DRAFT — Pending solicitor review. This document is not yet legally effective.
AlwaysVault is operated by Arkionix Ltd, a company registered in England and Wales. We are committed to protecting your personal data and your right to privacy.
Contact: [email protected]
We do not collect or hold vault contents. Your vault is encrypted on your device before it reaches our servers. We hold ciphertext only — without your key, we cannot access, read, or hand over your vault data, even in response to a legal request.
We do not sell your data. We do not share it with third parties for marketing.
Under UK GDPR, you have the right to access, correct, or delete your personal data. To make a data subject access request:
Important: If your vault has already been delivered to your chosen contacts, we cannot retrieve or delete those copies — they are in the recipients' physical possession.
Your vault is encrypted end-to-end using AES-256-GCM. AlwaysVault does not hold decryption keys. Even in the event of a server breach, vault contents cannot be decrypted.
We retain your personal data for as long as your account is active. If you delete your account, deletion is permanent: after you confirm your request there is a short cooling-off period during which you can cancel, after which your account is locked and erased. We complete erasure within 30 days of verifying your request.
If your vault is delivered to your chosen contacts, your account is retained for a period you choose — 18 or 24 months (18 by default) — and then permanently erased. We may retain certain records for a limited period where required by law.
We use the following third-party service providers (sub-processors) to operate AlwaysVault. Each handles personal data only as necessary to provide their service.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Hostinger | Web hosting & database | Site data, server logs, IP addresses | European Union |
| Cloudflare | CDN & DDoS protection | Traffic data, IP addresses | Global (EU SCCs in place) |
We do not sell your data. We do not share it with any party for marketing purposes.
We use cookies only where necessary for security (session tokens, CSRF protection) and privacy-respecting analytics. We do not use advertising or cross-site tracking cookies.
We may update this policy as the service develops. Significant changes will be communicated by email.