PRIVACY POLICY

Privacy, without surprises.

This policy explains the information processed by the Vault18 SaaS service and the Vault18 Vault browser extension. Effective July 26, 2026.

Who operates Vault18

Vault18 is operated by Oronzo. Questions and privacy requests can be sent to [email protected].

The browser extension

The unlocked Vault18 website can send the extension a freshly encrypted copy of active records for the selected organization. The extension accepts this ciphertext only from the exact Vault18 production origin and stores it in browser extension storage. Alternatively, you may select an encrypted export file. In either flow, the extension derives a decryption key from the master password you enter and decrypts only on your device. The master password, decrypted credentials, visited URLs, and autofill activity are not uploaded to Vault18 or a third party by the extension.

Decrypted items are held only in the extension background process memory and are cleared when you lock the extension, after ten minutes of inactivity, or when the browser terminates or suspends that process. The extension does not persist decrypted items or the master password. The encrypted envelope remains in extension storage for later unlocks until you replace it or choose Forget saved encrypted vault.

The extension needs access to HTTP and HTTPS pages to identify supported login and one-time-code forms, compare the current page with saved login origins, and display an autofill offer. Matching includes the exact scheme, hostname, and port. Ordinary navigation requires the user to select a matching login or approve the on-page offer. Choosing Launch & sign in creates a 60-second approval bound to the selected record and exact destination origin; the web page sends no credential to the extension. A user may explicitly enable auto-submit for an individual record; the extension then fills a unique matching field and submits only a same-origin POST form, while skipping CAPTCHA, ambiguous, cross-origin, and federated flows. The target website receives the filled or submitted credential as it would during a normal login. The extension contains no advertising, analytics, tracking SDK, or remotely executed code.

The Vault18 web service

When you request access or use the service, we process account and organization information such as name, work email, company, role, optional phone number, organization membership, domain configuration, access grants, attachment identifiers and encrypted sizes, and security audit events. Amazon Cognito processes authentication information and multi-factor authentication state.

Vault contents are encrypted in the browser before upload. The service stores ciphertext, cryptographic envelopes, wrapped record keys, record identifiers, revisions, sharing expiry and consumption state, and the minimum metadata needed to enforce organization and record access. File attachments are independently encrypted in the browser before being sent to a private Amazon S3 bucket. The original file name, type, contents, and per-file decryption key remain inside the encrypted record; the service receives ciphertext, its size, a random attachment identifier, and its associated record identifier. If you enable master-password recovery, the browser adds an authenticated ciphertext wrapper protected by a random recovery key that is shown only to you. Vault18 does not receive that recovery key and cannot use the wrapper to recover or read the vault. Vault18 is designed not to receive master passwords, plaintext vault records or attachments, TOTP seeds, or unwrapped record keys.

Why information is processed

  • Provide authentication, tenant isolation, encrypted storage, sharing, and support.
  • Prevent abuse, investigate security events, and maintain service reliability.
  • Send requested verification, recovery, invitation, and service messages.
  • Meet legal obligations and enforce applicable agreements.

Service providers and disclosure

Vault18 uses Amazon Web Services for hosting, authentication, databases, encryption-key services, logs, and content delivery, and Resend for transactional email delivery. These providers process information only to deliver their contracted services. We do not sell personal information or use vault data for advertising.

Information may also be disclosed when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate confidentiality protections.

Retention and deletion

Account and organization data is retained while the applicable account or customer relationship remains active and as needed for security, dispute resolution, and legal obligations. An organization owner can download an encrypted export and permanently delete the tenant from Settings. Live encrypted records, committed attachment objects, access grants, members, domains, and organization-identified secure links are removed immediately. Abandoned pending attachment ciphertext expires within one day. Legacy secure links created before organization tracking expire within 30 days. Sanitized security audit events are retained for up to 365 days, operational logs for up to 30 days, and encrypted point-in-time backups age out within 35 days.

Any plaintext or export previously saved by an authorized recipient is outside Vault18’s control and cannot be remotely erased. To request account closure, use Settings after transferring or deleting organizations you own. For access, correction, or privacy help, contact [email protected] from the account email. We may retain information that must be preserved for legal reasons.

Security and children

Vault18 applies encryption in transit, client-side encryption for vault contents, multi-factor authentication, tenant authorization checks, and restricted operational access. No system can promise absolute security. Vault18 is intended for organizations and is not directed to children under 16.

Changes

Material changes will be posted on this page with a revised effective date. If a change materially affects how browser-extension data is handled, the extension listing and disclosures will also be updated.