Privacy Policy
NextVault is designed around a simple principle: your credentials never leave your device. This policy explains what little data we do handle — and how we protect it.
Who We Are
Thingsmart Limited (“we”, “us”, “our”) operates the website https://thingsmart.co and publishes the NextVault Android application (package ID: app.nextvault).
We are a UK-based technology consultancy providing digital services including web development, automation, ERP implementation, IoT solutions, and infrastructure consulting for SMEs. NextVault is a free Android password manager published by Thingsmart Limited.
For the purposes of UK data protection law, we are the Data Controller of any personal data we process in connection with our website and services.
Contact us at in**@********rt.co
Thingsmart Limited · United Kingdom
What Data We Collect
A. NextVault App — Your Credential Data
NextVault is architected so that all credential data remains exclusively on your device. The app stores the following in a SQLCipher-encrypted local database (mysecrets_encrypted.db) — this data is never transmitted to Thingsmart or any third party:
- Login credentials (usernames, passwords, URLs)
- Banking and card details (account numbers, PINs, sort codes, CVVs)
- Personal identification data (passport, national insurance, dates of birth)
- TOTP/OTP authenticator secrets (Base32 seeds, otpauth:// URIs)
- WiFi credentials, SIM PINs, subscription details
- Secret notes and document photos (stored in private app-internal storage)
- Collections, category names, and vault structure
- Security audit log entries (event type, timestamp, detail — local only)
B. Data Processed Outside Your Device
NextVault makes four outbound network requests, all privacy-preserving by design:
- Website icons. When “Fetch website icons” is switched on (Settings → General; on by default), NextVault shows the icon of each website you save. To find it, the app sends the website’s domain name (for example, example.com) to our icon service at iconserver.thingsmart.co. Our service tells the app where that website’s icon is, and the app downloads the icon directly from the website. If the website has no icon, our service provides a generated letter icon instead. If our icon service cannot be reached, the app requests the icon from Google’s favicon service instead, and Google then receives the domain name. Only the domain name is sent. The full web address, your usernames, passwords, notes and all other vault data are never sent. As with any internet request, our icon service, the website and, in the fallback case, Google can see your device’s IP address. You can turn this off at any time in Settings → General → Fetch website icons; icons already downloaded stay on your device.
- Password breach checking (HIBP) — The Password Health dashboard optionally checks your passwords against the HaveIBeenPwned API using k-anonymity: only the first 5 characters of a SHA-1 hash are sent. Your actual passwords are mathematically impossible to reconstruct from this data.
- Google Maps directions — When viewing an Address record, tapping “Get Directions” opens
https://www.google.com/maps/dir/?api=1&destination=<address>in your device’s browser or Maps app. Only the address text you have stored is transmitted. This request is user-initiated and subject to Google’s own privacy policy. - Current address — The “Get Current Address” feature uses your device’s GPS via Android’s
FusedLocationProviderClientto get your coordinates. To turn the coordinates into a street address, Android’s built-in address lookup service is used; on most devices this is provided by Google and receives the coordinates. This happens only when you tap “Get Current Address”.
C. Information You Provide via Our Website
When you visit https://thingsmart.co or contact us, we may collect:
- Name, email address, phone number, company name
- Message content submitted via contact forms or quote requests
D. Automatically Collected Website Data
- IP address, browser type and version, device information
- Pages visited, time spent, referring website
- Cookies and analytics tracking technologies
Lawful Basis for Processing (UK GDPR Article 6)
We process personal data under the following lawful bases:
- Consent — When you submit a contact form or opt in to marketing communications.
- Contractual necessity — When processing is necessary to provide services you have requested.
- Legitimate interest — To improve our website, prevent fraud, and operate our business efficiently.
- Legal obligation — When required to comply with UK law.
How We Use Your Data
We use information collected via our website and services to:
- Respond to enquiries and provide quotes and services
- Communicate about ongoing projects
- Improve our website and services
- Send marketing communications (only if you opt in)
- Comply with legal obligations
The NextVault app processes your credential data solely on your device. All encryption, decryption, search, and export operations are performed locally. The only outbound requests are website icon lookup (domain name only, no credentials), the optional HIBP breach check (k-anonymity, no plaintext passwords), user-initiated Google Maps directions (address text only, opened in your browser), and the user-initiated Current Address lookup (your coordinates, converted to an address by Android’s built-in address lookup service).
Cookies & Tracking Technologies
Our website thingsmart.co may use cookies and similar technologies to:
- Analyse website traffic (e.g. Google Analytics)
- Improve user experience and remember preferences
A cookie consent banner is displayed on the website allowing you to opt in to non-essential cookies before they are set. You can also manage cookies via your browser settings at any time.
CAMERA (document photos), ACCESS_FINE_LOCATION (Get Current Address only), INTERNET + ACCESS_NETWORK_STATE (website icon lookup, HIBP breach check, Google Maps directions, and Current Address lookup), and USE_BIOMETRIC.Data Sharing
We may share website and business enquiry data with trusted third-party service providers, including:
- Website hosting providers
- Email service providers
- CRM systems
- Analytics providers (Google Analytics)
All third parties are required to protect your data and process it only in accordance with applicable UK data protection laws.
International Transfers
If we transfer personal data outside the UK or EEA in the course of our website or business operations, we ensure appropriate safeguards are in place, such as:
- UK International Data Transfer Agreement (IDTA)
- Standard Contractual Clauses (SCCs)
Apart from the optional website icon lookup described below, NextVault app data does not leave your device and is therefore not subject to international transfer considerations.
Website icon lookup (NextVault): if our icon service cannot be reached, the app requests the icon from Google’s favicon service and Google receives the website’s domain name. Google may process this outside the UK or EEA, under Google’s own privacy policy and transfer safeguards. This fallback is not used when our icon service responds, and none of it occurs if you turn off Fetch website icons.
Data Retention
We retain personal data only for as long as necessary:
- Website enquiries — up to 12–24 months
- Client project data — for the duration of the contract and up to 6 years for legal and accounting purposes
- Marketing data — until you withdraw consent
For NextVault app data: your vault contents remain on your device until you uninstall the app, perform a factory reset, or manually delete the database via the app’s Settings. The in-app security audit log auto-prunes entries older than 90 days. Exported vault files (.nextvault) and encrypted backup files (.nvbackup) stored on your device or cloud storage are solely under your control. Backups also contain your Document Photos and website icons, each encrypted.
Your GDPR Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure (“Right to be Forgotten”)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
📱 For NextVault app data: your credentials are held exclusively on your device, encrypted under your master password. You have complete control — you can export (
.nextvault), delete individual records, or wipe the entire vault via Settings at any time. Thingsmart holds no copy of your vault contents.Data Security
We implement appropriate technical and organisational measures to protect personal data across our website and business operations, including SSL encryption, secure hosting, access controls, and regular software updates.
NextVault is built with a defence-in-depth security architecture. Every credential is protected by three independent encryption layers:
Additional security controls include: FLAG_SECURE on all screens (prevents screenshots and screen recording), 30-second clipboard auto-clear, configurable auto-lock on idle, anti-phishing phrase on the login screen, app integrity check (APK signing certificate verification), and a full security audit log stored locally.
Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK supervisory authority:
Website: https://ico.org.uk
We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO. Please contact us at in**@********rt.co in the first instance.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the NextVault app, our website, or applicable law. Updates will be posted on this page with a revised “Last updated” date. For material changes, we will update the app store listing accordingly.
The current version covers NextVault v2.0.0 (versionCode 2, package app.nextvault, min SDK 26, target SDK 35).
