Privacy Policy
Last updated: 16 March 2026 – Your data belongs to you. Vaultill stores purchase receipts locally on your device. This statement transparently shows what is processed and which third-party services are used.
Privacy-first – Trust is not an extra. It's a core feature.
Vaultill is designed to feel like a calm, secure utility—not a cloud-mandated product.
Standard – Your receipts stay local.
Vaultill is built so that proof of purchase is stored on your device by default.
Local storage as default
Images, PDFs and purchase data are processed locally and stored on your device.
No account required to start
The core workflow works without registration or mandatory cloud use.
OCR – Text recognition stays controllable.
OCR helps pre-fill merchant, date and amount, and never blocks the manual flow.
Transparent suggestions
Recognised values remain visible and can be checked or overwritten at any time.
No hidden automation
Vaultill does not blindly adopt unclear values in the background.
Future development – Sync remains optional.
Cloud or multi-device sync is not a core requirement and would be consciously introduced later as an add-on.
Opt-in, not mandatory
If sync is added, its benefits must be clear and activation must be deliberate.
Clear communication
Privacy texts should be simple and not couched in legal jargon.
1. Data controller
Jan-Hendrik Warrelmann
John-F.-Kennedy-Allee 55/4
71686 Remseck am Neckar
Germany
Email: vaultill.support@gmail.com
2. Core principle
Vaultill is designed as an offline-first app. An account with name, email address or password is not required for use. Purchase receipts, deadlines and settings are stored locally on your device and do not leave it without your active action.
3. Local data storage
The app processes and stores user data exclusively locally on your device. This includes:
- Purchase receipts (images, PDFs)
- Merchant, purchase date, amount, category
- Warranty and return deadlines
- App settings and preferences
Technically, storage uses a local SQLite database (via Drift) and the system key-value store (SharedPreferences).
4. Camera, scan & text recognition
The device camera can be used for receipt capture. Document capture is performed locally. Automatic text recognition (OCR) runs entirely on your device (Google ML Kit)—no image or text data is sent to external servers.
ML Kit may occasionally fetch model updates from Google servers. This process is independent of receipts or personal data.
5. Notifications
Vaultill can send local push notifications for upcoming deadlines (returns, warranties, custom reminders). These notifications are generated and managed exclusively on your device. No server communication occurs for notifications.
6. Sharing
You can export receipt information via your operating system’s native share function. Data is passed directly from your device to the app you choose. Vaultill does not operate a sharing server—no data is transferred to Vaultill infrastructure.
7. In-app purchases & subscription management
Access to Vaultill Pro is handled via in-app purchases through the respective app store:
- Apple App Store (iOS)
- Google Play (Android)
Your device sends purchase-related data (device ID, platform, product ID, transaction token/receipt) directly to Apple or Google for purchase validation and subscription management. Billing and data storage for purchases is handled solely by the respective store providers.
8. Advertising (Google AdMob – Free version only)
The free version may display advertising via Google AdMob. Google AdMob may process in particular:
- IP address
- Device advertising identifiers
- Device and app parameters
- Diagnostic data
No advertising is shown in Vaultill Pro. On iOS, tracking consent (ATT) is requested before ad delivery.
9. Permissions
Depending on the feature used, the following system permissions may be required:
- Camera (receipt scan)
- Media access / photo library (receipt import)
- Notifications (deadline reminders)
- On iOS additionally: tracking permission (Free version only, for advertising)
Without the relevant permission, affected features may be limited or unavailable.
10. Recipients & service providers
Depending on the function used, data may be transmitted to:
- Apple App Store / Google Play (billing, purchase validation, restore)
- Google AdMob (Free version with advertising only)
Beyond that, no personal data is shared with third parties.
11. International data transfers
Google AdMob and app store billing (Apple, Google) may involve data processing outside the EU/EEA, in particular in the USA. These providers use Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR. Use is function-based and follows data minimisation principles.
12. Legal basis (GDPR)
Personal data is processed on the following legal bases:
- Art. 6(1)(b) GDPR: Contract and service performance (e.g. purchase validation via app stores)
- Art. 6(1)(f) GDPR: Legitimate interest (e.g. security, technical stability)
- Art. 6(1)(a) GDPR: Consent (e.g. advertising tracking on iOS)
Consent can be withdrawn at any time with effect for the future.
13. Retention period
- Local app data: until manual deletion in the app or uninstallation
- Purchase and subscription data: as required by law and store policies
- AdMob data: according to Google’s privacy policies
14. Your rights
Under the GDPR you have in particular the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
Since Vaultill works locally, receipts and settings are stored directly on your device and can be deleted at any time in the app or by uninstalling.
15. Data deletion & contact
You can delete local app data at any time directly in Vaultill or by uninstalling the app.
For requests regarding data protection rights or deletion of data processed via third-party services, please contact:
Email: vaultill.support@gmail.com
For identification purposes we may, where necessary, request the device ID generated in the app.
16. Changes
This privacy policy is updated when features, services used or legal requirements change. The date of the last update is shown at the top.
