Acceptance of Terms
By accessing and using VaultPlus, you accept and agree to be bound by the terms and provisions of this agreement. If you do not agree to these Terms of Service, please do not use VaultPlus.
Description of Service
VaultPlus is a client-side, zero-knowledge password management web application that provides:
- Secure storage of passwords and sensitive credentials in your browser's encrypted IndexedDB
- Client-side end-to-end encryption with AES-256-GCM and PBKDF2 key derivation
- Built-in cryptographic password generation and entropy analysis
- Optional client-side encrypted backup to your personal Google Drive account
- Import and export functionality for complete data portability (JSON / CSV)
User Responsibilities
As a user of VaultPlus, you are responsible for:
- Master Password: Creating and maintaining a strong master password. If you forget your master password, your encrypted data cannot be recovered by anyone.
- Backups: Creating regular encrypted backups of your vault. VaultPlus provides local and cloud backup tools, but it is your responsibility to maintain backups.
- Device Security: Keeping your physical device secure, applying operating system updates, and locking your vault when using shared or public workstations.
- Lawful Use: Using VaultPlus only for lawful purposes and in compliance with all applicable laws, regulations, and third-party rights.
No Warranty
VaultPlus is provided “AS IS” and “AS AVAILABLE” without warranties of any kind, either express or implied, including but not limited to:
- Warranties of merchantability or fitness for a particular purpose
- Warranties that the service will be uninterrupted, timely, or error-free
- Warranties regarding the accuracy or reliability of any information obtained through VaultPlus
Limitation of Liability
To the fullest extent permitted by applicable law, VaultPlus and its developers shall not be liable for:
- Loss of data or passwords resulting from a forgotten master password
- Unauthorized access to your device, browser cache, or compromised operating system
- Any indirect, incidental, special, or consequential damages arising from the use or inability to use VaultPlus
- Bugs or vulnerabilities in browser WebCrypto implementations or third-party dependencies
- Loss of data due to manual browser storage clearing, disk quotas, or operating system upgrades
Data Loss and Recovery
VaultPlus stores all encrypted vault entries locally inside your browser storage. This means:
- Clearing your browser site data or IndexedDB will remove your local vault
- Operating system disk cleaner utilities may affect local browser cache
- Because we have zero access to your master password, lost master passwords cannot be reset
- Vault data is strictly device-specific unless you export backups or sync via Google Drive
Crucial Data Recovery Notice
VaultPlus cannot recover your master password or decrypt your data if you lose your credentials. Please ensure you remember your master password and keep regular offline or Google Drive backups.
Google Drive Integration
If you choose to use the optional Google Drive cloud backup integration:
- You grant VaultPlus scoped permission to store encrypted backup files in your Google Drive (drive.file scope)
- Google's Terms of Service and Privacy Policy apply to files stored inside your Google Drive account
- You can revoke VaultPlus access at any time through your Google Account Security settings
- VaultPlus is not responsible for Google Drive service outages, network interruptions, or Google storage quotas
Intellectual Property
VaultPlus is open-source software. The source code is available under the terms of its repository license. While the software is free to inspect, use, and modify under license terms, the VaultPlus name and branding may be subject to trademark and identifier protections.
Privacy
Your use of VaultPlus is also governed by our Privacy Policy. Please review our Privacy Policy to understand our cryptographic zero-knowledge design.
Modifications to Service
We reserve the right to modify, enhance, or discontinue VaultPlus (or any feature) at any time. Because VaultPlus is client-side open source, you retain full data export portability at all times.
Changes to Terms
We may revise these Terms of Service periodically. We will post the revised terms on this page and update the “Last updated” timestamp above.
Termination
You may cease using VaultPlus at any time. You can wipe your account, delete local vaults, and clear all stored keys from the Settings page.
Governing Law & Severability
If any provision of these Terms is found to be unenforceable, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
Contact Information
If you have questions regarding these Terms of Service, please contact the maintainers through our GitHub repository.
