Legal

Privacy Policy

Updated 7/27/2026

Privacy Policy

Last updated: June 24, 2026

This policy explains how Vault handles data. Vault is a personal, self-hosted document platform operated as a private project.

1. Information Vault stores

Vault stores the information needed to provide accounts, documents, sharing, publishing, and uploaded assets.

This may include:

  • account identity from OAuth providers, such as name, email address, avatar, and provider account ID
  • Vault profile details, such as username and nickname
  • documents, document titles, Markdown content, history snapshots, and collaboration state
  • document permissions, share links, friend relationships, and moderation records
  • uploaded asset metadata and private object-storage keys
  • user settings, extension settings, and workspace preferences
  • session records and security-related logs generated by the app or infrastructure

2. Private, shared, and public content

Documents are private by default. Private documents and private uploaded assets should only be available to the owner and users who have been granted access.

If you share a document, the people or links you share it with may be able to view or edit it depending on the access level you choose.

If you publish a document or make an asset public, that content can be viewed by anyone with access to the public URL and may be indexed by search engines.

3. Uploaded assets

Uploaded assets are stored in private object storage and served through Vault permission checks. Raw storage URLs are not intended to be public.

Public assets and assets embedded in public documents may be fetched by browsers, crawlers, and other clients so the public page can render correctly.

4. OAuth providers and infrastructure

Vault uses OAuth providers such as GitHub and Google for sign-in. Those providers handle their own authentication flows and may process data according to their own policies.

Vault may also use infrastructure providers for hosting, DNS, reverse proxying, database storage, and private object storage. These providers may process operational data needed to deliver the service.

5. Cookies and sessions

Vault uses cookies and database sessions to keep you signed in and protect authenticated routes. Disabling cookies may prevent sign-in or workspace access from working.

6. Data retention

Vault keeps account, document, asset, and settings data while the account or content remains active. Deleted or archived content may remain in backups or history records for a limited time.

Backups are used for recovery and maintenance. They are not intended as a way to restore every deleted item on request.

7. Sensitive information

Vault is not designed for regulated or highly sensitive data. Do not store passwords, payment card numbers, government IDs, medical records, or other high-risk secrets in Vault.

8. Data sale and advertising

Vault does not sell user data and does not run advertising profiles.

9. Contact

If you have questions about privacy, account access, or data removal, contact the Vault operator directly.