Privacy Policy
Effective date: September 12, 2026
Product: Monolith Vault (com.vlemon.monolith.vault) · Publisher: Vlemon LLP · Contact: privacy@vlemon.com
This Privacy Policy describes how Monolith Vault ("Vault," "the App") handles information. Vault is designed as an offline, air-gapped credential vault. It does not require an account, does not sync to our servers, and — in the release store build — is intended to operate without network access.
Summary: We do not collect personal data from Vault. Your credentials stay on your device (or in encrypted backup files you control).
1. Who we are
Vlemon LLP ("we," "us") publishes Monolith Vault on the Apple App Store, Google Play, and/or Microsoft Store as a one-time paid application. Website: vlemon.org.
2. Data we do not collect
Vault does not:
- Create user accounts or require sign-in with us
- Upload credentials, PINs, or backups to our servers
- Use analytics, crash-reporting, or advertising SDKs in the intended release configuration
- Track you across apps or websites for advertising
- Sell or share your personal information with third parties for marketing
For App Store / Play "Data Not Collected" style disclosures, Vault is intended to qualify as no data collected by the developer.
3. Information stored only on your device
Vault stores the following locally on your device (not on our servers):
| Data | Purpose |
|---|---|
| Encrypted credential vault (titles, usernames, passwords, URLs, notes, tags, service types, TOTP/authenticator secrets, timestamps) | Provide the password-manager feature |
| PIN hash / salt and vault encryption key material (in platform secure storage / Keychain equivalents) | Unlock and encrypt the vault at rest |
| Biometrics preference (on/off) | Optional biometric unlock |
| Theme and idle-lock preferences | App settings |
| Import / export history metadata (time, direction, file name, status; not passwords or backup passphrases) | Audit of backup operations |
You can erase this local data with Settings → Reset all data (this also clears import/export history). Uninstalling the app removes the app sandbox data according to your operating system.
4. Backups you create
When you export a backup, Vault creates a password-protected file (.vault.vdoc). That file contains encrypted vault contents. We never receive it unless you choose to send it to someone (for example via AirDrop, email, or cloud storage you control).
Import accepts compatible encrypted backups (including Monolith Spark .monolith.vdoc files). Decryption happens on device using the passphrase you enter. You are responsible for safeguarding backup files and passphrases.
5. Permissions
Depending on platform, Vault may request:
- Camera — only to scan credential QR codes offline
- Biometrics / Face ID / fingerprint — optional unlock
- File / share access — to save or open encrypted backup files
These features run locally. Vault's release Android build is configured to omit the INTERNET permission so the package cannot open network connections under normal OS enforcement.
6. Children's privacy
Vault is not directed at children under 13 (or the minimum age in your country). Do not use Vault to store data of children in a way that violates applicable law.
7. International users
All processing of vault contents happens on your device. We do not operate a Vault cloud backend that transfers your credentials internationally. See our company-wide GDPR Compliance page for data subject rights available to EEA/UK individuals.
8. Data export, deletion, and migration
Full instructions for exporting, migrating, and deleting Vault data are on our shared Data Export & Deletion page.
9. Changes
We may update this policy when the product changes. The effective date above will be revised. Continued use after changes means you accept the updated policy. Material changes will be reflected in the store listing privacy URL when required.
10. Contact
Privacy questions: privacy@vlemon.com
Support: support@vlemon.com