Language Selection

You can view this privacy policy in 13 languages.

Privacy Policy

EGES Vault · Last updated: April 2025 · This policy explains how your data is handled while using the app.

✅ EGES Vault does not show ads, track user behavior, or sell data. Your passwords are encrypted on your device and are not sent to our servers.

1. Overview

EGES Vault is a privacy-first password manager designed for iOS. Our core principle is that privacy comes first: your passwords are encrypted on your device with AES-256-GCM. This policy explains what data is processed, why it is processed, and how it is protected.

2. Data We Process and Where It Is Stored

The table below summarizes the data categories processed by the app:

Data TypeWhere It Is StoredSent to Server?
Password entries (site, username, password, note)iOS Keychain (encrypted)No
PIN verification dataiOS Keychain (salt + hash)No
App preferences (theme, notifications)UserDefaults (on-device)No
Secure files (Pro)Encrypted on-device storageNo
Group Vault data (Pro – family sharing)Firebase Firestore (encrypted)Yes – sync only
Recovery emailOn-device + Firebase AuthYes – for recovery
Purchase recordsApple StoreKitYes – processed by Apple
Breach scan (optional)Not storedPartial – k-anonymity

3. Encryption and Security

All password entries are encrypted on-device with AES-256-GCM using a key derived from your PIN (PBKDF2 + random salt). This key never leaves your device.

4. Third-Party Services

4.1 Firebase (Google LLC)

Firebase Authentication is used only for account recovery through anonymous sign-in and email link sign-in. When Group Vault (Pro) is enabled, encrypted sync data is stored in Firebase Firestore. Google Privacy Policy

4.2 Have I Been Pwned (HIBP)

The Leak Scan feature is optional. Only the first 5 characters of your password’s SHA-1 hash are sent to the HIBP API using the k-anonymity model. Your actual password is never transmitted.

4.3 Apple StoreKit

In-app purchases are processed directly by the Apple App Store infrastructure. Your payment information is never transmitted to our app. Apple Privacy Policy

4.4 Apple CloudKit

If backup is enabled, your data may be transferred in encrypted form through Apple’s CloudKit infrastructure. This process is managed entirely through your iCloud account.

5. Location Data

EGES Vault does not collect or use location data under any circumstances.

6. Children’s Privacy

EGES Vault is not intended for children under the age of 13. We do not knowingly collect personal data from this age group. If a parent or guardian becomes aware of such a situation, please contact us.

7. User Rights

Users in Türkiye may have rights under Law No. 6698 (KVKK), including the right to:

Since your data is stored largely on your device, deleting the app or using Settings → Delete Data permanently removes local data.

8. Policy Updates

This privacy policy may be updated from time to time. Significant changes will be announced through an in-app notice. We recommend checking the “Last updated” date at the top of this page regularly.


9. Contact

For privacy-related questions:

EGES Vault · Privacy Policy · © 2025 Gökhan Öztürk. All rights reserved.