Skip to content
Turbo Ventura
Apps Practice Support Contact
01 Apps 02 Practice 03 Support 04 Contact

Pic Vault · Privacy

Pic Vault Privacy Policy

A vault is only worth having if nobody else holds a key. This page says exactly what the app sends, what it never sends, and who else is involved.

Last updated
13 September 2026
Issued by
Turbo Ventura, Dubai, United Arab Emirates
Applies to
Pic Vault: Hide Photos for iPhone and iPad

Contents

  1. 01 What this policy covers
  2. 02 Your vault stays on your device
  3. 03 Usage statistics
  4. 04 Advertising
  5. 05 Purchases and subscriptions
  6. 06 Recovery code by e-mail
  7. 07 Backups, transfers and services you connect
  8. 08 Permissions the app asks for
  9. 09 Retention and deletion
  10. 10 Children
  11. 11 Your rights
  12. 12 International transfers
  13. 13 Changes to this policy
  14. 14 Contact

See also

Turbo Ventura privacy policy

The company and this website: server logs, cookies and analytics.

In short

  • Your vault is encrypted on the device. We never receive it.
  • No account, no sign-in, nothing that identifies you.
  • Usage statistics only with your consent, and never with content.
  • Backups are encrypted before they leave, to a service you choose.
  • Purchases run through Apple — we never see payment details.
  • Advertising data is handled by Google AdMob, with your tracking choice respected.

A summary, not the agreement. The sections below are what applies.

01 What this policy covers

This policy covers Pic Vault: Hide Photos for iPhone and iPad, published by Turbo Ventura of Dubai, United Arab Emirates. It is the policy referenced by the app’s App Store listing.

The company and this website are covered by our general privacy policy; where the two overlap, this page is the more specific and it governs the app.

For anything here, write to [email protected].

02 Your vault stays on your device

Everything you put into Pic Vault is encrypted on the device before it is written to storage. We run no service you log in to and no server that receives your vault. The following never reaches us, and there is no mechanism in the app by which it could:

  • Your photos, videos, notes, voice memos, documents and records.
  • File names, album names, search terms and the structure of your vault.
  • Your passcode, your recovery code, and the passphrase of any backup.
  • Your browsing history, bookmarks and downloads in the private browser.
  • The log of failed unlock attempts and any intruder photo taken.

Files are encrypted with 256-bit ChaCha20-Poly1305, each under a key of its own; the master key is sealed with your passcode and, separately, with your recovery code. Server passwords and the passcode check are held in the iOS Keychain. Deleting the app removes the vault and everything in it.

03 Usage statistics

If — and only if — you allow it, Pic Vault records anonymous usage events: that a screen was opened, that a feature was used, and whether an action succeeded. No event carries content of any kind: no file names, no album names, no search terms, no addresses and nothing you have typed. Declining changes nothing about what the app can do, and the choice can be changed in the app’s settings. Should a third-party analytics provider be used to receive these events, it will be named in this section first.

04 Advertising

The app can show advertising supplied by Google AdMob, which acts as an independent controller of the data it receives under Google’s privacy policy. Ads are only requested after the vault is unlocked, never while the app is disguised, and never inside the vault’s content.

To request, show and measure an ad, the SDK may process your device’s advertising identifier (IDFA, only if you allow it), the IDFV, IP address, device and operating-system information, a coarse location derived from that IP address, and your interaction with the ad. Nothing from your vault is ever part of an ad request.

  • App Tracking Transparency. iOS asks your permission before the advertising identifier may be used. Decline and ads are non-personalised. You can change the answer in Settings › Privacy & Security › Tracking.
  • Consent in the EEA, the UK and Switzerland. Where required, Google’s consent form (UMP) is shown before personalised advertising is enabled, and it can be reopened from the app’s settings.

05 Purchases and subscriptions

Pic Vault Pro is sold through Apple’s In-App Purchase system using StoreKit. Apple takes the payment and holds the payment details; we never see your card, your billing address or your Apple Account credentials. The app keeps only the entitlement on the device, checked against Apple’s service. Refunds are handled by Apple at reportaproblem.apple.com.

06 Recovery code by e-mail

If you add a rescue e-mail address and then ask for your recovery code to be mailed, the app sends that address and the recovery code over HTTPS to our mail relay, which uses them only to deliver that one message. Nothing else about you or your vault is sent. If you never ask for a mail, nothing is sent at all — adding an address only stores it on your device.

07 Backups, transfers and services you connect

In every case the connection goes from your device straight to the service you chose — it does not pass through us, and we receive no copy of anything.

  • Cloud accounts (Google Drive, Dropbox, Yandex Disk): you sign in with the provider’s own screen, and the token it hands the app is stored in the Keychain. We never see your password.
  • Your own server (WebDAV, Nextcloud, ownCloud, SMB, SFTP, FTP, S3): the address and credentials you enter are stored in the Keychain and used to talk to that server directly.
  • Encrypted backups are encrypted on the device with a backup passphrase before they are uploaded. The service stores ciphertext it cannot read.
  • Wi-Fi transfer runs only on your local network, is gated by a PIN, runs only while its screen is open, and stops when the vault locks.
  • The private browser talks to the sites you visit like any browser would; those sites see your IP address and the requests you make.

08 Permissions the app asks for

Each request happens only when you use the feature that needs it, and declining one disables that feature and nothing else.

  • Face ID / Touch ID — to unlock the vault. The biometric match happens inside iOS; the app never receives your face or fingerprint.
  • Photos — to move photos and videos into the vault, to let iOS delete the originals, and to save an exported file back.
  • Camera — for the private camera, and, if you turn it on, to photograph whoever fails to unlock the vault. iOS shows the camera indicator whenever it is used.
  • Microphone — to record voice memos into the vault.
  • Contacts — to copy contacts you choose into the vault.
  • Location — only if you mark safe places, and only at the moment you unlock. Location is never stored off the device and never opens the vault.
  • Local network — for Wi-Fi transfer and to reach a server on your own network.
  • Tracking — see section 4.

09 Retention and deletion

  • Your vault — on your device until you delete it or remove the app. Items in the bin are removed after the period you set.
  • Backups — on the service you chose, until you delete them there.
  • Advertising data — retained by Google under its own policy.

We hold no copy of your vault and no key to it, so we cannot recover, read or delete its contents for you — only your passcode or your recovery code can open it.

10 Children

Pic Vault is a general-purpose tool and is not directed at children under 13, or the equivalent minimum age where you live. We do not knowingly collect personal data from them and hold no account data by which a child could be identified.

11 Your rights

Depending on where you live you may have the right to access, correct or delete personal data we hold about you, to restrict or object to its processing, to withdraw a consent you gave, and to complain to your supervisory authority — under the GDPR (EEA and UK), the KVKK (Türkiye), the CCPA/CPRA (California) and the UAE Personal Data Protection Law, among others.

We do not sell personal data and we build no profiles of individuals. To exercise a right, write to [email protected]. Because there is no account, we often cannot match a request to data we can identify as yours — that is a consequence of collecting so little, not a refusal.

12 International transfers

Google and the services you connect operate globally and may process data outside your country, including in the United States, under the transfer mechanisms set out in their own policies, such as the EU Standard Contractual Clauses.

13 Changes to this policy

When this policy changes materially — a new processor, a new category of data — the date at the top changes with it, the App Store privacy labels for Pic Vault are updated to match, and where the change affects what is collected we ask for your consent again inside the app.

14 Contact

Privacy questions and data requests: [email protected]
Help with the app: [email protected]
Legal notices: [email protected]

Turbo Ventura
Dubai, United Arab Emirates

Questions about this document?

The people who wrote it are the people who answer.

[email protected]
Turbo Ventura

An independent studio building media software for iPhone and iPad. We write our own engines, keep the work on the device, and maintain what we ship.

Apps

  • MP3 Converter
  • Pic Vault: Hide Photos

Studio

  • Practice
  • Work with us
  • Support

Legal

  • Privacy Policy
  • Terms of Service

Contact

  • [email protected]
  • Support

© 2026 Turbo Ventura · Dubai, United Arab Emirates

Set in Archivo & Space Mono · Analytics only with consent

Analytics

May we count this visit? One cookieless page count becomes a cookie that tells two visits apart — nothing of Google’s loads until you say yes, and we never build an advertising audience out of it.

What this stores →