Koma Vault Privacy Policy
Effective date: 19 July 2026
1. Summary
Koma Vault is a local-first comic and manga reader. In the current release, Koma Vault does not operate a Koma Vault account service, developer-operated content library, advertising service, analytics service, or automatic crash-reporting service.
Most Koma Vault app data stays on your device or is sent directly from your device to servers that you configure. We normally receive personal information only when you choose to contact us for support, participate in testing, use the website, or interact with an app store or platform in a way that makes information available to us.
This Privacy Policy explains how Koma Vault (we, us, our) handles information in connection with the Koma Vault app, website, manual, and support channels.
2. Information stored on your device
Koma Vault may store the following information locally on your device:
- library records, comic titles, filenames, file paths, source signatures, page counts, covers, thumbnails, and ComicInfo metadata;
- imported comic files, downloaded offline pages, downloaded archives, cached covers, cached thumbnails, cached recent pages, and Offline Vault records;
- reading progress, reader settings, source settings, paused-source settings, storage settings, and app preferences;
- saved remote source names and URLs for Komga, Kavita, and OPDS sources;
- credentials, API keys, or authentication tokens for remote sources you configure;
- diagnostic settings and diagnostic log files, if diagnostics are enabled; and
- technical app data required for performance, caching, import, scanning, and maintenance features.
This information is used to provide app functionality on your device. We do not automatically receive this local app data.
3. Credentials and remote-source security
When you add a remote source that requires authentication, Koma Vault stores the relevant credentials or tokens locally on your device so the app can reconnect to that source.
Komga, Kavita, and OPDS credentials, API keys, and authentication tokens use platform secure storage. Legacy Komga database credential fields are retained only for retryable migration compatibility and are cleared after the secure copy is verified.
You should only add servers you trust. If a device is lost, shared, sold, repaired, or recycled, remove saved sources and uninstall the app, and consider rotating credentials on the relevant remote servers.
4. Information sent to user-configured servers
If you add a Komga, Kavita, OPDS, or other remote source, Koma Vault connects directly from your device to the server or catalogue you configure. Depending on the source and features used, that server may receive:
- server URLs, connection tests, and request headers;
- usernames, passwords, API keys, authentication headers, bearer tokens, or query tokens;
- browse requests, library requests, series requests, book requests, publication-detail requests, and search query text;
- page requests, thumbnail requests, cover requests, stream requests, and archive download requests;
- reading progress and progress-sync information; and
- technical request information such as IP address, user agent, timestamps, and server logs created by the remote server.
We do not operate or control user-configured servers. Their privacy and security practices are controlled by their operators. You should review the privacy practices of any server or catalogue you choose to add.
5. Diagnostics and support information
Diagnostic logging is off by default. If you enable diagnostics, logs are stored locally on your device. Logs are shared only when you choose to export them, attach them to a support request, or send them to us through a support channel.
If you contact us for support, testing, feedback, or legal/privacy questions, we may receive information you choose to provide, such as your name, email address, app version, platform, device details, support messages, screenshots, diagnostic logs, issue descriptions, and any other information you include.
Please do not send credentials, access tokens, private server URLs, personal IP addresses, or copyrighted comic pages unless we specifically ask for them and you are comfortable sending them through the nominated private support channel.
6. Website information
The Koma Vault website is a static product website and manual. In the current website code, we do not intentionally add advertising cookies or analytics tracking.
Website hosting providers, content delivery networks, browsers, app stores, GitHub Pages, or other platform providers may process technical information needed to deliver and secure the website, such as IP address, browser type, device type, referring page, request time, and pages visited.
If we later add analytics, contact forms, newsletters, crash reporting, advertising, or other hosted services, we will update this Privacy Policy before or when those features are introduced.
7. How we use information
We use information we receive to:
- provide, maintain, test, and improve Koma Vault;
- respond to support requests, bug reports, privacy questions, and legal requests;
- investigate crashes, errors, security issues, compatibility problems, and performance issues;
- publish website and manual content;
- manage beta testing, release readiness, app store submissions, and support workflows;
- comply with legal obligations and enforce our Terms and Conditions; and
- protect Koma Vault, our users, and the public from misuse, security threats, or unlawful activity.
We do not sell personal information. We do not use Koma Vault app data for advertising or cross-app tracking in the current release.
8. When we disclose information
We may disclose information:
- to user-configured servers, where disclosure occurs because you configure the app to connect to those servers;
- to service providers that help us host the website, distribute the app, manage support, process emails, store project materials, or operate app store listings;
- to Apple, Google, GitHub, or other platform providers when you use their platforms to access Koma Vault or contact us;
- if required by law, court order, regulator, law enforcement request, or to protect rights, safety, or security;
- in connection with a merger, sale, reorganisation, or transfer of the Koma Vault project or business; or
- with your consent or at your direction.
9. Overseas disclosure
We are based in Australia. Some platform, hosting, app store, support, repository, email, and infrastructure providers may process information outside Australia, including in the United States and other countries where those providers operate.
User-configured servers may be located anywhere in the world, depending on the server or catalogue you choose to add. We do not control the location or handling practices of those servers.
10. Retention and deletion
Local app data remains on your device until you remove it, clear it, delete saved sources, delete offline items, clear caches/logs, or uninstall the app. Some temporary caches may also be removed automatically by Koma Vault maintenance features or by the operating system.
Data stored on user-configured servers must be managed on those servers. Removing a source from Koma Vault does not necessarily delete data held by the remote server operator.
Support emails, support messages, logs, screenshots, and beta feedback are kept only for as long as reasonably needed for support, development, record-keeping, security, dispute management, and legal purposes. You can ask us to delete support information that identifies you, subject to any legal or operational need to retain it.
Koma Vault does not currently operate a Koma Vault account service, so there is no Koma Vault account to delete. If a future version adds accounts, we will update this Privacy Policy and provide account-deletion information where required.
11. Access and correction
If you want to access or correct personal information that we hold about you, contact us using the details below. We may need to verify your identity before responding.
We usually do not hold your local app library, reading progress, credentials, or comic files because they remain on your device. To access or change that local information, use Koma Vault's in-app features or your device's file and app-management tools.
For information held by a remote server you configured, contact the operator of that server.
12. Security
We take reasonable steps to protect information we receive. However, no app, device, network, website, storage method, or support channel can be guaranteed to be completely secure.
For remote sources, use HTTPS where available. If you configure an HTTP server, information sent between your device and that server may not be encrypted in transit. You are responsible for choosing trustworthy servers, protecting credentials, and keeping your device and server software up to date.
13. Children
Koma Vault is not directed to children and does not knowingly collect personal information from children. If you believe a child has provided personal information to us through a support channel, contact us and we will take reasonable steps to delete it where appropriate.
14. Third-party links and services
The website and app may refer or link to third-party projects, services, app stores, documentation, websites, or servers. Those third parties handle information under their own privacy policies. We are not responsible for their privacy or security practices.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date and publish the revised policy on the website or in another appropriate place.
If a future release adds developer-operated accounts, hosted sync, analytics, advertising, automatic crash reporting, payment processing outside app stores, newsletters, contact forms, or other material data practices, this Privacy Policy should be updated before or when those features are introduced.
16. Contact and complaints
For privacy questions, access or correction requests, deletion requests, or complaints, contact:
Koma Vault
[email protected]
https://komavault.com/support
No postal address is published for support requests.
During the private Google Play Internal test, testers can also use the private testing-feedback channel shown on the Play opt-in page.
We will try to respond within a reasonable time. If you are in Australia and the Privacy Act applies to our handling of your personal information, you may also have the right to complain to the Office of the Australian Information Commissioner if you are not satisfied with our response.