Crestora Vault · Privacy

Crestora Vault Privacy Policy

Last updated: August 20, 2026 · Crestora Labs, a division of Crestora Property Group LLC
In short:
  • Crestora Vault is zero-knowledge and end-to-end encrypted. Your vault is encrypted on your own device before anything is stored or synced.
  • We store only encrypted data. We cannot read, decrypt, recover, or hand over the contents of your vault — there is no backdoor.
  • We don't sell your personal information. Payments go through Stripe — we never see your full card number.
  • You can access, correct, export, or delete your account data any time — email [email protected].
1

Zero-Knowledge & End-to-End Encryption

Crestora Vault is built on a zero-knowledge model. The information you store in the Vault (your "Vault Content") is encrypted on your device with keys that are derived from your credentials and that never leave your device in a form we can use.

  • Encrypted before it leaves you. Vault Content is encrypted locally, end-to-end. What reaches our servers — and what we sync between your devices — is ciphertext only.
  • We cannot read it. Because we never hold your encryption keys, we cannot decrypt, view, mine, or disclose your Vault Content, and we cannot produce it in response to a request from anyone.
  • Keys stay with you. Your encryption keys are generated and held on your device (and, for passkey/biometric unlock, protected by your platform authenticator). We store only the encrypted material needed to sync your Vault.
  • No backdoor / no recovery of contents. If you lose your master passphrase and your recovery key, your Vault Content cannot be recovered by anyone, including us. Please keep your recovery key safe.

This section governs your Vault Content. The account, subscription, licensing, and support information described below is metadata we process to run your account — it is separate from, and does not give us access to, your encrypted Vault Content.

2

Scope

This Policy explains how Crestora Labs, a division of Crestora Property Group LLC ("we," "us," or "our"), handles personal information in connection with Crestora Vault and related website, subscription, and account services (the "Services"). We are a United States-based company, and this Policy is written to align with the GDPR, UK GDPR, and CCPA/CPRA. It supplements our general Privacy Policy and does not cover third-party sites or services we don't control, even where linked from ours.

3

Information We Collect

Depending on how you use the Services, we collect:

  • Vault Content — the items you store in the Vault. We receive and store this only as end-to-end-encrypted ciphertext (see Section 1); we cannot read it.
  • Account & contact — your email and any name or organization you provide; for Corporate, your work-account or single sign-on identity.
  • Subscription & payment — plan, seats, billing status, and transaction history. Payments are processed by Stripe; we do not store full card numbers and typically receive only the card's last four digits, brand, and a transaction identifier.
  • Authentication & sync — the encrypted key material and non-content metadata needed to authenticate you and synchronize your Vault across your devices (for example, item counts, timestamps, and device identifiers), plus basic application, version, and operating-system details.
  • Support — the content of messages you send us.
  • Website & cookies — standard technical data (IP address, browser, device, referring pages) and cookies, as described in our Cookie Policy. Our desktop and browser applications do not use browser cookies to track you.
4

How We Use It

  • Provide, activate, secure, synchronize, maintain, and improve the Services, including updates.
  • Process subscriptions, payments, renewals, and seat/licence entitlements.
  • Authenticate users, enforce seat-based licensing, and prevent fraud or abuse.
  • Provide support and send service-related messages (activation, receipts, renewals, security notices).
  • Meet legal obligations and enforce our Terms.

We cannot and do not use your encrypted Vault Content for any of these purposes, because we cannot decrypt it.

5

Legal Bases (GDPR)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the Services you subscribe to), legitimate interests (to secure and improve the Services and prevent abuse, balanced against your rights), consent (for certain cookies, analytics, and optional communications — you may withdraw it at any time), and legal obligation.

6

How We Share It

We do not sell your personal information. We share it only with service providers who help us operate the Services:

  • Stripe — payments and billing.
  • Microsoft 365 — business email and communications.
  • OVHcloud — hosting and encrypted sync storage (data centers in Canada and the United States).
  • Cloudflare — CDN, DNS, and web application firewall (WAF) security.

Any Vault Content held by these providers is encrypted ciphertext only. We may also disclose information to professional advisors, in connection with a merger or asset sale, or where required by law or to protect rights and safety — but we cannot disclose the contents of your Vault, because we cannot decrypt it. Business customers may be covered by our Data Processing Agreement.

7

Cookies

We and certain third parties use cookies on the Website; our desktop and browser-extension applications do not use browser cookies to track you. See our Cookie Policy for details and controls.

8

Data Retention

We keep personal information only as long as needed for the purposes above and to meet our legal, tax, and accounting obligations. Retention periods are typically:

  • Encrypted Vault Content — for as long as your account is active; deleted (or scheduled for deletion) when you delete items or close your account.
  • Account and subscription data — the customer relationship plus up to 3 years.
  • Payment and transaction records — up to 7 years (U.S. tax and accounting).
  • Authentication, device, and activation data — the subscription plus up to 2 years.
  • Support communications — up to 2 years, longer where needed for legal or security reasons.

When it is no longer needed, we delete or anonymize it. Because Vault Content is encrypted with keys we do not hold, deleting your account renders any residual ciphertext permanently unreadable.

9

Security

We use technical and organizational measures to protect personal information, including end-to-end encryption of Vault Content, encryption in transit and at rest, access controls, and modern authentication (including passkeys/WebAuthn and, for Corporate, single sign-on). No system is completely secure, so we cannot guarantee absolute security. Please keep your master passphrase, recovery key, and account credentials confidential.

If a personal-data breach affects your information, we will notify you and the appropriate authorities where, and within the time, the law requires. Note that a breach of our storage does not expose your Vault Content, which remains encrypted with keys we never hold.

10

International Transfers

As a U.S.-based company using service providers in the United States, Canada, the EU, and elsewhere, personal information may be transferred across borders. Where it is, we rely on recognized safeguards such as the European Commission's Standard Contractual Clauses. See our Data Processing Agreement for details.

11

Your Rights

Subject to applicable law, you may access, correct, delete, restrict or object to processing, and export your personal information, withdraw consent, and lodge a complaint with a supervisory authority. California residents (CCPA/CPRA) have equivalent rights, and we do not sell or share personal information as those terms are defined there.

Because your Vault Content is end-to-end encrypted, you already hold and control it directly — export and deletion of Vault Content happen in the app, under your keys. For account, subscription, and support data, contact us below; we will verify your request and respond within the time the law requires, and you may use an authorized agent where permitted. If we decline a request, you may appeal using the details in Section 14.

12

Children

The Services are not directed to children, and we do not knowingly collect information from anyone under 16 (or under 13 in the United States). If you believe a child has given us information, contact us and we will delete it.

13

Changes

We may update this Policy from time to time. For material changes we will update the "Last updated" date above and, where appropriate, provide notice. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

14

Contact Us

For questions or to exercise your rights, contact [email protected], or write to:

Crestora Labs
6300 N Wickham Rd
# 130 - 422
Melbourne, FL 32940
United States

EU Representative & Data Protection Officer

As a U.S. company that does not target individuals in the European Union, we are not required to appoint an Article 27 EU representative, and we have not appointed a Data Protection Officer. For privacy questions, email [email protected].

Still have questions?

We're happy to help — reach out any time.

Email [email protected]