Sanctum Terms of Use
Last updated: 2026-09-18
1. Your License
Armlab BV (enterprise no. BE0899277201), Belgium, publishes Sanctum. In these terms, “we” means Armlab BV and “you” means the person using Sanctum.
We grant you a limited, non-exclusive, non-transferable license to use Sanctum on your Apple devices for personal, non-commercial use. Apple’s applicable App Store usage rules also apply.
You must not sell, rent, sublicense, or redistribute the app. You must not remove its ownership notices or copy, modify, or reverse engineer it, except where applicable law permits.
2. Responsible Use
You must not use Sanctum to break the law, infringe another person’s rights, gain unauthorized access, or disrupt the app or its services.
Keep your vault password and recovery phrase secure. Anyone who obtains your recovery phrase and encrypted data may be able to read your vault. We cannot reset your encryption key or recover content without the required key material.
3. Rules for Shared Content
These sharing rules cover shared photos, videos, album details, profiles, comments, and reactions. Share only content that you have the right to share.
Do not share:
- Sexual exploitation or abuse of children, or other illegal content.
- Intimate images shared without the depicted person’s consent, including fabricated intimate images.
- Sexually explicit or pornographic content.
- Threats, harassment, stalking, hateful abuse, or another person’s private information without permission.
- Content that promotes violence, exploitation, or serious harm.
- Spam, scams, phishing, impersonation, or deliberately deceptive content.
Sanctum encrypts vault and shared-album content before uploading it to iCloud. We do not receive your vault password, recovery phrase, or album decryption keys. We cannot inspect your encrypted albums through a support request.
Shared albums require owner approval before other members can see a member’s new photos or videos. Pending uploads are encrypted for their author and the album owner. Owners publish their own media directly. Owners must review submissions and reject content that breaks these rules. Approval applies to the exact version reviewed.
Existing albums must upgrade sharing to use owner approval. Participants need an updated app. The upgrade screen explains its effect on memberships, invitations, and album comments. Previously published media remains part of the album. Your private Library is outside this review process.
4. Reports and Support Review
Use the report controls in a shared album or its Members screen to report content, an album, or a participant. You can also contact support@sanctum.photos.
Sanctum support reviews abuse reports within 7 days of receipt. Resolution can take longer, especially when we need more information.
Before sending an in-app report, review its recipient and contents. The report includes your chosen reason, explanation, report identifier, creation time, and the displayed album, content, or participant identifiers. It can include the displayed album name and author identifier. You can add a reply email and choose whether to include the offered text or image evidence.
Only the information shown in the report preview is submitted. Reports pass through Cloudflare and Brevo to support@sanctum.photos. Support and these service providers can read the submitted information. Your vault password, recovery phrase, and encryption keys are not part of the report.
New reports are not posted to the shared album or automatically sent to the reported person. “Accepted for forwarding” confirms that our email service accepted the submission. It does not confirm delivery, a completed review, or a moderation decision. Keep the report ID if you contact support about its status.
Pending reports remain encrypted for your vault on this device. Retries preserve the same report ID and evidence. Leaving the album or removing a member does not discard a pending report. Deleting a local report cannot recall a request already sent to support.
Older versions stored reports inside shared albums. Those records may remain accessible to album participants. The new report flow does not forward them automatically. Older unsent reports require your review before you send them to support.
We delete resolved reports, their attachments, and related correspondence 90 days after resolution, unless law requires longer retention. See our Privacy Policy for details.
5. Blocking and Album Controls
Blocking hides a person’s contributions and profile in shared-album views on this device. It also hides joined albums owned by that person. Your personal Library remains available.
A local block does not remove either person’s album membership or revoke access to content already shared. Album owners can use Block & Remove to block someone locally and attempt to remove their album access. Check the removal result. Members can block an abusive owner and leave the album.
Removal changes access to the album and rotates its encryption key. It cannot recall copies or keys a recipient already kept. Participants can also retain screenshots or exported copies.
Support can review information you submit, explain available controls, and respond to lawful requests. Sanctum has no central account-ban system. Support cannot decrypt your vault, remotely erase a participant’s device, or centrally delete encrypted album content.
6. Your Content and Privacy
You keep ownership of your content. Sharing gives the album’s participants permission to view it and use the actions allowed by the album’s settings.
Participants can see shared content and relevant participant information. Apple processes the identifiers, membership, permissions, and other technical metadata needed for iCloud sharing. Content encryption does not hide all of this metadata.
Exports and evidence you choose to send can create readable copies outside the encrypted vault. Deletion and comment expiry depend on synchronization and cannot erase copies others retained. Our Privacy Policy explains these limits.
7. Availability, Warranties, and Liability
To the extent applicable law permits, Sanctum is provided “as is” and “as available.” We do not guarantee uninterrupted service, error-free operation, or recovery of lost data. Keep a secure recovery phrase and check that important media is backed up.
To the extent applicable law permits, we exclude implied warranties and liability for indirect or consequential loss. Our total liability under these terms is limited to the lower of US$100 or the amount you paid for the app.
These limits do not exclude liability or consumer rights that applicable law does not allow us to exclude. Your mandatory consumer guarantees remain in force.
8. License Termination and Export Rules
We may end your license if you materially breach these terms. This contractual right does not give us remote access to your vault or a technical account-ban capability.
You must comply with applicable export and sanctions laws when using or distributing the app. The app includes encryption software.
9. Governing Law and Changes
Belgian law governs these terms. Mandatory protections and court rights available to consumers in their country of residence remain unaffected.
We publish changes here and show the current terms through the app. Sharing features may require acceptance of updated terms. If one provision is unenforceable, the remaining provisions continue to apply.
10. Contact
Armlab BV, enterprise no. BE0899277201
Sint-Hubertusstraat 67, 3730 Bilzen-Hoeselt, Belgium