firebase Remote Config to retrieve app configuration such as free-item limits, hard-paywall status, dismissal timing, displayed plan and trial text, and legal links. Remote Config always processes country code, language code, time zone, OS version, Firebase Apple app ID, and bundle ID, and may process Analytics properties when Analytics-based targeting is used.
- Firebase Installations and transport components to identify an app installation, deliver Firebase services, and monitor SDK delivery quality, including event-cache size and dropped-event counts.
- Firebase Hosting to serve these public pages. Hosting may process request information such as IP address and browser or request metadata for delivery, security, and abuse prevention.
Google may process Firebase data on global infrastructure. Learn more in Firebase Privacy and Security and Google’s Privacy Policy.
5. Ads and Purchase Services
Calculator Vault may show Google Mobile Ads interstitial ads to non-premium users in vault-related surfaces. Pro access removes those ads while the entitlement is active. The app may request App Tracking Transparency permission before loading ads. If you allow tracking, Google Mobile Ads may use the advertising identifier to personalize ads and measure performance across apps and websites. If you decline, the app continues with non-personalized ad treatment and vault functionality remains available. Google Mobile Ads may process ad request, impression, click, device, app, and network metadata to deliver, limit, measure, secure, and report ads under Google’s terms.
We use RevenueCat to fetch available App Store products, process entitlement status, and restore purchases. RevenueCat may process app user ID, product identifiers, offering identifiers, transaction and entitlement status, device/app metadata, and related diagnostic information. Purchases are completed by Apple through the App Store purchase sheet.
6. Custom Analytics and Crash Breadcrumb Events
When the applicable Firebase collection is active, the app is configured to log the following developer-defined events. The same event names and parameters may be added to Crashlytics diagnostic breadcrumbs:
- App and configuration: app_started with the current app route; remote_config_fetched with fetch status, hard-paywall status, and free-item limit.
- Onboarding and vault state: onboarding_completed; vault_created; vault_unlocked with real or decoy mode; unlock_failed with the number of failed attempts in the current session; vault_locked with whether the privacy shield was preserved.
- Imports: import_source_selected with photo library, camera, document, password, or note; import_staged with count and item categories; import_started with selected count; import_finished with completed and failed counts.
- Paywall and ads: paywall_viewed with hard-paywall status and free-item limit; paywall_purchase_tapped with package and product ID; paywall_dismissed; ad_interstitial_requested; ad_interstitial_impression; ad_interstitial_clicked.
A purchase-button event records intent to continue, not confirmation that Apple completed a transaction.
7. What We Do Not Collect
We do not operate user accounts and do not collect your name, phone number, postal address, contacts, precise GPS location, microphone recordings, HealthKit data, financial account information, government identifiers, biometric templates, installed-app list, browsing history, or the contents of your Photos library beyond items you explicitly select for local import. Face ID matching is handled by iOS; Calculator Vault does not receive or store your Face ID template. We do not receive full payment-card details from Apple.
We do not assign a Calculator Vault account user ID. The app’s ATT request and Google Mobile Ads data use are described above. These public pages do not contain an account system, contact form, advertising pixel, or website analytics script.
8. Permissions and Your Choices
- Photos: the system photo picker lets you select media to import. Read/write Photos permission is requested only when needed to retrieve a selected asset or when you ask the app to delete its original from Photos. If an original is stored in iCloud Photos, Apple may download it through the Photos framework. An original deleted through iOS may remain in Apple’s Recently Deleted album under Apple’s rules.
- Camera: used when you choose Take Photo. If you separately enable Intruder Capture, the front camera may capture a local encrypted image after a failed PIN attempt.
- Face ID: used only if a Pro user enables the Face ID second step in Settings. After the correct PIN, iOS verifies Face ID before the real vault opens. Face ID can be disabled in app Settings, and the biometric template remains managed by Apple on your device.
- Tracking: ATT permission is requested before Google Mobile Ads loads. Allowing it permits use of the advertising identifier for personalized ads and cross-app ad measurement. Declining it keeps non-personalized ad treatment and does not block calculator or vault access. You can change this permission later in iOS Settings.
- Files: the iOS document picker gives temporary access only to documents you select for import.
You can revoke Photos, Camera, or Face ID permission at any time in iOS Settings. You can disable Intruder Capture and Face ID second step in the app’s Settings. Revoking a permission prevents future access but does not automatically remove items already imported into your encrypted vault. Core calculator use is not conditioned on granting Photos, Camera, or Face ID access.
Firebase Analytics and Crashlytics collection is initialized when the app launches; this version does not provide a separate in-app telemetry switch. To stop future telemetry from this version, stop using and remove the app. You may contact us about identifiable support records as described below.
9. Purchases
If the app offers functional premium access or subscriptions, Apple processes the transaction through the App Store. We do not receive your full payment card number. Apple, RevenueCat, and the Analytics SDK may process product identifier, product name, price, currency, transaction status, trial or subscription status, and entitlement information needed to complete, measure, or restore a purchase. Apple handles payment information under Apple’s Privacy Policy.
10. How We Use Information and Legal Bases
We use collected information only to operate and secure the app, provide configuration, serve and limit ads for non-premium users, understand aggregate feature use, diagnose crashes and errors, respond to support requests, enforce applicable terms, and comply with legal obligations. We do not use vault content for analytics, advertising, profiling, or artificial-intelligence training.
Where applicable law requires a legal basis, we process information as necessary to provide requested app or support services, for legitimate interests in reliability, security, fraud prevention, and product improvement where those interests are not overridden by your rights, with consent where required, and to comply with legal obligations. You may withdraw consent where processing relies on consent, without affecting earlier lawful processing.
11. Sharing, Sale, and Tracking
We do not sell or rent personal information. If you grant ATT permission, Google Mobile Ads may use the advertising identifier and ad interaction data for personalized advertising and measurement across apps and websites. If you decline, the app requests non-personalized ad treatment. We share limited technical data with Google Firebase, Google Mobile Ads, RevenueCat, and Apple only for the service purposes described above, and may disclose information if required by law, to protect rights or safety, or as part of a business transfer subject to appropriate protections.
We require service providers that process information for us to protect it under their agreements and applicable law with the same or equivalent protection described in this policy. We remain responsible for selecting providers whose protections are appropriate for the data they process.
12. Retention and Deletion
- Local vault data: remains on your device until you delete an item, use Delete All Data in the app, or remove the app. Removing an original from Photos is a separate action confirmed through iOS.
- Intruder log: remains encrypted on your device until you clear the log, use Delete All Data, or remove the app.
- Calculator history and preferences: calculator history remains locally until you clear it from Calculator Settings or remove the app. Delete All Data clears vault and security data but may not clear calculator history or every ordinary calculator preference.
- Deleted local files: deletion removes the app’s reference and asks iOS to delete the file. Flash storage and device backups are managed by Apple, so secure physical overwriting cannot be guaranteed.
- Crash data: Firebase states that Crashlytics retains crash stack traces and associated identifiers for 90 days before beginning removal from live and backup systems.
- Analytics data: user-level and event data is retained according to the retention period configured for the connected Google Analytics property. Aggregated reports may be retained longer under Google’s terms.
- Remote Config and Firebase service data: is retained according to Google’s applicable service controls and terms.
- Ad and purchase service data: is retained according to Google Mobile Ads, RevenueCat, and Apple service controls and legal requirements.
- Website request data: Firebase states that Hosting may retain IP data for a period of months for abuse detection and usage analysis.
- Support email: is retained only as long as reasonably necessary to answer the request, maintain support history, resolve disputes, and meet legal obligations.
Because there is no Calculator Vault account and vault content is not uploaded to us, we cannot view, export, remotely recover, or remotely delete your local vault. The unique 20-digit recovery code can reset the PIN locally on the same vault by entering it in the calculator and tapping equals; it is not transmitted to support. Use Settings > Delete All Data to erase vault files, local security data, and the intruder log from the app. You may also email us to request deletion of support communications or other information reasonably identifiable from details you provide. To stop future Firebase transmissions from this version, stop using and remove the app from your device.
13. Security and Recovery
We use on-device authenticated encryption, Apple Keychain protection, HTTPS for Firebase network traffic, and access controls appropriate to the services used. You are responsible for protecting your device, PIN, and recovery code. We cannot generate a universal code or recover encrypted vault content if both your PIN and recovery code are lost. Keep independent copies of important files; Calculator Vault should not be the only location where irreplaceable information exists.
14. Children’s Privacy
Calculator Vault is not directed to children under 13, or the minimum age required by local law. We do not knowingly collect personal information from children. A parent or guardian who believes a child has provided information through a support request should contact us so we can review and delete it where appropriate.
15. International Processing
Firebase, Google Mobile Ads, RevenueCat, Apple, and email service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, providers rely on contractual and legal safeguards for international transfers.
16. Your Privacy Rights and Choices
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or a copy of personal information we control. Since we do not maintain user accounts and most app data stays only on your device, we may need information from you to locate a support record, and we may be unable to associate Firebase telemetry with you personally. We will not discriminate against you for exercising applicable privacy rights.
If you are in the EEA, United Kingdom, or another jurisdiction with supervisory authorities, you may also complain to your local data-protection authority. Residents of applicable U.S. states may request to know, correct, or delete covered personal information and may appeal a denied request by replying to our decision. We do not sell personal information. You can deny or revoke ATT permission in iOS Settings to prevent access to the advertising identifier and request non-personalized ad treatment.
We may verify a request before acting and may retain information where permitted or required for security, legal compliance, fraud prevention, or dispute resolution. Authorized agents may submit requests where local law permits and adequate authorization is provided.
17. California and U.S. State Notice
During the preceding 12 months, the categories we may have collected are identifiers, internet or electronic network activity, approximate location inferred from network information, commercial information if a StoreKit transaction occurs, advertising interaction data, and diagnostics. Sources are the app, your device, Apple, Firebase, Google Mobile Ads, RevenueCat, and information you voluntarily send to support. We use and disclose these categories for the purposes described in this policy. We have not sold these categories. Google Mobile Ads use for personalized advertising and cross-app measurement depends on your ATT choice and any additional consent required in your region.
18. Changes to This Policy
We may update this policy when app features, service providers, or legal requirements change. We will update the effective date on this page. Material changes will be communicated through the app or another appropriate method when required.
19. Contact
For privacy questions, rights requests, or deletion requests, email abhi.shingala19@gmail.com. Please use the subject “Calculator Vault Privacy Request” and do not send your PIN or vault content.