Ultravault
Privacy policy

Privacy, locked in.

Ultravault holds your most sensitive information, so the rules are short: it stays on your Mac, iPhone, and iPad, it goes to iCloud only if you say so, and we never see it either way. Here’s exactly what that means.

Last updated: September 2026

Stays on your devices.

Your vault is stored on your Mac, iPhone, or iPad in encrypted form. There is no account to create and no Pixegen server holding a copy.

iCloud is your call.

Sync is off until you turn it on. When it’s on, your vault is stored in your own private iCloud account, under Apple’s terms, and we still can’t see it.

No tracking.

No ad networks, no analytics SDKs, no behavioral profiles. The app has nothing to report and no one to report it to.

What we collect

Nothing about you, and nothing about what you keep in your vault. Ultravault works without an account, so we never ask for your name, email, or identity to use the app. The passwords, logins, notes, receipts, and other items you store are written to your vault on your device and are not sent to Pixegen.

Your vault on your devices

Your vault is stored on your Mac, iPhone, or iPad in encrypted form. It is unlocked by you, on that device, and it locks again when you close it. Pixegen does not hold a copy of your vault or of whatever you use to unlock it, which also means we cannot recover, reset, or open your vault for you if you lose access to it. Please keep your unlock credential somewhere safe.

Ultravault reads and writes only its own vault. It does not scan your files or your other apps, and it does not inspect, log, or transmit what you put in it. In your browser, it acts only through the optional extension described below, which sends the host of the page you are signing in to so the app can find a matching entry, and nothing more.

iCloud sync (optional)

Ultravault can save your vault data to iCloud so that it stays consistent across the Macs, iPhones, and iPads you sign into with the same Apple Account. This is a choice you make, not a default. Here is the full arrangement.

Off until you turn it on

iCloud sync is off when you first open Ultravault. Until you enable it, no vault data leaves your device for any reason.

What happens when it’s on

  • Your vault data is stored in the private iCloud database that belongs to your Apple Account, using Apple’s CloudKit service. It is tied to your Apple Account, not to any account with us.
  • The data travels between your device and Apple’s servers, and between Apple’s servers and your other Macs, iPhones, and iPads. It never travels to, or through, a Pixegen server, because there isn’t one.
  • Pixegen has no access to your Apple Account or to the iCloud data in it. We cannot read, export, or delete your synced vault, and we receive no notice that you have turned sync on.
  • Sync needs an internet connection and a device that is signed into iCloud. If iCloud is unavailable, your local vault keeps working and sync resumes when the connection comes back.

What comes with that arrangement

  • Apple’s terms apply. Data stored in iCloud is held by Apple under the iCloud Terms of Service and Apple’s Privacy Policy, in data centers Apple chooses, which may be outside your country. Apple’s handling of that data, including any legal requests it receives, is governed by Apple’s policies rather than ours.
  • Apple encrypts it. Apple encrypts iCloud data in transit and at rest on its servers. If you turn on Apple’s Advanced Data Protection for your Apple Account, third-party app data stored through CloudKit, including your Ultravault data, is end-to-end encrypted so that only your trusted devices hold the keys. Enabling that is a decision you make with Apple, and we recommend it.
  • Your Apple Account is the perimeter. A copy of your vault in iCloud is as protected as the rest of your iCloud. Anyone who can sign into your Apple Account and pass Apple’s device checks may be able to reach synced app data, so use a strong Apple Account password and two-factor authentication.
  • It uses your storage. Synced vault data counts against your iCloud storage plan, the same as any other app’s data.
  • It shows up in Apple’s tools. Ultravault will appear in your iCloud storage management screens on your Mac, iPhone, or iPad, where Apple lets you see and delete an app’s data.

Turning it off and deleting the copy

You can turn iCloud sync off in Ultravault at any time. Turning it off stops that device from sending or receiving changes, and the vault on that device goes back to being strictly on-device. It does not by itself erase the copy Apple already holds. To remove that copy, delete Ultravault’s data from iCloud through Apple’s storage settings: on a Mac, System Settings, then your name, then iCloud, then Manage Storage; on an iPhone or iPad, Settings, then your name, then iCloud, then Manage Account Storage. Apple’s own retention and backup practices apply to how quickly deleted data disappears from its systems.

In one sentence: with sync on, your vault is stored by Apple, in your account, under Apple’s rules, and Pixegen still never sees it.

Browser extension (optional, Mac)

Ultravault offers optional browser extensions for Chrome, Brave, Firefox, and Orion on the Mac. The extension fills logins from your vault into the page you are signing in to. It is a separate install, it does nothing until you add it, and it works only alongside the Ultravault Mac app, which is where your vault stays. This section is the disclosure behind the data categories the extension declares in the Chrome Web Store and Firefox Add-ons listings: browsing activity, authentication information, personally identifying information, and website content.

What the extension handles

  • Website address (browsing activity). When a page contains a login form, the extension sends that page’s host name, such as example.com, to the Ultravault app on the same Mac so the app can look for matching entries. The host is used for that lookup and nothing else. The extension does not record which sites you visit, does not build a history, and does not send the host anywhere except to the app on your Mac.
  • Authentication and personally identifying information. When you choose an entry, the app hands that entry’s login details to the extension, which fills them into the form. That means the password and the username, which is often an email address or a name and therefore counts as personally identifying information. Credentials and usernames travel only between the app and the extension on your Mac, exist in the extension only long enough to fill the form, and are never stored by the extension or sent to Pixegen.
  • Website content. To find login fields and fill them, the extension reads the structure of the page you are on. It does not collect page content, does not act on pages that have no login form, and does not transmit page content to anyone.

Where that data goes

All communication is local, between the extension and the Ultravault app on the same Mac. No extension traffic goes to Pixegen or to any remote server, because there isn’t one. The extension has no analytics, no tracking, and no account.

Turning it off

Disable or remove the extension in your browser at any time. The app and your vault are unaffected. Removing the extension removes anything it held.

Network requests

Ultravault does not phone home. There is no Pixegen server that receives your vault, your preferences, or any signal that you are using the app. The only network traffic the app produces is iCloud sync, if you turn it on, which goes to Apple. The browser extension talks to the app on your Mac, not to the network. Downloading or updating Ultravault from the App Store or Mac App Store is traffic between you and Apple, under Apple’s policies, not ours.

Diagnostics

Ultravault does not include third-party analytics or crash-reporting SDKs. If macOS, iOS, or iPadOS offers to share a crash report with the developer, that goes through Apple’s own opt-in system and contains no vault contents. If something breaks, the useful report is the one you choose to send us through the contact form, and we will never ask you to include anything from your vault.

Your choices

You can add, edit, or delete items in your vault at any time, turn iCloud sync on or off, disable or remove the browser extension, and delete the whole vault if you want a fresh start. Removing Ultravault from a device removes the local vault and preferences it stored on that device. If you had sync on, the copy in iCloud stays until you delete it there, as described above. There is no server-side account for us to delete, because we never created one.

Children

Ultravault is not directed at children under 13 and does not knowingly collect personal information from them.

Changes to this policy

If we update this policy, we’ll revise the date above. Significant changes will be noted in the app’s release notes.

Questions about privacy?

We’re happy to explain anything in plain language.

Contact us