Privacy policy
Privacy policy
GrailVault is built so that we cannot read your passwords. This page says exactly what we do store, why, who helps us run the service, and how you can have it all erased. Last updated 6 October 2026.
The short version
- Your vault (logins, cards, notes and everything else you save) is encrypted on your own device before it reaches us. We store only the encrypted result and cannot decrypt it.
- We never receive your master password or your recovery key.
- We store your email address, your plan, and a short security activity log. We do not sell data, show ads or use trackers.
- You can delete your account yourself at any time, in Settings.
What we store
| Data | Why we need it | Can we read it? |
|---|---|---|
| Your email address | To sign you in, send your sign-up code and notices about your account | Yes |
| Your encrypted vault (every item, tag and your profile name and picture) | To give your vault back to you on any device | No. It is encrypted with a key built from your master password, which we never have |
| Keys needed for sign-in and recovery, in protected form (a hash of your login proof, your vault key wrapped by your password and by your recovery key) | To let you sign in and recover access | No. They are useless without your password or recovery key |
| Plan and billing status (plan, trial end, paid-until date, a subscription reference) | To apply your plan and the free trial | Yes |
| Sign-in sessions: when and from which browser and IP address you signed in | So you can see and end your sessions, and to protect your account | Yes |
| Security activity log (for example sign-ins, password changes, two-factor changes, plan changes), with time, IP address and browser; the newest 500 events from the last 180 days | So you can spot activity that was not yours | Yes. It never contains vault contents or item names |
| Size of your vault, number and size of items, and timestamps | To enforce limits and keep the service running | Yes (not the contents) |
| Two-factor and device-unlock settings (a sealed authenticator secret, backup-code hashes, the public part of any passkey) | To provide two-factor sign-in and device unlock | No secrets are readable by us in usable form |
Our server logs record requests for security and troubleshooting. They do not record request bodies, cookies or tokens.
What we do not do
- We do not read, scan, analyse or sell your vault.
- We do not use advertising or analytics trackers. This website sets no cookies. The app sets one cookie, a secure session cookie, only so you stay signed in.
- We do not share your data with advertisers or data brokers.
Who processes data for us
- Hosting. Our server and database run on a virtual private server we rent. Everything stored there is as described above, with your vault encrypted.
- Payments: Razorpay. When you pay, you are sent to Razorpay's page. Your card, UPI or bank details go to Razorpay and never reach us. We receive confirmation that a payment succeeded and your subscription reference. Razorpay's own privacy policy applies to what it collects.
- Email delivery. We send email (sign-up codes, security notices, trial reminders, payment confirmations and occasional service messages) through an email service provider. They process your email address and the message.
- Breach check (optional). The security check can ask whether a password has appeared in known breaches. Your device sends only the first five characters of a one-way fingerprint of the password, never the password, to the Have I Been Pwned range service through our server.
The browser extension
The extension fills and saves logins. To do that it:
- reads sign-in forms on the pages you visit, only on your click, to fill a login or to offer to save one. Page content is not sent anywhere except the login you choose to save, and that goes to our server only in encrypted form;
- talks only to https://app.grailvault.in;
- keeps your vault key and session in the browser's temporary storage, which is cleared when you close the browser or lock the extension; and
- stores locally which sites you told it never to offer to save.
The extension collects authentication information (your saved logins, sent encrypted) and your email address (to sign in). It does not track your browsing, and it does not send the pages you visit to us.
How long we keep data
- While your account exists: your account data, encrypted vault and activity log as described above.
- Ended trial or plan: your vault is kept and stays readable and exportable. We never delete it because a plan ended.
- When you delete your account: your account, encrypted vault, sessions and activity log are erased immediately, and any subscription is cancelled. Encrypted backups we keep for disaster recovery may hold an older encrypted copy until they are replaced by newer backups (a rolling set kept for a few weeks). They stay encrypted.
- Sign-up codes are kept for ten minutes and removed when used or expired.
Your choices and rights
- Access and portability. Export your whole vault at any time (CSV, or an encrypted backup).
- Correction. Change your master password, profile and settings in the app.
- Deletion. Delete your account in Settings. We cannot recover it afterwards, and nobody can.
- Questions or requests about your data: write to support@grailvault.in. We answer within 30 days.
If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights to access, correct and erase your personal data and to nominate someone to act for you, and to complain to us first. If you are in the European Economic Area or the United Kingdom, you have the corresponding rights under the GDPR, including the right to complain to your data protection authority. The legal basis for processing is to provide the service you asked for, to keep it secure, and to meet legal obligations.
Security
See how your data is protected, including an honest list of what GrailVault does not protect against. No system is perfectly safe. If we find that personal data was exposed, we will tell affected people and the authorities as the law requires.
Children
GrailVault is not meant for children under 18, and we do not knowingly collect their data.
Changes to this policy
If we change this policy in a way that matters, we will update the date above and, for significant changes, tell you by email or in the app.
Contact
Email support@grailvault.in, or call 63749 34589.