The Vault logo

The Vault

Privacy Policy

Last updated: 21 August 2026

The Vault is a private service for one household. This page explains, in plain terms, what it actually does with information — based on how the service is really built, not on a generic template.

You need an account

The Vault requires you to sign in. There is no anonymous or guest access, and access is limited to accounts that have been explicitly approved for the service. Approval is checked by the server on every request, so removing an account's access takes effect immediately rather than at the next sign-in.

Passwords and sessions

Your password is used to sign you in. The Roku app does not intentionally keep your password after authentication — what it retains is the access token the sign-in produces, stored in the Roku channel's own private per-user storage on your device, so you are not asked to sign in every time you open the app.

If you choose the option to save credentials on the sign-in screen, that choice is yours and is handled by the app's sign-in flow. Signing out clears the stored session on that device.

What the service processes

Running The Vault means the private server processes information including:

We would rather be accurate than flattering: this is a service that maintains sign-ins, playback positions, requests and storage accounting, so it plainly does hold information about your use of it. It is not a "we collect nothing" service and does not claim to be.

What it is used for

This information is used to operate the service and to keep it secure — signing you in, playing media, tracking requests, applying storage limits, and investigating problems or misuse. It is not used to build advertising profiles.

Artwork and catalogue data

To show posters, backdrops and details for titles you can request, the app loads artwork and catalogue information from the media server and from a third-party movie/TV metadata image service. Those requests are made to display the catalogue; they are not used to identify you to anyone.

Separation between accounts

The Vault is designed so that one account is not shown another account's private administrative information. Storage figures, requests and management actions are scoped to the account making them. Some things are shared by nature — a title in a shared library is visible to the people who have access to that library, and removing shared media will affect the other people who could watch it. The app tells you when that is the case before you confirm.

Retention

Account, playback, request and quota information is kept for as long as it is needed to run the service. Server-side audit and security records may be retained after the related media or request is gone, because their purpose is to provide an accurate history of what happened.

Sharing

Information is not sold, and is not shared for advertising purposes. The Vault runs on infrastructure and platforms operated by others — including Roku for the device and channel platform, and internet and network providers carrying the traffic. Those companies handle data according to their own policies, which are outside The Vault's control.

Your questions

For questions about your account, your access, or the information the service holds about you, please contact us through the support page.

Changes

The Vault is actively developed, and this policy may be updated as the service changes. The "last updated" date above will change when it does.