Privacy Policy

API Vault · Last updated 27 August 2026

The short version

Core vault use is local. API credentials are encrypted on your device. API Vault does not run an advertising or behavioral-analytics system around your keys. Network access is used only for features that actually require it, such as provider validation, Google Play billing, and optional account or encrypted-backup functionality.

What stays on your device

API credentials, labels, categories and notes are stored locally. Stored credentials are encrypted using Android security facilities. Revealing a credential can be protected by biometric or device authentication according to the settings you choose.

What may leave your device

Provider validation

When you save or check a credential, API Vault may make a minimal request directly to the relevant provider to determine whether the credential works. Golden Physics Project is not in that request path. The provider handles the request under its own privacy policy.

Optional account and encrypted backup

The local vault does not require an account. If you choose to sign in or enable encrypted backup, account identifiers and encrypted backup data may be sent to the configured account/backup service. Backup data is intended to be encrypted on the client before storage; readable API credentials are not intended to be stored by Golden Physics Project.

Google Play

Google Play handles app distribution, purchase and subscription transactions. Google may process device, account and billing information according to Google's own policies. Golden Physics Project does not receive your payment-card details.

What we do not do

API Vault does not sell your API credentials or use them for advertising. It does not intentionally transmit stored plaintext credentials to Golden Physics Project. There is no requirement to create an API Vault account in order to use the local vault.

Security, stated honestly

On-device encryption and authentication materially reduce risk, but no mobile application can promise absolute security. A rooted or otherwise compromised device, malware with sufficient privileges, screen capture outside the app's control, or disclosure of a credential elsewhere can defeat protections that API Vault itself provides. If you suspect exposure, revoke or rotate the affected credential at its provider.

Contact

Golden Physics Project, Ontario, Canada. Privacy questions can be sent to dtoupin@goldenphysics.org.

Your rights

Data stored only on your device remains under your control and can be removed by deleting the relevant entry or uninstalling the app. If an optional account service holds personal data associated with you, you may contact us to request access, correction or deletion subject to applicable law.

← Back to API Vault · Terms of Service