You own your data. We provide the encrypted storage and tooling. We cannot read your passwords. Do not use HexVault for anything illegal. Pay on time or your access pauses. Delete your account any time and take your data with you.
By creating a HexVault account or using any part of the HexVault service, you agree to be bound by these Terms of Service. If you do not agree, do not use the service.
If you are using HexVault on behalf of an organisation, you represent that you have the authority to bind that organisation to these terms.
HexVault provides an encrypted identity and secrets management platform. The service includes personal vault storage, family vault sharing, organisation credential management, breach monitoring, and associated security tooling.
We reserve the right to modify, suspend, or discontinue any part of the service at any time with reasonable notice. We will not discontinue the service without giving users adequate time to export their data.
You must be 16 or older to create a HexVault account. You are responsible for maintaining the security of your master password and account credentials. HexVault cannot recover your master password — losing it means losing access to your encrypted vault.
You are responsible for all activity that occurs under your account. Notify us immediately at [email protected] if you suspect unauthorised access.
You agree not to use HexVault to:
Violation of these terms may result in immediate account termination without refund.
HexVault operates on a subscription basis. Prices are shown in GBP and inclusive of applicable VAT.
Subscriptions renew automatically unless cancelled. You may cancel at any time from Settings → Account. Cancellation takes effect at the end of the current billing period. We do not offer refunds for partial billing periods except where required by UK consumer law.
If payment fails, we will notify you and provide a grace period before suspending vault access. Your data is retained for 90 days after subscription lapse before deletion.
You own your data. HexVault has no claim over the contents of your vault. We are a custodian of your encrypted data, not an owner.
You can export your vault data at any time from Settings → Data in standard formats (JSON, CSV). You can delete your account and all associated data at any time from Settings → Account → Danger Zone.
This is a feature, not a bug — it means even a full server compromise cannot expose your plaintext credentials. But it also means we have no recovery path for a lost master password.
HexVault is provided "as is". To the maximum extent permitted by law, HexVault Ltd shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the service.
Our total liability for any claim arising from these terms shall not exceed the amount you paid to us in the 12 months preceding the claim.
We do not warrant that the service will be uninterrupted, error-free, or secure. Security is a shared responsibility — we provide strong encryption and security controls, but cannot protect against attacks that compromise your device or master password.
You may terminate your account at any time. We may terminate or suspend your account for violation of these terms. Upon termination, your right to use the service ceases immediately.
On account deletion, your encrypted vault data is permanently deleted within 30 days. Billing records are retained as required by HMRC regulations (7 years).
These terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
If any provision of these terms is found to be unenforceable, the remaining provisions will remain in full force and effect.
We may update these terms from time to time. We will notify you by email at least 30 days before material changes take effect. Continued use of the service after that date constitutes acceptance of the updated terms.
Questions about these terms: [email protected]