Privacy Policy
Last updated: September 28, 2026
Summary
Ovik does not collect, store, or transmit any personal data. The app works entirely offline on your Mac. There is no server, no account system, no analytics, and no tracking of any kind.
What Data Ovik Accesses
Ovik accesses only the vault directory that you explicitly select using the system file picker. This access is limited to:
- Reading encrypted files from the vault directory to decrypt them locally
- Writing encrypted files to the vault directory when you add or modify files
- Writing a short plain-text file,
README-Ovik.txt, when you create a vault, explaining that the folder is an encrypted vault. It contains no vault name, date, user name or other personal information.
Ovik does not scan, index, or access any other files or directories on your Mac.
Data Collection
Ovik collects no data whatsoever:
- No personal information
- No usage analytics or telemetry
- No crash reports sent to external services
- No advertising identifiers
- No tracking of any kind
Network Access
Ovik makes no network connections. It does not communicate with any server, API, or external service. All encryption and decryption happens locally on your device.
If your vault folder is inside iCloud Drive, Dropbox, Google Drive, or another synced folder, that service's own app uploads the encrypted files. Ovik is not involved in that transfer, and those files are already encrypted before they are written.
Encryption
Your vault password is used to derive encryption keys locally on your device using the scrypt algorithm. The password and derived keys are never transmitted anywhere. When you lock a vault, keys are erased from memory.
Starting with the next update, on a Mac with Touch ID, after you first unlock a vault with its password, Ovik saves that password in your Mac's Keychain so you can unlock with Touch ID next time. It is protected so that it can be read only after a successful Touch ID check, it stays there after you lock the vault, and it is never synced to other devices. It becomes unusable if you change your enrolled fingerprints. You can turn off Touch ID for any vault in Ovik's Settings, which deletes the saved password; Ovik then won't save it again unless you turn Touch ID back on for that vault.
Third-Party Services
Ovik uses no third-party SDKs, analytics services, advertising frameworks, or external services of any kind.
Data Storage
The only data Ovik stores is:
- App preferences (via UserDefaults), such as auto-lock time and menu bar settings
- Vault list and folder bookmarks: the names of your vaults and security-scoped bookmarks that let Ovik reopen the folders you selected
- Unlock session data, only while a vault is unlocked: the vault password in your Mac's Keychain (this device only), plus session state and an encrypted working copy of the vault in the container shared between the app and its Finder extension. All of this is deleted when you lock the vault.
- Touch ID password, on Macs with Touch ID, unless you turn it off (see Encryption above)
While a vault is unlocked, macOS keeps local copies of the files you open so Finder can show them. When you lock the vault, Ovik asks macOS to remove these copies and removes the vault from Finder.
All of this data stays on your Mac, in the app's sandboxed containers and your Keychain.
Children's Privacy
Ovik does not collect any data from anyone, including children.
Changes to This Policy
If this privacy policy is updated, the changes will be posted on this page with an updated date. Since Ovik collects no data, meaningful changes are unlikely.
Contact
If you have questions about this privacy policy, please contact us at [email protected].