← Back to Vault

Privacy Policy

Last updated: 22 September 2026 · Applies to vaultwishlist.com and the Vault app
In short: Vault stores your account email and the wishlist data you create, so the app can work and sync across your devices. We don't run ads, we don't sell your data, and we don't use advertising or cross-site tracking. Your account is private by default: nothing you save is public unless you choose to turn on a public profile or share a list. Payments are handled entirely by Stripe, we never see your card details.

1. Data Controller

The data controller for Vault is:

The Vault team
Website: vaultwishlist.com
Contact: vaultwishlist@gmail.com

For any privacy-related request, email us at the address above with the subject "Privacy".

2. What data we collect and why

DataPurposeLegal basis (GDPR)
Email address and password (hashed)Creating and securing your account, sign-in, account recoveryArt. 6(1)(b), contract performance
Your vault content (saved items, titles, links, images URLs, prices, notes, lists, reminders)Providing the core service: storing and syncing your wishlists across devicesArt. 6(1)(b), contract performance
Subscription status (Free, Keeper, Collector or Vaulter)Activating paid features you purchasedArt. 6(1)(b), contract performance
Names entered by guests when reserving a gift on a shared gift listShowing other guests that a gift is taken, to avoid duplicatesArt. 6(1)(f), legitimate interest of the list participants
Public profile (nickname, optional display name, avatar, bio) — only if you turn on a public profileLetting other users find and view the profile you chose to make publicArt. 6(1)(a), your consent (you opt in and can turn it off anytime)
Social connections (who you follow, who follows you) and items you mark as public/featured — only if you use social featuresOperating the follow system and showing your chosen public items on your profileArt. 6(1)(a), your consent
Technical logs (IP address, timestamps) processed by our infrastructure providersSecurity, abuse prevention, service operationArt. 6(1)(f), legitimate interest

We do not collect: payment card numbers (handled by Stripe), precise location, contacts, advertising identifiers, or advertising / cross-site behavioural profiles.

3. Passwords

Passwords are never stored or transmitted in plain text. Authentication is operated by Supabase, which stores passwords using the industry-standard bcrypt hashing algorithm. Neither we nor Supabase can read your password.

4. Where your data lives (processors)

We use a small number of service providers ("processors") to run Vault:

ProviderRoleLocation / transfers
Supabase (Supabase Inc.)Database, authentication, backend functions, stores your account and vault dataProject hosted in the EU. Supabase privacy policy
Stripe (Stripe, Inc.)Payment processing for Vault subscriptions, card data is entered on Stripe's own pages and never touches our serversEU/US, Stripe participates in the EU-US Data Privacy Framework. Stripe privacy policy
GitHub Pages (GitHub, Inc.)Hosting of the app's static filesGlobal CDN, GitHub participates in the EU-US Data Privacy Framework. GitHub privacy statement

When you use "fetch data" on a product link, the request to read that page is made by our backend on your behalf; the target site sees our server's request, not your identity.

5. Cookies and local storage

Vault uses only technical storage that is strictly necessary for the app to function:

We use no analytics, advertising, or profiling cookies. Because this storage is strictly necessary, it does not require consent under the ePrivacy rules, we show a notice for transparency. If you clear your browser storage, local data is removed (cloud-synced data remains in your account).

Stripe's checkout pages, which open on stripe.com when you subscribe, set their own cookies as an independent controller, see Stripe's policy linked above.

6. How long we keep data

7. Your rights (GDPR Articles 15–22)

You have the right to:

To exercise any right, email vaultwishlist@gmail.com. We respond within 30 days.

8. Security

9. Social profiles and public content

Your account is private by default. Nothing you save is visible to anyone else unless you actively choose to make it so:

Because public profile fields are shown to others, please don't put anything there you wouldn't want to be public. We recommend using a nickname rather than your full legal name.

10. AI insights (Collector & Vaulter)

The paid Collector and Vaulter plans include optional "AI" features (taste profile, spending statistics, insights). These are computed on your own device from your own vault data — for example your average price, most-used category, or how many items you've bought. They produce a summary shown only to you.

This is not advertising or cross-site behavioural profiling: your vault content is never sold, never shared with advertisers, and is not used to track you across other websites or to build a marketing profile. We do not make automated decisions that produce legal or similarly significant effects about you (GDPR Art. 22).

11. Children

Vault is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

If we make material changes, we will show a notice in the app before the changes take effect. The "last updated" date at the top always reflects the current version.

© 2026 Vault™ · All rights reserved. Vault™ and the Vault logo are trademarks of the Vault team.