Privacy Policy
Last updated: August 2026 · Operated by Two Bit Digital (SMC-Private) Limited
This policy explains what StarkVault (“StarkVault,” “we,” “us”) collects, why, and what control you have over it. StarkVault is operated by Two Bit Digital (SMC-Private) Limited. If anything here is unclear, email sales@twobitdigital.com.
What StarkVault does
StarkVault lets you store documents, track expiry dates (passports, visas, licenses, domains, and similar), keep a record of your payment cards (last 4 digits and expiry only — we never collect a full card number) and subscriptions, and share individual documents through time-limited, revocable links. It’s available on web, iOS, and Android, all backed by the same account and data.
Information we collect
Account information. Email address, password (stored hashed by our authentication provider, never in plain text), and an optional display name.
Content you add. Documents you upload; the names, categories, and expiry dates you track; card nicknames, last-4 digits, and expiry months/years; subscription names, amounts, and billing dates; and the recipient name/email you enter when creating a share link.
Share link activity. When someone opens a link you’ve shared — including people who don’t have a StarkVault account — we log the IP address, browser/device user agent string, and timestamp of that view. This is what powers the view count and access log you see for your own links, and it’s tied to the link, not to a StarkVault identity.
Device push tokens. If you enable push notifications on iOS or Android, we store a device-specific push token so our alert system can reach that device. No push token is collected on web.
Notification preferences. Which alert thresholds and categories you’ve turned on or off.
Billing information, Plus subscribers only. If you subscribe to Plus, your payment card details are collected and processed entirely by our payment processor, Stripe — we never see or store your full card number. We store only your Stripe customer and subscription IDs and your current plan status, which is separate from the card nicknames/last-4/expiry you may enter yourself under Money Map to track your own subscriptions.
We do not use advertising or analytics tracking SDKs, and we do not collect precise location, contacts, or any card data beyond the last 4 digits and expiry you enter yourself.
How we use it
- To provide the service itself — storing and retrieving your documents and records, rendering your dashboard, and generating watermarked previews for documents you choose to share.
- To send you expiry, card-expiry, and subscription-at-risk alerts by email and push notification, based on the thresholds you’ve enabled in Settings.
- To enforce access control — row-level security scoped to your account, and instant revocation of share links you cancel.
- To detect and prevent abuse of the share-link and upload systems.
- To respond to support requests you send us.
We do not sell your data, and we do not share it with third parties for their own marketing purposes.
Who processes your data on our behalf
We rely on a small number of infrastructure providers (subprocessors) to run StarkVault. Each only receives what it needs to do its job:
- Supabase — our database, authentication, and file storage provider. Nearly everything described above is stored here.
- Resend — delivers the email alerts you’ve opted into.
- Expo — delivers push notification alerts to your registered devices.
- Vercel — hosts the web application and runs the scheduled job that triggers alerts.
- Stripe — processes payment for Plus subscriptions. Your card details go directly to Stripe; we never receive or store them.
Because StarkVault serves users globally, these providers may process and store data in countries other than your own. By using StarkVault you consent to this cross-border processing, which we limit to what’s needed to run the service.
How your data is protected
- All traffic between your device and our servers is encrypted in transit (TLS/HTTPS) — no exceptions.
- Documents are encrypted at rest by our storage provider.
- This is standard server-side encryption, not end-to-end / zero-knowledge encryption — our systems can read a document’s contents when needed to generate a watermark or preview for a share you create. We don’t read your documents for any other purpose.
- Row-level security scopes every database query to your own account — there is no code path where one user’s query can return another user’s rows.
- On mobile, your session is stored using the device’s secure hardware-backed keychain (iOS Keychain / Android Keystore), not plain unencrypted storage — and you can add an optional Face ID / Touch ID / fingerprint lock on top of your password.
How long we keep it
We keep your account and content for as long as your account exists. We don’t currently auto-delete data after a period of inactivity. If you delete your account (Settings → Danger Zone, on web or mobile), your documents, expiry watches, cards, subscriptions, share links, and push tokens are permanently deleted — including the underlying files in storage, not just the visible records — and this cannot be reversed. Share-link view logs tied to links you’ve created are deleted along with them.
Your rights
Wherever you’re located, you can:
- Access and correct your account information directly in Settings.
- Delete your account and all associated data at any time, in-app — see our account deletion page for details, including what to do if you no longer have the app installed.
- Request a copy of your data by emailing sales@twobitdigital.com — we don’t yet have a self-serve export button, but we’ll fulfill a reasonable request manually.
- Object to or restrict certain processing, or ask us questions about this policy, by emailing the same address.
If you’re in the EU, UK, or a similar jurisdiction, these map to your rights of access, rectification, erasure, restriction, and data portability. If you’re in California or a similar US state, these map to your rights to know, delete, and correct. We apply the same practical rights to everyone regardless of location rather than maintaining separate regional policies.
Children
StarkVault is not directed at children under 16, and we don’t knowingly collect information from anyone under that age. If you believe a child has created an account, email us at sales@twobitdigital.com and we’ll remove it.
Changes to this policy
If we make a material change to this policy, we’ll update the date at the top of this page. Continued use of StarkVault after a change means you accept the updated policy.
Contact
Questions, requests, or concerns about your data: sales@twobitdigital.com