Privacy Policy

Vault Zero

Effective date: June 13, 2026
Last updated: June 13, 2026

This Privacy Policy explains how Gordonbyte LLC (“we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Vault Zero mobile application (the “App”). Vault Zero is a personal, zero-based budgeting app that helps you plan your income and expenses and, optionally, connect your financial accounts to track balances and transactions.

If you have questions, contact us at email us.

1. Summary

  • We collect the information you give us (your account email and the budget data you enter) and, if you choose to link a bank, financial account information obtained through Plaid.
  • We use this information to provide and improve the App, including limited usage analytics and crash diagnostics; we do not sell it.
  • We do not sell your personal information, and we do not use it for advertising.
  • Your data is encrypted in transit and at rest, isolated to your account, and you can permanently delete your account and all associated data from within the App at any time.

2. Information We Collect

a) Account information. When you create an account, we collect your email address and authentication credentials managed by Google Firebase Authentication. If you sign in with Google, we receive your basic Google profile identifier and email. We do not store your password in readable form; authentication is handled by Firebase.

b) Budget and financial planning data you enter. The budgets, categories, planned amounts, savings goals, transactions you record, and app settings you create within Vault Zero.

c) Financial account data via Plaid (optional). If you choose to connect a bank or financial institution, we use Plaid Inc. to securely access information from that institution on your behalf. Through Plaid we may receive: your account names and types, account balances, account mask (last digits), transaction history (amounts, dates, descriptions, merchant names, categories), and institution name. We never receive or store your bank login credentials — those are handled by Plaid. Plaid provides us with an access token, which we store only on our secure servers, never on your device.

d) Consent records. When you create an account, we record that you accepted this Privacy Policy and our Terms of Service, including the policy version and a timestamp, as a record of your consent.

e) Device, usage, and diagnostic information. Limited technical data necessary to operate the App, such as app version, device model and operating system, language and region, in-app events and feature usage, and crash and performance diagnostics, collected through our analytics and crash-reporting providers. We use Google Firebase Analytics and Firebase Crashlytics for this purpose. We do not use this data for third-party advertising, and we do not sell it.

We do not intentionally collect biometric data. Face ID / Touch ID / device passcode and any in-app PIN are processed by your device’s operating system; we never receive your biometric information or PIN.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and operate the budgeting features of the App;
  • Authenticate you and keep your account secure;
  • Connect to and refresh data from financial institutions you choose to link (via Plaid);
  • Send you the notifications and reminders you enable in the App;
  • Respond to your support requests;
  • Maintain the security and integrity of our service and comply with legal obligations.

We process your data to perform the service you requested (contractual necessity) and based on your consent for optional features such as bank linking.

4. How We Share Your Information

We share information only as described below. We do not sell your personal information.

  • Plaid Inc. — our service provider for connecting to financial institutions. Plaid’s handling of your information is governed by the Plaid End User Privacy Policy. When you link an account, you also interact directly with Plaid’s consent flow.
  • Google (Firebase / Google Cloud Platform) — our cloud infrastructure provider, which hosts authentication, the database, serverless functions, and secret storage, and provides analytics and crash reporting (Firebase Analytics and Crashlytics), acting as a data processor on our behalf.
  • Legal and safety — we may disclose information if required by law, subpoena, or to protect the rights, property, or safety of our users or others.
  • Business transfers — if Gordonbyte LLC is involved in a merger, acquisition, or asset sale, your information may be transferred, subject to this policy.

We do not share your information with advertisers or data brokers.

5. Data Storage and Security

We take the protection of your financial information seriously:

  • Encryption in transit: all communication between the App, our servers, and our service providers uses HTTPS/TLS 1.2 or higher.
  • Encryption at rest: all stored data is encrypted at rest using AES-256 via Google Cloud / Firestore.
  • Account isolation: each user’s data is logically isolated and access-controlled so that one user can never access another user’s data.
  • Secret protection: sensitive credentials such as Plaid access tokens are stored only on our servers, are never exposed to the client app, and are kept in a dedicated secret store.
  • Authentication and access: administrative access to our infrastructure is protected by multi-factor (2-Step) verification, and the App requires re-verification (biometrics or passcode) before sensitive actions such as linking a bank account.

No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards. For more detail, see our internal Information Security Policy (available on request).

6. Data Retention

We retain your information for as long as your account is active. When you delete your account (see Section 8), we:

  • Revoke and remove all linked financial institution connections via Plaid;
  • Permanently delete your budget data, financial data, settings, and account records from our database;
  • Delete your authentication account.

Any residual copies in routine system backups are deleted or overwritten within 30 days. We may retain limited records where required by law (for example, to comply with financial, tax, or legal obligations), retained only as long as necessary for that purpose.

This Privacy Policy and our data deletion and retention practices are reviewed periodically and updated to remain consistent with applicable privacy laws.

7. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, and to withdraw consent. These include rights under the California Consumer Privacy Act (CCPA/CPRA) and the EU/UK General Data Protection Regulation (GDPR) where applicable.

You can exercise most of these rights directly in the App:

  • Access / correct: view and edit your data within the App at any time.
  • Delete: permanently delete your account and all associated data (Section 8).
  • Disconnect a bank: remove any linked institution at any time in the App.
  • Withdraw consent: stop using bank-linking features and disconnect your institutions.

To make any other request, or to ask a question about your data, email email us. We will respond within the time required by applicable law. We will not discriminate against you for exercising your privacy rights.

We do not sell or “share” personal information for cross-context behavioral advertising as those terms are defined under California law.

8. Deleting Your Account

You can permanently delete your account at any time:

  1. Open Vault Zero and go to the Account tab.
  2. Scroll to the App section and tap Delete Account.
  3. Confirm and verify your identity.

This permanently and irreversibly deletes your budgets, savings, linked-account data and transactions, settings, and your sign-in, and revokes any Plaid connections. This cannot be undone.

9. Children’s Privacy

Vault Zero is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact email us and we will delete it.

10. International Users

We operate in the United States and store data on infrastructure located in the United States. If you access the App from outside the United States, you understand your information will be processed in the United States, where data-protection laws may differ from those in your country.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the App or by email. Your continued use of the App after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

Gordonbyte LLC
Email: email us
Governing law: State of Florida, United States