Privacy Policy
Last updated: September 4, 2026
Your core saved inventory stays on your device.
AssetVault does not synchronize your complete saved vault to an AssetVault cloud account. Optional catalog, AI, photo, pricing, and barcode tools process selected inputs when you use them. Crash diagnostics and purchase verification can contact services automatically. Details matter, so they are set out below.
1. Your core inventory is stored locally
AssetVault stores saved inventory records in a local SQLite database and stores photos and documents in app storage on your device. The SQLite database is not separately encrypted by AssetVault. It relies on your operating system's app sandbox and device-data protections. The optional Encrypted Backup feature protects a backup file you create; it does not encrypt the live database.
AssetVault does not synchronize your complete saved inventory to an AssetVault cloud account. Optional features send selected inputs off-device when needed, and crash reporting and purchase verification can contact services automatically.
No AssetVault account, name, or email address is required to save an inventory.
2. Information we process
Crash and session diagnostics. AssetVault uses a self-hosted Sentry-compatible service. Crash events and session-health diagnostics may be sent automatically and can include app version, device and operating-system details, stack traces, timestamps, and technical metadata. Performance tracing is disabled. The app is configured to remove inventory-related request bodies, breadcrumbs, and extra fields from crash events before transmission, but diagnostic scrubbing should not be treated as an absolute guarantee.
Purchase information. Apple or Google processes purchases. RevenueCat receives a pseudonymous App User ID, store receipts, entitlement status, transaction information, and related technical information so the app can verify Pro and Collector+ access. CRL Digital does not receive your payment-card details.
Support communications. If you email support or share your Support ID, we receive the address, message, attachments, and identifier you choose to provide so we can respond.
3. Optional data processing
Your complete saved vault is not copied to an AssetVault inventory cloud. Optional tools process smaller inputs as follows:
- Catalog lookup. The typed search is sent to the self-hosted catalog. Operational query logs store hashed, nonreversible references rather than raw item text.
- Catalog contribution. After a catalog miss, eligible public-catalog categories may offer a separate "Submit" action. If you choose it, reference fields — which can include name, category, year, set or card number, estimated value, and notes — are retained in a private review queue. AssetVault 1.2.2 submissions remain private, are not automatically deleted, and do not appear in shared catalog lookup; there is no enabled publication route in this release. Rejected review metadata and any historical promoted-review metadata are deleted after 90 days, and the submission quota ledger is deleted after 31 days. The request also sends the original search for handling, but the queue and operational logs retain only a hashed, nonreversible search reference. Do not submit private notes. Photos, documents, and the serial-number field are not included.
- Correction feedback. If you tap "Wrong?" after an AI result, the original search, returned result fields, method, and any feedback note may be retained so we can investigate the mismatch. Avoid including personal information in a search or feedback note.
- AI tools. Photos and text you choose for AI Photo ID, Bulk Photo Import, AI Pre-Grade, Flag Check, or AI-assisted text lookup leave the device. Public 1.2.1 builds send selected AI inputs through AssetVault's self-hosted AI proxy to Google Gemini. AssetVault 1.2.2, when released, instead routes them through the self-hosted AssetVault Catalog Server to the Google Gemini Developer API. Neither AssetVault service is designed to retain submitted photo bytes, but Google's terms and retention practices apply after forwarding. Text or numbers visible inside a submitted photo travel with that photo. Reference fields produced by AI-assisted text lookup may be retained in a private review queue; AssetVault 1.2.2 does not add them to shared catalog lookup. Do not put private information in a lookup. The catalog may also receive the pseudonymous RevenueCat App User ID for entitlement verification and metering on paid paths.
- Pricing. An item description, grade when applicable, and pseudonymous RevenueCat app user ID are sent through the catalog service for entitlement verification and active-listing pricing.
- Paid-service identity and metering. For requests using the 1.2.2 catalog-side paid-service controls, AssetVault hashes the current RevenueCat App User ID into an app reference and RevenueCat's canonical original App User ID into a stable billing reference. After that service is deployed, the catalog stores those references with the entitlement identifier and status, environment, subscription period type, expiration and last-check times, webhook event type, source and receipt times, affected-user count and sequencing, and per-feature usage date, count, and update time. These records are used only to verify paid access, enforce trial and daily limits, prevent abuse, and control service cost. Raw RevenueCat App User IDs and webhook bodies are not stored by the catalog. The stable billing reference makes aliases, reinstalls, and restores share the same usage caps.
- Barcode lookup. Public 1.2.1 builds may send ISBNs to Google Books and UPC/EAN values to UPCitemdb or Open Food Facts. AssetVault 1.2.2 removes Google Books and sends only checksum-valid product barcodes to UPCitemdb or Open Food Facts; QR/serial payloads and invalid checksums stay local in 1.2.2.
4. Permissions
Camera and photos. To take or select item photos and scan barcodes or text. Saved copies remain in app storage unless you choose an online photo-processing feature or share/export them.
Device authentication. To lock and unlock your vault with authentication configured in your operating system. AssetVault does not receive or store your raw biometric data and does not create a separate app PIN.
File access. To import and create backup, archive, and PDF files. Generated files are handed to the operating-system share sheet; the destination you choose then controls them.
5. Services we use
Most inventory-processing network calls are user-triggered. Crash reporting and purchase verification can contact services automatically. These services do not receive a copy of the complete inventory database.
- Self-hosted Sentry-compatible service. Crash events and session-health diagnostics, with app-side scrubbing and disabled performance tracing as described above.
- RevenueCat. Purchase and entitlement verification using a pseudonymous App User ID, store receipt, entitlement and transaction information, and related technical information.
- Apple / Google. Payment processing under the platform's terms.
- AssetVault Catalog Server (catalog.chrisrulz.com, self-hosted). Public-reference lookup across more than 185,000 indexed records, optional catalog contributions and correction feedback, and pricing requests. AssetVault 1.2.2 also uses it for paid-service entitlement checks and metering after that service path is deployed. Operational records use hashed, nonreversible references as described above.
- Self-hosted AI routing and Google Gemini. Public 1.2.1 builds use AssetVault's self-hosted AI proxy; AssetVault 1.2.2, when released, uses the self-hosted Catalog Server. Both routes forward selected photo or text inputs to Google Gemini for optional AI features. AssetVault services are not designed to retain submitted photo bytes. Google's terms apply after forwarding. AssetVault does not guarantee that every submitted image has metadata removed, so crop or avoid sensitive details before using an AI feature.
- Public barcode databases. Public 1.2.1 builds may query Google Books, UPCitemdb, and Open Food Facts. AssetVault 1.2.2 removes Google Books and uses UPCitemdb and Open Food Facts for checksum-valid product barcodes. Open Food Facts results use metadata only and include provider attribution; AssetVault does not import Open Food Facts images.
- eBay Browse API through our catalog server. Receives the item description and grade when applicable and returns asking-price context from active listings. This is not completed-sale data or a formal appraisal.
Catalog data attribution. Public lookup may return reference data from Scryfall bulk data under its API usage policy, Rebrickable, Timepiecepedia metadata under CC0 1.0 Universal without third-party watch images, Wikidata CC0 structured data, and AssetVault-curated references.
AssetVault is unofficial Fan Content permitted under the Fan Content Policy. Not approved/endorsed by Wizards. Portions of the materials used are property of Wizards of the Coast. ©Wizards of the Coast LLC.
A private, disabled copy of Grand Comics Database issue metadata made available under CC BY-SA 4.0 is retained for audit but excluded from public lookup until written guidance and end-to-end record attribution are in place. YGOPRODeck rows are also preserved privately and excluded from public lookup pending written permission; all associated image URLs are disabled.
6. Data security, backups, and exports
On-device storage. Your inventory database, photos, and documents live in the operating system's app data area. Platform sandbox and device protections reduce access by other apps, but the live SQLite database is not separately encrypted by AssetVault.
App lock. AssetVault uses the device authentication configured in your operating system — such as Face ID, fingerprint, iris, or device passcode/PIN — when opening the app after backgrounding.
Encrypted Backup (.avbk). Wraps JSON backup data — including inventory metadata and local file references, but not the referenced photo binaries — in an AES-256-CBC envelope authenticated with HMAC-SHA256 and keyed via PBKDF2-SHA256 with 100,000 iterations. The passphrase is not persisted by AssetVault, and CRL Digital has no master key. A strong, unique passphrase is important.
JSON Backup. An unencrypted metadata backup. Anyone with the file may be able to read its contents.
Full Export ZIP. An unencrypted portability archive containing CSV, JSON, and media files the app can read. AssetVault can inspect and restore the ZIP directly. It shows a summary and requires confirmation before replacing the current vault. Verified archived media is reattached to restored records; unavailable media is reported.
Service-record retention. After the 1.2.2 catalog-side paid-service controls are deployed, hashed RevenueCat webhook-event records and paid-feature usage-meter rows are deleted after 90 days. Fully refreshed inactive entitlement-mirror rows are deleted after 90 days; active or unreconciled rows remain while needed for access verification. Pending catalog candidates remain private until reviewed and are not automatically deleted. Promoted or rejected review metadata is deleted after 90 days, and the submission quota ledger is deleted after 31 days. Catalog database backups rotate after 30 days, so a deleted service record may remain in a disaster-recovery backup until that copy expires.
7. How to delete your data
Inventory data. Delete individual items permanently from Trash, empty Trash, or uninstall the app to remove its local app data. Uninstalling does not delete backups, exports, PDFs, email attachments, cloud-drive copies, or operating-system backups outside the app; delete those separately.
Crash diagnostics. Email support@crldigital.com with the subject "Delete Crash Data" and include device type, OS version, app version, and approximate timestamps. Because identifiers are minimized, we may be unable to associate a particular event conclusively.
RevenueCat and catalog-side billing records. Share the Support ID from Settings and email a deletion request asking us to delete RevenueCat's record and, if a 1.2.2 catalog-side entitlement or metering record exists, that record as well. Apple and Google may retain purchase records under their own policies.
Catalog contribution or correction feedback. Contact support with the exact submitted fields and approximate date. Because these private queue records are not stored against an AssetVault account, identification may require those details.
For a one-page reference, see Delete Your Data.
8. Privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information we process. California residents may also have rights to opt out of sale or sharing. CRL Digital does not sell personal information or use inventory data for targeted advertising.
AssetVault does not maintain an account-linked copy of your complete inventory. To exercise an applicable right, email support@crldigital.com with the subject "GDPR Request" or "CCPA Request" and provide the Support ID or technical details needed to identify the relevant service record. We respond within the period required by applicable law.
9. Children's privacy
AssetVault does not knowingly collect data from children under 13, or the equivalent age under applicable regional law.
10. Cookies and tracking
The AssetVault app does not use advertising SDKs or the IDFA/advertising-ID ecosystem. The marketing website does not intentionally set advertising or analytics cookies. Hosting and network providers may still process standard request data such as IP address, user agent, timestamp, and requested path for delivery, security, and operations.
11. Changes to this policy
If we change this policy, we will update the "Last Updated" date and provide any additional notice required by applicable law or platform policy.
12. Contact us
CRL Digital
Email: support@crldigital.com
For privacy-specific concerns, use subject lines: GDPR Request, CCPA Request, or Delete Crash Data.