Privacy Policy
Last updated: July 2026
1. Introduction
This Privacy Policy explains what data vaultsuite.dev ("we", "us", "our") collects, how we use it, and your rights under the General Data Protection Regulation (GDPR). We are finalizing our formal GDPR compliance program; the commitments below apply today.
We are committed to privacy. Our core product is end-to-end encrypted — we cannot read your documents. This policy explains the minimal data we do collect to operate the service.
2. Data we collect
2.1 Account data
- Email address (for account creation and communication)
- Name (optional)
- Billing information (processed by Stripe; we do not store card numbers)
2.2 Usage data
- Instance metadata (creation date, status, storage usage)
- Login timestamps and IP addresses (for security auditing)
- Bandwidth consumption (for billing and fair-use enforcement)
2.3 Document data
We do not collect your document content. All documents are end-to-end encrypted. The encryption keys never leave your browser. We store only encrypted ciphertext, which we cannot decrypt.
3. How we use your data
We use your data to:
- Provide and maintain the Service
- Process payments and manage your account
- Send you important notices (security alerts, maintenance, billing)
- Monitor usage and prevent abuse
- Comply with legal obligations
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as necessary to provide the Service (see our subprocessor list).
4. Data storage and transfers
Your documents and your CryptPad instance are stored in the European Union (Amsterdam, Netherlands) and never leave it. Limited operational metadata — your account email and payment details — is processed by the vetted subprocessors below, under EU Standard Contractual Clauses where they operate outside the EEA.
Our subprocessors (Fly.io, Stripe, etc.) are also EU-based or have agreed to EU Standard Contractual Clauses (SCCs) where applicable.
5. Data retention
We retain your data for as long as your account is active. If you delete your account (or your subscription ends), your instance and its encrypted data are deleted immediately; residual daily backup snapshots age out automatically within 14 days.
We retain billing records for 10 years to comply with tax obligations.
6. Your rights under GDPR
Under GDPR, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Portability: receive your data in a machine-readable format
- Restrict processing: limit how we use your data
- Object: object to processing based on legitimate interests
- Withdraw consent: withdraw consent at any time (where processing is based on consent)
To exercise these rights, contact us at privacy@vaultsuite.dev. We will respond within 30 days.
7. Cookies
We use only essential cookies (session cookies for authentication). We do not use tracking cookies, analytics cookies, or advertising cookies.
8. Security
We implement appropriate technical and organizational measures to protect your data:
- TLS 1.3 for all connections
- Encryption at rest for backups
- Access controls and audit logging
- Regular security updates
See our Security page for details.
9. Children's privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or through the dashboard.
11. Contact
For privacy questions or to exercise your rights, contact us at privacy@vaultsuite.dev.
Our EU representative (if required) will be listed here once appointed.