Privacy Policy
Last updated: 1 September 2026
Valto for iOS ("the App") is developed and operated by Silver Tech App Team ("we", "us", "our") and distributed through Apple's App Store. This policy explains what the App collects, what it never collects, and what control you have over it. It forms part of our Terms of Use.
In short
Everything you put in the vault — passwords, notes, files, photos, videos, contacts — is encrypted on your device, with keys derived from your PIN or password. Those keys never leave your device.
We cannot read your vault. Not because we promise not to, but because we never hold your data or the keys to it. If you lose your PIN or password and any recovery method you set up, nobody can recover your data — including us.
What we do receive is limited to running your account and subscription, plus analytics and advertising you can switch off.
What never leaves your device
- Vault contents — encrypted with AES-256-GCM inside a database encrypted with SQLCipher. If you turn on cloud backup, encrypted copies go to your own iCloud or Google Drive account, never to us.
- Your PIN and password — used on your device to derive encryption keys (Argon2id). Never transmitted.
- Biometrics — Face ID and Touch ID are handled entirely by your operating system. The App receives only a yes/no result and never sees your fingerprint or face data.
- Intruder capture photos and attempted PINs — if you enable this feature, both are stored only in the encrypted database on your device. Break-in alert emails tell you that a failed attempt happened; they never contain the photo.
- Wireless transfer — moves data directly between your own devices on your local network, not through the internet or our servers.
What we collect
- Installation identifier — a random ID created on first launch, so subscriptions and recovery work without forcing you to register. Stored on our servers with session tokens and timestamps. It contains no vault content and no encryption keys.
- Email address (optional) — if you sign in with a one-time code, add a recovery email, or enable break-in alerts. Used only to send those messages, and removable in the App.
- Apple or Google sign-in identifiers (optional) — the account identifier and email address (or Apple's private relay address), used only to link and recover your account.
- Subscription status — Apple processes the payment and sends us a receipt, the product identifier, and the subscription status and expiry. We never receive your card number, bank details, or billing address.
- IP address — visible to our servers on every request. We use it to deliver the response, apply rate limits, and block abuse.
- Support communications — your email address and whatever you write to us.
- Analytics, crash, and attribution data — controlled by a Settings toggle; see below.
We do not collect your precise location, your browsing history, or your device's contact list. Contacts you deliberately import into the vault are encrypted on your device and stay there.
Permissions
- Camera — capturing photos and videos into the vault, scanning QR codes, and optional intruder capture.
- Microphone — recording audio as part of videos you capture into the vault.
- Photo library (add only) — saving an item from the vault back to your photo library when you choose to export it. The App never requests read access to your photo library.
- Network access — account, subscription, and (free tier) advertising requests.
Each permission is requested the first time you use the feature that needs it. Declining leaves the rest of the App working.
Analytics, crash reporting, and attribution
The App uses Firebase Analytics, Firebase Crashlytics, Firebase Remote Config, and AppsFlyer (install attribution).
In the EU, the UK, and the EEA this is off until you turn it on. It starts disabled, and the App asks you once, during first-run setup, whether to enable it. Nothing is collected unless you say yes.
Elsewhere it is on by default and you can turn it off at any time with a single toggle in Settings. Switching it off stops analytics, crash reporting, and attribution immediately, without restarting the App.
What is collected is a fixed set of app-usage events (such as which screens and paywall steps you reach), technical device information (model, OS version, app version), and crash diagnostics. Automatic screen tracking and advertising-ID collection are disabled. Never included: vault contents, PINs, passwords, encryption keys, filenames, or search queries.
On iOS, attribution uses Apple's SKAdNetwork and AdServices frameworks, with Apple Search Ads tokens relayed through our backend. The App does not request your advertising identifier (IDFA) and shows no App Tracking Transparency prompt.
Advertising (free tier only)
The free tier shows interstitial ads served by Google AdMob. Premium subscribers see no ads, and no ad requests are made for them.
Where the law requires it, including in the EEA and the UK, Google's consent form appears before personalized ads are served; if you decline, ads are non-personalized or limited. On iOS ads are always non-personalized, because the App requests no advertising identifier. Your vault contents are never used for advertising.
Cloud backup
Optional and off by default.
Your vault is encrypted on your device and then uploaded to your own cloud account — your private iCloud database, or a private app-data folder in your Google Drive. We operate no backup server, receive no copy, and hold no key. Apple and Google store only encrypted data they cannot read. Restoring requires signing back in to the same Apple or Google account.
You can delete backups from within the App or directly in your cloud account. Unlinking stops future uploads.
Who else receives data
- Amazon Web Services — hosts our backend.
- Kruso — delivers one-time codes, recovery, and break-in alert emails.
- Apple — App Store payments, Sign in with Apple, iCloud, Apple Search Ads.
- Google — Google Sign-In, Google Drive.
- Firebase — analytics, crash reports, remote config (with consent).
- AppsFlyer — install attribution (with consent).
- Google AdMob — ads on the free tier.
Each receives only what it needs for its own task and is not permitted to use it for anything else. We do not sell your personal information, and we never share vault contents.
Where a valid legal request compels disclosure we comply — but even then we cannot produce your decrypted vault contents, because we hold neither them nor the keys to them.
How your data is protected
AES-256-GCM encryption with a unique initialization vector per item; Argon2id key derivation from your PIN or password; master keys in hardware-backed storage (iOS Keychain and Secure Enclave); an encrypted database (SQLCipher); filenames replaced with random identifiers; secure overwriting on delete; TLS on all network traffic; screenshot blocking; auto-lock; and jailbreak detection warnings.
No system is perfectly secure, and we cannot guarantee absolute security. The design deliberately limits what a breach of our systems could expose — and it is not your vault.
How long we keep it
- On-device data — until you delete it or uninstall the App. We hold no copy.
- Cloud backups — until you delete them from your own cloud account.
- Account data — while your installation is active. Delete it at any time from Profile → Delete Account in the App, which removes your account records from our servers apart from anything we must keep for legal, tax, or fraud-prevention reasons.
- Subscription records — the life of the subscription plus the period required for accounting and dispute resolution.
- Analytics and crash data — according to Firebase's retention settings.
Deleting your account does not cancel an active subscription — manage that through the App Store.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, to object to or restrict certain processing, and to withdraw consent at any time. Consent is withdrawn with the Settings toggle, and account deletion is in the App. For anything else, email us.
Because accounts are pseudonymous, we may need you to prove control of the device account or recovery email before acting on a request. For vault contents there is nothing for us to act on — you already hold the only copy and the only keys, on your device.
Children
Valto is not directed at children under 13, and we do not knowingly collect personal information from them. Where local law sets a higher minimum age for consent to data processing, that age applies. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. The version published on this page is always the current one, and changes take effect when posted.
Contact
Questions or requests: silverapp19@gmail.com