Mars Interactive/Alcove - Vault for Everything/Privacy Policy
πŸ«₯

Privacy Policy

Alcove - Vault for Everything

Effective Date: September 16, 2026

Your privacy is our priority. Alcove ("the App") is built with privacy at its core by design. This Privacy Policy outlines how we collect, use, and protect your information.

1. Data Collection

We do not collect, store, or transmit any personal data to external servers. All data you create in Alcove β€” your photos, videos, notes, and site bookmarks β€” remains strictly on your device. This means that only you can be held responsible for where you store your device and how you secure it.

We do not:

The app is free of any tracker or form of data collection. We cannot use any of your data for testing or development.

Exception 1 β€” and it never leaves your device either: Alcove uses Apple's MetricKit to receive local crash, hang, and diagnostic reports from iOS. These reports are written only to your device's local storage and are never transmitted anywhere by the app β€” not to us, not to any third party. They exist so a future update from us can be informed by diagnostics you choose to share with us directly, not through automatic collection.

Exception 2 β€” Sites, and only because visiting a website requires it: Alcove's Sites feature lets you add a URL and opens it in an in-app browser. Visiting that site sends a request to that site's server β€” the same thing any browser does, and unavoidable for the feature to work at all β€” and that site (not Alcove) may set its own cookies or otherwise track you exactly as it would in Safari. Alcove adds no tracking of its own on top of this, never sends your Alcove usage or the rest of your vault's contents to any site you visit, and keeps each site's cookies and storage sandboxed from every other site and from the rest of your vault, the same way separate tabs are isolated in a browser. This is the only outbound network access anywhere in the app β€” everything else in this policy still applies unchanged to the vault itself.

2. Data Storage and Access

All information β€” your photos, videos, notes, album organization, and site bookmarks (including each site's own cookies and local storage) β€” is stored locally on your device, encrypted with AES-256-GCM. The encryption key itself is never stored in plain form: it exists only as ciphertext, sealed behind whichever of Face ID, your PIN, or your master password you use to unlock the app. You are in full control of your data; nothing is accessible to us or to anyone else without physical access to your unlocked device.

3. Permissions

With your explicit permission, Alcove may access:

Sites does not require any additional permission prompt β€” opening a page you added works the same as tapping a link in any app, just kept inside Alcove's sandbox instead of handing off to your regular browser.

None of this access is ever used to send data outside your device or for analytics.

4. Security

Alcove has no password-recovery mechanism beyond the single-use recovery codes you can generate yourself (Settings β†’ Recovery Codes): five codes, each usable once, that let you reset a forgotten master password. Recovery codes never leave your device β€” generating them displays each one once for you to write down; Alcove does not export, back up, or transmit them anywhere.

If you forget your master password and your PIN, and have no recovery codes left (or never generated any), the contents of your vault are permanently unrecoverable β€” there is no reset, no backend, and no way for us to help you regain access. This is a deliberate trade-off: the same design that keeps your data unreadable to anyone else also means we cannot read it either, ever, including to help you recover it.

5. Backups and Device Migration

Alcove does not sync or back up your vault automatically, and your vault remains deliberately excluded from iCloud and device backups. You can, however, create a backup yourself: Settings β†’ Export Vault produces a single encrypted archive β€” still AES-256-GCM, still unreadable without your credentials β€” that you can store wherever you choose (this device, an external drive, your own cloud storage). Alcove itself never transmits that archive anywhere; where it ends up after export is entirely up to you. Import reverses this, on the same device or a new one.

If you don't export before uninstalling the app or losing your device, or if you lose the exported archive along with your credentials, that data is unrecoverable β€” exporting is optional and manual, never automatic. You can also delete everything immediately and irreversibly at any time via Settings β†’ Erase Vault, or by uninstalling the app. Because Alcove does not collect or process personal data externally, there is no need to separately request access to or deletion of your data from us β€” we never had it.

6. Changes to this Policy

We may update this policy from time to time. If substantial changes are made, we will notify users through app updates.

7. Contact

Questions? Contact us at: mars_interactive@proton.me


Alcove was built to protect your privacy. This is and will remain one of the most important cornerstones of the app's philosophy.