What Vaulto does
Vaulto lets you share documents that are encrypted on your phone before upload, and control who can open them, for how long and how many times.
Data we process
- Account: your email address, display name and password (stored hashed by our authentication provider).
- Documents: the encrypted file, its name, type, size, upload time and the rules you set (expiry, watermark options). File contents are encrypted on your device. Each file's key is stored on our servers, itself encrypted, so that we can release it to people you allowed. We do not look at your documents.
- Sharing: email addresses you share documents with, view limits and view counts, and share links you create (we store only a hash of each link).
- Activity logs: when a document is uploaded, shared, opened, closed or access is denied, and security events reported by the app (screenshot attempts, screen recording, leaving the app while viewing, rooted or debugged devices). Each entry includes the viewer's email, time, device model, Android version, app version and a short device identifier derived from, but not equal to, the device ID. Document owners can see the logs for their documents.
- Subscriptions: if you buy Vaulto Pro, Google Play handles the payment and gives us the purchase: the plan, its price and currency, purchase, renewal and expiry dates, and a store transaction identifier. RevenueCat, our subscription provider, receives that purchase information together with your Vaulto account identifier (a random ID, not your email address) and basic technical details such as the app version and device type. Our server stores only whether you have Pro and until when, and how much of your monthly sharing allowance you have used. We never receive your card or other payment details.
- Beta waitlist: if you join the beta on our website, the email address and optional name you enter, whether you use Android, and when you joined. We use it only to invite you to test Vaulto and to tell you when it launches.
- Beta testing: when we invite you, we add that email address to our tester group on Google Groups and our test on Google Play, where Google's terms and privacy policy apply. We remove you whenever you ask.
- Website visits: our website uses Vemetric, a web analytics service, to measure visits, such as which pages are viewed and how visitors arrived, and actions on the site, such as opening an FAQ answer, trying a demo or joining the beta waitlist. These events never include your email address or name. Vemetric is not used on the page that opens links shared with you (vaulto.pro/open), so share-link tokens are never sent to it.
The Vaulto app contains no advertising, analytics or tracking SDKs. It includes RevenueCat's purchases SDK, which starts only when you open the Vaulto Pro screen and is used only to buy, restore and check subscriptions. We do not sell personal data.
Why we process it
To provide the service you asked for (contract), to keep documents secure and give owners an audit trail (legitimate interest), to understand how our website is used so we can improve it (legitimate interest), and to meet legal obligations.
Service providers
Our website uses Cloudflare hosting and Vemetric web analytics. Google Play processes payments for Vaulto Pro. RevenueCat (RevenueCat, Inc., United States) receives your purchase information and Vaulto account identifier to confirm your subscription, keep it up to date when it renews, is cancelled or refunded, and show us totals such as how many people subscribe. We do not receive your full payment-card details.
We use Supabase for database, authentication and encrypted file storage, with our project hosted in Tokyo, Japan (ap-northeast-1). Supabase sends account emails through Resend, our email delivery provider. Those providers may process operational or delivery data in other locations under their own service arrangements.
How long we keep it
- Documents stay until you delete them. Documents with an expiry date are deleted 7 days after they expire.
- Activity logs are kept for up to 365 days, and are deleted together with their document.
- Whether you have Pro, and your sharing allowance use, are deleted with your account. Google Play and RevenueCat keep purchase records under their own retention periods; you can ask us to delete your RevenueCat record at support@vaulto.pro.
- Waitlist entries and tester group memberships are kept until the beta ends, or until you ask us to remove yours at support@vaulto.pro.
- When you delete your account, your account, documents, shares, links and logs are deleted, and your email is removed from other people's activity logs. Invitations other people sent to your email are withdrawn, so they no longer give access; the person who sent one can still see that they invited your address until they delete that document.
Removal from the active service and encrypted-file cleanup may finish at different times. Provider backups can retain copies until their retention period ends. Payment providers may retain transaction records for their own legal and accounting requirements. Contact support for questions about a deletion request.
Your rights
You can view and change your name, change your password and delete your account in the app (Profile → Delete account). You can also contact us at support@vaulto.pro to access, correct, export or delete your data, or to object to processing. For instructions without the app, visit Delete your Vaulto account. You may complain to your data protection authority.
Security
Files are encrypted with AES-256 before upload, all traffic uses HTTPS, and access rules are enforced on the server. No system is perfectly secure: the service operator could technically decrypt files, and nothing can prevent someone photographing a screen. Watermarks can help identify the source of a disclosed copy, but are not proof of who disclosed it.
Children
Vaulto is intended for people aged 16 and older. Contact support@vaulto.pro if you believe a child has provided personal information.
Changes
We will post updates on this page and update the date above.