API Vault · Last updated 27 August 2026
Core vault use is local. API credentials are encrypted on your device. API Vault does not run an advertising or behavioral-analytics system around your keys. Network access is used only for features that actually require it, such as provider validation, Google Play billing, and optional account or encrypted-backup functionality.
API credentials, labels, categories and notes are stored locally. Stored credentials are encrypted using Android security facilities. Revealing a credential can be protected by biometric or device authentication according to the settings you choose.
When you save or check a credential, API Vault may make a minimal request directly to the relevant provider to determine whether the credential works. Golden Physics Project is not in that request path. The provider handles the request under its own privacy policy.
The local vault does not require an account. If you choose to sign in or enable encrypted backup, account identifiers and encrypted backup data may be sent to the configured account/backup service. Backup data is intended to be encrypted on the client before storage; readable API credentials are not intended to be stored by Golden Physics Project.
Google Play handles app distribution, purchase and subscription transactions. Google may process device, account and billing information according to Google's own policies. Golden Physics Project does not receive your payment-card details.
API Vault does not sell your API credentials or use them for advertising. It does not intentionally transmit stored plaintext credentials to Golden Physics Project. There is no requirement to create an API Vault account in order to use the local vault.
On-device encryption and authentication materially reduce risk, but no mobile application can promise absolute security. A rooted or otherwise compromised device, malware with sufficient privileges, screen capture outside the app's control, or disclosure of a credential elsewhere can defeat protections that API Vault itself provides. If you suspect exposure, revoke or rotate the affected credential at its provider.
Golden Physics Project, Ontario, Canada. Privacy questions can be sent to dtoupin@goldenphysics.org.
Data stored only on your device remains under your control and can be removed by deleting the relevant entry or uninstalling the app. If an optional account service holds personal data associated with you, you may contact us to request access, correction or deletion subject to applicable law.