Stays on your devices.
Your vault is stored on your Mac, iPhone, or iPad in encrypted form. There is no account to create and no Pixegen server holding a copy.
Ultravault holds your most sensitive information, so the rules are short: it stays on your Mac, iPhone, and iPad, it goes to iCloud only if you say so, and we never see it either way. Here’s exactly what that means.
Last updated: September 2026
Your vault is stored on your Mac, iPhone, or iPad in encrypted form. There is no account to create and no Pixegen server holding a copy.
Sync is off until you turn it on. When it’s on, your vault is stored in your own private iCloud account, under Apple’s terms, and we still can’t see it.
No ad networks, no analytics SDKs, no behavioral profiles. The app has nothing to report and no one to report it to.
Nothing about you, and nothing about what you keep in your vault. Ultravault works without an account, so we never ask for your name, email, or identity to use the app. The passwords, logins, notes, receipts, and other items you store are written to your vault on your device and are not sent to Pixegen.
Your vault is stored on your Mac, iPhone, or iPad in encrypted form. It is unlocked by you, on that device, and it locks again when you close it. Pixegen does not hold a copy of your vault or of whatever you use to unlock it, which also means we cannot recover, reset, or open your vault for you if you lose access to it. Please keep your unlock credential somewhere safe.
Ultravault reads and writes only its own vault. It does not scan your files or your other apps, and it does not inspect, log, or transmit what you put in it. In your browser, it acts only through the optional extension described below, which sends the host of the page you are signing in to so the app can find a matching entry, and nothing more.
Ultravault can save your vault data to iCloud so that it stays consistent across the Macs, iPhones, and iPads you sign into with the same Apple Account. This is a choice you make, not a default. Here is the full arrangement.
iCloud sync is off when you first open Ultravault. Until you enable it, no vault data leaves your device for any reason.
You can turn iCloud sync off in Ultravault at any time. Turning it off stops that device from sending or receiving changes, and the vault on that device goes back to being strictly on-device. It does not by itself erase the copy Apple already holds. To remove that copy, delete Ultravault’s data from iCloud through Apple’s storage settings: on a Mac, System Settings, then your name, then iCloud, then Manage Storage; on an iPhone or iPad, Settings, then your name, then iCloud, then Manage Account Storage. Apple’s own retention and backup practices apply to how quickly deleted data disappears from its systems.
In one sentence: with sync on, your vault is stored by Apple, in your account, under Apple’s rules, and Pixegen still never sees it.
Ultravault offers optional browser extensions for Chrome, Brave, Firefox, and Orion on the Mac. The extension fills logins from your vault into the page you are signing in to. It is a separate install, it does nothing until you add it, and it works only alongside the Ultravault Mac app, which is where your vault stays. This section is the disclosure behind the data categories the extension declares in the Chrome Web Store and Firefox Add-ons listings: browsing activity, authentication information, personally identifying information, and website content.
example.com, to the Ultravault app on the same Mac so the app can look for matching entries. The host is used for that lookup and nothing else. The extension does not record which sites you visit, does not build a history, and does not send the host anywhere except to the app on your Mac.All communication is local, between the extension and the Ultravault app on the same Mac. No extension traffic goes to Pixegen or to any remote server, because there isn’t one. The extension has no analytics, no tracking, and no account.
Disable or remove the extension in your browser at any time. The app and your vault are unaffected. Removing the extension removes anything it held.
Ultravault does not phone home. There is no Pixegen server that receives your vault, your preferences, or any signal that you are using the app. The only network traffic the app produces is iCloud sync, if you turn it on, which goes to Apple. The browser extension talks to the app on your Mac, not to the network. Downloading or updating Ultravault from the App Store or Mac App Store is traffic between you and Apple, under Apple’s policies, not ours.
Ultravault does not include third-party analytics or crash-reporting SDKs. If macOS, iOS, or iPadOS offers to share a crash report with the developer, that goes through Apple’s own opt-in system and contains no vault contents. If something breaks, the useful report is the one you choose to send us through the contact form, and we will never ask you to include anything from your vault.
You can add, edit, or delete items in your vault at any time, turn iCloud sync on or off, disable or remove the browser extension, and delete the whole vault if you want a fresh start. Removing Ultravault from a device removes the local vault and preferences it stored on that device. If you had sync on, the copy in iCloud stays until you delete it there, as described above. There is no server-side account for us to delete, because we never created one.
Ultravault is not directed at children under 13 and does not knowingly collect personal information from them.
If we update this policy, we’ll revise the date above. Significant changes will be noted in the app’s release notes.
We’re happy to explain anything in plain language.