VaultFace keeps your ID documents on your phone, opens only for your live face, and shares a card that tells people your name, age, city and country — never your document number, never your birth date.
One Google sign-in to start. Your vault never leaves your phone.
A photo or a video of you won’t. If someone tries too many times, the vault locks itself.
The number on your document is covered the moment you scan it — the app never keeps a readable copy.
After a one-time Google sign-in, adding, protecting, sharing and checking documents all work with no internet — your vault never touches a server.
A short sweep of your face becomes the only key to your vault. Rotate it any time — you stay you.
Point the camera at your ID. The sensitive number is covered on the photo itself, sealed and stored encrypted on your phone.
Send a share card or the protected photo. Anyone with VaultFace scans it and sees exactly what you chose to disclose — with an expiry you set.
Pick how long a shared card stays valid — from a minute for an in-person check to months for a landlord. The date is sealed into the card itself, so a screenshot can’t extend its own life. Your live card in the app always stays fresh; only copies carry the fuse.
Every share card carries a seal. Change one letter of what it claims and the seal breaks — any VaultFace app will show it.
The protected document photo carries its own scannable code: point VaultFace at it and see the card details and expiry — no separate file needed.
Every time you open a document, the app confirms the stored image is exactly the one it protected — and tells you if it isn’t.
Only once — to sign in with your Google account the first time. After that, everything — adding documents, protecting them, sharing cards, scanning and checking them — works with no connection at all.
Only on your phone, encrypted. Your Google sign-in identifies you, but no server holds your documents, face data, or activity. Deleting the app deletes everything it stored.
Your name, age, city, country, document type, and a valid-through date. Your document number appears only in its mostly-hidden form, and your birth date is never shown — only your age.
The screenshot inherits the expiry you chose. When the time is up, any scan of it says EXPIRED and asks for a freshly shared card.
No — the vault opens for a live face, not a picture or a video of one. Repeated failed attempts lock it down for a while.
VaultFace for Android — free, private, and offline after a one-time sign-in.
Get the appEffective 20 July 2026 · Applies to the VaultFace Android app
VaultFace asks you to sign in once with your Google account — and that is the only personal data that ever leaves your phone: your name, email address, and account ID, used solely to identify you. Your documents, your face data, and your activity records live encrypted on your phone, and only there; we run no server that holds any of them. The only other time information moves anywhere is when you deliberately share a card or a protected photo — and even then, only the fields you chose, for the time you chose.
Three things, all from your Google sign-in: your name, your email address, and your Google account ID. They are used only to sign you in and manage your account — never for advertising, analytics, or profiling, and never shared with anyone. Beyond that, the app contains no analytics, no advertising, and no tracking. We cannot see your documents, your face data, or your activity — there is no server on our side holding any of it.
When you sign in with your Google account, the app receives your name, email address, and account ID from Google to identify you. Your sign-in is handled by Google under Google’s Privacy Policy. We do not use this information for advertising and never share it with anyone.
When you share a card or a protected photo, the app prepares it on your device and hands it to the sharing channel you pick (for example a messaging app). What the recipient can see is limited to the disclosed fields — name, age, city and country, document type, and a valid-through date — and every shared copy carries the expiry you set. The sharing channel you choose handles delivery under its own privacy policy.
The app asks for camera access, used solely to capture your face and your documents as described above. It requests no access to your contacts, location, microphone, or files.
Documents and face templates are encrypted at rest with keys held in your device’s secure keystore. The vault opens only for a live face — not a photo or video — and locks itself after repeated failed attempts. The app also shields its screens from the app switcher and blocks screenshots of sensitive views.
You can delete any document, or your entire identity, inside the app at any time — no need to delete your account to do it. To delete your account and the sign-in data described above, use the delete option in the app’s settings, or email support@vaultface.net from your sign-in address and we will confirm the deletion. You can also revoke VaultFace’s access in your Google account settings. Uninstalling the app permanently deletes everything stored on your device — no copy of your vault exists anywhere else.
VaultFace is not directed at children under 13 and does not knowingly collect data from children.
If the app’s behavior ever changes in a way that affects your privacy, we will update this policy and the effective date above before the change ships.
Questions about privacy or this policy: support@vaultface.net