Harpo Vault

Privacy Policy

Developed by Vaelqis Studio

Contact: vaelqisstudio@gmail.com

Effective Date: September 11, 2026

1. Introduction

This policy describes how production Harpo Vault handles information when you store and manage content on your Android device. Google Play and external apps or storage providers you choose have their own data practices.

2. Local-first design

Harpo stores Vault and Quick Notes data on your device. Vaelqis Studio operates no Harpo cloud-storage or Harpo account service, and the app has no automatic Harpo-owned upload of Vault or Notes content. You do not create a remote Harpo account to use the app.

This does not mean that the app never uses the network. Google Play purchase services and supporting SDKs can communicate with Google. Your chosen external apps and storage providers can also transfer data, as described below.

3. Information stored on your device

The app handles files you select, including photos, videos, audio and documents. It also stores file and folder names, source-location references, sizes, timestamps, favorites, recent-item information and Trash state. Search operates on local data. Your files and notes may themselves contain personal or sensitive information.

REAL and RECOY Vaults have separate local databases, file storage and master keys. Local password-derived verifiers, wrapped keys and Folder Password credentials support authentication and access control. Android biometric authentication supplies a result; Harpo does not receive raw fingerprint or face templates.

Settings include Auto-Lock, biometric preferences, Browse Grid/List mode, Disguise Mode and Allow Screenshots. Some preferences are shared across REAL and RECOY. Local size records support their shared Vault quota; Quick Notes is outside that quota.

4. Vault encryption and temporary working files

Vault file content uses AES-GCM encryption with 256-bit master keys. Android Keystore manages the keys used to wrap stored master keys. Sensitive metadata fields are encrypted, but database structure, password verifiers and ordinary preferences are not all Vault-encrypted. Folder Password adds access control; it does not give each folder an independent content-encryption key.

Content must be decrypted for use. Temporary plaintext working copies can exist, including:

Harpo attempts to delete internal read/copy files when each operation ends, including ordinary failures. A crash, process termination or failed deletion can leave remnants. When the storage component is created or later read/copy operations run, recognized inactive read/copy files at least 24 hours old become eligible for cleanup. This is not a guaranteed deletion time, and locking the Vault does not guarantee immediate removal of every interrupted working file.

Preview files have workflow/session cleanup, removal of owned abandoned files when their storage component is created, and later stale-file checks. Other editing and thumbnail work uses separate cleanup rules. Recoverable external edits can remain while you authenticate again. A nonempty capture may be retained after failed import to avoid destroying its only copy; it is not deleted merely because it is old.

Clearing Android cache can remove cache-based work and unfinished captures, but does not remove internal read/copy files outside cache. Clearing app data or uninstalling removes app-private storage, including working files, and also removes your local Vault/Notes data. Filesystem deletion does not guarantee forensic erasure.

Android's app sandbox protects app-private files. An app you explicitly invoke can read or modify the working copy granted to it and may keep its own copy. Harpo cannot recall data that another app has already retained.

5. Device file and folder access

Harpo Vault uses Android's official Storage Access Framework (SAF) for device file and folder selection instead of requesting broad device-storage access. This keeps access limited to content the user explicitly selects. SAF is not a guarantee against every security risk.

Import Files from Device opens Android's file selector for one or multiple files of mixed types, including photos and videos. Import Folder from Device opens Android's folder selector. Harpo requests read access and the write access needed for Move operations. Selected providers may store content locally or in their own cloud services.

Where Android and the provider allow it, Harpo attempts to retain URI access permissions internally for later access, recovery or supported return destinations. Backup locations can also be remembered. These are app-local access references, not data uploaded to a Harpo server. Access can be revoked or become unavailable. A retained grant may outlast the operation; Harpo does not promise to release every grant immediately after import.

6. True Move behavior

Import is a Move, not a promise to leave a permanent external copy. Before requesting source deletion, Harpo streams the content into encrypted Vault storage, synchronizes and cryptographically verifies the copy, finalizes its storage location, durably records recovery information, commits Vault metadata and checks that the stored copy is recoverable. Folder import first builds and verifies the complete Vault hierarchy, including empty folders.

Only then does source cleanup begin. Harpo checks whether the source is confirmed deleted, confirmed present or unknown after a deletion attempt. If cleanup fails or remains uncertain, it preserves the verified Vault copy and reports an incomplete or failed Move. A provider exception does not cause the verified safety copy to be deleted. Before source deletion starts, incomplete Vault work may be rolled back while the source remains intact.

Source files are removed before empty source directories. Nested directories precede their parents, and the selected root folder is removed last. Folder cleanup failure stops further cleanup and retains the verified Vault hierarchy. Interrupted operations can leave encrypted copies and recovery records for later authenticated reconciliation; recovery does not automatically retry source deletion.

These safeguards depend on Android, the filesystem, storage hardware and the selected provider. They do not guarantee absolute power-loss immunity or protection from every hardware/provider failure. Provider deletion does not guarantee removal from that provider's backups or history.

7. Quick Notes

Quick Notes stores titles, bodies and timestamps in a separate local app-private database. It uses ordinary database storage and is not protected by Vault encryption. It is separate from REAL/RECOY, is not included in .vaultbackup, and is not counted toward Vault quota.

Notes search runs locally. Harpo provides no Notes cloud synchronization. Deleting a note removes it through the Notes database rather than moving it to Vault Trash.

8. Backup and restore

Harpo creates encrypted portable .vaultbackup archives using format v3, with supported legacy formats still readable. Archives contain supported REAL Vault records, content and key/credential information needed for restoration. RECOY and Quick Notes are excluded. They are not full-device backups of general app settings, purchase cache or temporary working directories.

You choose an external destination using the available storage/provider flows, a remembered authorized backup folder, or the supported local Downloads option. A cloud-backed provider can upload the encrypted archive. Archive names, sizes and format information can remain visible. Keep your archives and required credentials secure.

Restore uses local staging and recovery records and is not blocked by the current Free growth quota. The app disables Android automatic backup and configures cloud-backup/device-transfer exclusions for its app data. Those settings do not control backups you export yourself or every manufacturer's independent transfer tool.

9. Trash and deletion

Vault Trash keeps content encrypted. Items become eligible for permanent deletion after 30 days, when relevant app workflows run. Harpo does not guarantee deletion at the exact 30-day timestamp while the app remains unopened; failures can defer cleanup. Available permanent-delete controls can remove items sooner.

Local deletion cannot recall exports, archives, screenshots or copies held by other apps/providers. Deletion is not a promise of secure physical overwriting of storage.

10. Screenshot and security controls

Allow Screenshots is OFF by default. Protected Vault and authentication windows request Android screenshot/screen-recording protection. Enabling the setting requires warning confirmation and intentionally allows capture of protected content. Disabling it does not remove existing screenshots or recordings. REAL and RECOY share this preference; Quick Notes remains screenshot-capable.

Disguise Mode is an optional app-global Pro setting that presents the Quick Notes launcher. Hidden Vault still requires normal setup/login. Hidden-entry feedback acknowledges a gesture, not authentication, and does not itself log or transmit user data. Google SDK activity remains subject to section 11.

11. Google Play Billing and third-party services

Pro is a lifetime one-time purchase through Google Play Billing. Harpo handles product identifiers, ownership, purchase tokens, purchase state and acknowledgment results. It keeps a local entitlement cache, including a token hash and reconciliation information. The app has no payment-card entry or Harpo customer-account backend.

Entitlement checks can occur on startup/resume without a purchase attempt. Google processes purchase/service information under its own Privacy Policy and purchase terms. Clearing Harpo data does not delete Google's purchase records.

The app includes Google Play Billing and supporting DataTransport/CCT libraries. Its Internet and network-state permissions support these services and their diagnostic transport; they do not grant broad access to device files. Their diagnostic path can transmit SDK events and Android/app version, device model/build/manufacturer, locale/country, timezone and network/mobile-operator information to Google. Receiving services can observe connection information such as source IP. This is distinct from uploading Vault or Notes content. No Harpo server endpoint receives those SDK events in the reviewed implementation; this does not claim that Google provides no developer-facing purchase or diagnostic reports.

The default SDK diagnostic endpoint uses HTTPS. This does not establish every Google service's or selected provider's transport practices. Harpo does not claim the diagnostics are anonymous, that every event is sent on each launch, or that Google deletes server records on a specific schedule. Google controls service-side processing and retention.

No Harpo-owned analytics uploader, crash-report service, advertising integration, remote synchronization or HTTP account backend is implemented. Google SDK diagnostics are a separate network behavior, not an exception omitted from this policy.

12. User-directed transfers

Export writes decrypted content to your selected destination. Move Out verifies the external output before local permanent cleanup; a supported previously authorized original location can also be used. External viewing/editing grants the chosen app access to a plaintext working copy. Capture grants the chosen camera access to its output URI.

These actions can place content and names with third-party apps/providers, including cloud services, under their own policies. A provider may refuse cleanup of a partial output. Manage external copies separately: they can remain after local deletion or uninstalling Harpo.

13. Data sharing

The app implements no automatic Harpo-owned upload of Vault or Notes content. Google purchase/SDK processing and your selected external transfers are described separately above. External recipients may retain or further process data under their policies. This is not a claim that no third party receives information.

14. Data retention

Local content, preferences and operational records remain until their applicable workflow removes them, you delete them, or app data is removed. Interrupted moves can retain verified copies and encrypted recovery records. Temporary-file and Trash cleanup limits are described in sections 4 and 9; unresolved work has no universal deletion deadline.

Harpo has no remote account-creation or account-deletion service. Local passwords protect local Vaults. Use available app controls or Android app-data/uninstall controls to remove local data. Harpo cannot remotely erase your device, third-party copies or Google's records.

15. Children and age

Harpo Vault is intended for users aged 13 years and older. It is not designed or directed to children under 13.

Where applicable law requires parental or guardian consent for a minor's use of an app or service, users should comply with those local requirements.

16. Changes to this Privacy Policy

Changes to data practices may require updates to this policy. Updates will be posted on this page with their effective date.

17. Contact

Vaelqis Studio

vaelqisstudio@gmail.com

18. Effective Date

September 11, 2026