Verden is a local-first vault for the things that get you back into your accounts. What you enter is stored on your device, encrypted with a key that never leaves it, and — only if you turn it on — in your own private iCloud, still encrypted. There are no Verden accounts, no user database, no analytics, no advertising, no trackers and no third-party SDKs. We cannot read your vault, and no amount of asking us will change that, because we do not hold the key. This Privacy Policy is provided by Aleksandr Pavlov (Squirrel Apps), an independent developer.
There is exactly one service we operate, and it is a logo cache — see §7. It receives a public domain such as `netflix.com` and nothing about you.
1. What this covers
This policy covers the Verden app for iPhone and iPad and its Password AutoFill extension. Information you record about your own accounts, devices, documents and people is entered by you.
2. What Verden stores, and where
Verden holds what you put into it: services and how you get back into them, recovery addresses and phone numbers, backup codes, security-key details, device passports, documents and their attachments, notes, Wi-Fi credentials, software licences, developer secrets, seed phrases and private keys, emergency plans, trusted contacts, travel plans and a digital legacy plan.
All of it is encrypted on the device with your Vault Encryption Key using AES-256-GCM. That key is generated on the device, is never written to disk in the clear, and is never sent anywhere. It exists in memory only while your vault is unlocked.
If you turn on iCloud Sync, the same encrypted records are stored in your own private iCloud database under your Apple ID. Apple receives ciphertext, opaque identifiers, record sizes and timestamps — never content. We have no access to that database at all.
A few things are deliberately kept outside the vault because they contain nothing of yours: which categories Travel Mode hides on this device, the history of your last twenty recovery drills (the scenario, when you ran it and four counts — never an account or a label), and the cache of service logos.
3. What is never stored anywhere
Your Master Recovery Phrase is generated on the device, shown to you once, and stored nowhere — not on the device, not in iCloud, not with us. The same is true of the key that opens a Recovery Capsule you export. If you lose them, there is no escrow and no reset. That is the point of them, and it is stated in the app before you are asked to write one down.
4. Password AutoFill
AutoFill is off until you turn it on, in Settings → Password AutoFill. While it is off, no key and no file exist for the extension to read.
When it is on, Verden writes a second, much smaller store that the extension can open. It contains one record per account that has a password saved in Verden — five fields: an identifier, the service name, its domain, the username and the password. Nothing else from your vault is in it: not the recovery map, not your Master Recovery Phrase, not backup codes, seed phrases, private keys, documents, notes, attachments, device passports, plans or contacts.
That store stays on the device and is never synchronised. Its key is derived from your vault key rather than copied from it, and is held behind Face ID / Touch ID, so the extension must confirm it is you every time it fills something in.
Turning AutoFill off deletes the store and the key together.
The system tells the extension which website or app is asking for a password. The extension cannot see the rest of the screen, cannot read what you type, and cannot act on its own.
5. What Verden cannot see
Verden cannot read Apple Passwords, list the passkeys on your device, enumerate your accounts, or check with any service whether you have two-factor authentication switched on. Everything the app shows you — the Readiness score, the recovery map, every drill result — is built from what you entered or confirmed, and the app says so where it shows it.
Verden also has no way of knowing that anything has happened to you. The digital legacy plan is a document you prepare and hand over deliberately. Nothing is released on a timer, on a signal, or on inactivity.
6. Passwords, compared on the device
Passwords saved in Verden are compared with each other on the device, by fingerprint, so the app can tell you a password is reused. Those fingerprints exist only in memory while the comparison runs: they are never written to disk, never synchronised and never sent anywhere. We will not tell you they are irreversible — an unsalted hash of a weak password is not — which is exactly why they are never stored. The finding names the affected services, never the password. No breach database is consulted; Verden has no network path that could reach one.
7. Service logos (optional, switchable)
To show a recognisable logo next to a service, Verden can ask our own logo cache — a Cloudflare Worker we operate — for a logo by domain. That cache fetches from Brandfetch once and keeps the result for everyone, so Brandfetch is not contacted per user. If it has nothing, the app falls back to a site's favicon via DuckDuckGo.
The request carries only the service's public domain — for example `netflix.com`. No account data, no username, no identifier, nothing you typed into a record. As with any request to any website, our cache and those fallbacks necessarily see the IP address it came from; there is no account to attach it to and no profile is built.
Stated plainly, because it is the honest cost of the feature: a logo request tells that host which service one of your records concerns. Each domain is asked for at most once and then cached on your device, so it is not a running commentary on what you open — but it is not nothing either, and you should know it before deciding.
Privacy & Security → Load service logos turns this off entirely and clears the cache. Monograms are drawn instead, and the app is otherwise unchanged.
8. Network connections
Apart from the logo cache above, Verden makes exactly one kind of outbound connection: iCloud (CloudKit), and only when you have turned sync on. It carries ciphertext, opaque identifiers and timestamps, and is governed by Apple's privacy policy.
There is no other connection. The app is fully usable with the network off — the recovery map, the drills, emergency playbooks, Travel Mode and the legacy plan are all computed on the device.
9. Permissions
- Face ID / Touch ID — to unlock the vault and to authorise revealing, copying, exporting or deleting anything sensitive.
- Camera — only inside the QR scanner, to read a Master Recovery Phrase while restoring.
- Photos / Files — only through the system picker, which grants access to the one file you chose.
- Notifications — only if you turn reminders on. The text is fixed and contains no name, count or identifier; nothing derived from your vault reaches the lock screen.
Verden never writes to Photos or Files by itself. Exporting a Recovery Kit or an encrypted archive happens through the system share sheet, after authentication and an explicit warning.
10. Purchases
Verden Pro is sold through the App Store. Apple processes the payment; we never receive your card details, billing address or Apple ID. The app keeps a local flag for what is unlocked, and nothing else about the transaction.
Nothing to do with regaining access is ever behind the paywall. Your Master Recovery Phrase, your backup codes and exporting an encrypted archive work whether or not you have paid, and will continue to. A subscription that could lock you out of your own recovery data would defeat the purpose of the app.
11. Third parties
- Apple — CloudKit, if you enable sync; the App Store, for purchases.
- Cloudflare — hosts the logo cache we operate (§7).
- Brandfetch — the logo source behind that cache.
- DuckDuckGo — favicon fallback, used only when the cache has nothing.
There are no analytics, advertising, attribution or crash-reporting services, and no user database.
12. Deleting your data
- Settings → Privacy & Security → Delete local cache removes the local records and keeps the encrypted iCloud copy.
- Delete all vault data destroys the local records, every key envelope, the device key in the Keychain and — if sync is on — the iCloud zone. After that the data is unrecoverable, including by us.
- Turning AutoFill off deletes the password store and its key.
- Deleting the app removes its local container. If sync was on, the encrypted copy stays in your iCloud until you remove it in Settings → Apple ID → iCloud → Manage Storage.
Because we hold nothing of yours, there is no data-deletion request to send us. You are welcome to write with a question all the same.
13. A note on the name
Verden was called SafeHub while it was being built. Its bundle identifier, its iCloud container and the identifiers inside its cryptography still read `safehub`, and they will stay that way: changing them would derive different keys and every vault already in existence would stop opening. You may see the old name in iCloud storage listings. It is the same app.
14. Children
Verden is not directed at children and collects nothing from anyone, including children. It has no messaging, sharing or social features.
15. Changes
If this policy changes, the date at the top changes with it, and the previous text remains in the site's public history.
16. Contact
Questions about privacy: alexblessingx@gmail.com.
