Legal · Plain language

Privacy Policy

Protocol Vault is built around data minimization. The app is local-first, works offline, requires no account, and keeps your protocol information in a SQLCipher-encrypted database on your device.

Effective: September 27, 2026Last updated: September 27, 2026

At a glance

Your vault stays with you

Protocol entries are stored locally on your device. Protocol Vault does not require a cloud account or routinely transmit the contents of your vault to us.

  • No required Protocol Vault account.
  • No sale of personal information.
  • No advertising identifiers or cross-app behavioral tracking.
  • Backups are disabled unless you explicitly enable or initiate them.
  • You can delete local information from within the app or by clearing the app’s data.

1. Scope

This Privacy Policy explains how Protocol Vault handles information when you use the Protocol Vault mobile application and this website. “Protocol Vault,” “we,” “us,” and “our” refer to the developer and operator of the Protocol Vault app and protocolvault.app.

The app can contain sensitive health-related notes or routines that you choose to enter. Protocol Vault is an organizational tool; it is not a medical provider, medical record system, or emergency service.

2. Information handled by the app

Information you enter

You may enter protocol names, schedules, notes, completion records, and related details. This information is stored in the app’s local SQLCipher-encrypted database on your device. We do not receive it through normal use of the app.

Account information

No Protocol Vault account is required. We therefore do not collect account credentials or an account profile to provide the app’s core features.

Diagnostics and analytics

Protocol Vault does not use advertising trackers or analytics designed to follow you across apps or websites. We do not operate a diagnostic pipeline that receives the contents of your vault. If optional diagnostics are added in a future version, we will describe them before they are enabled and update this policy.

Website information

This static website may receive basic connection information that is technically necessary to deliver pages, such as an IP address, requested URL, browser type, and timestamp. Cloudflare may process this limited information as the website’s hosting, security, and content-delivery provider. We do not use the site to build advertising profiles.

Support communications

If you email us, we receive the information you choose to include, such as your email address, device details, and problem description. Please do not include private protocol or health details in a support request unless necessary.

3. How information is used

Information stored locally is used by the app to display, organize, search, and manage your protocols. Information you send to support is used to respond, diagnose problems, maintain security, and improve the product.

4. Local storage and security

The app stores its database locally using SQLCipher encryption. Encryption helps protect stored data, but no device or software is perfectly secure. Your device passcode, operating-system security, physical access controls, and timely updates remain important.

Because Protocol Vault is local-first, loss, damage, or reset of a device can make locally stored data unrecoverable when no backup or export exists.

5. Backups and exports

Protocol Vault backups are disabled unless you explicitly enable or initiate them. When you choose to export or back up information, you select the destination and initiate the transfer. The destination—such as device storage or a third-party storage provider—is governed by its own privacy and security practices.

Backup responsibility

Removing Protocol Vault from your device does not automatically erase copies you previously exported or stored with another provider. Delete those copies at their destination.

6. Sharing and disclosure

We do not sell or rent personal information. We do not share the contents of your local vault because we do not receive those contents through normal app use. Limited website or support information may be processed by service providers solely to host the site, secure services, and answer support requests.

We may disclose information we actually possess when required by law, to protect rights and safety, or in connection with a business transfer. Since core vault data remains on your device, we generally do not possess it.

7. Retention and deletion

Local protocol information remains on your device until you delete an entry, reset the app, clear its storage, or uninstall it. Support messages may be retained as reasonably necessary to resolve the request, keep business records, prevent abuse, and meet legal obligations.

For step-by-step instructions, visit Delete your data.

8. Children’s privacy

Protocol Vault is not directed to children under 13, and we do not knowingly collect personal information from children through an account service. A parent or guardian who believes a child sent us personal information can contact us to request deletion.

9. Changes to this policy

We may update this policy as the app changes. We will post the revised policy here and change the effective date. Material changes will be communicated through an appropriate in-app or public notice when feasible.

10. Contact

Questions or privacy requests can be sent to support@protocolvault.app.