Legal

Privacy Policy

ApiVault is a zero-knowledge secret management service. This policy explains what information we collect, how we use it, and the choices you have.

Overview

We built ApiVault for developers who need a secure place to store API keys and similar secrets. We collect only what is needed to operate the service, protect your account, and improve reliability. We do not sell your personal information.

By using ApiVault — including the web app, CLI, and MCP integrations — you agree to this Privacy Policy. If you do not agree, please do not use the service.

Information we collect

Account information

When you create an account, we collect information such as your email address, display name, and authentication credentials. If you sign in with Google OAuth, we receive basic profile information from Google according to your consent on their sign-in screen.

Vault data

ApiVault stores the secrets you choose to save, encrypted at rest. We also store associated metadata such as key names, services, environments, and notes you provide. In custom encryption mode, your vault passphrase is never stored on our servers — only you can decrypt your secrets with that passphrase.

Device and session data

We record active sessions and connected devices — including web browsers, CLI installations authorized via apivault login, and MCP clients — so you can review and revoke access. This may include device labels, IP addresses, and timestamps of last activity.

Technical and usage data

Like most web services, we automatically collect limited technical information when you use ApiVault, such as browser type, operating system, request logs, and error reports. We use this data to maintain security, diagnose problems, and improve performance.

How we use your information

We use the information we collect to:

  • Provide, operate, and maintain the ApiVault service
  • Authenticate you and manage your account and sessions
  • Encrypt, store, and retrieve your secrets at your direction
  • Send security-related notices, such as password changes or new device sign-ins
  • Detect, prevent, and respond to abuse, fraud, or security incidents
  • Improve the product and fix bugs

Encryption and zero-knowledge design

Secret values are encrypted before storage using industry-standard cryptography. In custom encryption mode, decryption keys are derived from your vault passphrase, which ApiVault never receives or stores. Even in default encryption mode, secret values are encrypted at rest and are not exposed in plaintext through our API except when you explicitly reveal them while authenticated.

For more detail on our security architecture, see our security documentation.

How we share information

We do not sell or rent your personal information. We may share information only in these limited circumstances:

  • Service providers — with vendors that help us run ApiVault (such as hosting and database providers), bound by confidentiality obligations
  • Authentication providers — when you choose to sign in with Google or another supported OAuth provider
  • Legal requirements — when required by law, regulation, legal process, or to protect the rights, safety, and security of ApiVault and its users
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy

Data retention

We retain your account and vault data for as long as your account is active. If you delete your account or specific secrets, we delete or anonymize associated data within a reasonable period, except where retention is required for security, legal compliance, or backup integrity.

Session and audit logs may be retained for a limited time to support security monitoring and troubleshooting.

Your choices and rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate account information in Settings
  • Delete your account and associated vault data
  • Revoke CLI, MCP, and OAuth connections from Settings
  • Export or manage your secrets through the web app or CLI

To exercise these rights or ask privacy-related questions, contact us at privacy@apivault.app.

Cookies and local storage

ApiVault uses cookies and similar technologies to keep you signed in, remember your theme preference, and protect against cross-site request forgery. The CLI stores authentication tokens locally on your machine under ~/.apivault/. You can sign out or revoke sessions at any time from Settings → Sessions & Devices.

Children's privacy

ApiVault is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you through the service or by email. Your continued use of ApiVault after changes take effect constitutes acceptance of the updated policy.

Contact

Questions about this Privacy Policy? Email privacy@apivault.app. For terms governing use of the service, see our Terms of Service.