STUBVAULT

Privacy

Updated July 2026

Stubvault is local-first. Cloud sync is off by default and stays off until you enable it in Settings. This page states exactly what the app stores, encrypts, and sends — every claim here corresponds to code in the build.

Data on your device

All data lives on the device, encrypted at rest:

Network calls

Stubvault makes outbound requests only to the destinations below. Everything else is unreachable: iOS App Transport Security enforces TLS 1.3 minimum with no arbitrary loads, and Android's network security config blocks cleartext and uses system trust anchors only.

Auth (only if you sign in)

Opt-in cloud sync

Diagnostics (opt-in)

What's not in the app

Stubvault ships with no third-party analytics or advertising SDKs. Confirmed transitively in the resolved bundle: no Segment, no Firebase Analytics / Crashlytics / Performance, no Mixpanel, no Amplitude, no AppsFlyer, no Adjust, no Branch, no AdMob / AppLovin / IronSource / Tapjoy or any ad-mediation SDK, no Facebook SDK, no OneSignal. The bundle audit is documented in the repository.

Retention

Contact

Questions: hello@getstubvault.com

← getstubvault.com Terms of Service →