RU /EN
Start a project
Privacy policy

VaultGuard

Updated: August 13, 2026

In short

VaultGuard works either with a local KeePass file on your device, or with a Bitwarden / Vaultwarden server you choose yourself — your own or a hosted one. The app has no backend of its own. In local mode no network request is made for vault data; in server mode data travels only between your device and the server you chose.

What data is processed

In local mode: the .kdbx file you select and the master password used to decrypt it. In server mode: the server address, the credentials you enter to connect, and the vault contents received from that server. All of it is used solely to run the app on your device.

Where data is stored on the device

The master password is never written to disk. Session keys and derived material are kept in the macOS Keychain, and vault contents in an encrypted local cache. The AutoFill extension can reach only a separate, minimal cache; it never receives the real vault key or any token. Locking, signing out and removing an account all revoke that access.

What is not collected

The app contains no analytics, no telemetry, no crash reporting, no tracking and no ads. The developer does not collect, store or share your data and receives no vault content.

Third parties

None. How data is handled on the server side is up to whoever administers that server — if the server is not yours, ask its owner about their terms.

Deleting data

Data on the device is removed when you delete the app; the local cache and Keychain entries are also cleared on sign-out and account removal. Server vault contents are deleted on the server using its own tools. Your local .kdbx file stays yours — the app does not delete it.

Children

The app is not directed at children and does not collect their data.

Changes

The current version of this policy is always available at this address. The date of the last change is shown above.

Contact

Questions about data handling:

a@krutilin.pro

Support page →