Last updated: August 3, 2026
This Privacy Policy explains how Access Vault handles information when you use the Application, the choices available to you, and how to contact us with privacy questions.
For purposes of this Privacy Policy:
Application means Access Vault, the Android software provided by the Company.
Company, we, us, or our means Nexus Dev Labs LLC.
Personal Data means information that relates to an identified or identifiable individual.
Service means the Application.
You means the individual using the Service, or the entity on whose behalf that individual is using it.
Access Vault is designed as a local-first password vault. We do not operate an Access Vault server, require an account, or receive your vault contents. The Application does not include advertising or an independent behavioral-analytics service. Google Play components may use a network connection for purchases, licensing, updates, and related operational or diagnostic information, but vault content is not sent to Google Play or the Company.
Your vault contents remain in the Application's private local storage unless you deliberately use an export, backup, clipboard, or Autofill feature. Google Play separately processes information needed for purchases, licensing, app distribution, diagnostics, and updates as described below.
Access Vault stores information you choose to enter, which may include account names, usernames, email addresses, passwords, passphrases, PINs, payment-card details, secure notes, Wi-Fi credentials, identity information, custom fields, categories, and similar sensitive content. It also stores entry history, recycle-bin content, internal identifiers, timestamps, and the settings needed to operate the Application.
Vault titles, category names, field labels and values, and entry-history snapshots are encrypted at rest using AES-256-GCM. The encryption key is protected by the Android Keystore and requires supported biometric or device-credential authentication to unlock. The decrypted vault key is held in memory only while the vault is unlocked.
We cannot view, recover, reset, or decrypt your vault. If the device encryption key becomes unavailable, or if you lose both your device access and any usable encrypted backup, the Company cannot recover your data.
Access Vault uses Android's system authentication interface. Fingerprint, face, screen-lock PIN, pattern, and password data are handled by Android and supported device hardware. The Application receives only the authentication result and cryptographic authorization; it does not receive or store your biometric template or device credential.
Autofill is optional and must be enabled by you in Android settings. When enabled, Android may provide Access Vault with the structure of a sign-in form, including the requesting application or website, web domain, field identifiers, Autofill hints, and values entered into eligible fields. Access Vault processes this information locally to identify matching entries, fill credentials you select, or offer to save or update a login.
Autofill form information and vault credentials are not transmitted to the Company. You can disable Access Vault as an Autofill service at any time in Android settings, and you can exclude selected vault categories from Autofill within the Application.
When you choose to copy a password, passphrase, or other value, Access Vault places that value on Android's system clipboard. The Application marks copied secrets as sensitive and attempts to clear a matching clipboard value after approximately 45 seconds. Clipboard behavior is ultimately controlled by Android, the device manufacturer, and other software on your device; depending on your Android version and device configuration, other applications or system features may be able to access clipboard contents.
The optional Premium credential-scanning feature lets you photograph a document or select an existing image. Access Vault lets you crop the image and uses bundled, on-device text recognition to identify possible login details within the selected area. The captured image, selected crop, and recognized text are processed locally, are not uploaded to the Company or Google for recognition, and are not saved by Access Vault to your gallery. Access Vault does not retain a copy of the source or cropped image after processing.
Recognition can be inaccurate. You must review and may edit or deselect each proposed entry before saving it. Only entries you approve are added to your encrypted vault. If you select an existing image, the original remains wherever you or its provider stored it and is subject to that provider's practices.
Application preferences, including appearance settings, category exclusions, backup schedules, and a cached Premium entitlement, are stored locally. Access Vault also asks Google Play whether the Premium product is owned so that purchased features can be unlocked or restored.
Manual and scheduled vault backups are created only when you enable or initiate those features. Vault backup files are encrypted using a password you provide. You select the destination through Android's system file picker, and Access Vault writes the encrypted file to that destination.
For scheduled backups, the selected destination, schedule, and an encrypted copy of the backup password are stored locally. Scheduled backups run after you interactively unlock the vault when a backup is due; they do not bypass device authentication.
If you select a cloud-storage application or other third-party document provider as the destination, that provider receives and stores the encrypted backup file under its own terms and privacy policy. Nexus Dev Labs LLC does not receive the file. You are responsible for protecting the backup password and deleting backup files from any destination where you no longer want them retained.
Access Vault can import its encrypted backup format and, when selected by you, plaintext CSV exports from supported browsers or password managers. Import files are read locally through Android's file-selection system and are not transmitted to the Company. CSV files can contain unencrypted credentials; you should protect them and securely delete them after import.
Access Vault disables Android cloud backup and device-to-device transfer for its private application data. User-created export and backup files are separate documents and remain wherever you chose to save them.
Access Vault uses Google Play for app distribution, in-app updates, license testing, and a one-time Premium purchase. Google Play and its included software components may process information such as your Google account, device and network information, country or region, app version, purchase status, order identifier, payment information, and operational or diagnostic events under Google's own privacy policy.
The Company does not receive or store your complete card number, bank-account details, or Google account password. Google may make limited transaction records, financial reports, installation statistics, crash or application-not-responding reports, device or Android-version summaries, and order-management information available to the Company for app maintenance, entitlement support, refunds, accounting, fraud prevention, and legal compliance. These records do not contain your vault contents.
For information about Google's data practices, see Google's Privacy Policy.
If you contact us by email or another support channel, we receive the information you choose to provide, such as your email address, message, screenshots, device or app details, and diagnostic information. We use it only to respond, provide support, protect the Service, and comply with legal obligations. Please do not send passwords, backup passwords, unencrypted vault exports, or other vault secrets in a support request.
Except for information you voluntarily send to us and limited information made available through Google Play as described above, the Company does not receive your locally processed Access Vault data. In particular, we do not receive:
Your vault entries, passwords, notes, history, or recycle-bin content;
Autofill form contents or the sites and applications where you use Autofill;
Generated passwords or passphrases;
Photos captured or selected for credential scanning, selected image crops, or text recognized from them;
Clipboard contents;
Imported files or encrypted backup files;
Biometric templates or device credentials;
Precise location, contacts, unrelated photos, microphone recordings, advertising identifiers, or browsing history; or
Vault-usage or behavioral analytics, or advertising data generated by Access Vault.
We do not sell or rent Personal Data, and we do not use Personal Data for advertising or cross-app tracking.
Because the Company does not receive your vault content, it cannot disclose that content. We may disclose information that we do possess, such as support correspondence or limited transaction records:
To service providers that process it on our behalf and are required to protect it;
To comply with applicable law, legal process, or valid requests from public authorities;
To protect the rights, safety, and security of users, the Company, or others; or
In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the commitments in this Privacy Policy.
User-directed transfers to a chosen file or cloud provider are controlled by you and are governed by that provider's privacy practices.
Local vault data remains on your device until you delete it, permanently empty it from the recycle bin, clear the Application's storage, or uninstall the Application. Removing an entry to the recycle bin does not permanently delete it until you permanently delete that entry or empty the bin. Entry history remains locally subject to the Application's history limits and deletion behavior.
Files you export remain at the selected destination until you delete them there. Uninstalling Access Vault does not delete user-created backup or CSV files stored outside the Application's private storage.
Access Vault does not create user accounts, so there is no server-side Access Vault account to delete. You can request deletion of support correspondence or other Personal Data held directly by the Company by contacting us, subject to information we must retain for legal, tax, security, fraud-prevention, or recordkeeping purposes. Google controls retention and deletion of data it processes through Google Play.
We use safeguards intended to protect information handled by Access Vault, including authenticated encryption, Android Keystore protection, system authentication, secure-window protections, sensitive clipboard labeling, automatic clipboard clearing, and exclusion of private app data from Android backup.
No storage or security method is guaranteed to be completely secure. You are responsible for maintaining device security, installing trusted software, safeguarding backup passwords and exported files, and keeping appropriate encrypted backups.
Access Vault is not directed to children under 16, and we do not knowingly collect Personal Data from children through the Application. If you are a parent or guardian and believe a child has sent Personal Data directly to the Company, contact us so we can review and, where appropriate, delete it.
We may update this Privacy Policy to reflect changes to the Application, legal requirements, or our practices. We will post the revised policy at this location and update the "Last updated" date. Material changes may also be communicated within the Application or through the Google Play listing when appropriate.
For questions or requests concerning this Privacy Policy, contact:
Nexus Dev Labs LLC
914 N Utah Street
West Plains, MO 65775
United States
By email: [email protected]