VaultGuard
DemoHow it worksWhat you getPricingFAQDocs
Setup guideStart freeLog in
← Legal centre

Privacy Policy

Effective date: 24 August 2026 Last updated: 25 August 2026

This Privacy Policy explains how dropie s. r. o., trading as VaultGuard (“VaultGuard”, “we”, “us”), handles personal data on vaultguard.cloud, during signup, in the hosted administration service, and in VaultGuard Sync (Cloud) (together, the “Service”).

It does not govern a Self-Hosted Community Edition deployment. The person or organisation operating that deployment determines its own privacy responsibilities.

1. Controller and contact

For account, billing, website, security, and support processing, the controller is:

  • Controller: dropie s. r. o.
  • Company identification number (IČO): 57 627 070
  • Registered office: Gagarinova 18127/10A, 821 05 Bratislava – mestská časť Ružinov
  • Country: Slovak Republic
  • Email: support@vaultguard.cloud

For content and personal data that a customer puts in a managed vault, the customer is normally the controller and VaultGuard is its processor. The Data Processing Addendum governs that processing.

2. What we collect

Account and organisation data

We process email address, display name, organisation name and slug, role, membership, authentication status, optional MFA settings, and account lifecycle information. Signup transmits the password over TLS to the signup service and Amazon Cognito; VaultGuard does not retain the plaintext password in its application database.

Billing data

We process plan, seat count, subscription status, Stripe customer and subscription references, payment amount, currency, and billing timestamps. Stripe handles payment-card and bank details. VaultGuard does not store full card numbers or security codes.

Vault content and metadata

Supported file bodies are encrypted on the device with AES-256-GCM before upload and are stored in Amazon S3 as ciphertext. To provide sync, permissions, recovery, sharing, and audit features, we also process service-visible metadata such as:

  • organisation and vault identifiers and vault names;
  • filenames, relative paths, sizes, versions, timestamps, and sync cursors;
  • memberships, roles, permission rules, shares, and key-lease records;
  • wrapped data-encryption keys and key references;
  • audit and operational events.

VaultGuard Sync (Cloud) uses KMS-backed server-managed key custody. Authorised service paths can unwrap keys and process plaintext transiently, including key-lease issuance, a permitted limited-access file read, version recovery, and re-encryption work. The managed service is therefore inside the trust boundary and is not a zero-knowledge system. We do not retain plaintext file bodies as the ordinary stored copy.

Local exclusions, application caches, Local Project Memory Mode content, and files visibly waiting for safe encrypted upload can remain plaintext on the user’s device. Customers control the devices and local vault folders they use with the Service.

Authentication, audit, and security data

We process IP address, user agent, request and response metadata, authentication events, session and verification records, security signals, audit events, and diagnostic information needed to protect and operate the Service. Audit records describe service operations; they do not observe every local file read on a device.

Cloudflare Turnstile processes browser, device, network, and challenge signals on signup and sign-in verification surfaces to distinguish people from abuse. It is treated as a necessary security tool, not an advertising tool.

Support and communications

We process messages, contact details, and attachments that a person chooses to send to support. Transactional messages such as invitations, verification, security, billing, and service notices are delivered through Amazon SES or the applicable billing provider.

Website and campaign measurement

Optional marketing tools load only after a visitor accepts them. They include Google Tag Manager, Google Analytics, Google Ads measurement, Apollo website visitor tracking, and the Meta Pixel. Depending on the tool, they process page URL, referrer, approximate location derived from IP, browser and device information, advertising identifiers, and interactions with our public pages.

If signup marketing consent is affirmative, VaultGuard can also send Meta a conversion event for registration and later trial or purchase milestones. Matching data can include a SHA-256-hashed email address, a hashed opaque organisation identifier, IP address, user agent, source URL, and Meta attribution identifiers. It does not include vault contents, filenames, paths, or encryption keys.

The Cookie Policy provides the current tool, storage, retention, consent, and opt-out details.

User-directed AI services

AI prompts and responses are not routed through VaultGuard’s managed API. When a user configures an AI provider or approved desktop agent, relevant content can be sent directly from the user’s device to that provider under the user’s account and the provider’s terms. VaultGuard can process scoped agent-bridge authorisation and audit metadata, but the customer chooses the provider and decides what to send.

3. Why we process data

Purpose Typical data GDPR basis where applicable
Create accounts and provide the Service Account, organisation, vault metadata, ciphertext, support data Contract
Authenticate users and protect the Service Authentication, network, device, audit, and security data Contract and legitimate interests in security and abuse prevention
Administer subscriptions and invoices Account, plan, transaction, and tax data Contract and legal obligation
Send essential service communications Account and service event data Contract and legitimate interests
Improve reliability and answer support requests Diagnostics, support communications, operational metadata Contract and legitimate interests
Measure campaigns and public-site use Website, device, and attribution data Consent where required
Establish, exercise, or defend legal claims and comply with law Relevant account, billing, audit, or content data Legal obligation and legitimate interests

Where we rely on legitimate interests, we balance those interests against the person’s rights. Consent can be withdrawn without affecting processing that was lawful before withdrawal.

4. Who receives data

We disclose personal data only as needed to:

  • infrastructure, authentication, email, security, support, and payment providers listed on the Subprocessor List;
  • optional measurement and advertising partners after consent;
  • professional advisers subject to confidentiality;
  • authorities or other parties when required by law or necessary to protect rights, users, or the Service;
  • a successor in a merger, financing, reorganisation, or sale, subject to applicable notice and protection requirements.

We do not sell personal data for money. Disclosures to optional advertising or measurement partners may be considered “sharing”, targeted advertising, or a sale under some US state privacy laws. Visitors can opt out through Only necessary, Cookie settings, or a recognised Global Privacy Control signal.

5. International transfers

The managed service’s primary AWS region is eu-central-1 (Frankfurt, Germany). Some providers or authorised support operations can process data in other countries. Where transfer law requires it, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK addendum or another approved mechanism, and supplementary technical and organisational safeguards as appropriate.

6. Retention

We keep personal data only for the purpose for which it was collected, including security, contractual, accounting, and legal requirements:

Category Typical retention
Active account, organisation, vault metadata, and ciphertext While the account or subscription is active
Audit records Customer-configurable; the managed-service default is 365 days
Production application and security logs Up to 365 days under the current production configuration
Noncurrent object versions and protected recovery copies Removed through configured lifecycle controls; noncurrent S3 versions can remain for up to 365 days
Billing and tax records For the statutory accounting and tax period
Support communications While needed to resolve the request and for reasonable legal or security follow-up
Consent preference 180 days, then the site asks again
Optional vendor identifiers As described in the Cookie Policy or until cleared

After termination or a valid deletion request, VaultGuard deletes or de-identifies data that it no longer needs. Protected copies can remain until their normal lifecycle expires and are not used for ordinary service access. We can retain limited records where law, fraud prevention, dispute resolution, or enforcement requires it.

7. Your choices and rights

Depending on where a person lives, they may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. California and other US state residents may also have rights to know, correct, delete, and opt out of sale, sharing, or targeted advertising.

To exercise a right, email support@vaultguard.cloud. We may ask for information needed to verify identity and authority. If VaultGuard processes the data only for a customer, we will direct the request to that customer or help it respond.

Marketing preferences can be changed through Cookie settings on the website or signup screen. A recognised Global Privacy Control signal is treated as an opt-out on that browser.

8. Security

Measures include device-side AES-256-GCM file-body encryption, KMS-wrapped server-managed keys, HTTPS using TLS 1.2 or newer with TLS 1.3 when negotiated, Cognito authentication with optional MFA, vault-scoped authorisation, time-bounded key leases, IAM controls, WAF protections, versioning and recovery controls, and service audit records.

No security measure eliminates all risk. The Cloud security guide explains the important boundaries, including service-visible metadata and authorised managed operations.

9. Children

The Service is not directed to children under 16, and we do not knowingly create accounts for them. Contact us if you believe a child has provided personal data.

10. Automated decisions

VaultGuard does not make solely automated decisions about individuals that produce legal or similarly significant effects. Fraud, security, and anti-abuse signals can cause a challenge, delay, or review.

11. Changes

We will update the date at the top when this Policy changes. We will provide additional notice for material changes when required by law or contract. If a change requires consent, we will ask for it.

12. Contact and complaints

Email support@vaultguard.cloud, or write to the controller at the address in section 1. EEA residents may complain to their local supervisory authority; the Slovak supervisory authority is the Office for Personal Data Protection of the Slovak Republic.

VaultGuard · Last updated 25 August 2026

Legal centrePrivacyCookiesTermsAcceptable useDPASubprocessorsCancellationLegal notice
VaultGuard

Break the ceiling. Build the keep.

An encrypted company brain, grown on the Obsidian you already use.

Product

What you getPricingDocsSetup guideAdmin panel

Open source

GitHubLicense (fair code)Community

Company

Our storyContactLegal notice

Legal

Legal centrePrivacyCookiesTermsAcceptable useDPA

VaultGuard builds on Obsidian. Obsidian is a trademark of its owners. Your vault stays yours, in plain markdown, always.

Cookies

Essential cookies keep this site running. Optional ones show us how people find VaultGuard and which parts they actually use. You can change your choice at any time. See our cookie policy for more information.