Legal

Privacy Policy

Effective date: September 16, 2026

This Privacy Policy explains how IDVault (“we”, “our”, or “the app”) stores, processes, and shares data when you use the app. IDVault does not require an IDVault account and does not use advertising, analytics, or tracking. Document data is processed on your devices. If you enable iCloud sync, IDVault encrypts sensitive document data before it is transmitted to and stored in your private iCloud account. IDVault may provide limited discovery metadata to Apple system features, and selected protected fields are sent to another app or assistant only when you initiate or approve the disclosure.

01

Data Stored in IDVault

IDVault stores the profiles and identity documents you add. Depending on the document and the information available, this may include names, document type and number, issuing country, nationality, date of birth, sex, expiry date, MRZ data, and optional NFC data such as a document photo, signature image, place of birth, address, phone number, or personal number. This information is used to organize your documents and provide the features you request.

02

Camera and NFC Usage

With your permission, IDVault uses the camera to scan the MRZ (Machine Readable Zone) of supported passports, identity cards, visas, and driver’s licenses. On compatible iPhones, you may also use NFC to read available data from a supported document chip. Camera recognition and NFC reading are performed on your device. IDVault does not upload scans to servers operated by us.

03

Storage and Security

Sensitive document fields and images are encrypted before storage using AES-GCM. Encryption keys are stored in Apple’s Keychain. IDVault also relies on the security protections of your Apple devices, including your passcode, Face ID, or Touch ID where available. No security system can guarantee absolute protection, so keep your devices and Apple Account secure.

04

iCloud and Cross-Device Sync Optional

When iCloud is enabled for IDVault, encrypted document records and certain app settings may be synchronized through Apple’s CloudKit and iCloud key-value storage so they are available on your supported Apple devices. This data is stored in your iCloud account and is governed by Apple’s terms and privacy policy. Private CloudKit data is not visible to us through the CloudKit developer console. You can control IDVault’s iCloud access in system settings.

05

Spotlight, Handoff, Siri, and Shortcuts

To help you find and open documents, IDVault may provide Apple system services with discovery metadata such as the person’s name, document type, issuing country, update date, and an internal document identifier. Spotlight can index this metadata, and Handoff can use an internal identifier to continue viewing a document on another supported device. Siri, Shortcuts, and compatible Apple Intelligence actions can request selected protected fields as described below.

06

Document Sharing and AI Assistants

When you start or approve a document-sharing workflow, IDVault may provide the selected fields to a compatible Siri, Shortcuts, or Apple Intelligence action. On Mac, you may also connect ChatGPT or Claude and approve a request for selected fields. Protected requests require device authentication, and IDVault can show an optional review of the requested fields. Each disclosure is a one-time response and does not grant ongoing access to your vault.

After you approve a disclosure, the receiving action, app, or assistant may process, transmit, or retain the data under its own settings and privacy policy. IDVault does not control data after it has been provided to the recipient. Review the recipient and requested fields before approving a disclosure.

07

Clipboard and Photos

If you choose to copy a document field or image, IDVault places that information on the system clipboard, where it may be available to other apps according to your operating system’s clipboard rules. If you choose to save a document image, IDVault requests permission to add it to your Photos library. Copies in the clipboard or Photos are outside the IDVault vault and are governed by your device and iCloud Photos settings.

08

Expiry Notifications

With your permission, IDVault schedules local notifications to remind you about approaching or passed document expiry dates. Notification scheduling is handled by your device. You can disable notification permission or change notification presentation in system settings.

09

Subscriptions and Request Limits

Optional Premium subscriptions are offered through Apple’s StoreKit. Apple processes purchases and payment information under its own terms and privacy policy; IDVault does not receive your payment card details. The app reads the StoreKit entitlement needed to unlock Premium and stores an encrypted count and reset date for the monthly free assistant-request limit in iCloud so the limit can remain consistent across your devices.

10

No Advertising, Analytics, or Tracking

IDVault does not include advertising SDKs, third-party analytics services, or tracking tools, and we do not build advertising profiles from your document or app-usage data. Operational data handled by Apple services and data you choose to send to another app are subject to the relevant provider’s privacy practices.

11

Retention, Deletion, and Your Choices

Documents remain in IDVault until you delete them. Deleting a document in the app removes its local record and the deletion is synchronized through iCloud when sync is available. You can delete all app data by removing documents and uninstalling IDVault, and you can manage IDVault’s iCloud data and permissions through Apple’s system settings. You can also disable notifications, camera or Photos access, turn off disclosure confirmation only if you accept the resulting risk, and disconnect supported assistants from IDVault settings.

Deleting data from IDVault does not delete copies you previously placed in Photos, on the clipboard, or shared with another action, app, or assistant. Those copies must be deleted through the relevant app or service. Because IDVault does not provide an IDVault account or operate a document-data server, we generally do not hold a separate server-side copy that we can delete on your behalf.

12

Changes to This Policy

We may update this policy when IDVault’s features or data practices change. The updated version will be published in the app or on this page with a revised effective date.

13

Contact

If you have a privacy question or need help understanding how to delete IDVault data, contact:

idvault@romanmazeev.com