Legal
Privacy Policy
Last updated: July 20, 2026
Vaulter ("we", "our") respects your privacy. This policy describes what data we collect and how we use it.
1. Who We Are
Vaulter ("we", "us") is a platform at vaulter.run where you describe an application and we build, host, and publish it for you. This policy explains what personal data we collect, how we use it, and the choices you have. You can reach us about anything in this policy at team@vaulter.run.
2. Data We Collect
Account data: your name, email address, and sign-in credentials (including sign-in via Google or other identity providers). Billing data: your plan, payments, and invoices, processed by Stripe; we never store your full card number. Content: the projects, prompts, code, files, and settings you create on the platform. Connected service data: when you connect a third-party service to a project, we store the connection metadata and, on your request, fetch data from that service (described in sections 5 and 6). Usage and technical data: build and deployment activity, API call logs, IP address, browser, and device information used to operate, meter, rate-limit, and secure the Service.
3. How We Use Data
We use data to provide and improve the Service, to build and run the apps you ask us to build, to bill you, to enforce plan limits and prevent abuse, to communicate with you about the Service, and to comply with legal obligations. We do not sell your personal data, and we do not use your data for third-party advertising.
4. AI Processing
Vaulter is an AI-powered product. Your prompts, project content, and, when you explicitly request it, data from services you have connected are sent to large language model providers (Anthropic, OpenAI, and Google) to generate code and responses. We use API tiers of these providers under agreements that do not permit them to train their models on your data. We do not use your content or your connected service data to train AI models.
5. Connected Third-Party Services
You can connect third-party services (for example Stripe, Slack, Notion, HubSpot, Google Calendar) to a project, either by authorizing access through the provider's own consent flow (OAuth) or by supplying an API key. Access tokens and keys are stored encrypted by our auth infrastructure provider (Nango) and are never exposed to your app's visitors or embedded in published code. We access a connected service only to power the features of your app or when you ask the AI assistant to read from it, and only within the scopes you granted. You can disconnect a service at any time from your project's Connectors tab, and you can additionally revoke Vaulter's access from the third-party provider's own security settings.
6. Google User Data
Where you connect a Google service (such as Google Calendar or sign-in with Google), Vaulter's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we only use Google data to provide the features you asked for inside your own apps, we do not transfer it to third parties except as necessary to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your permission, for security purposes, or where required by law. Google user data is never used to train AI models.
7. Service Providers
We rely on a small set of infrastructure providers that process data on our behalf: Supabase (database, authentication, storage), Vercel (application hosting), Cloudflare (app delivery, previews, thumbnails), Stripe (payments), Resend (transactional email), Nango (third-party connection management), and the AI providers listed in section 4. Each processes data only as needed to provide their service to us and is governed by its own privacy and security commitments.
8. Apps You Publish
Apps built on Vaulter can be published to the web and can have their own users and data. For those apps, the app owner (you) decides what data the app collects and is responsible for it; Vaulter processes that data as infrastructure on the owner's behalf. If you are an end user of an app built on Vaulter, the app's owner is your first point of contact for privacy questions about that app.
9. Retention and Deletion
We keep your data while your account is active. If you delete a project, its content and connected-service tokens are removed from active systems. If you delete your account, we delete or de-identify your personal data within a reasonable period, except where we must retain records for legal, billing, or security reasons. You can request deletion at any time at team@vaulter.run.
10. Security
We protect data with encryption in transit, encrypted secret storage, scoped and audited access to third-party connections, server-side enforcement of access rules, and rate limiting. No system is perfectly secure, but security is a core design constraint of the platform, and we review it continuously.
11. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can manage most data directly in your account settings, and you can contact us at team@vaulter.run to exercise any of these rights. We respond to verified requests within the timeframes required by applicable law.
12. Changes
We may update this policy as the Service evolves. If we make material changes, we will notify you by email or an in-product notice before they take effect. The date at the top of this page shows when it was last revised.
13. Contact
For privacy questions or requests, email team@vaulter.run.