ScoopVault Logo
ScoopVault
Back to ScoopVault

Privacy Policy

Last Updated: May 12, 2026

At Scoop Vault, we believe that privacy is a fundamental human right. ScoopVault is built on a fundamental principle: your data belongs exclusively to you. This Privacy Policy explains our offline-first architecture and what it means for your privacy.

1. Zero Data Collection

ScoopVault does not collect, transmit, share, or sell any personal information.

  • There are no user accounts.
  • There is no cloud synchronization.
  • There are no analytics, crash reporters, or tracking SDKs embedded in the application.
  • We literally cannot see what you store in your vault.

2. No Cloud Storage or Synchronization

All data you enter into ScoopVault—including passwords, notes, credit card numbers, and custom fields—remains entirely on your local device. The app does not make any external API calls or network requests to external servers for the purpose of data storage or telemetry.

3. Local Encryption & Security

Your data is secured locally using AES-GCM (and AES-256) encryption provided by the Web Crypto API.

  • Master Password: Your master password is never stored anywhere in plain text. It is used strictly to derive a cryptographic key locally (using PBKDF2 with 600,000 iterations).
  • Decoy Mode: The app supports a secondary "decoy" vault with isolated keys. Accessing the decoy vault leaves your primary vault cryptographically locked.

4. User-Controlled Exports

You have total control over your data. You may export your vault at any time. When you export an encrypted backup, it remains encrypted with your Master Password. If you export to a plaintext format (like PDF or Excel), it is your responsibility to secure those files.

5. Card Scanning & OCR

ScoopVault utilizes your device camera to scan credit and debit cards.

  • Local Processing: The Optical Character Recognition (OCR) is performed entirely on-device using local machine learning models.
  • No Uploads: Card images are never uploaded to any cloud service.
  • No Image Retention: Camera frames are strictly processed in volatile memory and instantly destroyed once text is extracted.

6. Biometric Data

If you choose to enable biometric unlock (fingerprint or face recognition), this process is handled entirely by your device's native secure hardware layer and operating system API. ScoopVault simply receives a success/fail token from the operating system. We do not have access to your raw biometric data.

7. Backups and Exports

Because ScoopVault does not sync to the cloud, you are entirely responsible for your data backups.

  • You may export your vault as an encrypted .svb file.
  • You may also export unencrypted PDFs or Excel files.
  • Once data is exported from ScoopVault, it is your responsibility to store these files securely.

8. Data Deletion Functionality

Because all data is stored locally, deleting your data is instantaneous and absolute. You can delete individual items, entire folders, or clear your entire vault. Uninstalling the app or utilizing the "Auto Vault Wipe" feature will permanently and irreversibly destroy the local encrypted database.

9. Changes to this Policy

We may update this Privacy Policy from time to time as new features are added. However, our core commitment—that your data never leaves your device—will never change.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us at [EMAIL_ADDRESS].

Have questions about this policy?