1. Scope
This policy covers VaultProof's website, app, scanner, init, API, MCP, and provider routing services.
This Privacy Policy explains how VaultProof Inc. collects, uses, shares, and protects information when you visit the website, use the dashboard, connect the VaultProof Model Context Protocol (MCP) server to ChatGPT or another approved client, run hosted init, download VaultProof files, use the scanner, or route provider calls through VaultProof.
If you use VaultProof for a company or organization, that organization may control some data in the account. Your use of VaultProof is also governed by the Terms of Service.
2. Data We Collect
We collect the data needed to operate and secure the service.
The exact data depends on how you use VaultProof. Most data falls into account, configuration, usage, billing, support, and device categories.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email address, name if provided, authentication metadata, workspace membership, plan state, and account settings. | Login, account management, security, notifications, and support. |
| Onboarding profile data | Name, job title, company or solo status, employee-count range, primary goal, and referral source. These non-secret profile values are editable in Settings. | Account setup, onboarding, support, and product improvement. |
| Eligibility and guardian-consent data | Age band, country, guardian email address and name, approval and billing-authorization times, accepted policy versions, and hashed one-time approval or registration records. We do not store the birth date entered at the age screen. | Confirm account eligibility, obtain and record guardian decisions, restrict billing, prevent replay or abuse, and respond to guardian requests. |
| Configuration data | Project names, provider types, token prefixes, environment labels, allowed routes, budgets, alert settings, and dashboard preferences. | Provide key management, routing, policy controls, alerts, and user workflows. |
| Usage metadata | Provider, route, status code, timestamp, latency, error class, request ID, approximate volume, and operational logs. | Operate the service, debug issues, detect abuse, show activity, and support incident review. |
| MCP connection data | Approved client identity, granted scopes, hashed token records, connection and revocation times, rate-limit state, and security-event metadata. | Connect approved AI clients, enforce authorization, let users revoke access, prevent abuse, and investigate security events. |
| Billing data | Plan, subscription status, customer ID, invoices, payment status, and billing contact details handled by our payment processor. | Process subscriptions, taxes, invoices, limits, and billing support. |
| Support data | Messages you send us, live chat conversations, screenshots, logs, issue details, abuse reports, and security reports. | Answer questions, investigate reports, fix issues, and improve documentation. |
| Device and site data | IP address, browser type, pages viewed, referrer, approximate location, and diagnostics from website and app analytics. | Security, fraud prevention, performance, analytics, and product improvement. |
3. Provider Data
Provider-key data is handled for key protection and runtime routing.
VaultProof is built to reduce where raw provider keys live. When you add a supported provider key or run hosted init, VaultProof may process provider key material, VaultProof-generated token values, provider-compatible base URLs, and metadata needed to route requests.
Setup
The init tool can detect supported keys, protect them, and write VaultProof values and base URLs into your app environment.
Runtime
When your app makes a provider request, VaultProof uses the required upstream credential to authenticate that request with the provider.
Logs
We record operational metadata such as route, status, timestamp, latency, and error information. We do not intentionally log raw provider keys.
4. How We Use Data
We use data to run, secure, support, bill, and improve VaultProof.
We process information only for practical service purposes and legal reasons.
- Provide the website, dashboard, hosted init, downloads, scanner, API, and provider routing services.
- Authenticate users, maintain sessions, manage accounts, and enforce workspace permissions.
- Check registration eligibility, obtain guardian approval for users ages 13–17, and separately enforce guardian billing authorization.
- Route supported provider requests and show activity, usage, alerts, errors, and status information.
- Detect abuse, investigate suspicious usage, protect against fraud, and enforce the Terms.
- Process billing, invoices, plan limits, taxes, payment status, and related support requests.
- Provide customer support chat, respond to support requests, and connect conversations with account context when available.
- Send service messages, security notices, product updates, and support replies.
- Measure site and product usage so we can improve onboarding, documentation, reliability, and performance.
- Comply with law, legal process, and legitimate requests from users, providers, or authorities.
5. Sharing
We do not sell customer data.
We share information only when needed to provide the service, work with trusted vendors, protect users, comply with law, or complete a business transaction.
Service providers
We use vendors for hosting, authentication, database infrastructure, payments, analytics, email, monitoring, support, security, and similar operations. Stripe processes payment and subscription information. Resend processes transactional guardian-approval and account-confirmation emails. VaultProof does not receive full payment-card details from Stripe.
Provider routing
When your app calls an upstream provider through VaultProof, the provider receives the request data needed to process that provider call.
Security and abuse
We may share or preserve information to investigate abuse, prevent harm, enforce our Terms, protect users, or coordinate with providers.
Legal and corporate events
We may disclose information when required by law, legal process, or as part of a merger, financing, acquisition, or sale of assets.
6. Data Policy
We keep data for clear purposes
We retain data to provide the service and meet specific legal, billing, or security needs—not as a permanent record of everything. Our policy is to delete or anonymize personal data when that purpose ends, unless a documented exception applies. Hiding or encrypting data is not the same as deleting it.
Canceling, closing, or deleting
Canceling a subscription stops future renewals under the confirmed cancellation terms. Closing an account ends normal access. Deleting personal data removes the information covered by a verified request, subject to justified exceptions. You can request closure and deletion together.
A plan's history-access window does not automatically delay a valid deletion request. A pending request is not proof of deletion or billing cancellation; we confirm each outcome separately. Existing invoices and refunds remain subject to the Terms of Service and applicable law.
Contact support@vaultproof.dev, even without dashboard access. We verify your identity and authority and review shared-workspace interests. We must protect other members' work without using it as a blanket reason to keep your unrelated personal data.
What may remain
- Account details and settings: while needed for the account or workspace. Continued retention after closure needs a specific purpose.
- Activity metadata: for agreed history, billing verification, support, or a specific security investigation. Routine history follows its applicable retention terms.
- Billing records: necessary invoices, payment references, and subscription events for tax, accounting, payment compliance, or disputes.
- Consent records: necessary policy versions, acceptance times, eligibility decisions, and guardian approval to establish what was agreed or meet an obligation.
- Security and privacy-request records: limited evidence of requests, cancellations, revocations, or incidents to verify outcomes and protect access.
- Support and dispute records: relevant messages and evidence while needed for the case or an applicable legal or security purpose.
There is no single retention period for all data. Where no fixed period is stated, we use the service purpose, applicable legal obligation, dispute period, or preservation requirement. You can ask us which records and retention periods or criteria apply to your request, subject to lawful disclosure limits.
Keys and other secrets
Provider keys, recoverable key shares, passwords, usable tokens, and request contents are not general-purpose compliance records. This policy does not authorize permanent copies or extra logging of them. Removing recoverable credentials and stopping access are separate steps to verify. A binding evidence-preservation requirement needs narrowly controlled handling.
Stopping VaultProof access does not revoke the original key at its upstream provider. Provider-side rotation or revocation may still be necessary. Other providers may also keep records under their own policies.
Specific retention windows
These specific windows remain separate from broader account and billing records. They are not extended merely because an account closes.
- A birth date submitted to the pre-registration age screen is used in memory to calculate an age band and is not stored by VaultProof. An under-13 result does not create a registration or guardian-consent record.
- Adult eligibility flows expire after 30 minutes. Guardian-approval flows for users ages 13–17 expire after 24 hours. Unused expired registration and guardian-consent records are scheduled for deletion after 30 days.
- One-time guardian links and registration receipts are stored as cryptographic hashes where possible. Consent evidence associated with an account may be retained while the account is active and afterward when needed for security, fraud prevention, billing, disputes, or legal compliance.
- MCP authorization requests expire after 10 minutes and authorization codes after 1 minute. They are deleted when consumed; expired stored records are removed within 24 hours after expiration.
- MCP access tokens expire after 10 minutes and refresh-token families after 30 days. VaultProof stores keyed token hashes rather than usable token values; expired token records are removed within 24 hours after expiration.
- Revoked MCP grants and their revocation markers are retained for up to 30 days to enforce revocation and support security investigation, then removed by automated cleanup.
- Cloudflare Workers security logs and traces are retained for no more than 7 days in the native observability service. Other backups and logs follow their documented operational or legal retention cycle.
Legal holds and access
A legal hold preserves relevant records for a legal requirement or specific claim. We review whether the reason still applies; it is not permission to keep every account's data indefinitely.
Records kept only for legal, accounting, or security purposes remain covered by our security safeguards. Access must be limited to authorized people and providers who need them for that purpose, not ordinary dashboard or MCP use. Losing dashboard access does not remove applicable privacy rights.
Backups and deletion results
Active systems and backups may have different deletion schedules. Backups follow documented expiry cycles, not indefinite retention. Restored data must respect previous deletion and access-revocation decisions.
Where required, we also address copies held by providers processing data for us. Independent providers may have their own duties. We explain what is complete, what must remain, and any pending steps.
7. Cookies and Analytics
VaultProof uses local storage, cookies, and analytics for service operation and improvement.
We use browser storage and similar technologies to keep users signed in, remember preferences, maintain security state, understand product usage, and improve onboarding and documentation.
| Tool | Use |
|---|---|
| Authentication storage | Stores session information so authenticated users can stay signed in and use the dashboard securely. |
| Local preferences | Stores interface preferences, dismissed notices, and other product state where useful. |
| Analytics | Measures pages, events, onboarding paths, and product usage. The site currently loads Google Analytics and Mixpanel. |
| Support chat | Loads Intercom Messenger when enabled for customer support conversations. Intercom may use browser storage to remember conversations and connect messages with account or contact context. |
You can control cookies and local storage through your browser settings. Blocking storage may break login, dashboard features, or preference-saving behavior.
8. Security
We use technical and operational controls to protect VaultProof data.
Security measures include access controls, encryption in transit, provider-key handling controls, logging, monitoring, and abuse prevention. No internet service can guarantee perfect security.
9. Your Choices
You can access, update, export, or request deletion of data.
Depending on your location and account role, you may have rights to request access, correction, deletion, export, restriction, or objection to certain processing.
- Update account and workspace settings in the dashboard where available.
- Rotate, revoke, or remove provider keys through VaultProof and the upstream provider.
- Export or review available activity and billing information from dashboard workflows where supported.
- Opt out of non-essential emails by using unsubscribe links or contacting us.
- Contact support@vaultproof.dev for privacy requests, account closure, deletion, or questions about retained data, even if you cannot sign in.
- A parent or legal guardian may request access to, correction or deletion of, or withdrawal of authorization for a minor's account, subject to identity and authority verification.
How to make a privacy request
- Tell us whether you want access, correction, export, account closure, deletion, or another privacy action. Include enough information to identify the account, without sending passwords, API keys, payment-card details, or MFA codes.
- We may ask for proportionate information to verify your identity and, where relevant, your authority for a workspace or minor's account.
- We review the request under applicable law and explain what can be completed, what requires further action, and any justified retention exception. We respond within applicable legal deadlines and explain permitted extensions or reasons for declining a request.
- If you disagree with the outcome, contact us for review. Depending on your location, you may also have a right to appeal or complain to the relevant privacy authority.
Access requests are reviewed separately from normal product access. They do not authorize disclosure of another person's information, usable credentials, or information protected by an applicable legal or security restriction.
10. International Transfers
VaultProof may process data in the United States and other countries.
We and our vendors may process information in countries where we or they operate. Those countries may have data protection laws different from the laws where you live. Where required, we use appropriate safeguards for international transfers.
11. Children and Teens
VaultProof requires users to be at least 13.
VaultProof is not directed to children under 13, and children under 13 may not create an account. We use a neutral age screen before collecting registration contact details. A birth date entered into that screen is used in memory only to determine an age band and is not stored by VaultProof. An under-13 result does not create a registration or consent record.
For a United States user age 13–17, we collect the parent or legal guardian email address, guardian name, approval time, accepted policy versions, and whether the guardian separately authorized billing. Approval links and registration receipts are one-time, expire automatically, and are stored as cryptographic hashes where possible. We use this information to verify account eligibility, prevent abuse, enforce billing restrictions, and maintain consent records.
VaultProof does not sell or share a minor's personal information for cross-context behavioral advertising. Parents and legal guardians may contact support@vaultproof.dev to request access, correction, deletion, account closure, or withdrawal of their authorization. Withdrawal does not affect records we must retain for security, fraud prevention, legal compliance, accounting, or dispute resolution. If you believe a child under 13 created an account or provided personal information, contact us without sending the child's birth date, password, payment-card information, API key, or other secret.
12. Changes
We may update this Privacy Policy.
If we make material changes, we will provide reasonable notice by email, dashboard notice, website notice, or another appropriate method. Continued use after the effective date means the updated policy applies.
13. Contact
Questions about privacy?
Contact us at support@vaultproof.dev. Parents and legal guardians may use the same address for access, correction, deletion, account-closure, or authorization-withdrawal requests. For security issues, use security@vaultproof.dev. For abuse reports, use abuse@vaultproof.dev.