Privacy Policy
Last updated August 6, 2026
At Veault, your privacy is our foundation. Our Service is built on a zero-knowledge principle. This means that, technically, we can never access the content of your vault.
This policy explains what data we process, why we do so, and how we protect your privacy in accordance with the General Data Protection Regulation (GDPR).
1. Data Controller
The party responsible for processing your personal data is:
Leval AS
Asperholen 58A
4329 Sandnes
Norway
Org. number: 935 999 170
For all privacy-related questions or to exercise your rights, please contact us at: privacy@veault.com
2. What Personal Data Do We Process?
We process various types of data, which we specify below.
A. Data we CANNOT access (Zero-Knowledge)
The contents of your vault belong to you alone.
- Vault Content: All personal information, notes, drafts, and documents you choose to store in your vault.
- Files and Documents: All files you upload.
Important: All of this data is encrypted on your device (client-side) using AES-256 encryption before it reaches our servers. We do not possess your encryption keys and have no technical way to decrypt or access your vault contents.
B. Personal data we do process (Account and Security Data)
In order to provide the Service to you, we process the following categories of data:
- Identity Data:
- Email address (for authentication and communication)
- First name and last name
- Language preference
- Market information
- Technical Data:
- Authentication tokens (to securely manage your login session)
- Subscription status and anonymized billing information (managed via Stripe)
- Server and security logs, including IP addresses (for security and fraud prevention)
- Anonymous usage analytics (no personal identification; see Section 4)
- Lead data (free guide):
- Email address and first name of visitors who request a free guide via our website
- Marketing data (upon consent):
- Click IDs such as a GCLID, which we store in your browser only after your consent via our cookie banner (see Section 4.3), used to attribute an ad to a conversion
3. Why We Process Your Data (Purposes and Legal Bases)
We only process your personal data (category B above) for specific purposes and based on a valid legal basis (in accordance with Article 6 of the GDPR).
We base our processing on the following three legal bases:
A. Based on Performance of a Contract (GDPR Art. 6(1)(b))
- Purpose: Providing the secure vault service and managing your account.
- Data: Identity data, Technical data.
- Purpose: Authenticating users and securing accounts.
- Data: Identity data (email), Technical data.
- Purpose: Processing subscriptions and payments.
- Data: Identity data, Technical data (subscription status).
- Purpose: Providing customer support and service communications.
- Data: Identity data.
- Purpose: Sending the free guide to those who request it.
- Data: Identity data (email address, first name).
B. Based on Legitimate Interest (GDPR Art. 6(1)(f))
- Purpose: Securing the Service, monitoring abuse, and fraud prevention.
- Data: Technical data (incl. IP logs).
- Purpose: Improving our website and service via anonymous, privacy-friendly analytics.
- Data: Anonymous usage analytics (Vemetric).
C. Based on Your Explicit Consent (GDPR Art. 6(1)(a))
- Purpose: Sending optional marketing communications (newsletters), including the email series for those who requested the free guide and gave consent via an unchecked opt-in box.
- Data: Identity data (email, name).
- Purpose: Measuring ad effectiveness and conversion attribution.
- Data: Marketing data, Technical data.
4. Cookies, Analytics, and Tracking
We distinguish between essential, analytical, and marketing technologies.
4.1. Essential Cookies
We may use functional cookies that are essential to operating the Service (for example, managing your login session). Consent is not required for these.
4.2 Privacy-Friendly Analytics (Default)
We use Vemetric for website analytics. This service was specifically chosen because it uses no cookies and collects no personally identifiable information (PII). It is fully anonymous, GDPR-compliant, and is loaded by default based on our legitimate interest.
4.3 Optional Cookies
For the following purposes, we only place items in your browser (cookies or browser storage such as local storage) after you have given consent via our cookie banner:
- Live chat: to allow you to use live chat on our website, we set a cookie for this function.
- Ad conversion measurement: when you arrive on our website via an ad (for example, a Google Ad), we store a click ID (such as a GCLID) in your browser. If you subsequently register for Veault, we use this click ID to measure that this registration resulted from that ad, and we share the click ID and anonymized/hashed data with Google. We never share the contents of your vault or any other vault data.
If you decline consent for these optional purposes, nothing is stored in your browser for them, and no conversion tracking occurs. You can withdraw your consent at any time via our cookie settings or your browser settings.
5. Data Sharing (Recipients)
We never sell your personal data. We distinguish between two types of recipients.
5.1 Subprocessors (processing strictly on our instructions)
We share your data with the following partners, who are strictly necessary to deliver the Service and process data exclusively according to our instructions:
- Stripe (Ireland): For processing all payments and managing subscriptions.
- Amazon Web Services (AWS) (Ireland/Sweden): For hosting our servers and your encrypted data, and for sending support and marketing emails.
- Vercel (EU): For hosting our marketing website.
- Neon (EU region): For the database storing contact details of visitors who request the free guide.
- Vemetric (EU): For collecting anonymous website analytics (does not process personal data).
5.2 Independent Data Controllers (upon your consent)
For ad measurement, strictly upon your consent (see Section 4.3), we share a click ID and/or hashed data with the following parties. They do not receive this data as subprocessors, but act as independent data controllers determining the purpose and means of their own further processing:
- Google (Google Ads): For measuring ad effectiveness. See Google's own privacy policy for details on how Google processes this data.
6. Data Storage and Transfer
Your privacy and data sovereignty are crucial to us.
6.1 Primary Storage Within the EEA
All data necessary for the core functionality of the Service (your account data, your encrypted vault data, lead data from guide requesters) is stored within the European Union. Our subprocessors (Stripe, AWS, Vercel, Neon, Vemetric) also process this data within the EEA.
Google (see Section 5.2), acting as an independent data controller, may also process data outside the EEA. This occurs strictly on the basis of transfer safeguards established by them, such as the EU-US Data Privacy Framework or Standard Contractual Clauses.
7. Retention Periods
We do not retain your data longer than strictly necessary (data minimization).
- Account and Vault Data: This data is retained for as long as you have an active account. Following a request to delete your account, all of this data (including all encrypted vault content) is permanently deleted from our production systems within 30 days.
- Security Logs: Server and security logs (including IP addresses) are retained for a maximum of 90 days.
- Billing and Transaction Data: Data related to your subscription (such as invoices) is, even after your account is deleted, retained in accordance with statutory (tax) retention periods (typically 7–10 years).
- Inactivity Policy: An account is considered 'inactive' if there is no active paid subscription period (monthly/annual) or no 'Lifetime' access active. 30 daysAfter an account reaches 'inactive' status (for example 30 days after the expiration of a trial period or an unrenewed subscription), the account and all associated vault data are permanently deleted.
8. Your Rights
You have full control over your data. You have the right at any time to:
- Access the account data we hold about you.
- Update your profile data (rectification).
- Download your vault data (data portability).
- Permanently delete your account and all your data (right to erasure).
- Manage your subscription via the self-service portal.
- Withdraw your consent for marketing cookies.
- Object to processing based on our legitimate interest.
- Request restriction of processing.
- Lodge a complaint with your local supervisory authority (such as the Dutch Data Protection Authority / Autoriteit Persoonsgegevens) or the Norwegian authority (Datatilsynet), if you believe we are not handling your data properly.
You can exercise most of these rights directly through your account settings. For other requests, you can contact privacy@veault.com. We will respond as soon as possible, and at the latest within 30 days.
9. Changes to this Policy
If we make significant changes to this privacy policy (for instance, by adding new trackers or subprocessors), we will inform you via email or a prominent notice on our website.