The data controller for Vault is:
The Vault team
Website: vaultwishlist.com
Contact: vaultwishlist@gmail.com
For any privacy-related request, email us at the address above with the subject "Privacy".
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address and password (hashed) | Creating and securing your account, sign-in, account recovery | Art. 6(1)(b), contract performance |
| Your vault content (saved items, titles, links, images URLs, prices, notes, lists, reminders) | Providing the core service: storing and syncing your wishlists across devices | Art. 6(1)(b), contract performance |
| Subscription status (Free, Keeper, Collector or Vaulter) | Activating paid features you purchased | Art. 6(1)(b), contract performance |
| Names entered by guests when reserving a gift on a shared gift list | Showing other guests that a gift is taken, to avoid duplicates | Art. 6(1)(f), legitimate interest of the list participants |
| Public profile (nickname, optional display name, avatar, bio) — only if you turn on a public profile | Letting other users find and view the profile you chose to make public | Art. 6(1)(a), your consent (you opt in and can turn it off anytime) |
| Social connections (who you follow, who follows you) and items you mark as public/featured — only if you use social features | Operating the follow system and showing your chosen public items on your profile | Art. 6(1)(a), your consent |
| Technical logs (IP address, timestamps) processed by our infrastructure providers | Security, abuse prevention, service operation | Art. 6(1)(f), legitimate interest |
We do not collect: payment card numbers (handled by Stripe), precise location, contacts, advertising identifiers, or advertising / cross-site behavioural profiles.
Passwords are never stored or transmitted in plain text. Authentication is operated by Supabase, which stores passwords using the industry-standard bcrypt hashing algorithm. Neither we nor Supabase can read your password.
We use a small number of service providers ("processors") to run Vault:
| Provider | Role | Location / transfers |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, backend functions, stores your account and vault data | Project hosted in the EU. Supabase privacy policy |
| Stripe (Stripe, Inc.) | Payment processing for Vault subscriptions, card data is entered on Stripe's own pages and never touches our servers | EU/US, Stripe participates in the EU-US Data Privacy Framework. Stripe privacy policy |
| GitHub Pages (GitHub, Inc.) | Hosting of the app's static files | Global CDN, GitHub participates in the EU-US Data Privacy Framework. GitHub privacy statement |
When you use "fetch data" on a product link, the request to read that page is made by our backend on your behalf; the target site sees our server's request, not your identity.
Vault uses only technical storage that is strictly necessary for the app to function:
We use no analytics, advertising, or profiling cookies. Because this storage is strictly necessary, it does not require consent under the ePrivacy rules, we show a notice for transparency. If you clear your browser storage, local data is removed (cloud-synced data remains in your account).
Stripe's checkout pages, which open on stripe.com when you subscribe, set their own cookies as an independent controller, see Stripe's policy linked above.
You have the right to:
To exercise any right, email vaultwishlist@gmail.com. We respond within 30 days.
Your account is private by default. Nothing you save is visible to anyone else unless you actively choose to make it so:
Because public profile fields are shown to others, please don't put anything there you wouldn't want to be public. We recommend using a nickname rather than your full legal name.
The paid Collector and Vaulter plans include optional "AI" features (taste profile, spending statistics, insights). These are computed on your own device from your own vault data — for example your average price, most-used category, or how many items you've bought. They produce a summary shown only to you.
This is not advertising or cross-site behavioural profiling: your vault content is never sold, never shared with advertisers, and is not used to track you across other websites or to build a marketing profile. We do not make automated decisions that produce legal or similarly significant effects about you (GDPR Art. 22).
Vault is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
If we make material changes, we will show a notice in the app before the changes take effect. The "last updated" date at the top always reflects the current version.
© 2026 Vault™ · All rights reserved. Vault™ and the Vault logo are trademarks of the Vault team.