Data Export & Deletion
Effective date: September 12, 2026
Publisher: Vlemon LLP · Contact: privacy@vlemon.com / support@vlemon.com
This page explains how you can export, migrate, and delete data in Monolith Spark and Monolith Vault. It supports privacy rights requests (access/portability/erasure) where applicable.
Because vault contents are stored on the device (not on our cloud), most requests are fulfilled by you in the app or by uninstalling.
1. Access / portability (export)
In-app encrypted export
- Unlock the app
- Open Settings → Export / Import (Backup)
- Choose a strong backup passphrase and confirm it
- Export: Spark creates a
.monolith.vdocfile; Vault creates a.vault.vdocfile
The file is encrypted. Keep the passphrase safe. We cannot decrypt your file without it.
Single-credential QR
You may share one entry via on-device QR (JSON including optional totp_uri). Treat QR content as sensitive.
Authenticator (2FA / TOTP)
Entries may store a Google Authenticator–compatible otpauth://totp/… secret. TOTP secrets are included in encrypted .vdoc backups and in credential QR JSON.
Bulk migration: Monolith can import and export Google Authenticator Transfer accounts QRs (otpauth-migration://). Use this when moving from Google Authenticator into Monolith, or exporting Monolith 2FA entries elsewhere. Migration QRs contain secrets in cleartext encoding — treat them as highly sensitive. HOTP accounts in a migration payload are skipped.
Import / export history
Settings shows a read-only history of import/export events (timestamps, file names, success/failure). It does not store passwords or backup passphrases. History cannot be deleted item-by-item.
2. Migration between Spark and Vault
- Export from the source app (password-protected
.vdoc) - Install the destination app and complete PIN setup
- Import the file with the same backup passphrase
- Choose merge or replace when importing
PIN, biometrics preference, and theme do not transfer — only vault credentials.
3. Deletion / erasure
Option A — Reset all data (recommended): Settings → Reset all data, then type RESET to confirm. This deletes all vault credentials, import/export history, PIN / local encryption keys in app secure storage, and related in-app preferences stored by Monolith. You return to first-run setup.
Option B — Uninstall: Uninstalling removes the app's sandbox data according to iOS / Android / Windows. Encrypted backup files you saved outside the app (Files, Drive, email) remain until you delete them.
Option C — Contact us: If you believe we hold personal data about you outside the on-device vault (for example support email correspondence), email privacy@vlemon.com. We do not host Spark/Vault credential databases on our servers in the current product design. For advertising data held by Google from Spark, use Google's privacy tools and your device ad settings — we cannot delete Google's ad logs on your behalf.
4. What we cannot do
- Reset or recover your PIN remotely
- Decrypt your
.vdocwithout the passphrase - Delete backups stored in your personal cloud or email
5. Retention after deletion
After Reset or uninstall, on-device Monolith data is removed as described above. Support emails may be retained for a limited period for customer service and legal obligations.
6. Your rights under GDPR
See our company-wide GDPR Compliance page for the full list of data subject rights available to EEA/UK individuals — this page is the practical "how to" for exercising access, portability, and erasure specifically within Spark and Vault.