Sanctum Privacy Policy
Last updated: 2026-09-18
1. Who We Are
Armlab BV (enterprise no. BE0899277201), Sint-Hubertusstraat 67, 3730 Bilzen-Hoeselt, Belgium, publishes Sanctum.
Sanctum stores your photo and video library in encrypted form on your devices and in your iCloud account. Armlab does not receive the keys needed to decrypt your vault or shared albums.
When you send a report or contact support, you choose information to disclose outside your vault. Armlab is responsible for our handling of those submissions and related support records. This policy covers both the app and sanctum.photos.
Contact support@sanctum.photos for privacy questions or data requests.
2. Your Vault, Keys, and iCloud
Photos and Videos
Sanctum encrypts photos, videos, and thumbnails on your device before uploading them to Apple’s CloudKit service. Personal media uses your vault key. Each shared album has a separate album key. Encryption uses AES-256-GCM with fresh random nonces.
The app decrypts media on your device so you can view, edit, or export it. Capture, editing, playback, and export can use temporary local files containing readable media. The app attempts to remove these files after use.
Importing an item does not automatically remove its original from Photos. If you choose to delete originals, check Photos, including Recently Deleted. Copies you export or share through other apps follow the destination’s storage and deletion rules.
Password, Biometrics, and Recovery
Your Sanctum password protects access to the vault key. The app stores a password-protected copy of that key in Apple Keychain, with iCloud Keychain synchronization. Optional Face ID or Touch ID unlock uses a separate copy protected on that device.
The device passcode alone does not replace your Sanctum password. Device authentication can protect access to the recovery screen, but recovery still requires your recovery phrase.
Your recovery phrase represents your vault key. Keep it secret. Armlab does not receive it and cannot replace it. Reinstalling or changing devices requires available encrypted data and a working way to recover the matching key. Neither a reinstall nor an iCloud sign-in guarantees recovery.
Visible Metadata
Content encryption protects media and selected fields such as filenames, album names, and comment text. Apple still processes technical and sharing information, including:
- Record identifiers, upload and modification times, record counts, and encrypted file sizes.
- Shared-album participants, public identity keys, permissions, and membership changes.
- References connecting shared items, comments, reactions, and their authors.
Album participants can see shared content and participant information needed for the album. Public identity keys are identifiers, not the private keys that unlock your vault. Your personal vault is not exposed merely by joining an album.
Removing a member changes access and rotates the album key. Removal cannot take back content or keys that the person already retained. Shared-album permissions also depend on participants using the app’s access controls.
3. Shared Content and Reports
Owner Approval in Shared Albums
Before publishing a member’s new photo or video, Sanctum encrypts it with a separate key for its author and the album owner. Other album members do not receive that key. The owner can open the pending upload, then approve or reject the exact version reviewed. Approval creates an encrypted album copy for participants. Owners can publish their own media directly.
The app records a signed approval or rejection. Pending and decided submissions remain encrypted in the shared album. A deliberate resubmission can replace the earlier submission. Ending sharing or deleting the album removes its cloud zone through the app’s cleanup process. The author’s personal original remains in Library unless they delete it separately.
Older albums require a sharing upgrade before new uploads can use this process. The upgrade preserves previously published media. Its confirmation explains changes to memberships, invitations, comments, reactions, and display names. Private Library media is not submitted for owner review.
Reports to Sanctum Support
Reports go to Sanctum support at support@sanctum.photos. Sanctum support reviews abuse reports within 7 days of receipt. Resolution may take longer.
An in-app report contains:
- A stable report ID, creation time, chosen reason, and your written explanation.
- The displayed album and target identifiers, including the item, comment, reaction, or participant being reported.
- The album name and reported author identifier when shown in the preview.
- A reply email, only if you provide one.
- Text or a reduced JPEG image, only if you choose to include that evidence.
The report screen shows the recipient and complete submission before you send it. The explanation requires 10–4000 characters. Optional text evidence has the same maximum. A selected JPEG attachment is limited to 256 KiB. The report does not include a video file, your whole vault, your password, your recovery phrase, or private encryption keys.
The app submits reports over HTTPS to our Cloudflare-hosted contact service. Brevo forwards the submission to our support inbox. Support, Cloudflare, Brevo, and our email provider process the submitted information. It is readable outside the vault’s encryption. We use it to assess the concern, communicate with you when possible, and record the action taken.
The report is not posted to the album. Album participants and the reported person do not automatically receive it. We limit access to people and providers needed to handle the report. We may disclose relevant information when law requires it.
“Accepted for forwarding” means our email service accepted the report. It does not establish delivery or human review. The report ID helps support identify retries and follow-up messages. Without a reply email, support cannot contact you for more information or send an outcome.
Reports Saved on Your Device
The app stores report drafts, pending submissions, and accepted receipts with their note and evidence in files encrypted for your vault. These local files remain until you delete the report or complete vault erasure. They are separate from the shared album and do not depend on its membership or encryption key.
Retries preserve the report ID and the information you reviewed. Leaving an album does not silently discard a pending report. Deleting a local report stops future retries for that entry, but cannot recall a request already sent or delete support’s copy.
Reports from Older App Versions
Older versions stored reports in shared albums. Album participants may still be able to read those records and notes. Updating the app does not make those existing records private, and the app does not automatically forward them to support.
Older unsent reports are moved into encrypted local drafts. They require your review before submission to support. Legacy data that the app cannot read is preserved locally in encrypted form rather than submitted automatically.
4. Support Messages and Website Traffic
The website contact form collects your name, email address, chosen topic, and message. Cloudflare handles the submission, and Brevo forwards it to our support inbox. Direct emails and any attachments you send are also readable by support and our email providers.
We use this information to answer your request, investigate problems, handle privacy requests, and prevent misuse of the support service. Do not send your vault password or recovery phrase. Include only the evidence needed for your request.
Our hosting and email providers also process technical information needed to operate their services, such as IP addresses, request details, and delivery records. Their service and security records follow the relevant provider’s retention rules. The contact handler does not create a separate database of report content.
We do not use support submissions for advertising or sell them. The app contains no advertising or third-party analytics SDKs. We do not use reports to build advertising profiles.
5. Local Diagnostics and Blocking
Sanctum keeps a local diagnostic log with recent app events, sync errors, and technical identifiers. The app regularly trims the log to about 200 lines. It stores the log as readable text within the app’s protected storage and does not automatically send it to Armlab.
If you choose to copy diagnostic information into a support request, that copy becomes part of the support correspondence. You can clear the local log using the app’s advanced diagnostic controls. Apple’s separate device diagnostics and iCloud services follow Apple’s policies and your Apple settings.
The local block list stores public identity identifiers. It hides blocked contributors’ media, comments, reactions, and profiles in shared views on this device. It also hides joined albums owned by a blocked person. Blocking preserves your personal Library and does not itself change membership or revoke another person’s access.
6. Retention and Deletion
| Information | How long it remains | How to remove it |
|---|---|---|
| Vault and shared-album data | Until deleted through the available app controls; synchronization affects completion | Delete items or use Erase All Data. Other participants’ copies can remain. |
| Vault keys and local app data | Until the corresponding cleanup completes | Use Erase All Data and clear local app data on your other devices. |
| Local reports, evidence, and receipts | Until you delete the local report or complete vault erasure | Use the report’s delete control or Erase All Data. |
| Reports and support correspondence held by Armlab | While the case is open, then 90 days after resolution | Contact support to request earlier deletion. A legal retention duty can require us to keep specific records longer. |
| Local diagnostic log | Recent entries, trimmed regularly | Clear the log or complete vault erasure. |
| Provider service records and backups | Under the provider’s applicable retention rules | Contact us about records we control; contact Apple about your Apple account data. |
The 90-day support period includes report attachments and related case notes. A reopened case remains active until it is resolved again. We limit any legally required longer retention to the relevant records. Deleting app data does not automatically delete a report or email already received by support.
Erasing the Vault
Open Settings → Erase All Data and follow both confirmations. Sanctum records a resumable request for the current iCloud account. It removes the private vault and owned shared albums, leaves albums owned by others, then removes local data and keys after cloud cleanup succeeds.
Keep the app installed and follow any retry instructions until Erasure complete appears. An interrupted erase can resume. Changing iCloud accounts does not authorize erasing data from a different account.
During some incomplete erasure stages, Recover remaining originals lets you export personal originals still present on this device. Recovery requires authentication. It does not restore deleted cloud data, reopen shared albums, or complete the erase. It becomes unavailable when local cleanup removes the files and keys.
Keep Sanctum closed on your other devices until their local app data is cleared. Those devices can retain and upload copies. Uninstalling alone does not erase iCloud content.
Individual deletion and comment expiry depend on app activity and successful synchronization. We do not promise a fixed deletion delay across devices. CloudKit acknowledgements do not establish when Apple removes its internal backup or service copies. Those copies follow Apple’s retention rules.
7. Purposes, Providers, and Your Rights
We process support information to provide requested help, investigate abuse, operate and secure the service, and meet applicable legal obligations. Where European data protection law applies, the relevant bases include providing the requested service, our legitimate interests in safety and support, and legal obligations.
Apple provides iCloud and Keychain services. Cloudflare hosts our website and contact service. Brevo handles form and report forwarding. These services can process information in countries other than your own. Their privacy information describes their handling and applicable transfer safeguards: Apple, Cloudflare, and Brevo.
Depending on applicable law, you can request access, correction, deletion, restriction, or portability of personal data we hold. You can also object to processing based on legitimate interests. Send requests to support@sanctum.photos, with the report ID if relevant. We may need enough information to verify your connection to the request. We will not ask for your vault password or recovery phrase.
You can view and export accessible media through the app. Armlab cannot decrypt inaccessible vault content in response to a data request. This limitation does not remove your rights concerning support data we hold.
You may complain to your local data protection authority, including the Belgian Data Protection Authority. Your legal rights are not limited by this policy.
8. Children and Policy Changes
Sanctum is not directed at children under 13. A parent or guardian can contact support about a child’s use or information submitted to us. Device parental controls and the app’s erasure controls can help manage access and stored content.
We publish policy updates on this page and link to the current policy in the app. The date above identifies the latest version. Changes that require a new choice or consent will be presented through the relevant app flow.