This Privacy Policy describes how Azica LLC ("Azica," "we," "us," or "our") collects, uses, and protects information in connection with the Azvault mobile application (the "App"), available on iOS and Android. This Privacy Policy is incorporated into and forms part of our Terms of Service, which govern your use of Azvault.
1. Who We Are
Data Controller:
Azica LLC
California, United States
Email: support@azicanet.com
Azvault is a password manager, two-factor authentication (2FA) vault, and secure data organizer. We designed the App so that we are unable to access your vault data at any time, and so that your secrets never leave your device in an unencrypted form.
2. The Core Privacy Principle: Zero Knowledge
Azvault is built on a zero-knowledge architecture:
- All vault data is encrypted on your device before it is stored, using AES-256-GCM encryption with a key derived from your master password using industry-standard key derivation.
- We do not have your master password. It is never transmitted to us or any third party.
- We do not have your encryption key. It is derived locally on your device and never sent anywhere.
- Azvault is designed so that we cannot read your vault contents. Neither can Apple, Google, or anyone else, unless a party has your master password and physical access to your device.
Your vault is encrypted on your device, with keys we never receive, before any of it is ever transmitted. That's built into how Azvault works, not something we're just promising to do.
3. Information We Collect
3.1 Information We Do NOT Collect
We (Azica LLC) do not collect, transmit, or store any of the following:
- Your master password
- Your 2FA secret keys or TOTP codes
- Your saved passwords, credentials, or credential history
- Your custom field values (phone numbers, URLs, dates, PINs, recovery codes, or any other data you store)
- Your vault contents in any form
- Your name, email address, or personal identity (unless you contact us for support)
- Your device's precise location
- Your contacts, messages, or media
- Behavioral analytics or usage data
- Crash reports or diagnostic telemetry
Note on advertising identifiers: Azica LLC does not directly collect advertising identifiers (IDFA on iOS, GAID on Android). However, our subscription management processor RevenueCat may access advertising identifiers as described in Section 3.3 below.
Note on crash and diagnostic data: Azica does not embed any crash-reporting or analytics SDK in Azvault. Apple and Google, however, may provide their own OS-level crash and performance diagnostics to app developers (for example, through App Store Connect or Google Play Console) when a user has opted in to sharing that data with the platform. Azica may have access to this aggregated, platform-provided diagnostic data through those developer consoles, governed by Apple's and Google's own privacy policies, separately from anything Azvault itself collects.
3.2 Information Collected Automatically
Time Synchronization. When you use the Sync Time feature, the App connects to a trusted public time server to correct your device clock for accurate TOTP code generation. This connection transmits no personal data beyond what's inherent to any network request. The offset is stored locally on your device.
Camera. If you scan a QR code to add a 2FA account, the App requests access to your camera. The camera feed is processed entirely on-device. No images or video are transmitted anywhere.
Biometric Authentication. If you enable Face ID or fingerprint unlock, authentication is handled entirely by your device's secure enclave (Apple Secure Enclave or Android StrongBox). Azvault never accesses, stores, or transmits your biometric data. We only receive a boolean true/false result from the operating system.
3.3 Purchase Information (Collected by RevenueCat)
Azvault uses RevenueCat to process in-app purchases and manage subscription entitlements. When you make a purchase, RevenueCat receives information such as your purchase receipt, an anonymous app user ID, your subscription status, and your device platform. Subject to your device's privacy permissions, RevenueCat's SDK may also access advertising identifiers for attribution and fraud-prevention purposes; on iOS this is governed by Apple's App Tracking Transparency framework, and declining tracking prevents RevenueCat from receiving your IDFA.
RevenueCat does not receive your name, email, vault contents, or any other personal vault data. RevenueCat acts as a data processor on our behalf. For information on how RevenueCat handles data, see their privacy policy at revenuecat.com/privacy.
Actual payment processing (credit card, Apple Pay, Google Pay) is handled entirely by Apple and Google. Azica LLC never sees or stores your payment card information.
3.4 Security Health Checks (Opt-In, User-Initiated Only)
Azvault provides optional security health features that, when you choose to enable them, make outbound network requests to third-party services. These features are always opt-in and user-initiated. They never run automatically without your explicit action.
Password Breach Check (Have I Been Pwned). When you tap "Check for Breaches" in the Security tab, Azvault checks whether your passwords have appeared in known data breaches using Have I Been Pwned ("HIBP"), a service operated by Troy Hunt, through a privacy-preserving lookup method that never transmits your actual passwords. As with any network request, your IP address is exposed to HIBP's servers when a check runs. Results stay on your device; Azica does not receive or store them, and a cooldown period is enforced between checks to limit how often this request is made.
Service Breach Awareness. The Security tab also displays a list of recently breached services sourced from HIBP's public breach database. Fetching this list exposes your IP address to HIBP but transmits no personal data.
Your Control: You may decline these checks at any time. The Security tab displays a consent prompt before the first check. If you choose not to consent, no data is sent and the feature remains disabled. You can reset your consent at any time in Settings.
3.5 Support Communications
If you contact us at support@azicanet.com, we receive the contents of your message, your email address, and any information you choose to include. We use this information solely to respond to your inquiry. We do not add you to marketing lists.
4. How We Use Information
The limited information we do receive is used only for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Processing in-app purchases and verifying subscription entitlements | Performance of contract (Art. 6(1)(b)) |
| Responding to support inquiries | Legitimate interests (Art. 6(1)(f)) |
| Password breach detection via HIBP (opt-in, withdrawable at any time in Settings) | Consent (Art. 6(1)(a)) |
| Time synchronization, necessary for accurate TOTP code generation | Legitimate interests (Art. 6(1)(f)) |
| Enabling Family/Team Pairing (Section 9), only when you opt in to the feature | Consent (Art. 6(1)(a)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not use your information for advertising, profiling, or sale to third parties.
5. Data Sharing and Third Parties
We do not sell your personal information. We do not share your information with advertisers. We do not use third-party analytics SDKs.
We share limited data with service providers and platform partners solely to operate the App:
| Third Party | Purpose | Privacy Policy |
|---|---|---|
| RevenueCat, Inc. | Subscription management (Section 3.3) | revenuecat.com/privacy |
| Apple Inc. | App distribution, payment processing (iOS), iCloud backup (opt-in) | apple.com/legal/privacy |
| Google LLC | App distribution, payment processing (Android), Google Drive backup (opt-in), time sync (fallback) | policies.google.com/privacy |
| Cloudflare, Inc. | Time synchronization (primary, for TOTP accuracy) | cloudflare.com/privacypolicy |
| Supabase Inc. | Infrastructure for Secure Password Sharing (Section 8) and Family/Team Pairing (Section 9), each only if you use that feature | supabase.com/privacy |
| Have I Been Pwned (Troy Hunt) | Password breach detection (opt-in, user-initiated only, Section 3.4) | haveibeenpwned.com/privacy |
Each provider only receives what's necessary to perform its function, described in more detail wherever that feature is discussed elsewhere in this policy. None of them receive plaintext vault data or your direct identity (name, email) through these integrations.
We may disclose information if required to do so by law, court order, or governmental authority.
Business Transfers: If Azica is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require any successor to continue to honor the commitments in this Privacy Policy, or to provide notice and, where required by law, seek your consent before materially changing how your information is handled.
6. Data Storage and Security
Your vault data is stored exclusively on your device, using your operating system's own secure storage (the iOS Keychain or Android Keystore, with hardware-backed protection where your device supports it). It stays in your app's sandboxed storage and is not uploaded to any cloud service by default. The exceptions are described below.
Encrypted Backups
If you use the Export Backup feature, or opt in to automatic Cloud Backup in Settings, your vault is encrypted with your master password before it ever leaves your device, whether it's written to a local file or uploaded to iCloud (iOS) or Google Drive (Android). Azica has no access to the contents of either kind of backup, and this network activity happens directly between your device and your own iCloud or Google Drive account, not through any Azica server. You may disable automatic backup at any time in Settings.
What the Vault Stores
Everything you save in Azvault, including your passwords, usernames, notes, 2FA secrets, custom fields, documents, password history, and how you organize it all, is encrypted on your device before it's ever written to storage. None of it is accessible to Azica LLC or any third party.
On-Device Convenience and Security Data
A small amount of additional data, such as your recent search history, a local record of unlock attempts, and security alerts about breached or aging passwords, is kept on your device outside your encrypted vault, using the same secure storage. It exists to power convenience and security features (like lockout protection and the Security Events screen) and is never transmitted to Azica or any third party. Features that let you export or transfer your Secret Key, whether for backup or moving to a new device, work entirely on-device or through your operating system's own share mechanism; Azica never receives a copy.
Security Measures
- AES-256-GCM encryption for your vault contents
- Strong, industry-standard key derivation to protect your master password, calibrated to your device
- Hardware-backed secure storage where your device supports it
- Automatic vault lock, failed-attempt lockout with progressive delays, and screen protection against app-switcher snapshots
- Travel Mode, which limits what's visible until you re-authenticate
Breach Notification
The data we hold about you is minimal by design, given the zero-knowledge architecture described throughout this policy, but it is not nothing: it can include the device identifiers and group metadata described in Section 9, or your name and email address if you've contacted support. If we experience a security incident that compromises this data in a way that triggers a notification requirement under applicable law, we will notify affected users and any required regulators without unreasonable delay, consistent with our obligations under applicable U.S. state breach-notification laws and, where applicable, Articles 33 and 34 of the GDPR.
iOS AutoFill and Home Screen Widget
Azvault supports iOS AutoFill and an optional Home Screen widget, so you can access saved credentials and 2FA codes more conveniently without opening the full app. Both work entirely on-device, using the same encryption as the rest of the app: neither independently collects, logs, or transmits any data, and both lose access immediately if you reset your vault. The widget is off by default, requires you to explicitly turn it on and choose what it displays, and shows a code only for as long as your vault would otherwise stay unlocked.
7. Data Retention
Because we do not receive your vault data, there is nothing for us to retain or delete.
Deleted items (passwords, notes, documents, and 2FA accounts) are moved to an on-device Trash rather than erased immediately, so you can recover something you deleted by mistake, and are automatically and permanently erased after a period of time, or immediately if you choose to delete them yourself. This entire process happens on your device; Azica does not receive or store your deleted items at any point.
Purchase records are retained by RevenueCat for as long as necessary to manage your subscription and comply with applicable financial regulations.
Support emails are retained for as long as needed to resolve your inquiry and to meet our own recordkeeping and legal obligations, then deleted.
On-device convenience and security data (recent searches, the unlock attempt log, security alerts, and Secret Key export/transfer features) is described in Section 6, and none of it is ever received by Azica.
8. Secure Password Sharing
When you use the Share via Secure Link feature, Azvault uploads an AES-256-GCM encrypted version of the credential to Supabase, a third-party database service. Only the encrypted payload is stored; no plaintext password, username, or other personally identifiable information is ever transmitted or stored. The decryption key travels separately, embedded in the link itself in a way that never reaches Supabase's servers, and no account or personal information is required to use the feature. Share records are deleted automatically within a short, fixed window, or as soon as the link is first viewed, whichever happens first.
Sub-processor: Supabase Inc. See the Supabase Privacy Policy.
9. Family/Team Pairing
If you use Family/Team Pairing, we store the technical information needed to operate it on our servers: an identifier and public key for each paired device, your group membership, and end-to-end encrypted data for anything a member chooses to share, including your group's own name and appearance and any shared documents (kept separately as encrypted files). We cannot decrypt any of it. Decryption keys are generated on and never leave member devices, and none of this includes your name, email address, or anything else that identifies you personally, unless you separately contact support.
Leaving a group, or being removed from one, does not delete this data. It immediately and permanently cuts off that device's own ability to read the group going forward, enforced on our servers, but your device's identifiers and its share of the encryption keys remain stored, and anything you shared stays visible to the rest of the group. Only the organizer deleting the group entirely erases all of it, for every member at once.
Sub-processor: Supabase Inc. (same as Section 8).
10. Children's Privacy
Azvault is not directed at children under the age of 13. Use of Azvault requires users to be at least 13 years of age, as set out in our Terms of Service. We do not knowingly solicit, collect, or process personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information or has used the Service in violation of our age requirements, please contact us immediately at support@azicanet.com. We will take prompt steps to delete any such information and terminate the child's access to the Service.
For users between the ages of 13 and 18, use of the Service requires parental or guardian consent as described in the Terms of Service.
Note for users in the European Economic Area and UK: Some of Azvault's optional features, including the HIBP password breach check (Section 3.4) and Family/Team Pairing (Section 9), rely on your consent under the GDPR. The age at which a minor can give that consent without a parent or guardian varies by country, from 13 to 16 depending on where you live. If you are under the digital consent age set by the law of your country of residence, only use these consent-based features with a parent or guardian's involvement, consistent with the eligibility requirements in our Terms of Service.
11. Your Rights Under GDPR (EEA, UK, and Switzerland)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access (Art. 15): request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): request correction of inaccurate data.
- Right to Erasure (Art. 17): request deletion of your personal data (right to be forgotten).
- Right to Restriction of Processing (Art. 18): request that we restrict processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): object to processing based on legitimate interests.
- Right to Withdraw Consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at support@azicanet.com. We will respond within the time period required by applicable law.
Because Azvault is a zero-knowledge application, we do not have access to your vault data, so most of the above rights are satisfied by default for that data, since it never reaches us in a readable form.
The one exception is Family/Team Pairing (Section 9), which stores a small amount of pseudonymous data server-side while a group exists. None of it includes your name, email address, or other information that directly identifies you, consistent with Section 9's "what is not stored" and the zero-knowledge principle in Section 2.
Family/Team Pairing data. The device identifiers, public keys, and group metadata described in Section 9 are not linked to your name, email address, or any other information that identifies you, and we have no independent means of determining which specific person a given device or group belongs to. Under Article 11(1) GDPR, where a controller is not in a position to identify a data subject, the rights set out in Articles 15 to 20, including the right of access and the right to erasure, do not apply to that data unless you provide additional information enabling your identification.
If you contact us at support@azicanet.com and provide information sufficient to identify your device or group, for example your device's public key or the approximate date you joined a specific group, we will evaluate your request under Articles 15 to 20 in accordance with Article 11(2) GDPR.
Leaving a group, or being removed from one, immediately and permanently ends that device's ability to read the group going forward. This happens automatically on our servers whether or not you contact us, and doesn't require identifying yourself first. What we can't do is selectively erase a single identified member's stored data from a group that's still active, because the remaining members' ability to read items they haven't deleted depends on that group's shared key structure, and removing one member's key share would break it for everyone else. The only way to fully erase a departed member's stored data is for the group's organizer to delete the group entirely, which erases everyone's data at once, as described in Section 9. If you're the organizer, you can do that yourself at any time. If you're not, you can ask your organizer to do it, or contact us and we'll walk you through your options.
International Transfers: Some of the limited data described in this policy, including purchase data processed by RevenueCat and the Family/Team Pairing and Secure Password Sharing data processed by Supabase, may be transferred to and processed in the United States. Our providers represent that such transfers are protected by recognized mechanisms such as Standard Contractual Clauses. See each provider's own privacy policy, linked in Section 5, for details. If you contact our support team from outside the United States, your message and any information you include are also transferred to and processed in the United States, where Azica LLC is based.
12. Your Rights Under U.S. State Privacy Laws
A number of U.S. states, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, have enacted comprehensive consumer privacy laws that grant rights like the ones described below. These laws generally apply to businesses that meet certain revenue or data-volume thresholds. Azica LLC has not determined that it meets those thresholds in any state. Regardless of whether a specific state's law formally applies to us, we extend the following rights to residents of any state with a comprehensive consumer privacy law, including any state that enacts a substantially similar law after the date of this Privacy Policy, as a matter of policy:
Right to Know
You have the right to request disclosure of the categories and specific pieces of personal information we have about you, the purposes we use it for, and whether we sell or share it.
Right to Delete
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
Right to Correct
You have the right to request correction of inaccurate personal information.
Right to Opt-Out of Sale or Sharing
Azica LLC does not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising or targeted advertising, under any state's definition. No opt-out is required.
Right to Non-Discrimination
We will not discriminate against you for exercising any of the rights described in this section.
Categories of Personal Information Collected in the Last 12 Months
| Category | Collected | Retention | Purpose |
|---|---|---|---|
| Identifiers (name, email) | Only if you contact support | Until your inquiry is resolved and our recordkeeping obligations are met (Section 7) | Support responses only |
| Unique/device identifiers | Only if you use Family/Team Pairing (Section 9) | Until the group is deleted by its organizer; leaving or being removed from a group ends that device's access but does not delete its rows (Section 9) | Enabling encrypted sharing within your group |
| Commercial information (purchase records) | Via RevenueCat | Retained by RevenueCat as needed for subscription management and financial compliance (Section 7) | Subscription management |
| Advertising identifiers (IDFA/GAID) | Via RevenueCat SDK, subject to platform consent | Not retained by Azica LLC; governed by RevenueCat's own retention practices | Attribution and fraud prevention by RevenueCat |
| Internet/network activity | Limited exposure to service providers described in Section 5, not collected by Azica LLC directly | Not retained by Azica LLC | N/A |
| Biometric information | No | N/A (not collected) | N/A |
| Geolocation | No | N/A (not collected) | N/A |
| Inferences drawn from personal information | No | N/A (not collected) | N/A |
To submit a state privacy rights request, email us at support@azicanet.com with the subject line "State Privacy Rights Request." We will verify your identity and respond within the time period required by the applicable law in your state.
13. Do Not Track and Global Privacy Control
Some browsers and devices allow you to broadcast a "Do Not Track" signal or a Global Privacy Control ("GPC") opt-out signal. As explained in Section 12, Azica LLC does not sell or share your personal information, so there is no sale or sharing for these signals to opt you out of. We honor the substance of both signals by never selling or sharing personal information in the first place, and we do not track you across apps or websites.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page.
Non-material changes, such as clarifications or formatting, take effect upon posting, and your continued use of Azvault after that date constitutes your acceptance.
For material changes, we will provide notice through the App or via email if you have contacted us and we have your address. Material changes follow the affirmative-acceptance process described in Section 1.2 of the Terms of Service.
We encourage you to review this policy periodically.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Azica LLC
Email: support@azicanet.com
We are committed to working with you to resolve any privacy concerns.