The data you enter into aWallet or aWallet Cloud is stored in an encrypted form in your own device. The encryption key is derived from your Master Password.
aWallet Cloud can optionally sync the encrypted data backup (the data.crypt file) into your own selected cloud account (Google Drive, Dropbox or WebDAV). The data.crypt file is transferred by aWallet Cloud to/from your selected cloud using an encrypted network connection.
When Google Drive sync is used, the app needs to remember the Google account's email and stores it only in the local device storage in the private app file storage space. The stored Google account email is only accessible by aWallet Cloud app and is NOT accessible by other apps installed on the device. The user name is only displayed in the app's Settings Cloud section and is not stored permanently.
In the case of Dropbox, aWallet Cloud finds out the cloud user name and email. The user name and email are only displayed in the app's Settings Cloud section and are not stored permanently.
If you decide to export data to the CSV format, your data will be stored in an unencrypted form in the local storage of your device.
Your data and master password are NOT known to the author of the app and are NOT shared with any third party.
aWallet and aWallet Cloud do NOT collect any data about you. Both apps also do NOT collect any anonymous or statistical data.
Everything you enter into aWallet Next is stored in encrypted form on your own device. The encryption keys are derived from your master password, which is never sent anywhere. The author of the app cannot read your data and has no access to it.
If you enable cloud sync, the encrypted vault file (data.crypt2) and encrypted attachment files are stored in your own iCloud Drive, Google Drive, Dropbox or WebDAV storage, transferred over encrypted connections. The cloud provider sees only encrypted files. For Google Drive and Dropbox the app stores the sign-in token on the device only; the account name is shown in Settings and not stored elsewhere.
The optional breach check sends the first five characters of a password's SHA-1 hash to the Have I Been Pwned service, never the password or the full hash. Results are cached only on the device.
Subscriptions are processed by the Apple App Store or Google Play. To validate purchases the app uses the RevenueCat service, which receives a random app-generated identifier (or, if you sign in as described below, that sign-in's account identifier) and the store's purchase receipt; it never receives your name, e-mail address or any vault data. RevenueCat acts as our data processor for this purpose only.
Optionally, you can sign in with your Apple or Google account to use one subscription on your other devices. Firebase Authentication (Google) then keeps the sign-in record (account identifier and, as provided by Apple or Google, e-mail address and name), which we use solely to link the subscription; no vault data is ever sent, and the feature is optional.
When you tap "Change password" on an entry, the app contacts that entry's website directly to find its password-change page. Nothing from your vault is sent.
If you export data to CSV, the exported files are unencrypted; handle them with care.
aWallet Next collects no analytics, no telemetry and no statistical data about you, and shows no advertising.
Contact for privacy questions: see Contact.
aWallet Next uses Google services only when you choose to: Google Drive as your cloud for sync, or signing in with your Google account to use one subscription on your other devices.
What we access. With Google Drive sync, the app asks only for the "files created by this app" permission (drive.file): it can see and change only the encrypted vault and attachment files it created itself in your Drive — none of your other files. With Google sign-in, Google shares your account's basic profile: account identifier, e-mail address and name.
How we use it. Drive access is used only to store, update and download your own encrypted vault and attachments, so your devices stay in sync. Your Google sign-in is used only to link your subscription across your devices; the e-mail address (or name) is shown to you in Settings so you can see which account is signed in.
Where it is stored. Your vault and attachments are stored in your own Google Drive, encrypted on your device before upload; Google and the author of the app cannot read them. The Drive sign-in token stays on your device. For the subscription link, Firebase Authentication (Google) keeps the sign-in record — account identifier, e-mail address and name.
Sharing. We do not sell, share, or transfer Google user data to anyone. It is not used for advertising, analytics, or to train any models, and no person reads it.
Deleting your data. Remove aWallet Next's access to your Google account at any time at myaccount.google.com/permissions, and delete the aWallet Next files from your Google Drive if you no longer need them. "Sign out" in Settings ends the subscription link on that device. To have your sign-in record deleted from Firebase, contact us (see Contact).
aWallet Next's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access. With Dropbox sync, the app has access only to its own app folder in your Dropbox (Apps ▸ aWallet Next) — the encrypted vault and attachment files it creates there, none of your other files. It also reads your Dropbox account name and e-mail address, only to show you in Settings which account is connected.
How we use it. Only to store, update and download your own encrypted vault and attachments, so your devices stay in sync.
Where it is stored. In your own Dropbox, encrypted on your device before upload; Dropbox and the author of the app cannot read your files. The Dropbox sign-in token stays on your device.
Sharing. We do not sell, share, or transfer your Dropbox data to anyone.
Deleting your data. Disconnect aWallet Next at any time in your Dropbox settings under Connected apps, and delete the Apps ▸ aWallet Next folder if you no longer need it.
With WebDAV sync, the encrypted vault and attachment files are stored on the server you enter (for example your own NAS or a storage provider you choose), and the app connects only to that server.
The server address and user name are stored on your device; the password is kept in the device's secure storage (Keychain on iOS, Keystore on Android). They are never sent to anyone else, including the author of the app.
With iCloud sync, the encrypted vault and attachment files are stored in aWallet Next's folder in your own iCloud Drive. Your Apple Account sign-in is handled by iOS; the app never sees your Apple credentials, and Apple cannot read the encrypted files.
This software is provided "AS IS" without warranty of any kind. In no event will the author be liable for any damages caused by using this product.
You may not rent, lease, lend, sell, redistribute or sublicense this software. You may not modify, or create derivative works of this software.