← Folio Vault·All apps →

Folio Vault — a Windows app by Zarzara

Privacy
Policy

Effective date: 20 August 2026

Folio Vault is a secure Documents and Records organizer for Windows. It stores documents, Records and their typed values, extracted metadata, OCR text, vault names, settings, persistent diagnostics, and encrypted vault backups locally on the user’s Windows device or in locations the user selects.

01

Local Data

Imported files are copied into a local encrypted vault. Vault databases use authenticated SQLite3MC ChaCha20 encryption and document files are stored as authenticated encrypted blobs. New vaults default to Windows account auto-unlock; users may instead require a vault password. Vault passwords are not stored by Folio Vault. If a password-required vault loses both its vault password and recovery key, its data cannot be recovered. A vault database in any other format is rejected without modification. The app deletes and replaces that vault's local data only after the user explicitly types REPLACE; canceling leaves the data untouched.

Encrypted document source bytes used by previews, the editor, and OCR are decrypted only into bounded in-memory lease buffers that Folio Vault zeroes when released or when the vault closes. Decoded presentation objects are released when their preview closes. Third-party decoded presentation allocations and internal KDF scratch memory cannot be deterministically zeroed. Folio Vault does not create ordinary plaintext preview files. Startup may remove bounded session-* residue left by older app versions. To use a document outside the vault, export it first.

Failed password and recovery-key attempts are delayed inside Folio Vault. This application throttling cannot stop offline guessing against copied vault data.

Uninstalling Folio Vault does not automatically remove local vaults, logs, or settings. Settings can clear Documents, Records, or both after a warning and typed confirmation. Clearing removes links but does not delete the opposite domain; structure, unlock methods, other vaults, and exports remain.

02

OCR and Field Extraction

Folio Vault indexes text files during import. Images and PDFs are indexed in the background with the installed Windows on-device OCR engine where local rendering and OCR are available, and manual OCR remains available as a correction path. Folio Vault does not upload documents or OCR text for OCR processing.

OCR results and extracted field values are stored in the local encrypted vault. They remain local unless the user exports or backs up the vault to a location they choose.

03

Network and Cloud Use

Folio Vault does not add a cloud upload path for documents, Records, typed values, extracted metadata, OCR text, vault names, or vault exports. Microsoft Store licensing, purchase, trial, and entitlement checks are handled by Microsoft Store services when the Store package is used.

04

Diagnostics

Folio Vault keeps persistent local diagnostics for troubleshooting. Logs remain on the user's device unless the user chooses to share them.

Diagnostics may include technical details such as file paths, document or record titles, operation names, app version, Microsoft Store licensing state, and error messages. Diagnostics are not intended to include document contents, Record summaries or typed values, OCR text, encryption keys, passwords, recovery secrets, or full extracted field values.

Diagnostic logs rotate locally to limit retained size.

05

Backups and Exports

Four outputs hold the complete Documents and Records catalog. A vault backup is restorable and encrypted only when you set a password; without one its contents, names, metadata, and links are unprotected. A ZIP file is plaintext, or AES-256 encrypted except for entry names, and is always one-way; Restore rejects it. Plaintext may surface in ZIP names, indexes, thumbnails, backups, sync, and extracted copies. CSV, print, and PDF are plaintext.

Changing a vault password rotates the key and encrypted data of the newly published local vault. It cannot revoke vault/configuration copies captured before rotation or already-created backups; those copies remain protected by the credentials they captured.

06

User Controls and Access

Users control what documents are imported, what Records are entered, what OCR or field extraction is run, where backups, CSV, printed reports, or PDFs are exported, and whether diagnostics are shared with support. Users can clear Documents, Records, or both and can delete folders, vaults, local backup files, and diagnostic logs from their device.

07

Disclosure

Folio Vault does not sell personal information and does not share documents, OCR text, extracted fields, vault contents, or diagnostic logs with third parties. Data leaves the device only when the user chooses a location outside the device, shares diagnostics, or uses Microsoft Store licensing, purchase, trial, or entitlement services.

08

Support and Contact

For privacy questions or support, contact us:

Email: foliovaultsupport365@gmail.comWebsite: zarzara.app
Folio Vault · by Zarzara
Product pageSupport
zarzara.

A small studio. A lot of care.

Our appsThe studioJournalSay hello
© 2026 ZarzaraThoughtfully made. Independently built.Back to top ↑