This preview describes the proposed User License Agreement (the "Agreement") for the Unoctu Vault desktop package distributed by Unoctu ("we," "us," or the "Operator"). It is separate from the Unoctu Platform Terms, Privacy Policy, and Refund and Digital Delivery Policy, which are also currently preview-only. Paid checkout and package delivery remain disabled until the approved documents are published. Nothing in this Agreement reduces a right you have under an applicable open-source license or under mandatory consumer protection law; where this Agreement conflicts with such a right or license, that right or license controls.
1. Definitions
- "Account" — your Unoctu customer account used for catalog access, purchase records, entitlement records, and package delivery.
- "Download Grant" — a short-lived, signed authorization that permits an authenticated download of a private package artifact.
- "Device" — a computer or hardware device that you own or control.
- "Entitlement" — the access scope associated with your plan or purchase, as displayed at checkout or in your Account.
- "Integration Features" — optional capabilities connecting the Software with other programs, devices, or services, including browser integration through the KeePassXC-Browser extension and its native messaging proxy, auto-type, passkey support, hardware security keys (for example FIDO2 tokens), favicon or icon downloads, remote database locations accessed through configured protocols, and operating-system credential services.
- "Key File" — a file you choose as an additional or alternative unlock factor for a KDBX Database.
- "KDBX Database" ("Vault File") — the encrypted database file in the KeePass KDBX format that the Software creates, opens, or modifies at your direction.
- "Master Password" — the primary secret you choose to protect a KDBX Database.
- "Open-Source Licenses" — the licenses under which the Upstream Software and Third-Party Components are distributed, including the GNU General Public License version 2 or later and additional licenses identified in the package notices.
- "Package Materials" ("package") — collectively: installer artifacts delivered by Unoctu containing the Upstream Software; Unoctu's catalog presentation, metadata, release notes, SHA-256 hashes, signatures, Download Grants, launcher integration, and verification steps; and Documentation.
- "Recovery Material" — the Master Password, any Key File, hardware security keys, recovery codes or export files, and tested backups from which a KDBX Database can be restored.
- "Services" — Unoctu's delivery, verification, update-notification, entitlement, and support activities related to the package, as distinct from the Software itself.
- "Software" — the desktop password manager application included in the package: the official KeePassXC application with its bundled components, as delivered by Unoctu.
- "Third-Party Components" — components in the package whose copyright belongs to parties other than Unoctu or the KeePassXC Team, distributed under licenses identified in the package notices.
- "Update" — a revised package artifact, metadata refresh, or notice published by Unoctu from time to time.
- "Upstream Project" — the independent KeePassXC project (keepassxreboot/keepassxc) maintained by the KeePassXC Team.
- "Upstream Software" — the KeePassXC application as published by the Upstream Project.
- "you" ("Customer") — the individual who installs or uses the package and, if installed or used on behalf of an organization, that organization.
2. Interpretation
Headings are for convenience only. Singular words include the plural and vice versa. "Including" means "including without limitation." References to a policy include it as amended or replaced over time. This Agreement is written in English; the English text controls over translations except where applicable law provides otherwise.
3. What the Software is — and is not
The Software is a local desktop password manager based on the KeePassXC open-source project. It lets you create, open, and manage encrypted KDBX Databases containing passwords, passkeys, secure notes, attachments, TOTP seeds, and related credentials on your Device. Encryption, storage, and unlock happen locally using factors you control.
The Software is not, and Unoctu does not operate or provide: a hosted personal vault; a shared or team vault; a cloud backup service; a synchronization or conflict-resolution service; a password-recovery, vault-repair, or forensic service; or an escrow for secrets. Your Account exists for package access, Entitlement, delivery records, and support; it is not your vault. Through the normal Account and delivery flow, Unoctu does not receive the contents of a KDBX Database, Master Passwords, Key Files, passkeys, secure notes, attachments, or Recovery Material.
4. Acceptance, eligibility, and authority
By installing, copying, downloading through Unoctu delivery, or using the package or the Unoctu-specific portions of the Package Materials, you accept this Agreement. If you received the Upstream Software from another source, your rights come from the Open-Source Licenses regardless of this Agreement.
You represent that you have reached the age of legal majority or otherwise have capacity to contract under applicable law (or a parent or guardian accepted on your behalf where permitted), and that if you install or use the package in the course of employment or for an organization you are authorized to bind that organization, or the organization has separately agreed to these terms.
If you do not accept this Agreement, do not download, install, or use the Unoctu-delivered package components. You retain rights in the Upstream Software granted directly by the Open-Source Licenses from the Upstream Project or other authorized sources.
5. Relationship to other agreements; order of precedence
- Mandatory rights you hold by law always control.
- An Open-Source License controls the code it covers, including all rights it grants (use, study, modification, redistribution) and its conditions; those cannot be restricted by this Agreement.
- For the same subject matter concerning the Software itself, the applicable Open-Source License controls over this Agreement.
- This Agreement controls Unoctu-specific Package Materials and the Services to the extent they are not governed by clause 3.
- The Platform Terms govern Accounts, Entitlements, checkout, billing, refund administration, and platform conduct. Where they conflict with this Agreement about the package specifically, this Agreement controls for the package.
The Privacy Policy describes how Unoctu handles platform data. Product privacy behavior of the Software itself is described in sections 3, 10, and 11 and in the Upstream Project's own documentation.
6. License grant to Unoctu Package Materials
Subject to your compliance with this Agreement and to section 7, Unoctu grants you a non-exclusive, non-sublicensable, worldwide, royalty-free license, for the duration of this Agreement, to:
- download the package through authorized Unoctu channels while you hold a valid Entitlement or while the package is offered without charge;
- install the package on Devices you own or control;
- use the Software for personal or internal business purposes; and
- keep and continue using an installed copy of the Software after your Entitlement ends or Unoctu stops distributing the package, subject to sections 10 through 14 and to the Open-Source Licenses, which independently govern the Software.
This Agreement does not transfer ownership of anything. Unoctu does not sell the Software or any copyright in it. All rights not expressly granted are reserved by the Operator, except rights granted directly by an Open-Source License or by law. You may make archival copies of the installer as reasonably necessary for backup, consistent with the Open-Source Licenses.
7. Open-source software; upstream rights control
KeePassXC is copyright the KeePassXC Team and is licensed under the GNU General Public License as published by the Free Software Foundation, either version 2 or, at your option, any later version (GPL-2.0-or-later). The package also contains Third-Party Components under compatible licenses identified in the package notices, which may include GNU Lesser General Public License, BSD, MIT, CC0, and SIL Open Font License terms.
The Open-Source Licenses — not this Agreement — grant your rights to use, study, modify, and redistribute covered code, and impose conditions such as preserving copyright and license notices, providing corresponding source code where required, and documenting changes where required. Complete license texts accompany the package.
For the Upstream Software and any GPL-licensed Third-Party Components as distributed in this package, the complete corresponding source code is available at https://github.com/keepassxreboot/keepassxc and, for three years from your download, from Unoctu upon written request to jorgeruizwilliams@gmail.com (subject: "KeePassXC source request") or at https://unoctu.com/legal/notices/ where Unoctu publishes an R2 mirror of the exact tarball used for this package. This offer is made pursuant to GPL-2.0 §3(b) and is valid for anyone who receives the object code. Where the GPL requires warranty disclaimers and liability limits to travel with the program, those provisions apply as written in the license itself.
Nothing in this Agreement limits your rights under an Open-Source License, imposes additional restrictions on covered code beyond what the applicable license imposes, makes Unoctu a party to or guarantor of any Open-Source License between you and third parties, or creates any obligation of the Upstream Project or the KeePassXC Team toward you. The KeePassXC Team licenses its work "as is"; Unoctu does not modify those terms.
8. Trademarks and attribution
"KeePassXC," its name and logos, and their goodwill belong to the KeePassXC Team or their respective owners. "Unoctu" and "Unoctu Vault" identify Unoctu's delivery, presentation, and support of the package. Neither this Agreement nor your use grants rights in either party's trademarks except as permitted by trademark law or the respective owner. Unoctu is not affiliated with, endorsed by, or sponsored by the Upstream Project. Attribution, copyright statements, and notices included with the package must be preserved as required by the applicable licenses.
9. Restrictions on Unoctu Package Materials
Except where a right applies under law or an applicable Open-Source License, you may not:
- remove, obscure, or alter notices, hashes, signatures, attribution, or license information attached to Unoctu-specific Package Materials;
- redistribute or resell private package downloads, Download Grants, login links, or Entitlement access obtained through Unoctu;
- circumvent authentication, entitlement checks, rate limits, integrity verification, or other technical controls protecting Unoctu delivery;
- misrepresent the origin of the package, imply Unoctu endorsement of a redistribution, or present the package as official publication by the Upstream Project; or
- use the Services to violate applicable law, the Platform Terms, or the rights of others, including unlawfully collecting credentials of others.
These restrictions concern Unoctu's delivery and added materials and user conduct. They do not restrict your rights in the Upstream Software or Third-Party Components under the Open-Source Licenses.
10. Your vault data, credentials, and security responsibilities
The Software reads and writes, at your direction: local KDBX Databases; Key Files; attachments; configuration and settings; and integrations with operating-system credential services or hardware security keys that you enable. You are solely responsible for:
- choosing strong, unique Master Passwords and protecting them;
- safeguarding Key Files, passkeys, and hardware security keys, including physical security of tokens;
- maintaining independent backups of every KDBX Database and of Recovery Material, stored separately from the working copy;
- verifying that a backup actually restores before relying on it;
- securing your Devices, operating systems, browsers, browser extensions, provider accounts, and local networks; and
- deciding who may access a Device or Database you control.
Encryption protects data only as strongly as its secret. A lost Master Password with no Key File or hardware-key factor may be unrecoverable, and a damaged or overwritten Vault File without a backup may be lost permanently. Do not send a Master Password, Key File, recovery phrase or code, KDBX Database, secure note, attachment, or other secret to Unoctu support, an account form, or a checkout form. Unoctu cannot recover a lost Master Password, reconstruct a damaged database, or restore deleted data, and will ask you to rotate any secret shared by mistake.
11. Integration Features and network activity
Integration Features are optional and disabled until you configure them. When enabled, they may communicate with browsers and extensions on your Device, the operating system, configured remote storage providers, icon-download sources, and other endpoints implied by the feature. Network behavior depends on your configuration, Device, and the Upstream Software's implementation. Before enabling an Integration Feature, review its requested permissions and the terms and privacy practices of any provider involved. Unoctu does not host, proxy, synchronize, or back up data exchanged through Integration Features, and availability of a feature is not warranted.
12. Delivery, verification, updates, and changes
Unoctu may provide package metadata, release notes, SHA-256 hashes, signatures, installers, Updates, and related tooling. The native launcher may verify downloaded bytes against recorded hashes and signatures before starting an installer. Verification is a delivery-integrity measure against tampering and corruption during Unoctu distribution; it does not certify that the Upstream Software is defect-free, secure in every environment, or fit for any particular purpose.
Unoctu may add, change, pause, or stop distributing a convenience package, update channel, metadata, or Support at any time for operational, security, legal, or commercial reasons, subject to the Platform Terms' refund and notice rules. Stopping distribution does not uninstall the Software, delete local files, or revoke rights the Open-Source Licenses continue to grant. Where required by law or the Platform Terms, advance notice will be given of material changes affecting paid entitlements.
13. Support; scope and limits
Support, where offered, is provided by email through the published contact path on a reasonable-efforts basis. Support can address package delivery, installation issues attributable to the package, and questions about Unoctu-specific features. Support does not include recovering a Master Password or Key File; repairing, decrypting, or extracting damaged databases; forensic recovery; administering third-party accounts, browsers, providers, or devices; guaranteed response times or resolution; or ensuring every Integration Feature works everywhere. Unoctu may refer issues in the Upstream Software to the Upstream Project's public channels.
14. Acceptable use
You must comply with applicable law, this Agreement, the Platform Terms, and the licenses shipped with the software. You must not probe or test Unoctu systems without authorization; interfere with or disrupt the Services; impersonate another customer or Unoctu personnel; distribute malware; attempt to obtain another person's credentials or vault contents; attack systems you do not own; or misrepresent identity or location to evade sanctions, export controls, or lawful restrictions. Responsible disclosure of a genuine security issue through the published contact path is welcome.
15. Privacy boundary
Unoctu's handling of Account, payment, delivery, support, cookie, and analytics data is described in the Privacy Policy. Vault contents and Recovery Material stay local under your control and are not collected through normal account flows. If you enable Integration Features involving third-party providers, those providers process data under their own terms. Unoctu cannot sell or share vault data because it does not receive it.
16. Feedback
If you send Unoctu suggestions or other feedback about the package or Services, you grant Unoctu a perpetual, irrevocable, royalty-free, transferable license to use and incorporate that feedback without obligation or restriction, without identifying you as the source unless you request attribution. Feedback must not include secrets, vault contents, or confidential material.
17. No warranty
To the maximum extent permitted by applicable law, the Unoctu-specific Package Materials and the Services are provided "as is" and "as available," with all faults and without warranty of any kind. Unoctu disclaims all conditions, representations, and warranties, express, implied, or statutory, including merchantability, fitness for a particular purpose, accuracy, quiet enjoyment, non-infringement, and warranties arising from course of dealing or usage of trade. Unoctu does not warrant uninterrupted or error-free Service, corrected defects, detection of all tampering, continued availability, or function on every system.
Nothing here excludes or limits a warranty, condition, remedy, or consumer guarantee that cannot lawfully be excluded or limited, including under mandatory consumer protection law. Where such guarantees apply, you may be entitled to remedies this Agreement cannot take away.
18. Assumption of risk
Password management concentrates risk: one file holds the keys to many services. Data loss, lockout, or exposure can result from factors outside Unoctu's control — weak Master Passwords, lost Recovery Material, failed storage media, compromised Devices, malicious browser extensions, or user error. Unoctu's review, hashing, signing, and verification reduce but do not eliminate delivery risk. Maintain tested backups and recovery plans appropriate to the value of what you store.
19. Limitation of liability
To the maximum extent permitted by applicable law, neither Unoctu nor its officers, members, employees, suppliers, or service providers will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or anticipated savings, however caused and under any theory of liability, even if advised of the possibility. To the maximum extent permitted by law, Unoctu's total aggregate liability for claims relating to the package or Services will not exceed the amount you actually paid to Unoctu for the package or membership giving rise to the claim in the twelve months before the first event giving rise to liability, or fifty United States dollars (USD $50), whichever is greater.
These limitations do not exclude or limit liability that cannot be excluded or limited under applicable law, including fraud, fraudulent misrepresentation, gross negligence, willful misconduct, death or personal injury caused by negligence, mandatory statutory consumer remedies, or other non-limitable liability. Nothing here limits remedies an Open-Source License requires to flow from its licensor or creates liability for the Upstream Project or the KeePassXC Team.
20. Indemnification
To the extent permitted by applicable law, you will defend and indemnify Unoctu and its members, managers, employees, and agents against third-party claims, proceedings, and resulting damages, penalties, costs, and reasonable attorneys' fees arising from your breach of this Agreement, the Platform Terms, or applicable law; your use of the Services in violation of sections 9 or 14; or content or data you introduce into a KDBX Database or transmit through an Integration Feature. This does not require indemnification for claims arising from Unoctu's own breach, misconduct, or violation of law, and does not apply where indemnity demands against consumers are restricted by law.
21. Term and termination
This Agreement takes effect when you first accept it and continues until terminated. Rights under the Open-Source Licenses to the Upstream Software and Third-Party Components are governed by those licenses and are not terminated here; ending this Agreement does not erase a local vault file or revoke license-granted rights.
Unoctu may suspend or terminate your access to the Services — delivery, Download Grants, Updates, and Support — for material breach, abuse, security threats, fraud, non-payment, or legal or operational necessity, with notice where practicable and required by law. You may terminate at any time by ceasing use of the Services and uninstalling Unoctu-delivered components. Sections 10 and 16 through 27 survive termination, together with any provision that by its nature should survive. Termination of the Services does not cancel or create refunds; billing and refunds follow the Refund and Digital Delivery Policy and payment-provider rules.
22. Changes to this Agreement
Unoctu may amend this Agreement; the current version and effective date will be posted at this URL. Material changes affecting paid entitlements or consumer rights will be announced as required by law, ordinarily before taking effect. Installing an Update, refreshing a package, or using the Services after a change's effective date constitutes acceptance for subsequent use, subject to any consent requirement under applicable law. If you disagree with a change, you may stop using the Services; your license to installed Software continues per section 21 and the Open-Source Licenses.
23. Assignment
You may not assign or transfer this Agreement without Unoctu's prior written consent. Unoctu may assign or transfer it to a successor in connection with a merger, acquisition, reorganization, or sale of assets, or to a parent or affiliate, with notice where required by law. There are no third-party beneficiaries except as an Open-Source License itself provides.
24. Export, sanctions, and legal compliance
You represent that you are not located in, or a national of, any jurisdiction subject to comprehensive sanctions administered by the United States or other applicable authorities, and are not listed on any restricted-party list, to the extent such restrictions apply. You will comply with applicable export-control and sanctions laws, including laws regarding encryption software, and use the Software and Services only for lawful purposes.
25. Governing law and disputes
This Agreement is governed by the laws of the jurisdiction in which the Operator maintains its principal place of business, without regard to conflict-of-law rules. Subject to the next paragraph, courts located there with jurisdiction will handle disputes arising out of or relating to this Agreement or the package.
Nothing here deprives you of a forum, process, or remedy that mandatory law gives you. You may bring qualifying claims in small-claims court; use regulatory complaints, chargebacks, or statutory dispute processes; and rely on mandatory consumer protections of your residence where they apply and cannot be waived. Before filing suit, please contact Unoctu through the published support path.
26. General provisions
If a provision is held unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder stays in force subject to mandatory law. Failure to enforce a provision is not waiver; waivers must be written and signed. This Agreement, its referenced documents, and the Open-Source Licenses form the entire agreement about the package, without limiting non-waivable statutory rights. Notices may be given by posting at the published URLs, in-product messaging, or email associated with your Account.
27. Notices and contact
Operator: NaNZeta LLC
Business address: 2325 Granite Hill Dr
Jurisdiction: Texas, United States
Contact: jorgeruizwilliams@gmail.com
EULA URL: https://unoctu.com/legal/unoctu-vault-eula/
Source offer: Complete corresponding source for GPL-licensed components as distributed is available for three years at https://unoctu.com/legal/notices/ or by request to jorgeruizwilliams@gmail.com (GPL-2.0 §3(b)).
Report suspected package, delivery, or security issues through the published support path. Never include secrets, vault files, or Recovery Material in a report.