This is an archived version.
It was in force from 7 September 2026, and is kept so you can read the wording that applied then rather
than today's. Read the current Privacy Policy ·
All versions
Welcome to Vauz, a secure password manager offered by Sealzi. This Privacy Policy sets out what we collect, what we do with it, and what we never receive in the first place.
One point belongs at the top, because the rest of this document rests on it. Your vault stays on your own device. The Vauz application does not send it to us, does not tell us anything about it, and does not report on your use of it. What we hold is an account record, plus the small amount of housekeeping a sign-in page needs to work and to resist attack; both are described below. Our website does not behave identically to the application, so the two are described separately throughout, because they are not the same thing.
2. Information We Collect
The Vauz application on your device
Nothing. The application transmits no vault contents, no entry counts, no list of the sites you saved, no usage statistics, no error or crash reports, and no check-in of any kind — not to us, and not to anyone else. Choosing a support or documentation item from its menu opens your own browser or mail client, and any request made after that belongs to that program rather than to Vauz.
Your Vauz account, if you create one
- Your name and email address.
- Your passkeys, or rather the public half of each: a public key, the identifier the authenticator gave it, a counter used to detect a cloned device, and whatever nickname you gave it. The private half never leaves your device and we never see it. There is no password to store, because there is no password.
- A reference that identifies your customer record with our payment processor. We do not hold your card details.
- Which subscription you have, and the dates it runs between.
- If you join a family plan, the fact that you are a member of it.
- Your acceptance of the terms: when you ticked the box at signup, which version you accepted, and the IP address and browser you accepted from. Encrypted at rest, and read only to answer a payment dispute. Section 4 of our Terms of Service covers how long it is kept.
Our website, including the sign-in and dashboard pages
- A cookie holding a security token, set when you use the sign-in or dashboard pages. It exists to protect those pages against forged requests, not to follow you between visits.
- A cookie that keeps you signed in, and a record on our side of the sessions it belongs to, so that signing out ends them everywhere. That record holds no IP address and no browser details: we do not keep a history of when or from where you signed in, and there is nothing to show you on that subject because there is nothing kept.
- While someone is repeatedly failing to sign in, a short-lived counter that lets us slow them down. It is keyed by a one-way code derived from the address or identifier being tried, never by the value itself, and it is deleted once the attempts stop. Successful sign-ins are not counted or recorded.
- Our servers record web requests in the ordinary way, which includes IP addresses.
- If you send the contact form on our homepage, we receive what you typed — your name, your email address, a phone number if you gave one, and your message — together with your IP address and your browser's user-agent string. Those last two are included so that we can identify abuse of the form. The whole of it arrives as an email in our support mailbox.
- If you send feedback or a support request from the dashboard, we receive what you wrote, along with the name and email address on your account.
The Vauz browser extension
The extension sends us no vault data and no record of the pages you visit. It does load our logo image from our own server in order to draw its autofill button, and that request reaches us in the same way as any other request for a file on our site.
3. Use of Information
We use what we hold to:
- Provide and maintain our services.
- Process transactions and manage subscriptions.
- Answer you when you contact us, and act on feedback you choose to send.
- Communicate with you about your account, security notices, and support.
- Ensure compliance with our terms of service and legal obligations.
We do not build usage profiles, and we hold no analytics from which one could be built. There is no advertising on our website, and we do not sell your information.
4. Data Security
Your vault is encrypted on your own device and is readable only on that device. The encryption is built on an algorithm regarded as among the strongest in the field, with a further algorithm of our own creation applied in addition to it. We do not publish how either is put together. A detailed account of a defence tends to be worth more to the person trying to get past it than to the person relying on it.
The account information described in section 2 is transmitted only over encrypted connections. What our design protects you from, and what it deliberately does not, is set out in our threat model.
5. Sharing of Information
We do not sell your personal information, and we do not share it with third parties except as necessary to provide our services or to comply with legal obligations. This includes:
- Service providers who handle sign-in and payment processing on our behalf.
- Legal authorities, if required by law or to protect our rights and safety.
Your vault is not on that list, and cannot be. We never receive it, so there is nothing for us to produce — including in response to a legal demand.
6. Cookies, Tracking and Third-Party Content
We use no analytics, no advertising, and no tracking cookies. There is no third-party analytics service anywhere on our website and no cross-site tracking. The only cookie we set is the security token described in section 2, on the sign-in and dashboard pages.
Our pages load their fonts, icons, stylesheets and images from our own servers. Nothing about how a page looks is fetched from anyone else. Our delivery network, cdn.sealzi.com, serves the shared page furniture; it is our infrastructure, not a third party.
Two service providers, both named in section 5, are contacted only on the pages that need them:
- Corbado (corbado.io) — passkey sign-in, on the sign-in page and the dashboard. Their component also sends them usage telemetry and, on a small fraction of loads, contacts a monitoring endpoint belonging to the fingerprinting library it uses.
- Stripe (stripe.com) — payment. Reached only when you start a checkout, and it is Stripe, never us, that receives your card details.
Neither carries anything about your vault, and we do not use either to identify you. If you never sign in and never buy anything, no request leaves our servers on your behalf.
7. Your Data Rights
Depending on where you live, you may have certain rights over the personal data we hold, including:
- Access: Request a copy of your data.
- Correction: Correct any inaccuracies in your data.
- Deletion: Request the deletion of your data.
These rights cover the account record described in section 2. They cannot extend to your vault, because we do not hold it. A copy of your vault is something only you can produce, from your own device, and deleting your account removes our record of you without touching anything on your machine.
To exercise these rights, please contact us at support@sealzi.com.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the date at the top of this page changes with it, and it is worth reviewing periodically.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: support@sealzi.com.