Skip to document
OneVault
Terms of Service Privacy Policy Cookies & advertising Acceptable use Developer terms
Sign in

ONEVAULT LEGAL

OneVault Privacy Policy

Version
2026-10-v1
Effective date
1 October 2026

Controller: OneVault LLC, a limited liability company in the United States

In short: OneVault ID gives you one account for signing in to participating websites and apps. We collect what we need to run and secure that account. We do not sell your OneVault account data, and we never use it for third-party advertising. When you sign in to a OneVault App (an app operated by OneVault LLC or its affiliates, such as Tweely, Gloodz, Wiredly or ToyoSuper), we share your OneVault profile information with it, including a verified phone number, as described in Section 5. A third-party app receives only the information it requests and you approve on its consent screen. Our public marketing websites may show advertising that uses cookies; you can control that as described in Section 9. This policy explains the details and your rights.

Contents
  1. 1. Who we are and what this policy covers
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. Legal bases for processing
  5. 5. Information shared with connected apps
  6. 6. Service providers
  7. 7. Other disclosures
  8. 8. We do not sell your account data
  9. 9. Advertising and cookies on our public websites
  10. 10. International data transfers
  11. 11. How long we keep information
  12. 12. How we protect information
  13. 13. Your choices and controls
  14. 14. Your privacy rights
  15. 15. European Union, EEA, United Kingdom and Switzerland
  16. 16. United States privacy rights, including California
  17. 17. Sri Lanka
  18. 18. United Arab Emirates
  19. 19. Children
  20. 20. Automated security decisions
  21. 21. Changes to this policy
  22. 22. Contact us

Contents

  1. 1. Who we are and what this policy covers
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. Legal bases for processing
  5. 5. Information shared with connected apps
  6. 6. Service providers
  7. 7. Other disclosures
  8. 8. We do not sell your account data
  9. 9. Advertising and cookies on our public websites
  10. 10. International data transfers
  11. 11. How long we keep information
  12. 12. How we protect information
  13. 13. Your choices and controls
  14. 14. Your privacy rights
  15. 15. European Union, EEA, United Kingdom and Switzerland
  16. 16. United States privacy rights, including California
  17. 17. Sri Lanka
  18. 18. United Arab Emirates
  19. 19. Children
  20. 20. Automated security decisions
  21. 21. Changes to this policy
  22. 22. Contact us

1. Who we are and what this policy covers

OneVault LLC ("OneVault", "we", "us") provides OneVault ID, a service that lets you create one account and use it to sign in to participating websites and mobile apps ("connected apps") using OpenID Connect. OneVault LLC is the controller of the personal data described in this policy.

This policy covers personal data we process through:

  • OneVault ID registration, sign-in, consent and account recovery;
  • the account site at account.onevault.org, including Security, Connected apps and Privacy & data;
  • developer access applications and the developer area of your account;
  • our public websites, including onevault.org and regional sites such as onevault.us, onevault.ae and onevault.lk; and
  • our contact form, support and security communications.

This policy does not cover how connected apps handle information after they receive it. Each connected app, including each OneVault App, handles data it receives under its own privacy policy. Third-party apps are operated by independent developers, and their privacy policies govern their handling of your data.

2. Information we collect

Information you give us when you register:

  • username (8 to 32 lowercase letters or digits);
  • first and last name;
  • country or region;
  • date of birth (used to confirm you meet the minimum age, and shared with apps only as described in Section 5);
  • gender (you may choose "Prefer not to say"; shared with apps only as described in Section 5); and
  • email address. Registration currently accepts Gmail and iCloud addresses only, to reduce spam and fraud.

Verification information: the fact and time that your email address was verified, and, if you choose optional "Silver" phone verification (initially offered for Sri Lankan mobile numbers, by SMS), your mobile phone number and its verification status.

Authentication information: your password and passkeys are processed by OneVault's authentication system (identity provider). Passwords are stored only in protected, non-reversible form, and passkeys work with a public key that we store while the private key stays on your device or with your passkey provider. Staff never see your password, and connected apps never receive it. We also keep recovery-code status and session information.

Security and activity information: sign-in times and outcomes, IP address and the approximate location derived from it, browser and device information reported by your browser or app, account changes (for example, a password change or profile correction), security events (for example, failed sign-in attempts or suspicious activity), and records of actions taken by our staff on your Account. We use this information to recognize devices and browsers you have signed in from, so that we can ask you to confirm a sign-in from an unrecognized one with a one-time code sent by email. Browser and device descriptions are reported by your software and may be inaccurate.

Connected-app and consent information: which apps you have connected, when you approved or removed them, what information each app was allowed to receive, and the version of the consent screen you saw.

Agreement records: the version and a cryptographic fingerprint of the terms you accepted, when you accepted them, and (for a limited period) the IP address and browser information associated with the acceptance.

Support and privacy requests: information you send through the contact form or in support conversations, and records of privacy requests (such as data exports and deletion requests) and how we responded.

Developer applicant information: if you apply for developer access, the business or trading name, your role, website, business address, verified official email address, social media profiles, WhatsApp number and other evidence you provide, and our review decisions.

Public website information: when you visit our public websites, your browser sends technical information (such as IP address, browser type, pages viewed and referring page). Our public websites may use cookies and similar technologies, including third-party advertising and analytics cookies, as described in Section 9 and our Cookie and Advertising Policy. Bot-protection services may process technical signals to distinguish people from automated traffic.

Information from others: connected apps may tell us about sign-in errors or security problems relating to your use of OneVault sign-in, and our service providers (for example, email and SMS delivery providers) tell us whether messages were delivered.

3. How we use information

We use personal data to:

  1. provide your Account: create and maintain it, authenticate you, let you sign in to connected apps, show you consent screens, and share information with the apps you sign in to as described in Section 5;
  2. secure the Services: prevent, detect and investigate fraud, account takeover, automated or bulk registrations, abuse, spam and other harmful or illegal activity; enforce rate limits; confirm sign-ins from unrecognized devices, including by sending a one-time code by email from [email protected]; protect users, connected apps and OneVault;
  3. support you: respond to requests, help you recover access, and handle privacy requests and complaints;
  4. communicate with you: send verification codes, security notices (for example, that your password was changed), service notices and notices about changes to our terms and policies;
  5. review developers: conduct authenticity reviews of developers and apps and monitor compliance with our Developer Terms;
  6. enforce our terms: investigate breaches of our Terms of Service and Acceptable Use Policy, and take enforcement action;
  7. comply with law: meet legal, regulatory, tax, accounting and sanctions obligations, respond to lawful requests, and establish, exercise or defend legal claims;
  8. operate and improve the Services: monitor reliability and performance, fix problems and develop features, using aggregated or minimized data where possible; and
  9. operate our public websites: display the websites and, where permitted and subject to your choices, show advertising and measure its performance (Section 9).

We do not use your OneVault account data (such as your name, email, phone number, date of birth, gender, sign-in history or connected apps) to target advertising, and we do not provide it to advertisers.

4. Legal bases for processing

Where the GDPR, UK GDPR or a similar law applies, we rely on the following legal bases:

Purpose Legal basis
Creating and operating your Account, sign-in and consent screens, and sharing your OneVault profile information (including a verified phone number, date of birth and gender) with the OneVault Apps you sign in to Performance of our contract with you (Terms of Service); our legitimate interests in providing one account across OneVault Apps
Security, fraud prevention, abuse detection and investigations Our legitimate interests in protecting users, connected apps and our Services; legal obligation where applicable
Essential service and security communications Performance of contract; legitimate interests
Sharing information with a third-party app Your consent, given on the app's consent screen for the information it requests, which you can withdraw for the future by removing the connection in Connected apps
Developer authenticity review Legitimate interests in keeping the platform authentic and safe; steps taken at your request before entering into the Developer Terms
Responding to legal requests, sanctions compliance and record-keeping Legal obligation; legitimate interests where the obligation arises under non-EU/UK law
Establishing, exercising or defending legal claims Legitimate interests
Non-essential cookies, advertising and analytics on our public websites Your consent, where required by law
Reliability monitoring and service improvement Legitimate interests, using minimized data

Where we rely on legitimate interests, we have balanced those interests against your rights; you may object as described in Section 15. Accepting our Terms is not consent to unrelated processing.

5. Information shared with connected apps

OneVault does not sell your personal data. What a connected app receives depends on whether it is a OneVault App or a third-party app.

OneVault Apps. OneVault Apps are apps operated by OneVault LLC and its subsidiaries or affiliates. They currently include:

  • Tweely;
  • Gloodz;
  • Wiredly; and
  • ToyoSuper.

We update this list when we add or remove a OneVault App. When you use OneVault ID to sign in to a OneVault App, OneVault shares your OneVault profile information with that app, without a separate consent screen:

  • a user identifier, which is the same for all OneVault Apps so that they recognize the same account;
  • username;
  • first and last name;
  • email address and whether it is verified;
  • country;
  • date of birth;
  • gender;
  • phone number and its verification status, if you have verified a phone number with OneVault; and
  • assurance level (for example, Basic or Silver verification).

If you verify your phone number once in OneVault, including when the verification starts from inside a OneVault App, the verified number is available to every OneVault App you use. You can remove your phone number from your Account at any time, which stops future sharing of it. OneVault may also notify OneVault Apps when your profile information changes or your Account is disabled, so that they can keep your details current.

Third-party apps. A third-party app receives only the information it requests and you approve on the consent screen when you sign in. The consent screen lists everything the app is requesting, which may include any of the items listed above, and each app must state a purpose for every item it requests. The app decides which information it needs for its service, and you approve the request as a whole: if you do not want to share any of the requested information, you can decline to connect, and you then cannot use that app with OneVault. If an app later asks for more information, you will see a new consent screen. A third-party app receives a user identifier that is shared only with other apps of the same developer, so that apps of different developers cannot use it to link your activity.

What apps never receive. Connected apps do not receive your password, passkeys, recovery codes, one-time codes, sign-in history, IP address history or OneVault security records through OneVault sign-in.

Managing connections. You can review and remove third-party app connections at any time in Connected apps in your Account. Removing a connection stops future sharing with that app. For OneVault Apps, you can stop future sharing of your phone number by removing it from your Account, and deleting your Account stops all future sharing. None of these steps deletes data an app has already received. Each app's own privacy policy governs that data, and you should contact the app directly to access or delete it.

Each app is responsible for its own data handling. Each OneVault App handles the information it receives under its own privacy policy. Third-party apps are operated by developers that passed our authenticity review, but they are not controlled by OneVault. They are separate controllers of the information they receive, and our Developer Terms require them to have their own privacy policy, use OneVault data only for their app, not sell it, and honour disconnection and deletion requests.

6. Service providers

We use service providers that process personal data on our behalf under contracts that restrict their use of it. Our current principal providers are:

Provider Service Location of processing
Amazon Web Services Cloud hosting, databases and storage United States (us-west-2, Oregon)
Zoho ZeptoMail Transactional email delivery (verification, security and new-device sign-in emails, sent from [email protected]) As operated by the provider
Notify.lk SMS delivery for phone verification of Sri Lankan mobile numbers Sri Lanka
Cloudflare Network security, content delivery and Turnstile bot protection Global network

We may also use providers for support tooling, monitoring and professional services (such as legal and accounting advisers). We may change providers from time to time and will update this policy when we add a principal provider. Providers of advertising and analytics on our public websites are described in Section 9 and our Cookie and Advertising Policy.

7. Other disclosures

We may also disclose personal data:

  • within the OneVault group: to our subsidiaries and affiliates that help us provide or secure the Services, subject to this policy, and to OneVault Apps as described in Section 5;
  • for legal reasons: to law enforcement, regulators, courts or other authorities when we believe in good faith that disclosure is required by law or legal process, or is reasonably necessary to prevent fraud, illegal activity, imminent harm or threats to safety, to protect our rights, property or users, or to report apparent illegal content where the law requires;
  • to protect people and the Services: to connected apps or other service operators where reasonably necessary to investigate or stop fraud, account takeover or abuse affecting them, limited to the information needed;
  • in business transfers: to a buyer, successor or financing party in connection with a merger, acquisition, reorganization, financing, sale of assets or insolvency, subject to confidentiality obligations and with notice to you where required; and
  • with your direction or consent: in other cases where you ask us to or agree.

8. We do not sell your account data

OneVault does not sell your OneVault account data, and does not share it for cross-context behavioural or targeted advertising. Your account data is not provided to advertisers or data brokers.

Our public marketing websites may use third-party advertising cookies, as explained in Section 9. Under some United States state laws, allowing third-party advertising cookies to collect information on a website can be treated as a "sale" or "sharing" of personal information, or as "targeted advertising", even though no money is exchanged for the data. To be transparent, we treat that public-website activity as such, and we give you the ability to opt out (Sections 9 and 16). This does not apply to the account site, which does not show advertising.

9. Advertising and cookies on our public websites

Our public marketing websites (onevault.org and regional sites) may display advertising, including ads served by Google (for example, through Google AdSense) and other advertising partners, and may use analytics. The signed-in account area (account.onevault.org) and our staff systems do not display advertising.

  • Third-party vendors, including Google, use cookies to serve ads based on your prior visits to our websites or other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to our sites and/or other sites on the internet.
  • You can opt out of personalized advertising from Google by visiting Google Ads Settings. You can opt out of some third-party vendors' use of cookies for personalized advertising by visiting www.aboutads.info/choices, and, in Europe, www.youronlinechoices.eu.
  • Information about how Google uses data from sites that use its services is available at policies.google.com/technologies/partner-sites.

Consent where required. In the European Union, EEA, United Kingdom, Switzerland and other places where the law requires consent, we do not place non-essential cookies (including advertising and analytics cookies) until you agree, and you can change your choice at any time. Where we serve ads without consent to personalized advertising, any ads shown may still use cookies for limited purposes such as frequency capping and fraud prevention, where the law permits.

Opting out in the United States. Where we use third-party advertising cookies, you can opt out of the "sale" or "sharing" of personal information and of targeted advertising through the "Your Privacy Choices" link on our public websites. We also treat a Global Privacy Control (GPC) signal sent by your browser as a valid opt-out request for that browser. Because opt-outs through cookies apply to the browser and device you use, you will need to opt out on each browser and device.

More details, including categories of cookies and how to control them, are in our Cookie and Advertising Policy.

10. International data transfers

OneVault is based in the United States and our primary hosting is in the United States. If you use the Services from another country, your personal data will be transferred to, stored in and processed in the United States and other countries where our service providers operate, including Sri Lanka for SMS delivery. Those countries may not have the same data protection laws as your country.

Where the law of your country requires, we protect transfers with appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision or other lawful transfer mechanism, together with additional measures where needed. You may request a copy of the relevant safeguards by contacting us (Section 22).

11. How long we keep information

We keep personal data only for as long as necessary for the purposes described in this policy, including to meet legal, security and dispute-resolution needs. We apply these criteria:

  • Account and profile data is kept while your Account is active.
  • When you request deletion in Privacy & data, there is a 7-day cancellation window. After the window ends, we process the deletion of your Account and profile data.
  • Security records (such as IP addresses and browser information) are kept for a limited period for security purposes and deleted or aggregated after that period, unless they are needed for a specific investigation.
  • Records we must keep after deletion may be retained where necessary for legal obligations, security, fraud prevention, dispute resolution, legal holds and consent and audit records (such as proof of which terms you accepted and when, and records of privacy requests), limited to the information needed and with restricted access.
  • Backups are kept for a limited period and are overwritten on a rolling schedule; deleted data may remain in backups until they are overwritten, and is not restored into active use.
  • Developer application records are kept for the duration of the developer relationship and for a limited period after a decision or termination.

When personal data is no longer needed, we delete it or anonymize it so that it can no longer be associated with you.

12. How we protect information

We use administrative, technical and physical safeguards designed to protect personal data, including encryption in transit, encryption of sensitive records, protected handling of passwords and passkeys, role-restricted and audited staff access, bot protection, rate limits and monitoring. Our authentication services are designed to follow recognized standards such as OpenID Connect, OAuth 2.0 security best practices and NIST-aligned authentication practices. These statements describe our design goals and are not a certification. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and authorities where the law requires. You help protect your Account by keeping your credentials and devices secure.

13. Your choices and controls

In your Account you can:

  • update certain profile details;
  • manage your password, passkeys, recovery codes and active sessions in Security;
  • review and remove connected apps in Connected apps;
  • request an export of your data, and request deletion of your Account, in Privacy & data; and
  • choose whether to verify a phone number and whether to keep it in your Account (a verified number is shared with the OneVault Apps you use, and removing it stops future sharing), and whether to connect to a third-party app after reviewing the information it requests.

On our public websites, you can manage cookie choices and opt out of advertising as described in Section 9.

You cannot opt out of essential security and service messages while you hold an Account, because they protect your Account.

14. Your privacy rights

Depending on where you live, you may have some or all of the following rights:

  • to know what personal data we process and to access a copy of it;
  • to correct inaccurate data;
  • to delete your data;
  • to receive your data in a portable format (data portability);
  • to restrict or object to certain processing;
  • to withdraw consent where we rely on consent, without affecting processing before withdrawal;
  • to opt out of the sale or sharing of personal information and of targeted advertising;
  • to not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, in the circumstances set out in law;
  • to appeal our decision on your request; and
  • to complain to a data protection authority.

How to make a request. Use the tools in your Account (Privacy & data provides export and deletion), or submit a request through our contact form and choose "Privacy request". We will verify your identity before acting, usually by asking you to sign in or confirm control of your Account email. You may use an authorized agent where the law allows; we may ask the agent for proof of authority and ask you to verify your identity. We will respond within the time required by applicable law (for example, one month under the GDPR, extendable in some cases, and 45 days under California law, extendable once by 45 days). We will not discriminate against you for exercising your rights.

Some rights are subject to limits: for example, we may keep information we are legally required to keep or need to defend legal claims, and we cannot delete data that a connected app already holds. We will explain if we cannot fully honour a request.

15. European Union, EEA, United Kingdom and Switzerland

If the GDPR, UK GDPR or Swiss data protection law applies to our processing of your data:

  • OneVault LLC is the controller. Our legal bases are listed in Section 4.
  • Right to object: you may object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. We will stop unless we have compelling legitimate grounds or need the data for legal claims.
  • Provision of data: the information marked as required at registration is necessary to enter into the contract; without it we cannot create an Account. Optional information (such as a verified phone number) is not required.
  • Representatives and data protection officer. If you are in the European Union, EEA, United Kingdom or Switzerland, send requests and questions through our contact form and choose "Privacy request". Where the law requires, OneVault will appoint an EU representative (GDPR Art. 27), a UK representative (UK GDPR Art. 27) or a data protection officer, and will publish their contact details in this policy.
  • Complaints: you may complain to the data protection authority in the country where you live or work or where an alleged infringement occurred. In the UK, this is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.

16. United States privacy rights, including California

This section supplements this policy for residents of California and other US states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Texas, Oregon and others), to the extent those laws apply to OneVault.

Categories of personal information collected in the last 12 months:

Category Examples Disclosed for a business purpose to Sold or shared?
Identifiers Name, username, email address, phone number (if verified), app-specific user identifier, IP address, cookie and device identifiers Service providers; connected apps you sign in to Account identifiers: No. Cookie and device identifiers and IP address collected on our public websites by advertising partners: may be, unless you opt out
Personal records (Cal. Civ. Code § 1798.80(e)) Name, phone number Service providers; connected apps you sign in to No
Characteristics of protected classifications Date of birth (and age), gender Service providers; connected apps you sign in to No
Internet or other electronic network activity Sign-in history, browser and device information, security events; interactions with our public websites and ads Service providers Account activity: No. Public-website browsing and ad interactions: may be, unless you opt out
Geolocation data (approximate, not precise) Country; approximate location derived from IP address Service providers Public-website IP-based location used by advertising partners: may be, unless you opt out
Professional or commercial information Developer applicant business details Service providers No
Inferences Security risk assessments used to prevent fraud Service providers No
Sensitive personal information Account log-in credentials (username with password) Our authentication service providers only No

Sources: you, your browser or device, connected apps (for sign-in errors and security issues), our service providers, and advertising partners on our public websites.

Purposes: the business and commercial purposes described in Section 3.

Sale and sharing. We do not sell or share OneVault account data. Third-party advertising cookies on our public websites may be treated as a sale or sharing to advertising partners (such as Google) for cross-context behavioural advertising. You can opt out through the "Your Privacy Choices" link on our public websites, and we honour Global Privacy Control signals as an opt-out for the browser that sends them. We do not knowingly sell or share the personal information of consumers under 16.

Sensitive personal information. We use sensitive personal information only to provide and secure the Services and as permitted by law, not to infer characteristics about you. We therefore do not offer a "limit the use" option, which is not required for these uses.

Retention: see Section 11.

Your rights: see Section 14. If we deny your request, you may appeal by replying to our decision or through the contact form; we will respond within the time required by law, and if we deny the appeal you may contact your state Attorney General.

No financial incentives. We do not offer financial incentives in exchange for personal information.

Shine the Light. California residents may ask whether we disclosed personal information to third parties for their direct marketing purposes. We do not.

17. Sri Lanka

If the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka (as amended) applies to our processing, you have the rights provided by that Act as they come into operation, including rights to access, to withdraw consent, to rectification and completion, to erasure, and to request a review of certain automated decisions. We process your data under the lawful bases described in Section 4, which correspond to the conditions for lawful processing in that Act. SMS for phone verification in Sri Lanka is delivered by Notify.lk. Your data is transferred to the United States as described in Section 10. You may exercise your rights through the contact form, and you may complain to the Data Protection Authority of Sri Lanka.

18. United Arab Emirates

If Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to our processing, you have the rights provided by that law, including rights to obtain information, to request transfer of your data, to correction and erasure, to restrict and to stop processing in the circumstances set out in the law, and to object to decisions based solely on automated processing. Your data is transferred to the United States and other countries as described in Section 10. You may exercise your rights through the contact form and may complain to the UAE Data Office.

19. Children

OneVault ID is not directed to children under 13, and you must be at least 13 (or older where your local law sets a higher age of digital consent) to create an Account. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, or from a person below the minimum age that applies to them, without the consent required by law, we will delete it and close the Account. If you believe a child has provided us with personal information, please tell us through the contact form.

We do not knowingly sell or share the personal information of anyone under 16, and we do not use account data of any user for targeted advertising.

20. Automated security decisions

To protect accounts, we use automated systems that may allow, challenge, delay or temporarily block a registration or sign-in, based on signals such as request rates, network information, email eligibility, bot-protection results and known abuse patterns. These decisions protect you and others. If you believe an automated decision has wrongly affected you, contact us through the contact form and a member of our team will review it. Where the law gives you rights regarding decisions based solely on automated processing with legal or similarly significant effects, we will honour them.

21. Changes to this policy

We may update this policy from time to time. We will post the updated policy with a new version number and effective date. If changes are material, we will notify you in advance, for example by email or by a notice when you sign in, and where the law requires, we will ask for your consent.

22. Contact us

OneVault LLC United States

To make a privacy request or ask a question about this policy, use our contact form and choose "Privacy request". Requests from the European Union, EEA, United Kingdom and Switzerland are handled through the same form (see Section 15).

Back to top

OneVault

OneVault LLC · One secure identity

Terms of Service Privacy Policy Cookies & advertising Acceptable use Developer terms Security