Back to home

TwoWayVault

Your privacy

Privacy Policy

A plain-language explanation of how TwoWayVault handles the data needed to hold and find a private message.

Last updated August 9, 2026

What we collect

To operate TwoWayVault, we process the phone number you verify, the recipient phone number you enter, and the private message you choose to lock. We also process the technical data needed to protect the service, such as security and rate-limit records.

Verification codes are delivered through Telegram. Your phone number must be connected to Telegram for the current verification flow to work.

How we use it

We use this information only to verify access, create and retrieve vaults, prevent abuse, maintain your signed-in session, and operate the service.

TwoWayVault does not use locked-message content for advertising or profile people based on its content.

Where it is processed

TwoWayVault uses Cloudflare to host and protect the service, Turso to store service records, and Telegram Gateway to deliver verification codes. These providers process only the information needed to provide their part of the service.

Private messages and phone data are encrypted in storage. Encryption protects stored data, but this is not an end-to-end encrypted messaging service.

Retention and deletion

Verification requests expire after ten minutes. Signed-in sessions expire after thirty days unless you sign out sooner.

An active vault remains available until its sender deletes it or it is removed under our operational retention practices. Deleting a vault removes it from the product and cannot be undone.

Payments

Public payments are not currently available. If paid features are introduced, payment processing will be handled by Stripe and this policy will be updated before real charges are enabled.

Your choices

You can sign out from the account menu and delete vaults you created. A public support contact will be added here before general public launch so you can request help with your data.

Updates to this policy

We may update this policy as the service changes. When we do, we will update the date at the top of this page.