Legal
IDVault Platform
Terms & Conditions
These terms govern your access to and use of IDVault — our digital identity card platform and encrypted password vault. Please read them carefully before using the service.
By creating an account or using IDVault in any way, you agree to these Terms. If you disagree with any part, you must stop using the platform immediately.
About IDVault
IDVault is a personal digital identity platform built for individuals who want to manage their online presence professionally. It provides two core features:
- Digital ID Cards — create a shareable, public-facing profile card with your name, role, bio, contact info, and social links.
- Password Vault — an AES-256-GCM encrypted store for your login credentials, accessible only to you.
IDVault is operated as a personal project hosted at id-vault.vercel.app. It is provided free of charge with no subscription fees.
Eligibility
To use IDVault you must:
- Be at least 13 years of age. If you are under 18, you confirm that a parent or guardian has reviewed and consented to these Terms.
- Provide accurate, current, and complete information during registration.
- Not be prohibited from using the service under any applicable law or jurisdiction.
Accounts & Security
You are fully responsible for your IDVault account. This includes:
- Keeping your password confidential — never share it with anyone.
- All activity that occurs under your account, whether or not authorised by you.
- Notifying us immediately if you suspect any unauthorised access.
- Using a strong, unique password. We recommend enabling a password manager (like the IDVault Vault itself).
IDVault uses JWT-based authentication. Session tokens are stored in httpOnly cookies and expire after inactivity. We are not responsible for losses resulting from your failure to safeguard your credentials.
Digital ID Cards
Each account may hold one Digital ID Card. By creating a card you confirm that:
- All information on the card is truthful and accurate. Impersonating real individuals is strictly prohibited.
- You own or have the right to use any profile image you upload.
- You understand that making a card Public exposes it to anyone with the link.
- You can toggle your card between Public and Private at any time from your dashboard.
- Deleting your card is permanent — your public link will stop working immediately.
Profile images are stored securely on Cloudinary. They are only used to display your card and are not used for advertising or sold to third parties.
Password Vault
The Password Vault stores your credentials using AES-256-GCM encryption with a per-user key derived from a server-side secret. Passwords are encrypted before being written to the database and decrypted only at the time of retrieval within your authenticated session.
- Never store banking OTPs, government ID numbers, or other highly sensitive information in the Vault without understanding the security model.
- If you delete your account, all vault entries are permanently and irreversibly deleted.
- The Vault is a personal productivity tool — it is not a certified enterprise password manager. Use accordingly.
We strongly recommend keeping a separate backup of critical passwords outside IDVault.
Data & Privacy
We collect and store:
- Account information: your name, email address, and hashed password.
- Card information: everything you enter on your Digital ID Card.
- Vault data: your encrypted password entries.
- Usage metadata: basic server logs (IP address, request timestamps) for security purposes.
We do not:
- Sell, rent, or share your personal data with third parties for marketing.
- Store plain-text passwords — all vault data is encrypted at rest.
- Use your card or vault data to train AI models.
- Serve advertisements or track you across other websites.
Third-party services used: MongoDB Atlas (database), Cloudinary (image hosting), Vercel (hosting). Each has its own privacy policy and data processing terms.
Public Sharing
When you set your ID Card to Public, it becomes discoverable on the IDVault Discover page and accessible to anyone who has your card URL.
- You can revert to Private at any time — the public link will stop resolving immediately.
- Do not include private information (national ID, bank account numbers, home address) on a public card.
- IDVault may display your public card in community-facing sections of the platform (e.g., the Discover page).
- IDVault is not responsible for screenshots or copies of your card made by third parties while it was public.
Prohibited Conduct
You may not use IDVault to:
- Impersonate any person or organisation, including public figures or IDVault itself.
- Upload or share content that is illegal, abusive, defamatory, obscene, or discriminatory.
- Attempt to reverse-engineer, probe, scan, or exploit any part of the platform.
- Use automated tools (bots, scrapers) to harvest data from IDVault.
- Circumvent any security or authentication measure.
- Create accounts on behalf of others without their explicit consent.
- Use the Vault to store credentials that belong to accounts you do not own.
Violation of these rules may result in immediate account suspension and deletion without notice.
Intellectual Property
All design, code, branding, and copy of the IDVault platform are the intellectual property of the creator. You may not copy, reproduce, or distribute them without written permission.
You retain full ownership of the content you create — your card information, uploaded images, and vault entries. By using IDVault, you grant us a limited licence to store and display that content solely for the purpose of operating the service.
Termination
You may delete your account at any time from the Dashboard → Delete Account. This immediately and permanently erases your user record, all vault entries, and your ID card.
We may suspend or terminate your account without notice if you violate these Terms, engage in abusive behaviour, or if the platform is discontinued.
Deleted accounts and their data cannot be recovered. Export anything important before deletion.
Disclaimers
IDVault is provided "as is" without warranties of any kind — express or implied. We do not guarantee:
- Uninterrupted or error-free operation of the service.
- That the platform will be available at any specific time.
- That data stored on the platform will never be lost (always keep backups of critical credentials).
- The accuracy of data entered by other users on public cards.
Limitation of Liability
To the fullest extent permitted by applicable law, IDVault and its creator are not liable for any indirect, incidental, special, or consequential damages arising from:
- Unauthorised access to your account due to credential compromise on your end.
- Loss of data resulting from account deletion or service disruption.
- Any actions taken by third parties who view your public ID card.
- Reliance on information displayed on other users' public cards.
Our total liability to you for any claim shall not exceed the amount you paid for the service (which is zero, as IDVault is free).
Changes to Terms
We may update these Terms at any time. When we do, we will update the "Last updated" date at the top of this page.
Continued use of IDVault after changes are posted constitutes your acceptance of the revised Terms. If you disagree with a change, stop using the service and delete your account.
Contact Us
Questions, concerns, or abuse reports? Reach out — we read everything.
Platform
id-vault.vercel.appThese Terms are governed by the laws of India. Any disputes arising shall be subject to the exclusive jurisdiction of the courts of India. If any provision of these Terms is held to be invalid, the remaining provisions continue in full force.