Effective Date: March 25, 2026
Auth Box uses end-to-end encryption (AES-256-GCM) with keys derived from your seed phrase. All encryption and decryption happens exclusively on your device. Our servers — if you choose to use them — store only encrypted blobs that are mathematically impossible for us to decrypt.
If you choose to enable server sync, we store:
If you use Auth Box in offline mode (no sync), we collect nothing.
Auth Box uses Apple's LocalAuthentication framework for biometric unlock. Biometric data is processed entirely by the iOS Secure Enclave — it never leaves your device and is never accessible to Auth Box or any third party.
We do not use analytics SDKs, advertising networks, or third-party trackers.
Local data is stored on your device and deleted when you delete the app or reset your vault. Server-synced data is retained until you delete your account. Arweave backups are permanent by design (blockchain immutability) but are encrypted and useless without your seed phrase.
Auth Box is not directed at children under 13. We do not knowingly collect personal information from children.
We will notify users of material changes via the app. The latest version is always available at this URL.
For privacy questions: maurice_wen@proton.me