Privacy policy
Valtira is a password manager built so that we cannot read what you store. This policy explains what little we do process — on this website, in the Valtira app and, if you choose to use it, in encrypted sync.
1. Who is responsible
The controller is Stanley Kunz, trading as Kunz Global · Kunz Systems, Ruta 1 km 51, Departamento de San José, Uruguay, RUT 220451740014. Contact: contact@kunzsystems.com.
2. What we cannot see
Everything you store in your vault — names, website addresses, usernames, passwords, notes, card details, identities, two-factor secrets, tags, favorites and trash — is encrypted on your device with AES-256-GCM before it is saved or synced. The key is derived from your master password on your device; we never receive your master password, your vault key or your recovery key. We therefore cannot read, analyse, sell or hand over your vault content.
3. This website
The website valtira.kunzsystems.com is a static site hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you visit it, Vercel processes technical data needed to deliver the pages and to protect the service — your IP address, date and time, requested page, browser and operating system — in server logs that Vercel keeps for a limited period. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
The website sets no cookies, loads no analytics, advertising or tracking scripts and embeds no third-party content. Fonts and images are served from our own domain.
4. The Valtira app without an account
You can use Valtira without an account. Your encrypted vault is then stored only in your browser’s storage on your device. The app stores a few non-sensitive preferences (theme, language, list sorting, generator options) in your browser’s local storage. The app itself is delivered by Vercel as described in section 3.
5. Encrypted sync (optional account)
If you turn on sync, we process the following data to provide the service you requested (Art. 6(1)(b) GDPR):
- your email address (your account identifier);
- key-derivation settings and a keyed hash of a login proof derived from your master password on your device (not your master password);
- your encrypted vault key and encrypted vault items, with technical metadata: random item identifiers, revision numbers and timestamps;
- devices you sign in with: a name you can change (e.g. “Chrome on Windows”), the platform, when it was added and last used;
- sessions: a hash of the session token and expiry times; a strictly necessary session cookie (“__Host-valtira_session”) in the web app;
- security events (for example sign-ins, failed sign-ins, password changes, device removals), shown to you in the app and deleted after 12 months;
- for protection against password-guessing attacks, short-lived keyed hashes of IP addresses and email addresses used for rate limiting and deleted within 48 hours (Art. 6(1)(f) GDPR).
6. Optional breach check
In the Security Center you can check your passwords against known data breaches. This uses the “Pwned Passwords” service of Have I Been Pwned (haveibeenpwned.com), delivered via Cloudflare. Your device sends only the first five characters of the SHA-1 hash of a password — never the password or the full hash. As with any web request, the service receives your IP address. The check runs only when you start it.
7. Processors and international transfers
We use Vercel Inc. (USA) for hosting and serverless functions, and a managed PostgreSQL provider for the sync database. Where data is transferred outside your country, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. Because vault content is end-to-end encrypted, these providers cannot read it either.
8. How long we keep data
Sync account data is kept until you delete your account in the app; deletion removes your account, encrypted vault, devices, sessions and security events from our database. Sessions expire after 30 days at the latest. Rate-limit data is deleted within 48 hours. Encrypted data on your devices stays under your control until you remove it. Backups of the database, if made, are overwritten in regular cycles.
9. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests. You can export your vault and delete your account directly in the app. To exercise other rights, write to contact@kunzsystems.com. You also have the right to lodge a complaint with a data protection supervisory authority, for example in your country of residence, or with the Unidad Reguladora y de Control de Datos Personales (URCDP) in Uruguay.
10. Security
Details of our security architecture are published on the Security page. No system is completely secure; we describe known limits openly and ask security researchers to report vulnerabilities to contact@kunzsystems.com.
11. Changes
We update this policy when our processing changes. The date at the top shows the latest version.