Privacy Policy
Last Updated: May 12, 2026At Scoop Vault, we believe that privacy is a fundamental human right. ScoopVault is built on a fundamental principle: your data belongs exclusively to you. This Privacy Policy explains our offline-first architecture and what it means for your privacy.
1. Zero Data Collection
ScoopVault does not collect, transmit, share, or sell any personal information.
- There are no user accounts.
- There is no cloud synchronization.
- There are no analytics, crash reporters, or tracking SDKs embedded in the application.
- We literally cannot see what you store in your vault.
2. No Cloud Storage or Synchronization
All data you enter into ScoopVault—including passwords, notes, credit card numbers, and custom fields—remains entirely on your local device. The app does not make any external API calls or network requests to external servers for the purpose of data storage or telemetry.
3. Local Encryption & Security
Your data is secured locally using AES-GCM (and AES-256) encryption provided by the Web Crypto API.
- Master Password: Your master password is never stored anywhere in plain text. It is used strictly to derive a cryptographic key locally (using PBKDF2 with 600,000 iterations).
- Decoy Mode: The app supports a secondary "decoy" vault with isolated keys. Accessing the decoy vault leaves your primary vault cryptographically locked.
4. User-Controlled Exports
You have total control over your data. You may export your vault at any time. When you export an encrypted backup, it remains encrypted with your Master Password. If you export to a plaintext format (like PDF or Excel), it is your responsibility to secure those files.
5. Card Scanning & OCR
ScoopVault utilizes your device camera to scan credit and debit cards.
- Local Processing: The Optical Character Recognition (OCR) is performed entirely on-device using local machine learning models.
- No Uploads: Card images are never uploaded to any cloud service.
- No Image Retention: Camera frames are strictly processed in volatile memory and instantly destroyed once text is extracted.
6. Biometric Data
If you choose to enable biometric unlock (fingerprint or face recognition), this process is handled entirely by your device's native secure hardware layer and operating system API. ScoopVault simply receives a success/fail token from the operating system. We do not have access to your raw biometric data.
7. Backups and Exports
Because ScoopVault does not sync to the cloud, you are entirely responsible for your data backups.
- You may export your vault as an encrypted
.svbfile. - You may also export unencrypted PDFs or Excel files.
- Once data is exported from ScoopVault, it is your responsibility to store these files securely.
8. Data Deletion Functionality
Because all data is stored locally, deleting your data is instantaneous and absolute. You can delete individual items, entire folders, or clear your entire vault. Uninstalling the app or utilizing the "Auto Vault Wipe" feature will permanently and irreversibly destroy the local encrypted database.
9. Changes to this Policy
We may update this Privacy Policy from time to time as new features are added. However, our core commitment—that your data never leaves your device—will never change.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us at [EMAIL_ADDRESS].
Have questions about this policy?