Last updated: July 15, 2026

Privacy Policy

VaultCopy is designed around a local data path: your Mac creates the snapshot, your iPhone stores the copy, and VaultCopy does not operate a hosted note-backup service.

Scope

This policy covers the VaultCopy iPhone app, VaultCopy Agent for Mac, and this product website. VaultCopy is a local-first backup utility for folder-based Markdown vaults.

Data VaultCopy does not collect

  • VaultCopy does not upload note contents or backup archives to VaultCopy servers.
  • VaultCopy does not upload backup passphrases, pairing tokens, full QR payloads, or .vaultcopy restore packages.
  • The local backup workflow does not require a VaultCopy account.
  • The app does not include advertising or third-party analytics SDKs.

How local backup data is handled

The Mac Agent reads only the vault folder you select, creates a snapshot, and serves it to the paired iPhone over a reachable local network. The iPhone stores recent verified snapshots inside the app's local storage and creates a restore package only when you choose to export one.

Pairing uses a short-lived code for the first connection and a saved device token for later local reconnection. Pairing credentials are not placed in public Bonjour records or sent to this website.

Encryption

Encrypted snapshots are optional. When enabled in the Mac Agent, the passphrase is used locally to create an encrypted archive. If you choose to remember the passphrase, it is stored in the macOS Keychain on that Mac. VaultCopy cannot recover a forgotten passphrase or decrypt an old archive without it.

Permissions

  • Local Network: used by iPhone to discover and connect to your Mac Agent.
  • Camera: used only to scan the Mac Agent pairing QR code.
  • Mac folder access: used by the Agent to read the vault folder you choose and write snapshots or restored files to locations you select.
  • macOS Keychain: used only when you explicitly ask the Agent to remember an encrypted-backup passphrase.

Purchases

The lifetime unlock is processed by Apple through StoreKit and the App Store. Apple handles payment and Apple Account information under Apple's own terms. VaultCopy receives the entitlement result needed to unlock backup creation; it does not receive your full payment-card details.

Website and support

This static website does not use advertising cookies, tracking pixels, fingerprinting, or browser storage for measurement. It hosts product information, the privacy and support pages, the signed Mac Agent download, and the Sparkle update feed.

The website's deidentified measurement access log records only the request hour rounded to the whole hour, one fixed channel label, one fixed route label, a coarse event type (page request, iOS outbound, or Mac outbound), HTTP status, response bytes, and a human, bot, or unknown classification. The classification is derived transiently from the request's User-Agent; the full User-Agent is not written to the measurement log.

The fixed route label is limited to the approved source and outbound route vocabulary; it is not the original request path. The measurement log does not contain IP addresses, cookies, query strings, full User-Agents, Referers, request or session IDs, or other user or device identifiers. Deidentified raw log lines are retained for no more than 30 days. Daily channel aggregates, containing only counts, status totals, bytes, and coarse client classes, are retained for no more than 12 months.

If you email support@tokenlane.tech, the message and address you provide are used to respond to your request. Do not send passphrases, pairing tokens, full QR payloads, backup packages, or note contents.

Contact

Questions about this policy can be sent to support@tokenlane.tech.