Privacy Policy
What we collect, what we cannot see, and how we handle your data.
Effective Date: June 25, 2026
LORIIQ ("LORIIQ," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and, most importantly, what we cannot access because of our zero-knowledge architecture.
By using LORIIQ, you agree to this Privacy Policy.
1. Our Privacy Philosophy
LORIIQ is designed so that your passwords, secure notes, API keys, SSH keys, and other vault contents are encrypted on your device before they are transmitted to our servers.
Your master password is never transmitted to LORIIQ.
Our servers store encrypted vault data only.
We cannot decrypt your vault.
2. Information We Collect
Depending on how you use LORIIQ, we may collect:
Account Information
- Email address
- Account creation date
- Account status
- Subscription information (if applicable)
Device Information
For security purposes we may store:
- Device name
- Device type
- Browser information
- Operating system
- Last login timestamp
Operational Metadata
To provide synchronization and maintain service reliability we may process:
- Encrypted vault size
- Synchronization timestamps
- Vault version numbers
- Request timestamps
- IP address
- Error logs
- Authentication events
This information does not include your decrypted vault contents.
3. Information We Do Not Collect
LORIIQ is designed so we cannot access:
- Master passwords
- Passwords
- Secure notes
- API keys
- SSH keys
- Recovery codes
- Credit cards
- Identity information stored inside your vault
- Decrypted vault contents
Encryption occurs on your device before data is uploaded.
4. How We Use Your Information
We use collected information to:
- Create and manage your account
- Authenticate your identity
- Synchronize encrypted vault data
- Detect fraud and abuse
- Secure your account
- Improve reliability
- Respond to customer support requests
- Meet legal obligations
We do not sell your personal information.
5. Encryption
LORIIQ follows a zero-knowledge architecture.
Your vault is encrypted locally before transmission.
Only encrypted data is synchronized.
Our infrastructure does not possess the cryptographic keys necessary to decrypt your vault.
6. Third-Party Services
LORIIQ may use trusted infrastructure providers including:
- Google Cloud Platform
- Google Cloud Storage
- Google Cloud SQL
- Google Secret Manager
- PauBox (email delivery)
- Payment processor (if applicable)
These providers process information only as necessary to provide their services.
7. Cookies
LORIIQ may use cookies and similar technologies for:
- Authentication
- Session management
- Security
- User preferences
We do not use cookies to read or access vault contents.
8. Data Retention
Account information is retained while your account remains active.
Encrypted vault data remains stored until you delete your account or request deletion.
Certain logs may be retained for security, fraud prevention, auditing, or legal compliance.
9. Account Deletion
You may request deletion of your account at any time.
Upon deletion:
- Account information will be removed or anonymized where practical.
- Encrypted vault data will be permanently deleted according to our retention schedule.
- Certain records may be retained where required by law.
Deletion of your account does not allow LORIIQ to recover encrypted vault contents.
10. Security
We use industry-standard security practices including:
- TLS encryption
- Encryption at rest
- Rate limiting
- Authentication controls
- Audit logging
- Infrastructure monitoring
No security system is completely immune from compromise. We continually improve our security practices but cannot guarantee absolute security.
11. International Data Transfers
Your information may be processed in countries where LORIIQor its service providers operate.
Appropriate safeguards are used where required by applicable law.
12. Children's Privacy
LORIIQ is not intended for children under the age of 13 (or the minimum age required in your jurisdiction).
We do not knowingly collect information from children.
13. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your information
- Correct inaccurate information
- Delete your account
- Export your data
- Object to certain processing
- File complaints with applicable regulators
Because LORIIQ follows a zero-knowledge architecture, we cannot provide access to decrypted vault contents.
14. Legal Requests
If LORIIQ receives a lawful request for user information, we may disclose information that we possess and are legally required to provide.
Because LORIIQ does not possess your master password or decrypted vault contents, we cannot provide decrypted vault data that we do not have.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically.
Material changes will be communicated through our website or application.
The updated Effective Date will appear at the top of this document.
16. Contact
If you have questions regarding this Privacy Policy, contact:
VITATECH SOLUTIONS INC.
Email: privacy@vitatechgroup.com
Summary
LORIIQ is built around a simple principle:
Your secrets belong to you.
Your vault is encrypted before it leaves your device, synchronized only as encrypted data, and designed so LORIIQ cannot access its contents.