Privacy Policy
Last updated: September 1, 2026
The short version
IncidentVault has no accounts and no servers. Your incident records — dated entries, descriptions, witnesses, screenshots and workplace details — are stored only on your device. We cannot see them, sell them, or lose them, because they never reach us.
Data stored on your device
- Incident records you enter (dates, times, descriptions, witnesses, reporting details).
- Screenshots and photos you attach, kept in the app's private storage.
- Workplace entries (employer, role, dates) used to organize records and title your PDF chronology.
- App settings (theme, app lock).
This data leaves your device only when you export it: as a PDF chronology or CSV, or a backup archive shared through the iOS share sheet to destinations you choose.
Purchases
In-app purchases are processed by Apple. We use RevenueCat to validate purchase receipts; it receives an anonymous app identifier and purchase status — never your records or personal details.
What we do NOT do
- No user accounts, no passwords, no email collection.
- No analytics SDKs, no advertising identifiers, no tracking.
- No cloud copies of your records.
Face ID
If you enable the app lock, authentication is performed entirely by iOS. IncidentVault only receives a yes/no result and never touches biometric data.
Your control
Deleting the app deletes all data stored in it. Backups you exported remain wherever you saved them and are yours to keep or delete.
Contact
Questions about privacy: support@vaultlabs.app.
Changes
If this policy changes, the updated version will be posted at this address with a new date.