Legal · Privacy Policy

HackVault
Privacy Policy

HackVault is a field penetration testing reference app. We built it to work entirely offline. This privacy policy explains exactly what data we collect — which is none.

Effective: 1 September 2026 Last updated: 1 September 2026 Applies to: HackVault iOS App
Summary: HackVault does not collect, store, transmit, or share any personal data. The app works fully offline. No account is required. No analytics are embedded. Your use of the app is entirely private.

1. Who We Are

HackVault is developed and maintained by Cyber Analyst Academy, an independent cybersecurity education platform.

2. Data We Collect

We collect no personal data whatsoever. Specifically, HackVault does not collect:

  • Name, email address, or any account credentials
  • Device identifiers, advertising IDs, or fingerprints
  • Location data (the app never requests location permission)
  • Usage analytics, session data, or behavioural telemetry
  • Crash reports sent to our servers
  • Search queries, bookmarks, or notes entered in-app
  • Network traffic (the app does not make any network requests)

All content in HackVault is bundled locally in the app binary. Nothing is fetched from our servers at runtime.

3. Data Stored on Your Device

HackVault may store the following data locally on your device only, never transmitted externally:

  • Bookmarks: Techniques or commands you mark as favourites are stored in iOS local storage (UserDefaults or Core Data) on your device.
  • Search history: Recent in-app searches may be retained locally to improve the search experience. This data never leaves your device.
  • Preferences: Display settings such as font size, theme, and sort order are stored locally.

You can clear all locally stored data at any time by deleting and reinstalling the app, or through iOS Settings → HackVault → Reset.

4. Third-Party Services

HackVault integrates no third-party SDKs, analytics libraries, advertising networks, or social login providers. The App Store download process itself is governed by Apple's Privacy Policy.

Apple may collect standard App Store metrics (download counts, crash data via iOS) as part of their platform services. We receive only aggregate, anonymous statistics from Apple's App Analytics — we cannot identify individual users from this data.

5. Permissions Requested

HackVault requests only the permissions required for core functionality:

  • No camera access
  • No microphone access
  • No contacts access
  • No location access
  • No network access beyond App Store update checks managed by iOS itself

If a future update requires any new permission, this policy will be updated and the reason disclosed in the App Store release notes before the update is published.

6. Children's Privacy

HackVault is designed for cybersecurity professionals and students. It is not directed at children under 13. We do not knowingly collect data from minors. If you are a parent or guardian and believe your child has provided personal information through the app, please contact us and we will address it promptly — though given our no-collection architecture, no data would have been transmitted.

7. International Users

HackVault is available globally on the App Store. Because we collect no personal data, there is no cross-border data transfer. GDPR, CCPA, PIPEDA, and equivalent regional privacy regulations impose no additional obligations on us beyond this policy — and we meet all of them by design through our no-collection architecture.

8. Security

All content within HackVault is served from local storage on your device. Local data (bookmarks, preferences) is protected by iOS's standard sandboxing and device encryption. If your device uses Face ID, Touch ID, or a passcode, local app data inherits that protection.

9. Changes to This Policy

If we change this privacy policy — for example, if a future feature requires a new permission or any data collection — we will:

  • Update this page with the new effective date
  • Post a clear changelog notice in the App Store release notes
  • Provide an in-app notification if the change is material

We will never retroactively apply a more permissive data collection policy to data collected under a more restrictive one.

10. Your Rights

Because we collect no personal data, there is no data subject access request (DSAR), erasure request, or portability request to fulfil.