Privacy Policy - SessionVault

Privacy Policy

Last Updated: August 2026

Welcome to SessionVault. We are committed to protecting your privacy and ensuring the absolute security of your clinical and financial data. Because of our strict zero-knowledge architecture, we handle data differently than traditional cloud applications.

1. Zero-Knowledge Architecture & Local Encryption

SessionVault is a local-first application. All data you enter into the application is encrypted locally on your device using industry-standard AES-256-GCM encryption before it ever leaves your browser.

We cannot see, read, access, or decrypt your data. We do not store your Master Password, nor do we store your encrypted data on our own servers.

2. Google Drive Integration & Limited Use

To provide secure backups and seamless syncing, SessionVault allows you to connect your Google Drive account. We request access only to the specific files created by SessionVault (using the drive.file scope).

Google API Services User Data Policy: SessionVault's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Data Collection and Usage

Because SessionVault operates entirely within your browser, we do not collect personal usage data, clinical notes, or client identifiable information. The only information processed is standard anonymous web traffic data required to host the application shell.

4. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation (UK GDPR), you have the right to access, rectify, or erase your personal data. Because SessionVault is a zero-knowledge tool, you hold total control over your data. You can permanently erase all local and cloud data associated with SessionVault at any time using the "Clear All Data & Factory Reset" function within the application.

5. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at: [Insert Contact Email Here]

Ultimo aggiornamento: Agosto 2026

Benvenuti su SessionVault. Ci impegniamo a proteggere la tua privacy e garantire la sicurezza assoluta dei tuoi dati clinici e finanziari. A causa della nostra rigorosa architettura zero-knowledge, gestiamo i dati in modo diverso rispetto alle tradizionali applicazioni cloud.

1. Architettura Zero-Knowledge e Crittografia Locale

SessionVault è un'applicazione "local-first". Tutti i dati inseriti vengono crittografati localmente sul tuo dispositivo utilizzando lo standard AES-256-GCM prima che lascino il tuo browser.

Non possiamo vedere, leggere, accedere o decifrare i tuoi dati. Non memorizziamo la tua Master Password, né conserviamo i tuoi dati crittografati sui nostri server.

2. Integrazione con Google Drive e Uso Limitato

Per fornire backup sicuri, SessionVault ti consente di connettere il tuo account Google Drive. Richiediamo l'accesso solo ai file specifici creati da SessionVault (utilizzando lo scope drive.file).

L'uso e il trasferimento da parte di SessionVault di informazioni ricevute dalle API di Google aderiranno alla Politica sui dati degli utenti dei servizi API di Google, inclusi i requisiti di Uso Limitato.

3. Raccolta e Utilizzo dei Dati

Poiché SessionVault opera interamente all'interno del tuo browser, non raccogliamo dati di utilizzo personali, note cliniche o informazioni identificabili dei clienti.

4. I Tuoi Diritti (UK GDPR)

Ai sensi dell'UK GDPR, hai il diritto di accedere, rettificare o cancellare i tuoi dati personali. Poiché SessionVault è uno strumento zero-knowledge, hai il controllo totale sui tuoi dati. Puoi cancellare permanentemente tutti i dati utilizzando la funzione "Clear All Data" all'interno dell'applicazione.

5. Contattaci

In caso di domande, contattaci all'indirizzo: [eyt.sasn@gmail.com]

עדכון אחרון: אוגוסט 2026

ברוכים הבאים ל-SessionVault. אנו מחויבים להגן על פרטיותך ולהבטיח את האבטחה המוחלטת של הנתונים הקליניים והפיננסיים שלך. בשל ארכיטקטורת ה-zero-knowledge המחמירה שלנו, אנו מטפלים בנתונים באופן שונה מאפליקציות ענן מסורתיות.

1. ארכיטקטורת Zero-Knowledge והצפנה מקומית

SessionVault היא אפליקציה המבוססת על המכשיר המקומי. כל הנתונים שאתה מזין מוצפנים מקומית במכשיר שלך באמצעות תקן AES-256-GCM לפני שהם עוזבים את הדפדפן שלך.

איננו יכולים לראות, לקרוא, לגשת או לפענח את הנתונים שלך. איננו שומרים את סיסמת האב (Master Password) שלך, ואיננו שומרים את הנתונים המוצפנים שלך בשרתים שלנו.

2. שילוב עם Google Drive ושימוש מוגבל

כדי לספק גיבויים מאובטחים, SessionVault מאפשר לך לחבר את חשבון ה-Google Drive שלך. אנו מבקשים גישה רק לקבצים הספציפיים שנוצרו על ידי SessionVault (באמצעות הרשאת drive.file).

השימוש של SessionVault במידע שהתקבל מ-Google APIs יעמוד ב-מדיניות נתוני המשתמשים של שירותי API של Google, כולל דרישות השימוש המוגבל (Limited Use).

3. איסוף ושימוש בנתונים

מכיוון ש-SessionVault פועלת במלואה בתוך הדפדפן שלך, איננו אוספים נתוני שימוש אישיים, רשימות קליניות או מידע מזהה על לקוחות.

4. הזכויות שלך (UK GDPR)

תחת תקנות הגנת המידע של בריטניה (UK GDPR), יש לך את הזכות לגשת, לתקן או למחוק את הנתונים האישיים שלך. מכיוון ש-SessionVault הוא כלי zero-knowledge, יש לך שליטה מלאה על הנתונים שלך. תוכל למחוק לצמיתות את כל הנתונים באמצעות הפונקציה "Clear All Data" באפליקציה.

5. צור קשר

אם יש לך שאלות, אנא פנה אלינו בכתובת: [eyt.sasn@gmail.com]