Privacy Policy
Privacy Policy
OnVault is built around keeping sensitive documents on the user device whenever reasonably possible. Even so, certain surrounding information may still need to be handled in connection with website operation, support, paid offerings, incident response, and legal compliance. This Privacy Policy explains what information we collect or otherwise handle in connection with the OnVault website, iOS app, support, and related services, together with the purposes of use, third-party sharing rules, security measures, and user rights.
1. Core approach
We aim to collect as little information as necessary, to define the purpose of use as clearly as possible, and to handle information lawfully and appropriately under applicable privacy and data protection rules.
The OnVault app is designed so that scanned documents, OCR output, search indexes, and similar sensitive data remain on the user device by default. Unless the user chooses to export, share, or otherwise connect the data outward, sending document data to our server is not intended to be part of the ordinary product flow.
That said, some surrounding information such as access logs, contact details, transaction-related information, and support materials may still be processed for website operation and service administration.
2. Scope and definitions
This policy applies to the OnVault website, contact handling, the app, support handling, paid offering administration, and related services.
Terms such as “personal information,” “personal data,” and “retained personal data” are used in this policy in the sense generally given to them under applicable Japanese privacy law.
In this policy, “we,” “us,” or “our” means the operator of OnVault. The operator’s legally required disclosure items, address, and telephone number will be disclosed without undue delay upon request in accordance with the Specified Commercial Transactions Act disclosure page.
In this policy, “user data” means document images, OCR output, search indexes, notes, preferences, and other data created, imported, or stored by the user in the app.
3. Information we collect or otherwise handle
When the website is used, technical data such as IP address, access time, requested URLs, referrer, browser type, operating system, device information, and error logs may be automatically recorded by our hosting environment or service operators acting on our behalf.
When a user sends an inquiry, makes a disclosure request, requests statutory seller disclosure, or otherwise contacts us, we may handle the user’s name, email address, affiliation, message content, transaction references, and other information voluntarily provided by the user.
After paid offerings begin, we may handle or reference transaction-related information received through Apple and RevenueCat, including the purchased item, product identifier, lifetime-purchase history, purchase status, restore status, refund status, and active entitlement status, to the extent necessary to confirm purchases, restore entitlements, verify lifetime-license status, and process refunds or support cases.
When anonymous usage analytics are enabled, the app may collect the following events: app_first_open, scan_started, scan_completed, ocr_result_viewed, saved_to_vault, and paywall_viewed. Fields are limited to the event name, timestamp, app version, language, storefront country, platform, first-session flag, a session ID generated for each app launch, and allowed minimal attributes such as capture source, page-count bucket, OCR mode and result, and paywall type and placement.
Within the app, document images, OCR output, search indexes, app settings, and similar user data are intended to stay on the user device. We do not ordinarily collect that content data in the normal service flow. Purchase verification, entitlement restoration, optional error-log upload, and anonymous usage analytics do not send file contents, document images, full OCR text, search terms, file names, folder names, tag names, document titles, or user-entered text to our server, unless a user voluntarily sends materials for support or troubleshooting.
Given the regulatory sensitivity of certain categories of information, OnVault is intentionally not designed to support extraction or retention of My Number information. Highly sensitive information such as passport MRZ data is also intended to be processed and retained only to the minimum extent necessary.
4. How information is obtained
We obtain information directly from users when they enter, send, register, purchase, inquire, or otherwise communicate with us.
We may also receive technical or transaction-related information from hosting providers, app store operators, payment-related providers, operating system providers, or similar third parties where necessary for service administration.
We do not intentionally obtain personal information through deception or other improper means.
5. Purposes of use
We use information to provide and operate the website and app, verify identity where needed, process purchases, administer licenses, investigate incidents, provide support, respond to inquiries, maintain security, prevent misuse, comply with law, resolve disputes, and perform related administrative tasks.
Technical logs and related data may be used for stable operation, performance improvement, vulnerability response, incident analysis, abuse prevention, and general maintenance.
Purchase-related information received from Apple and RevenueCat, or made available for reference through those services, may be used to confirm purchase status, restore a lifetime license, reconcile entitlements, prevent misuse, and support customer inquiries.
Anonymous usage analytics may be used to aggregate the flow from first launch through scan, OCR-result viewing, saving to the vault, and paywall display, in order to understand feature use, improve usability and app quality, and detect issues earlier. We do not use these events for advertising, user-specific behavioral profiles, or analysis of document contents.
Only where a user explicitly enables error-log upload in the app settings may we use minimal technical diagnostics such as exception metadata, masked messages, masked stack traces, timestamps, runtime environment data, app version, build number, device model, OS version, and tag information for incident analysis and quality improvement.
Materials voluntarily sent by a user, including screenshots, logs, or document samples, are used only to the extent reasonably necessary to respond to that inquiry or support request.
We do not use user-originated content, including content entered into current or future AI-related features, outputs from those features, inquiry messages, or support materials, to train or fine-tune generative AI models or other machine-learning models, or to build general-purpose evaluation datasets, unless the user gives separate explicit consent.
Except as permitted by law, we do not use personal information beyond the scope necessary to achieve the purposes described above.
6. Third-party sharing and outsourcing
We do not provide personal data to third parties without the data subject’s consent unless permitted or required by law.
We may outsource parts of our operations, such as hosting, email delivery, support intake, payment-related coordination, or incident handling. In that case, we select service providers appropriately and supervise them through contractual or practical controls as needed.
Payments, app delivery, refund handling, and related processing carried out through the App Store or similar third-party platforms involve information separately collected and managed by those providers. Apple may handle payment and storefront information, and RevenueCat may handle product identifiers, purchase status, lifetime-purchase history, and entitlement-sync information. Their handling of such information is governed by their own terms and privacy policies.
If optional error-log upload is enabled, masked error events may be transmitted to a Cloudflare Worker / D1 based diagnostics environment used for incident investigation. The intended payload is limited to technical items such as exception name, masked message, masked stack trace, timestamp, app version, build number, device model, OS version, and similar tag data.
When anonymous usage analytics are enabled, the allowed events and minimal attributes described above may be sent to an ingestion environment using Cloudflare Workers and handled in Cloudflare D1 or similar infrastructure as short-lived raw events and daily aggregates. Cloudflare handles this information as our service provider to the extent necessary to provide that infrastructure.
If user-submitted inquiry messages, attachments, or logs need to be shared with contractors, we limit that sharing to those with a need to know and require confidentiality, purpose limitation, and appropriate security controls through contractual or practical measures.
7. Transfers to foreign third parties
At present, we may rely on Apple and RevenueCat for purchase verification, entitlement restoration, and license-state reconciliation, and on a Cloudflare-based environment for optional error-log intake and anonymous usage-analytics ingestion and aggregation. These providers may maintain servers or business operations in the United States or other countries outside Japan.
Where information is handled in connection with those providers, we review their published information, contractual terms, and security arrangements, and we will take measures required by applicable law, which may include obtaining consent where necessary and implementing contractual or operational safeguards.
We may also transfer user information to a successor if the business relating to the service is transferred through a business transfer, merger, company split, or similar transaction, to the extent permitted by applicable law.
8. External transmission, cookies, and similar technologies
For website delivery, stable operation, or security, technical information associated with access may be transmitted to hosting providers and similar infrastructure operators.
Within the app, communications may occur with Apple and RevenueCat in order to verify purchases, restore entitlements, and reconcile license status. If a user explicitly enables error-log upload in settings, masked error events containing limited technical diagnostics such as exception details, stack traces, app-version data, and device/OS information may also be sent to a Cloudflare-based ingestion environment.
When anonymous usage analytics are enabled, the app sends the minimal content-free events described in Section 3 to a Cloudflare-based ingestion environment. Users can disable this transmission in the app settings. After analytics are disabled, the app stops recording and transmitting new events and removes events that remain unsent on the device.
As of this policy, we do not use persistent trackers or SDKs whose principal purpose is behavioral advertising. Diagnostic error-log upload is default-off and only active if the user explicitly enables it. Anonymous usage analytics are not used for advertising tracking, and users can change whether they are enabled in the app settings.
Users may be able to control cookies and similar identifiers through browser or operating-system settings, but doing so may impair some website or service functions.
9. Security measures
We seek to implement organizational, human, physical, and technical safeguards to protect personal data against leakage, loss, damage, unauthorized access, and misuse.
These measures may include access control, limiting data collection to what is necessary, restricting the scope of managed information, protecting transmission paths and storage locations, supervising contractors, responding to vulnerabilities, and maintaining incident response procedures.
For optional error-log upload, we keep the feature default-off and apply masking to emails, phone numbers, addresses, and identifying numbers before transmission. OCR text, search queries, file names, PERSONKEY values, document images, and similar high-risk contents are not intended to be included in transmitted diagnostics.
For anonymous usage analytics, event names and attribute values are restricted by allowlists, and unapproved events or attributes are rejected or removed before transmission and upon ingestion. Document images, full OCR text, search terms, file names, folder names, tag names, document titles, and user-entered text are excluded from transmission.
Because much of the most sensitive user data is intended to remain on the user device, device loss, operating-system settings, backup settings, device locking, sharing settings, and other user-side controls materially affect security. Users remain responsible for managing their own devices appropriately.
10. Retention
We retain information only for as long as necessary to achieve the relevant purpose or for any longer period required by law, after which it is deleted, anonymized, or otherwise put out of active use by reasonable means.
Inquiry records, support records, and transaction-related information may be retained for a reasonable period for dispute handling, fraud prevention, accounting, tax, or similar compliance needs.
For anonymous usage analytics, events remaining in the on-device queue are deleted once they are more than seven days old. Raw events received by the ingestion environment are retained only briefly, while long-term storage is primarily based on daily counts by date, storefront country, and event name. Disabling analytics does not necessarily remove aggregate statistics created before disabling because those statistics are not linked to a particular user.
User data stored on the user device may be removed because of user action, app deletion, operating-system behavior, or other circumstances beyond our direct control.
11. User rights
Where applicable under law, a data subject may request notice of purpose of use, access, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or similar handling with respect to retained personal data we hold.
We may request identity verification materials and other information reasonably necessary to process such requests. If a request cannot be honored under applicable law, we will seek to explain the reason.
The contact point for such requests is the inquiry channel stated at the end of this policy.
12. Information relating to minors
If a minor makes an inquiry, purchases, or otherwise submits information, the involvement or consent of a parent or other legal guardian should be obtained.
If we become aware that we have received personal information directly from a minor without the necessary guardian involvement, we will consider appropriate action in light of the circumstances and applicable law.
13. Changes to this policy
We may revise this policy in response to legal amendments, service changes, operational updates, or other reasonable needs.
If a material change is made, we will provide notice on the website or through another appropriate method.
14. Contact
Questions about this policy, personal-data handling, requests for disclosure, complaints, and related matters should be directed to [email protected].
Our address and telephone number will be disclosed without undue delay upon request as described in the Specified Commercial Transactions Act disclosure page.