Privacy Policy - CloudVault — Backup & Storage

 PRIVACY POLICY — CloudVault: Backup & Storage


Effective Date: July 10, 2026

Last Updated: July 10, 2026

Developer: Fyno Tech

App: CloudVault — Backup & Storage

Package: com.fynotech.cloudvault


─────────────────────────────────────────


Your privacy is our priority. This Privacy Policy explains what data CloudVault collects, why we collect it, how we protect it, and your rights over it. We believe in complete transparency — no hidden data collection, no selling your personal information to third parties. Ever.


By downloading, installing, or using CloudVault, you agree to the practices described in this Privacy Policy.


─────────────────────────────────────────

1. INFORMATION WE COLLECT

─────────────────────────────────────────


We collect only the minimum data required to provide CloudVault's backup, storage, and restore services.


Information You Provide to Us:


• Email Address — Used for account creation, login, and password recovery. Required.

• Password — Stored as a cryptographic hash only. We never store or see your plain-text password. Required.

• Google Account (optional) — Name and email if you choose to sign in with Google.

• Files You Back Up (optional) — Photos, videos, documents, audio, and contacts — only what you explicitly choose to upload.

• Backup Preferences (optional) — WiFi-only setting, backup frequency, and folder selections.

• Language Preference (optional) — Your chosen app display language.


Information Collected Automatically:


• Storage Usage Data — Amount of storage used, file counts per category, and your plan tier. Used to display your storage dashboard.

• File Metadata — File names, sizes, types, and upload timestamps. Used to organise your file browser.

• Push Notification Token — A Firebase device token, only if you enable notifications.

• Crash Reports — Anonymised error logs via Firebase Crashlytics to help us fix bugs. Not linked to your identity.

• Advertising Identifier — Android Advertising ID, for free users only, used by Google AdMob to show relevant ads.

• IP Address — Used for security, fraud prevention, and approximate location for ads.


What We Do NOT Collect:


We never collect precise GPS location, call logs, SMS messages, browsing history, your contacts list (unless you initiate a contacts backup), biometric data, financial information, or data from any other apps on your device.


Important: The photos, videos, and files you upload to CloudVault are your property. We store them encrypted to provide the backup service only. We never scan, analyse, sell, or use your files for any other purpose.


─────────────────────────────────────────

2. HOW WE USE YOUR INFORMATION

─────────────────────────────────────────


We use the data we collect exclusively for the following purposes:


• To provide the backup and restore service

• To authenticate your account and manage your login

• To send push notifications (only if you opt in)

• To display your storage dashboard and file browser

• To detect and fix app crashes and bugs

• To serve advertisements to free-tier users via Google AdMob

• To process subscription payments via Google Play Billing

• To automatically purge files you have deleted after their recovery period ends

• To protect against fraud and unauthorised access

• To comply with applicable laws


We do not use your data for: selling to third parties, building advertising profiles beyond what AdMob does, training AI or machine learning models, or any purpose not listed above.


─────────────────────────────────────────

3. HOW WE STORE AND PROTECT YOUR DATA

─────────────────────────────────────────


All CloudVault data is stored on Amazon Web Services (AWS) cloud infrastructure in the South Asia region. Your data is physically stored within the South Asian region — closer to you than most competitor services.


Security measures we apply:


• Encryption at Rest — All files are encrypted using AES-256 server-side encryption.

• Encryption in Transit — All data travels over HTTPS / TLS 1.3.

• Time-Limited File Links — Upload and download links expire automatically.

• Token-Based Authentication — Every API request requires a valid signed token. Unauthenticated requests are rejected.

• Private Storage — Your files have no public URLs. Only you can access them via authenticated requests.

• Isolated User Data — Each user's files are in a logically separate folder. Cross-user access is not possible.

• Zero-Knowledge Passwords — Passwords are handled via Secure Remote Password (SRP) protocol. We never see your password.

• DDoS Protection — File delivery is routed through a global CDN with built-in protection.

• Continuous Monitoring — Error rates and access patterns are monitored around the clock.


─────────────────────────────────────────

4. DATA SHARING AND THIRD-PARTY SERVICES

─────────────────────────────────────────


We do not sell your personal data. We never sell, rent, trade, or monetise your personal information to any third party.


We share data only with service providers strictly required to operate the App:


Amazon Web Services (AWS)

Purpose: Cloud file storage, database, authentication, API delivery, notifications, and email.

Privacy Policy: https://aws.amazon.com/privacy/


Google AdMob

Purpose: Serves ads to free-tier users. May collect advertising ID, device info, and IP address.

Privacy Policy: https://policies.google.com/privacy


Firebase Crashlytics

Purpose: Anonymised crash reports to detect and fix bugs. No personal data linked.

Privacy Policy: https://firebase.google.com/support/privacy


Firebase Cloud Messaging

Purpose: Delivers push notifications using a device token only.

Privacy Policy: https://firebase.google.com/support/privacy


Google Sign-In

Purpose: Optional Google account login. Receives your name and email with your consent.

Privacy Policy: https://policies.google.com/privacy


Google Play Billing

Purpose: Processes subscription payments. We receive only a purchase confirmation token — never your card details.

Privacy Policy: https://policies.google.com/privacy


Other circumstances for disclosure:


We may share your data only when required by law or court order, to protect the safety of our users, or in the event of a business acquisition (you will be notified in advance). For any other purpose, only with your explicit consent.


─────────────────────────────────────────

5. DATA RETENTION AND DELETION

─────────────────────────────────────────


• Backed-up files — Kept until you delete them or close your account.

• Soft-deleted files — Kept for a recovery period that varies by your subscription plan. Permanently purged after the recovery window.

• Account information — Deleted immediately when you request account deletion.

• Crash reports — Retained for 90 days by Firebase Crashlytics.

• Push notification tokens — Retained until app uninstall or permission revoked.

• Advertising identifiers — Managed per Google AdMob's retention policy. Resettable anytime in Android Settings.

• Payment records — Managed by Google Play. We do not store payment data ourselves.


CloudVault runs a scheduled daily cleanup. Files that have passed their recovery window are permanently and irreversibly removed from our servers during this process.


─────────────────────────────────────────

6. YOUR RIGHTS AND CHOICES

─────────────────────────────────────────


You have full control over your data. We honour the following rights for all users worldwide:


• Right to Access — View all your data in the App at any time.

• Right to Correct — Update your account information via App Settings.

• Right to Delete — Delete individual files or your entire account and all data.

• Right to Portability — Download your files anytime. Your data is never locked in.

• Right to Object — Opt out of personalised ads at any time.

• Notification Control — Enable or disable push notifications anytime in Settings.


How to exercise your rights:


• Delete a file: App → My Files → Long-press → Delete

• Recover a deleted file: App → Deleted Files → Restore

• Delete your account: App → Settings → Account → Delete Account

• Opt out of personalised ads: Android Settings → Privacy → Ads → Delete Advertising ID

• Disable notifications: App → Settings → Notifications → Off

• Contact us: sherazahmad383@gmail.com


Regional Rights:


European Union and UK (GDPR): You have the right to restrict processing, lodge a complaint with your Data Protection Authority, and withdraw consent at any time.


California, USA (CCPA/CPRA): You have the right to know what data we collect, delete it, and opt out of its sale. We do not sell personal data.


Pakistan and India: We respect India's Digital Personal Data Protection Act (DPDPA) 2023 and applicable Pakistani data protection regulations. Your data is stored within the South Asian region.


─────────────────────────────────────────

7. CHILDREN'S PRIVACY

─────────────────────────────────────────


CloudVault is not designed for or intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13.


If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at sherazahmad383@gmail.com and we will delete that information promptly.


─────────────────────────────────────────

8. INTERNATIONAL DATA TRANSFERS

─────────────────────────────────────────


Your files and account data are stored on AWS cloud infrastructure in the South Asia region. Some data processed by Google's SDKs (AdMob, Firebase Crashlytics, Firebase Cloud Messaging) may be processed in the United States by Google LLC. These transfers are governed by Google's privacy policies and are protected by standard contractual clauses and other legally recognised data transfer mechanisms.


─────────────────────────────────────────

9. ADVERTISING AND ANALYTICS

─────────────────────────────────────────


Advertising (Free Users Only)


The free plan is supported by advertising via Google AdMob. Ads appear only to free-tier users. Upgrading to a paid plan removes all ads permanently.


AdMob may collect: Android Advertising ID, device identifiers, IP address, app interaction data, and diagnostic information for fraud prevention. All AdMob data is encrypted in transit via TLS.


To opt out of personalised ads: Android Settings → Privacy → Ads → Delete Advertising ID.


More information: https://policies.google.com/technologies/ads


Crash Analytics


We use Firebase Crashlytics only to detect and fix app crashes. Crash reports are anonymised (device model, OS version, app version, error trace) and are not linked to your identity. We do not use Firebase Analytics or any user behaviour tracking platform.


No Cross-App Tracking


CloudVault does not track your activity across other apps or websites and does not use any cross-app tracking tools.


─────────────────────────────────────────

10. IN-APP PURCHASES AND SUBSCRIPTIONS

─────────────────────────────────────────


CloudVault offers optional paid subscription plans providing additional storage and an ad-free experience. Current plan details and pricing are displayed within the app at the time of purchase.


All payments are processed entirely by Google Play Billing. We receive only a purchase confirmation token — we never receive, store, or process your credit card number or any financial information.


Subscriptions automatically renew unless cancelled at least 24 hours before the renewal date. Manage your subscription at: Google Play → Account → Subscriptions.


For refund requests, contact Google Play support. For CloudVault-specific questions, contact us at sherazahmad383@gmail.com.


─────────────────────────────────────────

11. PERMISSIONS REQUESTED

─────────────────────────────────────────


CloudVault requests only the permissions necessary for its core features. All permissions are requested at the point of use.


• READ_MEDIA_IMAGES — Access photos for backup (Android 13+). Optional.

• READ_MEDIA_VIDEO — Access videos for backup (Android 13+). Optional.

• READ_EXTERNAL_STORAGE — Access files for backup (Android 12 and below). Optional.

• READ_CONTACTS — Read contacts for backup, only when you initiate it. Optional.

• WRITE_CONTACTS — Restore contacts to your phone, only when you initiate it. Optional.

• INTERNET — Connect to CloudVault servers. Required.

• ACCESS_NETWORK_STATE — Detect WiFi vs mobile data for WiFi-only backup mode. Required.

• FOREGROUND_SERVICE — Run background backup while the app is minimised. Optional.

• RECEIVE_BOOT_COMPLETED — Restart scheduled backup after device reboot. Optional.

• POST_NOTIFICATIONS — Send backup and storage alerts (Android 13+). Optional.


All optional permissions can be revoked at any time via Android Settings → Apps → CloudVault → Permissions.


─────────────────────────────────────────

12. ACCOUNT DELETION

─────────────────────────────────────────


As required by Google Play policy, CloudVault provides complete, permanent account deletion. Deleting your account removes all your data from our servers.


Method 1 — Delete in the App:

1. Open CloudVault

2. Tap Settings

3. Tap Account

4. Tap Delete Account

5. Confirm by tapping Delete Permanently


Method 2 — Request via Email:

Send an email to sherazahmad383@gmail.com with subject "Account Deletion Request" from your registered email address. We will delete your account within 7 business days.


What gets deleted:

• All your backed-up files permanently removed from cloud storage

• All file metadata and records removed from our database

• Your user account record permanently removed

• All settings and preferences removed

• Your authentication credentials and identity removed


Warning: Account deletion is permanent and irreversible. Once deleted, your data cannot be recovered. Please download any files you wish to keep before deleting your account. Cancel any active subscription through Google Play separately to stop future billing.


─────────────────────────────────────────

13. CHANGES TO THIS PRIVACY POLICY

─────────────────────────────────────────


We may update this Privacy Policy from time to time to reflect changes in our features, legal requirements, or operating practices.


When we make material changes, we will:

• Update the "Last Updated" date at the top of this page

• Send an in-app notification

• Email your registered address for changes that significantly affect your rights


Your continued use of CloudVault after changes take effect constitutes acceptance of the updated policy.


─────────────────────────────────────────

14. CONTACT US

─────────────────────────────────────────


Have a question about this Privacy Policy or how we handle your data? We respond to all privacy inquiries within 48 hours.


Email: sherazahmad383@gmail.com


Fyno Tech

Developer of CloudVault — Backup & Storage

Google Play Package: com.fynotech.cloudvault

Rawalpindi, Pakistan


─────────────────────────────────────────


This Privacy Policy was last updated on July 10, 2026 and is effective immediately.

© 2026 Fyno Tech. All rights reserved.


Comments