01
Your data is none of our business
Vault-Budget encrypts everything locally before any transmission. Our servers store cryptographic noise, nothing else. We are not a trusted partner promising to behave, we are technically incapable of reading your data.
02
Encryption is the default, not an option
AES-256-GCM for content, Argon2id for key derivation, HMAC-SHA-256 for integrity. No degraded mode, no marketing toggle, no plan-based compromise.
03
One passphrase, no magic recovery
If you lose your passphrase and your BIP39 Recovery Kit, your data is unrecoverable. This may seem harsh, but it is the only serious zero-knowledge guarantee.
04
Offline-first, optional sync
The app works offline by design. Multi-device sync is an end-to-end encrypted bonus, never a prerequisite.
05
No ads, no tracking, no resale
No Google Analytics, no Facebook pixel, no third-party cookies. Our business model is subscription, not your data, not your attention, not your contacts.
06
Absolute portability
Standardized .vault-budget format, VB01 magic bytes, documented schema. Leave whenever you want, take everything with you, attachments included.
07
Code open to audits
Cryptographic contracts (vectors, formats, algorithms) are public. Third-party audits are welcome, under standard contractual clauses to protect security teams' work.