We built Grovia Vault on a zero-knowledge foundation — we cannot read your backups even if we wanted to. This policy explains what we do collect, why, and how we protect it.
The short version: Your backup data is encrypted on your device before it reaches us. We hold the ciphertext, not the plaintext. Your encryption passphrase never leaves your device. Not even Grovia Vault staff can read your files.
Grovia Vault is a product of Webzworld, a company registered in India. References to "Grovia Vault", "we", "us", or "our" in this policy refer to Webzworld operating the Grovia Vault service. Our primary contact email is info@groviavault.com.
Your files are encrypted on your device using AES-256-GCM before transmission. We receive and store only encrypted ciphertext chunks. We have no ability to decrypt or access your file contents. Encryption keys are derived from your passphrase using SHA-256 key derivation and never transmitted to our servers.
We do not sell, rent, or broker your personal data to any third party.
All customer data — including encrypted backup ciphertext, account records, and telemetry — is stored in India (AWS Mumbai, ap-south-1). No personal data is transferred outside India except where you explicitly configure an international storage destination in your backup policy.
Air-gap copies may be stored on Backblaze B2 (EU) by default for disaster-recovery isolation. These copies are encrypted before leaving India and the receiving provider holds only ciphertext.
As a Data Principal under India's Digital Personal Data Protection Act 2023, you have the right to:
To exercise any of these rights, email info@groviavault.com with the subject line "Privacy Request". We will respond within 30 days.
The Grovia Vault website uses only essential session cookies required for authentication and CSRF protection. We do not use advertising trackers, third-party analytics SDKs, or behavioural profiling cookies. You can disable cookies in your browser; note that this will prevent you from logging into the dashboard.
We use the following sub-processors to deliver the service:
Each sub-processor is bound by a data processing agreement and may not use your data for their own purposes.
Grovia Vault is a business service intended for organisations and professionals. We do not knowingly collect data from individuals under 18 years of age. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
We will notify registered users by email at least 15 days before making material changes to this policy. The "Last updated" date at the top of this page will always reflect the current version. Continued use of the service after the effective date constitutes acceptance of the revised policy.
For privacy questions, data requests, or complaints:
We're happy to walk you through how Grovia Vault handles your data in plain language.
Contact us