NovaPulse Zero Vault Privacy Policy
Effective date: 2026-08-16 · Last updated: 2026-08-16
Published by Vasa Serafin, Serafin Imports DOO · Contact: vasa_serafin@hotmail.com
This Privacy Policy describes how NovaPulse Zero Vault (“the App”, “we”, “us”) handles information when you use our mobile application on Android. The App is published by Vasa Serafin.
On-device vault. Files and notes you add are encrypted on the device with AES-256-GCM. We do not operate a vault or backup server. Lost password means lost data — there is no recovery backdoor.
Summary
- We do not sell your personal information.
- Offline-first. Encryption and decryption run on your device without our servers.
- No cloud AI or machine learning.
- Local data stays local. Ciphertext, notes, and settings live in the app until you delete them or uninstall. Uninstalling removes app storage (including any decrypted share cache).
Information we process
- Files you pick — opened through the system picker. Encrypted on-device. Not uploaded to us.
- Notes you type — encrypted on-device. Not uploaded to us.
- Decrypted share cache — a file you choose to decrypt is written to app cache so Android can share it via FileProvider. Not uploaded to us. Locking the vault wipes that cache.
- Biometric wrap (optional) — after a password unlock, the vault key may be wrapped in Android Keystore so you can re-unlock with fingerprint or face. Changing enrolled biometrics invalidates the wrap. We do not receive biometric templates.
- Decoy vault (Pro / No Ads) — a second local namespace (
zkv-decoy) with its own password and file list. Unlocking decoy does not open the primary vault. Not uploaded to us.
- Purchase status — Google Play confirms No Ads (INAPP
com.vasaserafin.zerovault.noads or SUBS com.vasaserafin.zerovault.noadssub) or Pro (com.novapulse.zerovault.pro). We store a local entitlement flag only.
- Advertising (Lite only) — Google AdMob may collect device identifiers and ad interaction data per Google’s Privacy Policy. A banner may show on vault screens; a full-screen ad may show once on first open and every 5 unlocks. UMP consent is requested before ads.
What we do not do
- We do not sell personal information.
- We do not upload your files, notes, or vault keys to our servers.
- We do not keep a password-recovery service. Lost password means lost data.
- We do not require a cloud account to use the vault.
- We do not use location or microphone permissions.
Legal bases (EEA/UK)
- Contract — providing vault, decoy, biometric re-unlock, and ads-free features you request.
- Consent — personalized ads in Lite where required (Google UMP).
Retention and deletion
Uninstalling the App or clearing its storage removes the encrypted vault, decoy namespace, biometric wrap, and decrypted share cache. Original files you picked stay where they were (the vault stores its own ciphertext). Ad partners and the Play Store may retain purchase or ad data under their own policies.
Your rights
Depending on your region you may have rights to access, correct, delete, or port your data. Because vault contents are stored locally and encrypted with a key we do not hold, deletion is typically achieved by uninstalling or clearing app data. We cannot decrypt a vault for you. Contact vasa_serafin@hotmail.com.
California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA.
Contact
Vasa Serafin, Serafin Imports DOO
Email: vasa_serafin@hotmail.com
Site: https://playstore-ads.web.app
All privacy policies · App catalogue