IronVault · IronMesh
Privacy policy
Last updated 30 September 2026
IronVault is a password manager and emergency vault. It is built so that we cannot read what you keep in it. This policy covers the IronVault website at vault.ironmesh.cloud, the IronVault apps for Android, iOS, Windows, macOS and Linux, and the IronVault browser extension for Chrome and Firefox.
Who we are
IronVault is operated by ATS All Technology Solutions (Pty) Ltd, South Africa. We are the responsible party under the Protection of Personal Information Act (POPIA). Contact us about privacy at privacy@ironmesh.cloud.
What we cannot see
Everything you store in IronVault is encrypted on your own device before it is sent to us, with keys made from your master password. That includes passwords, usernames, website addresses, notes, one-time-code secrets, passkeys, cards, files and the names of your vaults, folders and devices. We hold only the encrypted form. We cannot decrypt it, we cannot recover your master password, and we cannot hand your vault contents to anyone, because we do not have them.
What we do hold
- Your account: your email address, your role in your organisation's IronVault (if you use it through work), and the information needed to check your master password without learning it.
- Your devices: for each device you sign in on, its type (web, extension, desktop, Android or iOS), its public keys, and when it was last used. Its name is encrypted.
- Sharing and emergency access: who you have shared a vault with, and the email addresses of the people you name as emergency contacts. We email them when you set them up or when emergency access is requested.
- An activity log: records such as "signed in", "item viewed", "item filled" or "password sent to another device", with the time and the device. It never includes the contents of an item. You can see your own log; if you use IronVault through your organisation, its administrators can see the log for shared team collections.
- Push tokens: on Android (and iOS, when available), the token that lets us wake the app when something changes.
- Server logs: our servers briefly record IP addresses and the requests made, to stop abuse (for example repeated password guessing) and to fix faults.
What we use it for
Only to run IronVault: to sign you in, keep your devices in sync, deliver what you send between your own devices, send the emails the service needs, and protect the service against abuse. We do not sell personal information, we do not use it for advertising, and IronVault contains no advertising or tracking.
Services we rely on
- Google Firebase Cloud Messaging and Apple Push Notification service deliver wake-up messages to phones. A wake-up says only "something changed" and carries a random identifier. It never contains a password or any vault content; the app then fetches the encrypted data from us directly.
- Have I Been Pwned (api.pwnedpasswords.com), when you check your passwords for breaches. Your device sends only the first five characters of a SHA-1 hash of a password, and compares the answer itself. The password, and its full hash, never leave your device. Your organisation can turn this check off.
Your encrypted data and files are stored on IronMesh servers operated by ATS in South Africa. Our email is sent through our own mail servers.
The browser extension
To offer to fill and save passwords, the extension looks at the login forms on the pages you visit. This happens inside your browser: page contents and the addresses of the sites you visit are not sent to us. The extension talks only to vault.ironmesh.cloud and, if you have it installed, the IronVault desktop app on the same computer. It uses the clipboard only when you copy something from IronVault, or when you send a password to that browser from another of your devices, and it clears what it copied after about 30 seconds.
The apps
The Android and iOS apps fill passwords and passkeys in other apps and websites only when you choose to. They see which app or website is asking so they can suggest the right login; that stays on your phone. Unlocking with your fingerprint, face or phone PIN is handled by your phone; we never receive biometric data. A copy of your vault is kept on each device, encrypted, so it works offline.
How long we keep it
- A password sent to another of your devices is deleted as soon as that device receives it, and after two minutes if it never does.
- Deleted items are kept, encrypted, for a short time so your other devices learn they were deleted, then removed.
- Your account and everything in it is kept until you delete it or your organisation removes you. When you delete it, it is deleted seven days later (you can change your mind until then); encrypted file bytes whose keys are already destroyed can stay in our storage's recycle area for up to 35 days more.
Your rights and deleting your account
You can delete your account yourself in IronVault's Settings on the web, or from Settings in the Android or iOS app; how to delete your account explains the steps and what stays. You can also ask us what we hold about you, ask us to correct it, object to how we use it, or ask us to delete your account, by emailing privacy@ironmesh.cloud from the address you signed up with. Deleting your account removes your vaults, items, files, devices and emergency arrangements. If your account belongs to an organisation, it may ask us to keep its audit records for its own legal duties. You may also complain to the Information Regulator (South Africa), inforegulator.org.za.
Children
IronVault is not directed at children under 13, and we do not knowingly collect their information.
Changes
If we change this policy, we will update the date above, and tell you in the app or by email if the change is significant.