Privacy Policy
Who We Are
AlwaysVault is operated by Arkionix, a UK-based business. We are committed to protecting your personal data and your right to privacy.
Contact: [email protected]
What We Collect
Account and subscription data
- Your email address and name
- Check-in records: when you last checked in and your check-in schedule
- Chosen contact email addresses, and the names and postal addresses we use to post their USB keys. These are encrypted at rest on our servers.
- Billing information (handled and stored by Stripe; we do not hold raw card data)
What we cannot read
We cannot read your vault contents. Your vault is encrypted on your device before it reaches our servers, using your master password, which only you know. Our servers hold encrypted data only and cannot open it.
How We Use Your Data
- To provide, operate, and maintain the AlwaysVault service
- To process your subscription and payments via Stripe
- To send check-in reminders and service notifications
- To deliver your vault to chosen contacts if check-ins stop
- To comply with our legal obligations under UK law
We do not sell your data. We do not share it with third parties for marketing.
Your Rights (DSAR)
Under UK GDPR, you have the right to access, correct, or delete your personal data. To make a data subject access request:
Important: If your vault has already been delivered to your chosen contacts, we cannot retrieve or delete those copies; they are in the recipients' physical possession.
Data Security
Your vault is encrypted on your device with AES-256-GCM, using keys made from your master password. We never receive your master password or your vault keys, so our servers cannot decrypt your vault contents, including in the event of a server breach.
Your chosen contacts' email and postal addresses are encrypted at rest on our servers. We hold the keys for these, because we need them to verify your contacts and post their USB keys, so a copy of our database alone does not reveal them.
Data Retention
We retain your personal data for as long as your account is active. If you delete your account, deletion is permanent: after you confirm your request there is a short cooling-off period during which you can cancel, after which your account is locked and erased. We complete erasure within 30 days of verifying your request.
If your vault is delivered to your chosen contacts, your account is retained for a period you choose, 18 or 24 months (18 by default), and then permanently erased. We may retain certain records for a limited period where required by law.
Sub-Processors
We use the following third-party service providers (sub-processors) to operate AlwaysVault. Each handles personal data only as necessary to provide their service.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Hostinger | Web hosting & database | Site data, server logs, IP addresses | European Union |
| Cloudflare | CDN & DDoS protection | Traffic data, IP addresses | Global (EU SCCs in place) |
We do not sell your data. We do not share it with any party for marketing purposes.
Cookies
We use cookies only where necessary for security (session tokens, CSRF protection) and privacy-respecting analytics. We do not use advertising or cross-site tracking cookies.
Changes to This Policy
We may update this policy as the service develops. Significant changes will be communicated by email.