VaultWeb — Privacy Policy

Last updated: July 12, 2026

VaultWeb ("we," "us") is built on a zero-knowledge architecture: we design the system so that we cannot read the contents of your notes, under any circumstances, including in response to a legal request — we simply do not hold the key.

1. What We Collect

Account data: email address, username, password hash (never your plaintext password), and account creation/login timestamps.

Encrypted vault data: your notes, stored as ciphertext. Encryption and decryption happen entirely in your browser using a key derived from your password via PBKDF2. This key is never transmitted to or stored on our servers.

Billing data: handled directly by Stripe, Inc., our Merchant of Record via Stripe Managed Payments. We receive only subscription status (active/canceled/plan type), not your full payment details — Stripe never shares your card number with us because we never receive it.

Technical data: IP address and basic request logs for security and abuse prevention, retained for 90 days.

2. What We Cannot See

Because encryption happens client-side before any data leaves your device, we cannot read your note content, note titles beyond what's needed for file paths, or attached files/images. This is a deliberate architectural constraint, not a policy promise — even if compelled by a court order, we have no technical means to decrypt your vault.

3. How We Use Data

Account and technical data are used solely to operate, secure, and support the service. We do not sell personal data, and we do not use your account data for advertising.

4. Third Parties

Stripe, Inc. — payment processing and tax compliance (Merchant of Record)
Hetzner Online GmbH — infrastructure hosting (Germany/Finland, EU-based)
Resend — transactional email delivery (account verification, password reset)

We share only the minimum data necessary with each of these providers to operate the service.

5. Data Location

Your encrypted vault data is stored on servers located in the European Union. See our infrastructure notes for current details.

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. You can export your full vault at any time from account settings. To request deletion of your account and all associated data, contact info@isalpi.com or use the in-app delete-account option.

7. Children

VaultWeb is not directed at children under 16, and we do not knowingly collect data from them.

8. Changes

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice.

9. Contact

Questions about this policy or your data: info@isalpi.com