Privacy Policy
Effective date: 24 August 2026 Last updated: 25 August 2026
This Privacy Policy explains how dropie s. r. o., trading as VaultGuard (“VaultGuard”, “we”, “us”), handles personal data on vaultguard.cloud, during signup, in the hosted administration service, and in VaultGuard Sync (Cloud) (together, the “Service”).
It does not govern a Self-Hosted Community Edition deployment. The person or organisation operating that deployment determines its own privacy responsibilities.
1. Controller and contact
For account, billing, website, security, and support processing, the controller is:
- Controller: dropie s. r. o.
- Company identification number (IČO): 57 627 070
- Registered office: Gagarinova 18127/10A, 821 05 Bratislava – mestská časť Ružinov
- Country: Slovak Republic
- Email: support@vaultguard.cloud
For content and personal data that a customer puts in a managed vault, the customer is normally the controller and VaultGuard is its processor. The Data Processing Addendum governs that processing.
2. What we collect
Account and organisation data
We process email address, display name, organisation name and slug, role, membership, authentication status, optional MFA settings, and account lifecycle information. Signup transmits the password over TLS to the signup service and Amazon Cognito; VaultGuard does not retain the plaintext password in its application database.
Billing data
We process plan, seat count, subscription status, Stripe customer and subscription references, payment amount, currency, and billing timestamps. Stripe handles payment-card and bank details. VaultGuard does not store full card numbers or security codes.
Vault content and metadata
Supported file bodies are encrypted on the device with AES-256-GCM before upload and are stored in Amazon S3 as ciphertext. To provide sync, permissions, recovery, sharing, and audit features, we also process service-visible metadata such as:
- organisation and vault identifiers and vault names;
- filenames, relative paths, sizes, versions, timestamps, and sync cursors;
- memberships, roles, permission rules, shares, and key-lease records;
- wrapped data-encryption keys and key references;
- audit and operational events.
VaultGuard Sync (Cloud) uses KMS-backed server-managed key custody. Authorised service paths can unwrap keys and process plaintext transiently, including key-lease issuance, a permitted limited-access file read, version recovery, and re-encryption work. The managed service is therefore inside the trust boundary and is not a zero-knowledge system. We do not retain plaintext file bodies as the ordinary stored copy.
Local exclusions, application caches, Local Project Memory Mode content, and files visibly waiting for safe encrypted upload can remain plaintext on the user’s device. Customers control the devices and local vault folders they use with the Service.
Authentication, audit, and security data
We process IP address, user agent, request and response metadata, authentication events, session and verification records, security signals, audit events, and diagnostic information needed to protect and operate the Service. Audit records describe service operations; they do not observe every local file read on a device.
Cloudflare Turnstile processes browser, device, network, and challenge signals on signup and sign-in verification surfaces to distinguish people from abuse. It is treated as a necessary security tool, not an advertising tool.
Support and communications
We process messages, contact details, and attachments that a person chooses to send to support. Transactional messages such as invitations, verification, security, billing, and service notices are delivered through Amazon SES or the applicable billing provider.
Website and campaign measurement
Optional marketing tools load only after a visitor accepts them. They include Google Tag Manager, Google Analytics, Google Ads measurement, Apollo website visitor tracking, and the Meta Pixel. Depending on the tool, they process page URL, referrer, approximate location derived from IP, browser and device information, advertising identifiers, and interactions with our public pages.
If signup marketing consent is affirmative, VaultGuard can also send Meta a conversion event for registration and later trial or purchase milestones. Matching data can include a SHA-256-hashed email address, a hashed opaque organisation identifier, IP address, user agent, source URL, and Meta attribution identifiers. It does not include vault contents, filenames, paths, or encryption keys.
The Cookie Policy provides the current tool, storage, retention, consent, and opt-out details.
User-directed AI services
AI prompts and responses are not routed through VaultGuard’s managed API. When a user configures an AI provider or approved desktop agent, relevant content can be sent directly from the user’s device to that provider under the user’s account and the provider’s terms. VaultGuard can process scoped agent-bridge authorisation and audit metadata, but the customer chooses the provider and decides what to send.
3. Why we process data
| Purpose | Typical data | GDPR basis where applicable |
|---|---|---|
| Create accounts and provide the Service | Account, organisation, vault metadata, ciphertext, support data | Contract |
| Authenticate users and protect the Service | Authentication, network, device, audit, and security data | Contract and legitimate interests in security and abuse prevention |
| Administer subscriptions and invoices | Account, plan, transaction, and tax data | Contract and legal obligation |
| Send essential service communications | Account and service event data | Contract and legitimate interests |
| Improve reliability and answer support requests | Diagnostics, support communications, operational metadata | Contract and legitimate interests |
| Measure campaigns and public-site use | Website, device, and attribution data | Consent where required |
| Establish, exercise, or defend legal claims and comply with law | Relevant account, billing, audit, or content data | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we balance those interests against the person’s rights. Consent can be withdrawn without affecting processing that was lawful before withdrawal.
4. Who receives data
We disclose personal data only as needed to:
- infrastructure, authentication, email, security, support, and payment providers listed on the Subprocessor List;
- optional measurement and advertising partners after consent;
- professional advisers subject to confidentiality;
- authorities or other parties when required by law or necessary to protect rights, users, or the Service;
- a successor in a merger, financing, reorganisation, or sale, subject to applicable notice and protection requirements.
We do not sell personal data for money. Disclosures to optional advertising or measurement partners may be considered “sharing”, targeted advertising, or a sale under some US state privacy laws. Visitors can opt out through Only necessary, Cookie settings, or a recognised Global Privacy Control signal.
5. International transfers
The managed service’s primary AWS region is eu-central-1 (Frankfurt, Germany). Some providers or authorised support operations can process data in other countries. Where transfer law requires it, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK addendum or another approved mechanism, and supplementary technical and organisational safeguards as appropriate.
6. Retention
We keep personal data only for the purpose for which it was collected, including security, contractual, accounting, and legal requirements:
| Category | Typical retention |
|---|---|
| Active account, organisation, vault metadata, and ciphertext | While the account or subscription is active |
| Audit records | Customer-configurable; the managed-service default is 365 days |
| Production application and security logs | Up to 365 days under the current production configuration |
| Noncurrent object versions and protected recovery copies | Removed through configured lifecycle controls; noncurrent S3 versions can remain for up to 365 days |
| Billing and tax records | For the statutory accounting and tax period |
| Support communications | While needed to resolve the request and for reasonable legal or security follow-up |
| Consent preference | 180 days, then the site asks again |
| Optional vendor identifiers | As described in the Cookie Policy or until cleared |
After termination or a valid deletion request, VaultGuard deletes or de-identifies data that it no longer needs. Protected copies can remain until their normal lifecycle expires and are not used for ordinary service access. We can retain limited records where law, fraud prevention, dispute resolution, or enforcement requires it.
7. Your choices and rights
Depending on where a person lives, they may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. California and other US state residents may also have rights to know, correct, delete, and opt out of sale, sharing, or targeted advertising.
To exercise a right, email support@vaultguard.cloud. We may ask for information needed to verify identity and authority. If VaultGuard processes the data only for a customer, we will direct the request to that customer or help it respond.
Marketing preferences can be changed through Cookie settings on the website or signup screen. A recognised Global Privacy Control signal is treated as an opt-out on that browser.
8. Security
Measures include device-side AES-256-GCM file-body encryption, KMS-wrapped server-managed keys, HTTPS using TLS 1.2 or newer with TLS 1.3 when negotiated, Cognito authentication with optional MFA, vault-scoped authorisation, time-bounded key leases, IAM controls, WAF protections, versioning and recovery controls, and service audit records.
No security measure eliminates all risk. The Cloud security guide explains the important boundaries, including service-visible metadata and authorised managed operations.
9. Children
The Service is not directed to children under 16, and we do not knowingly create accounts for them. Contact us if you believe a child has provided personal data.
10. Automated decisions
VaultGuard does not make solely automated decisions about individuals that produce legal or similarly significant effects. Fraud, security, and anti-abuse signals can cause a challenge, delay, or review.
11. Changes
We will update the date at the top when this Policy changes. We will provide additional notice for material changes when required by law or contract. If a change requires consent, we will ask for it.
12. Contact and complaints
Email support@vaultguard.cloud, or write to the controller at the address in section 1. EEA residents may complain to their local supervisory authority; the Slovak supervisory authority is the Office for Personal Data Protection of the Slovak Republic.