Vaultgram Privacy Policy

**Effective date:** 29 August 2026  

**Last updated:** 29 August 2026

Vaultgram is an iOS photo and video vault published by **Digibump**. This policy explains what information Vaultgram handles, where it is stored, when it leaves your device, and the controls available to you.

Vaultgram does not operate an account or media-storage server. We do not use advertising, tracking, third-party analytics, or remote crash-reporting SDKs, and we do not sell personal data. Optional services provided by Apple and Google process information only when you use the corresponding feature, as described below.

## 1. Information handled on your device

### Vault media and documents

When you import photos, videos, Live Photos, GIFs, or PDF scans, Vaultgram encrypts their file contents on your device using AES-256-GCM before storing them in the app’s private container. Vault encryption keys are protected using your PIN and Apple’s Keychain. Vaultgram can also maintain a separate decoy vault with separate local key material.

Your PIN is not stored as readable text. It is used to derive cryptographic key material and is then discarded. Vaultgram does not know or receive your PIN.

### Local metadata

Vaultgram stores information needed to organize and operate the vault in databases inside the app’s private container. Depending on the item and features you use, this can include:

– album names and visibility settings;

– filenames, file types, sizes, dates, dimensions, durations, favorites, and import identifiers;

– location coordinates already embedded in a photo you import;

– deletion, backup, and sync status;

– locally generated OCR text, classification labels, face counts, and perceptual hashes used for search, smart categories, and duplicate detection; and

– app preferences and feature settings.

This operational metadata is protected by the iOS app sandbox but is not encrypted in the same file-container format as the media itself. Encryption keys and sensitive recovery material are stored through Apple Keychain rather than in this database.

Vaultgram’s map feature displays saved coordinates from photos. It does not request or track your device’s current location.

### Apple Photos smart search

If you grant Photos access and open the Tools features, Vaultgram can analyze accessible photos on your device using Apple’s Vision and Core Image frameworks. The app creates a local search index containing identifiers, dates, categories, OCR text, face-presence results, QR/document indicators, and similar derived information. This analysis runs on the device. Source images and the local search index are not sent to Digibump or to an AI service.

You can restrict Vaultgram to selected photos through iOS Limited Photos Access, change access in iOS Settings, or remove access entirely. Removing Photos access stops further analysis. Uninstalling Vaultgram removes its local search index.

### Editing and media tools

Editing features can open a photo from the vault or one you explicitly select from the Photos picker. Resize, compression, filters, text, drawing, background and portrait tools, EXIF removal, and video-to-GIF processing run on your device. Vaultgram does not send editor inputs to a remote AI service. Saving an edit creates a new copy; the source remains unchanged unless you separately choose to delete it.

If you use Remove EXIF Data, Vaultgram creates a new copy without source metadata such as location, camera information, and capture dates. It does not change the original.

### Face ID, Touch ID, and Optic ID

Biometric authentication is performed by iOS. Vaultgram receives only the authentication result and never receives or stores your facial, fingerprint, or iris data. If enabled, biometric unlock occurs only after you tap the biometric unlock control; the app does not automatically initiate it when the lock screen appears.

### Sign in with Apple and PIN recovery

If you enable PIN recovery or first enable biometric unlock, Vaultgram can ask you to authenticate with Sign in with Apple. The app requests no name or email address. It receives an Apple-provided, app-specific user identifier and authorization credentials. Vaultgram verifies the credential with Apple’s system framework, uses the identifier to bind recovery to the correct Apple Account, and stores that binding and encrypted recovery material locally in Keychain. Vaultgram does not receive your Apple Account password.

Recovery setup is specific to this vault and device and is separate from iCloud Sync. If iCloud Passwords & Keychain is enabled, Apple may sync eligible Keychain material between your trusted devices under Apple’s terms. You can remove the local recovery binding by resetting the vault, but doing so may make a forgotten PIN unrecoverable.

### Break-in log

The optional Break-in Log is off by default. If you enable it and grant Camera access, Vaultgram can use the front camera after repeated failed PIN attempts. Captures are encrypted and stored only on the device, with their capture time. Public iOS camera APIs may play the normal shutter sound. You can review or clear the log in Settings or turn the feature off. Turning it off stops future captures; use Clear Log to remove existing entries.

### Recently Deleted

Items deleted from the vault normally remain as encrypted files in Vaultgram’s Recently Deleted area for up to 30 days. You can restore them or permanently delete them sooner. Expired items are permanently deleted the next time Vaultgram performs its cleanup process, normally when the app launches.

## 2. Optional services that transmit information

### iCloud Sync

iCloud Sync is off by default and requires Vaultgram Pro. If enabled, Vaultgram uses Apple’s CloudKit to store records in the private database associated with the Apple Account signed in on the device.

Vault media files are uploaded in their Vaultgram-encrypted form. The app also uploads the information required to reconstruct and synchronize the vault, including encrypted or wrapped key material and operational metadata such as album names, filenames, media attributes, dates, locations, OCR text, classification labels, and deletion state. This operational metadata is protected by Apple’s private CloudKit access controls but is not separately encrypted by Vaultgram in the same way as media file contents.

Digibump does not operate a server in this transfer and does not receive your Apple Account password. Apple processes and stores iCloud data under the terms and privacy policy applicable to your Apple Account.

Turning off iCloud Sync stops future syncing on that device but does not automatically delete records already stored in iCloud or copies already downloaded to another device. You can manage or delete application data through your Apple Account’s iCloud storage controls. Deleting cloud data may prevent recovery on other devices.

### Google Photos Backup

Google Photos Backup is off by default, requires Vaultgram Pro, and currently uploads photos rather than videos. If enabled, Vaultgram opens Google’s OAuth authorization page using an Apple system authentication session and requests only the `photoslibrary.appendonly` permission. That permission lets Vaultgram add new media to your Google Photos library; it does not let Vaultgram read, modify, or delete existing Google Photos items.

Vaultgram sends the photo bytes, content type, and source filename directly from your device to Google Photos. Google receives and stores those copies in the Google Account you select. Vaultgram does not receive your Google password. A Google OAuth refresh token is stored in Apple Keychain so backup can continue; short-lived access tokens are held in memory. Digibump does not operate an intermediary server and does not receive the uploaded media or OAuth tokens.

Vaultgram uses Google user data only to provide the visible Google Photos backup feature. It does not use Google user data for advertising, analytics, credit decisions, or training generalized AI models; does not sell or transfer it to data brokers or other third parties; and does not permit human access to it. Vaultgram’s use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Disconnecting Google Photos in Vaultgram deletes the locally stored refresh token and stops future uploads. You can also revoke access from your [Google Account connections page](https://myaccount.google.com/connections). Disconnecting or revoking access does not delete photos already uploaded; delete those copies in Google Photos if you no longer want Google to retain them.

### Purchases and subscriptions

Vaultgram offers monthly and yearly auto-renewable subscriptions and a lifetime non-consumable purchase. Apple processes purchases, payment information, refunds, and subscription management. Vaultgram uses StoreKit to request localized product information and verify whether a valid Vaultgram Pro entitlement is active. Digibump does not receive or store your payment card details. Apple may provide developers with transaction, financial, and aggregated sales information under Apple’s applicable terms.

## 3. Permissions and their purposes

Depending on the features you choose, Vaultgram may request:

– **Photos:** browse and import accessible media, build the on-device smart-search index, display photo locations on a map, export copies, or delete originals only after you expressly confirm the deletion;

– **Camera:** capture photos or scan documents into the vault, and operate the optional Break-in Log;

– **Microphone:** record audio when capturing video;

– **Face ID or other supported biometrics:** authenticate access using iOS;

– **Files:** read PDF documents you explicitly select for the Scans album; and

– **Network access:** communicate with Apple for StoreKit, Sign in with Apple, and optional iCloud Sync, and with Google for optional Google Photos authorization and backup.

You can change Photos, Camera, Microphone, and Face ID permissions in iOS Settings. Some features will stop working when the corresponding permission is removed.

## 4. What Digibump does not collect

The released app does not send Digibump:

– vault photos, videos, documents, thumbnails, or edited images;

– PINs, biometric measurements, Apple Account passwords, or Google passwords;

– local OCR, face, search, duplicate, or location results;

– advertising identifiers or cross-app tracking data; or

– analytics events, usage profiles, or third-party crash reports.

Vaultgram contains no advertising SDK and does not use data for targeted advertising or tracking.

## 5. Retention, deletion, and your choices

You control locally stored data through the app and the operating system:

– Delete vault items, permanently delete them from Recently Deleted, or wait for the 30-day cleanup window.

– Clear the Break-in Log from Vaultgram Settings.

– Revoke Photos, Camera, Microphone, or Face ID access in iOS Settings.

– Turn off iCloud Sync or Google Photos Backup at any time.

– Disconnect Google Photos and revoke its OAuth access.

– Delete separately uploaded copies through iCloud or Google Photos controls.

– Uninstall Vaultgram to remove its app container and local index from that device, subject to iOS behavior and any separate iCloud, Keychain, Google Photos, Photos-library, device-backup, or other copies you control.

Vaultgram does not maintain a developer-hosted user account or server copy for Digibump to retrieve or delete on your behalf. If you contact Digibump for support, information you voluntarily provide through the website is handled only to respond, maintain necessary support records, protect the service, or meet legal obligations. It is retained only as long as reasonably necessary for those purposes. You may use the contact method below to request access, correction, or deletion of support information, subject to applicable legal exceptions.

## 6. Security

Vaultgram uses application-layer encryption for vault media, Apple Keychain for key and token storage, iOS data protection for designated temporary and security-sensitive files, and the iOS app sandbox. No storage or transmission system can be guaranteed completely secure. Keep your device, Apple Account, Google Account, recovery methods, and PIN protected. If you lose both your PIN and configured recovery access, Digibump cannot decrypt the vault for you.

## 7. Children’s privacy

Vaultgram is not directed to children under 13 or the minimum age required in their jurisdiction. Digibump does not knowingly collect personal information from children through the app. A parent or guardian with a concern can contact us using the method below.

## 8. International processing and third parties

Apple and Google may process information in countries other than the one where you live, according to their own terms, privacy policies, and safeguards. Their handling of information is governed by their policies. Vaultgram limits each user-directed transfer to the information needed for the feature described in this policy and does not authorize either service to use that information on Digibump’s behalf for advertising or unrelated purposes. Vaultgram does not disclose app data to any other external recipient.

Relevant third-party policies include:

– [Apple Privacy Policy](https://www.apple.com/legal/privacy/)

– [Apple iCloud Terms](https://www.apple.com/legal/internet-services/icloud/)

– [Google Privacy Policy](https://policies.google.com/privacy)

– [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy)

## 9. Changes to this policy

If Vaultgram’s data practices change, Digibump will update this policy and its “Last updated” date before applying a materially different use of data. Where required, we will provide an in-app notice or request renewed consent. Earlier versions may be retained for reference.

## 10. Contact

For privacy questions, support requests, or concerns, contact Digibump through:

Contact

Because Digibump does not receive vault contents or maintain a Vaultgram account database, include only the information needed to describe your concern and do not send your PIN, recovery keys, or private media.