File 001 · Privacy

Privacy Policy

Unlike Vault is made by Adamanture Private Limited, which is the data controller for everything described here. This policy covers the Unlike Vault apps for Windows and Android, the Unlike Vault web app, and the Unlike Vault website.

Last updated: 16 September 2026

The short version

We store the minimum needed to let you sign in and to hand your own encrypted key back to you. We cannot read your files. We cannot read your passphrase. We cannot unwrap your key. There is no analytics, no crash reporting, no advertising, and no third party we share anything with.

What we store about you

  • Your email address. Supplied by the identity provider you signed up with. It identifies your account and is unique across accounts.
  • Whether your provider said the address was verified, as a timestamp. Google asserts this; Microsoft and Zoho do not, and the field stays empty for them.
  • Your provider identity: which provider you used (Google, Microsoft or Zoho) and the immutable subject identifier that provider assigns you, plus a display copy of the address and the times the identity was created and last used. We never store a token from your provider. The token your device obtains at sign-in is spent verifying who you are and then dropped.
  • A keyed proof of your passphrase — not the passphrase, and not a plain hash of it. It lets us confirm you know your passphrase without ever seeing it.
  • Your wrapped account key, together with the key-derivation salt and parameters. This is the encrypted form of the key that opens your vault. It is wrapped by a key derived from your passphrase, which we do not have, so we cannot open it. It is stored so you can move to a new device.
  • An optional passphrase hint you may write yourself. It is stored as plain text and shown back to you. Do not put anything secret in it.
  • Passkeys you register on the web: the credential's public key and the metadata WebAuthn needs (signature counter, authenticator identifier, transports, backup flags, a label you choose), plus that credential's own wrapped copy of your account key. Passkeys are a web feature and are not used by the Android or Windows apps.
  • Your sessions and devices: a one-way hash of each session token — never the token itself — with the session type, a per-installation device identifier, a friendly platform label, the times it was created, last used and expires, so you can see and revoke your devices.
  • Short-lived sign-up and sign-in state, which expires within minutes and is swept automatically.

What we never store

No file, no folder name, no file contents, no encryption key we can open, no passphrase, and no access or refresh token for any cloud account. Our database has no column for any of them, by design.

Your files

Files are encrypted on your device. What the encryption produces is ciphertext, and our servers never receive it.

If you choose to connect Google Drive or OneDrive on Windows or Android — a separate, optional step, never part of signing in — the encrypted files are uploaded to your own Drive or OneDrive, inside a vault folder Unlike Vault creates. Each one is stored as a separate object under a random identifier, in a single flat folder. Your file names, your folder names and your folder structure are never uploaded in any form, because nothing in that layout records them.

What your cloud provider can still see. The number of encrypted objects in that folder, how big each one is, and when each was written. Those are properties of the storage itself and we cannot hide them from the provider. Names are random and contents are ciphertext, but the shape of your activity is visible. One plain-text file sits alongside the objects recording only the product name, the vault format version, a random vault identifier and a creation date — no information about you or your files.

Unlike Vault requests only the narrowest cloud permission each provider offers: on Google Drive, a scope that can see only the files the app itself creates; on OneDrive, an app-folder scope. Neither grants any view of the rest of your storage.

Disconnecting. Disconnecting Google Drive revokes the permission at Google. Disconnecting OneDrive cannot: Microsoft publishes no per-application revocation for an application of this kind, so Unlike Vault destroys its own copy of the token and tells you how to finish the job from your Microsoft account page.

Cloud vaults are a Windows and Android feature and are not released yet. This section describes how they behave when they are, so that nothing about them arrives as a surprise.

Why we hold what we hold

To authenticate you, to return your own wrapped key to your devices, to let you see and revoke your sessions, and to enforce rate limits that protect your account. Nothing else.

Who we share it with

Nobody. We do not sell, rent, or share your data with third parties. We run no analytics, no crash reporting, no advertising, and no advertising identifier. Your identity provider learns that this account signs in to Unlike Vault, and when — that is inherent to signing in with them, and happens at your direction. Your cloud provider stores the encrypted objects described above, in your own account, at your direction.

What we cannot protect you from

Your passphrase cannot be reset, by you or by us. If you lose it, your vault stays encrypted permanently. This is deliberate: a reset we could perform would be a door we could be compelled to open.

How long we keep it

For as long as your account exists. Expired sessions and expired sign-up state are deleted automatically on a schedule.

When you delete your account, the rows go from the live database immediately.

Deleting your account

Delete your account from within the app, or from unlikevault.com/delete-account/. Deleting the account removes every row we hold for you — identity, wrapped key, passkeys, sessions and devices — in a single cascading delete. It is immediate and irreversible.

Deleting your account does not delete the encrypted files in your own Google Drive or OneDrive, because they are yours and live in your storage, not ours. Delete the vault folder yourself if you want them gone. Without your passphrase they cannot be opened by anyone, including us.

Your rights

Wherever you are, we honour access (a copy of what we hold about you — the list above is all of it), correction, erasure, portability and objection. In the EU and the UK, our lawful basis is performance of the contract — running the account you asked for. In India, requests under the Digital Personal Data Protection Act 2023, including a grievance about how we handled one, go to the same address.

All of it: dev@adamanture.com, which is also our grievance contact. A human reads it, usually within days rather than months.

Exercising the first four is short work here, because there is so little to exercise them on: we hold your address, your provider identity, a wrapped key we cannot open, and your sessions. Erasure is the same operation as deleting your account, above.

Children

Unlike Vault is for adults. You must be 18 or older to use it — that is a condition of the terms, not something the app checks. It is not directed to children, we do not advertise it to them, and we do not knowingly collect data from anyone under 18. If you believe a child has created an account, write to the address below and we will delete it.

Security

All traffic is encrypted in transit. Files are encrypted with AES-256-GCM, and the key that wraps your account key is derived with Argon2id. On Windows and Android you may let the operating system's secure hardware hold your unlocked key behind Windows Hello or a fingerprint; the passphrase always still works.

Changes

We will update this page and change the date at the top. If a change is material, we will email you before it takes effect, and keep the previous version available. No silent edits.

Contact

dev@adamanture.com · Adamanture Private Limited.

Terms of ServiceDelete your account