P PetraLabs

Privacy Policy

Vault: Private Photo & Video · Last updated: July 1, 2026

PetraLabs (“we”) builds Vault, a private photo and video app. This policy explains what data the app and its optional sync service handle. Your media is encrypted on your device. If you enable sync, your vault’s encryption key is also backed up to the server so you can recover your photos on a new device — see Key backup & recovery below.

What we do not collect or see

Key backup & recovery

So you can restore your library after switching or reinstalling on a device, enabling sync backs up your vault’s encryption key to the server, stored encrypted at rest. Because the server holds this key, the server operator can technically decrypt your synced media — so sync is not zero-knowledge. This is the trade-off that makes password-based recovery possible. If you don’t want it, don’t enable sync; your media then stays encrypted on-device only.

What we process (only if you enable sync)

Content moderation

To keep the service safe and lawful, we may scan content stored on our servers for illegal material (for example, child sexual abuse material) and may suspend or permanently ban the account and device involved, and report it to the relevant authorities where required by law. Because sync stores your encryption key (see Key backup & recovery), such scanning is technically possible on synced content only.

Anti-theft camera (optional, off by default)

If you explicitly enable anti-theft, then when your decoy vault is opened the app captures a photo from the front and back cameras and uploads them to your sync account as evidence of who did it (a decoy being opened usually means coercion or snooping). This feature is off by default and requires a decoy set up, your on-screen consent, and camera permission before it can be turned on. It photographs whoever is holding the device at that moment; you are responsible for using it lawfully where you live. Capture is not covert — the device shows its camera indicator. You can disable it at any time in Settings, and the captured images are removed when you delete your sync account.

How the data is used

Strictly to provide the sync/backup service, authenticate your account, and protect it against abuse. We do not sell your data or use it for advertising.

Self-hosting

Vault’s sync server is self-hostable. If you (or your provider) run your own server, that server operator controls storage of the encrypted data described above.

Device permissions

Retention & deletion

You can permanently delete your sync account and all of its server-side data at any time from Settings → Delete sync account. Resetting the vault erases all local data on the device. Deleted data is not recoverable.

Children

Vault is not directed to children under 13 (or the age required by your local law).

Changes & contact

We may update this policy; material changes will be posted here. Questions: privacy@petralabs.io.

← Back to PetraLabs