Skip to content

PRIVACY

Privacy policy

How we use personal data when you visit our website or use Cryptex Vault and Online Services.

Last updated: 25 September 2026

Cryptex Industries d.o.o.

Cryptex Industries d.o.o., Croatia, operates Cryptex Vault and Online Services and is the controller for the personal data we process to run them. Our Croatian personal identification number, OIB, is 55912170784. For privacy questions, contact [email protected].

Your vault is encrypted on your device.

You can use the local vault without Online Services. Encryption and decryption happen on your device. Device synchronization is end-to-end encrypted, and managed backups are encrypted before upload. Online Services does not receive your plaintext vault contents, master password, vault recovery code, or the keys needed to decrypt your vault.

Loading the hosted application still sends network requests to our servers. For details about local storage, transmitted metadata, and diagnostic logs, read Privacy and metadata.

What we receive and why

ActivityData receivedPurpose
Website requests and securityIP addresses, request details, timestamps, outcomes, and security diagnostics.Deliver the website, investigate failures, and prevent abuse.
Managed device connectionsDevice and connection identifiers, network addresses, connection timing, and traffic volume. Relays carry encrypted traffic.Connect your devices and relay their encrypted synchronization when needed.
Managed backupsEncrypted backup files, their sizes, identifiers, source devices, and upload or deletion timestamps and status.Store and retrieve your backups, enforce storage limits, and apply retention and deletion rules.
SubscriptionsPayment-provider identifiers, subscription dates, payment status, and cancellation status.Activate and manage access to paid Online Services.

Legal bases

We process data necessary to provide the Online Services you request to perform our contract with you, under GDPR Article 6(1)(b). This includes managed connections, backups, and subscription access. Without the data needed for a feature, we cannot provide that feature; local vault use remains available.

We rely on legitimate interests under Article 6(1)(f) to deliver and protect the hosted website, diagnose failures, and prevent abuse. Our interests are keeping the service available and protecting users and infrastructure. This processing must be necessary and proportionate, taking your rights into account.

Hosting, security, and payments

Our production infrastructure, connection servers, and managed encrypted backup storage are hosted in Europe. We use hosting and storage providers to operate these services. If you self-host or configure your own connection servers, the providers and settings you choose apply to those servers.

We use Cloudflare to proxy website traffic and run Turnstile bot checks. These services receive network, browser, and request information. We use Cloudflare's HTTP Traffic analytics to monitor requests and bandwidth handled by its servers. Cloudflare Web Analytics and RUM are not enabled; we do not load their browser analytics script. See Cloudflare's privacy policy.

Stripe Managed Payments uses Link as the merchant of record. Stripe and Link collect the contact, billing, and payment details you enter at checkout. We receive the identifiers and status information needed to manage your subscription, not your full card number or security code. See Stripe's privacy policy.

Cloudflare and Stripe may process data outside the European Economic Area, including in the United States. Their transfer arrangements use the EU-US Data Privacy Framework where applicable and EU Standard Contractual Clauses for transfers that require those safeguards. The terms are available in Cloudflare's Data Processing Addendum and Stripe's Data Processing Agreement, including its Data Transfers Addendum.

We may also disclose information to competent authorities when applicable law requires it.

How long we keep data

Deleting your Online Services account removes its account, device, subscription, and payment-event records from our active database. Copies can remain in database backups until those backups expire, within seven days. These database backups are separate from your encrypted vault backups.

We retain operational and security logs for 30 days. This period applies to our logs, not logs held independently by third parties or on self-hosted servers.

Managed backups are pruned over time, with the latest backup from each current root device protected from routine pruning. The full schedule and the 90-day access period after backup entitlement ends are described in the backup retention rules.

Deleting your Online Services account queues its managed backups for deletion without the 90-day grace period. It does not erase local vaults or downloaded files. See deletion and your controls.

Account controls and privacy questions

Applicable GDPR rights include access, correction, deletion, restriction, objection, and portability, subject to their legal conditions.

Online Services accounts are not linked to email addresses. We cannot identify your account or verify ownership from an email request. An email address does not authorize access to account data or account deletion.

Use the authenticated controls in the application to manage your Online Services account and delete it from an authorized root device. There is currently no feature to download a package of Online Services account information. Encrypted vault backups are separate from account information.

For general privacy questions, contact [email protected]. This mailbox is not an account-verification or account-recovery channel. Do not send your master password, recovery secrets, or plaintext vault contents.

Your GDPR rights include lodging a complaint with a competent supervisory authority, such as Croatia's Personal Data Protection Agency, AZOP.