Skip to main content
Skip to main content

Privacy Policy

Last updated: March 26, 2026

TL;DR: We collect no data. All processing happens locally in your browser. We have zero access to your inputs, files, or outputs.

1. Information We Do Not Collect

ZeyroVault's tools run entirely in your browser: the data you provide is processed locally on your device, and we do not collect, store, or process it ourselves. Our tools do not collect the following:

  • Your inputs, passwords, or encrypted data
  • Files you process through our tools
  • IP addresses for tracking or profiling (hosting-related request logs are handled by Cloudflare as our service provider; see Section 3)
  • Browser fingerprints or device information for tracking
  • Usage patterns or analytics data (analytics are disabled by default)
  • Tracking cookies or identifiers (we set no tracking cookies; Cloudflare may set essential security cookies; see Section 3)

2. How Our Tools Work

All ZeyroVault tools run entirely in your web browser using client-side JavaScript and the Web Crypto API. When you use our tools:

  1. The application code is downloaded to your browser
  2. All processing occurs locally in your device's memory
  3. Your data never leaves your device or travels over the network
  4. No data is stored after you close the browser tab

You can verify this by opening Developer Tools (F12), switching to the Network tab, and using any tool—you will see zero outbound requests containing your data.

3. Cookies and Tracking

ZeyroVault does not set its own cookies, localStorage, sessionStorage, or any other persistent storage mechanisms to track users or store data. However, third-party services used to deliver the website may set essential cookies: our CDN provider (Cloudflare) may set temporary security cookies for bot detection and load balancing. These are strictly necessary for service delivery and are not used for tracking. You can verify cookie usage by opening Developer Tools (F12) at any time while using our site.

4. Third-Party Services

By default, we do not integrate with third-party analytics, advertising, or tracking services. Our tools do not load external scripts that could access your data. If we introduce advertising in the future, we will update this section to describe what is used and how it works.

The only external resources we load are static assets (HTML, CSS, JavaScript) from our own servers and CDN for delivering the application code.

5. Data Retention

There is no data to retain. Since all processing occurs in your browser's memory and no data reaches our servers, we maintain no databases, logs, or storage systems containing user data. When you close the browser tab or navigate away, all data in memory is immediately released.

6. Your Rights Under Privacy Laws

Because we collect no personal data, many standard privacy rights (access, deletion, portability) are technically unnecessary. However, we respect your privacy rights under applicable laws:

GDPR (EU/UK)

Our tools process user-provided content entirely in your browser; we do not use personal data for tracking, profiling, or advertising. Where hosting logs involve personal data (such as IP addresses), they are processed by Cloudflare as our service provider under its Data Processing Addendum. Whether GDPR duties such as data-controller obligations apply to a specific activity depends on the context; this page describes our design and is not a legal conclusion.

CCPA/CPRA (California)

We do not sell personal information as defined under CCPA, and we do not share personal information for cross-context behavioral advertising. User-provided content is processed locally in your browser and is not collected by us. Hosting-related technical data is handled by Cloudflare (see the Privacy Policy). If you have questions about your CCPA rights, please contact us.

PIPEDA (Canada)

PIPEDA consent requirements apply to collecting, using, or disclosing personal information in the course of commercial activity. Our tools process user-provided content locally on your device, and we do not collect personal information for our own purposes.

LGPD (Brazil)

LGPD principles are met by design: user-provided content is processed locally, and we do not use personal data for tracking or advertising. Hosting logs are handled by Cloudflare.

7. Security

While we implement security best practices for our code delivery (HTTPS, secure headers), the security of your data primarily depends on:

  • Your device security (free from malware and keyloggers)
  • Browser security (up-to-date, trusted extensions only)
  • Network security (use HTTPS, avoid public Wi-Fi for sensitive operations)

8. Children's Privacy

Our tools are not specifically directed at children under 13. However, since we collect no personal information from any user, we do not knowingly collect data from children. Our encryption and cryptographic tools are designed for developer and professional use and are not intended for unsupervised use by minors. Parents and guardians are encouraged to supervise their children's online activities. ZeyroVault complies with the Children's Online Privacy Protection Act (COPPA) in the United States, GDPR-K in the European Union, and the UK Age Appropriate Design Code.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. Since we have no way to contact users (we collect no contact information), we encourage you to review this policy periodically.

10. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at privacy@zeyrovault.com. We aim to respond to all inquiries within 5 business days.

By using ZeyroVault, you acknowledge that you have read and understood this Privacy Policy.