Last updated July 2026

Privacy Policy

How we collect, use, and protect personal data when you use Vault PDF. Core PDF tools never upload your files to our servers.

Who we are

Not Another Software Company("we", "us") operates Vault PDF, a browser-based PDF toolkit with team collaboration features. We are the data controller for personal data described in this policy.

Registered address: 150, Greenfields Soc., Palodia, Gandhinagar, India 382115

Vault PDF is offered to business teams in the United States, the EU/UK, and other international markets. We do not currently market or tailor the service to customers in India.

For GDPR-specific information and Data Processing Agreement (DPA) requests, see our GDPR page, US Privacy Notice, and DPA page. Contact details are in the Contact section below.

How PDF processing works
The privacy architecture that keeps client documents off our servers.

PDF processing runs entirely in your browser using permissive open-source libraries (pdf-lib, PDF.js, qpdf). We do not use AGPL-licensed processing modules. Your files are never uploaded to our servers for core PDF tools.

The PDF engine runs as a separate static container. It does not receive uploaded PDF bytes for core tools. Optional Slack notifications, when enabled by your team admin, share privacy-safe job metadata only, never file contents or filenames.

What we collect
Account and operational data needed to run the SaaS shell.
  • Account information (email, display name) via Supabase Auth
  • Team and billing metadata (organization name, subscription status, seat usage, payment provider customer ID)
  • Privacy-safe activity metadata (tool used, file count, compression mode, never filenames or PDF content)
  • Audit log entries for team administration and security events
  • Optional integration data when you connect Slack (encrypted OAuth tokens and channel preferences)
What we do not collect
  • PDF file contents or filenames from core browser-local tools
  • Passwords used to decrypt PDFs in your browser
  • Marketing or advertising tracking cookies
Is providing data required?

To create an account and use Vault PDF, you must provide an email address and authentication credentials (password or Google sign-in). Without this information we cannot provide the service, manage your subscription, or support your workspace.

PDF files processed in browser-local tools are not transmitted to our servers, so no upload is required for those operations.

Legitimate interests (Art. 6(1)(f))
Why we rely on legitimate interests and how we balance them.

Usage and activity metadata

Our interest: Operating the service, showing team activity, generating deletion receipts, and demonstrating compliance to your clients

We collect metadata only (tool, file count, timestamps), never PDF content or filenames. You may object via our privacy contact.

Audit and security logging

Our interest: Detecting abuse, securing accounts, and maintaining an accountability trail for team administration

We store administrative actions and HMAC-hashed IP addresses for security events, retained for 90 days with export available to org admins.

Sub-processors

We use the following services to operate Vault PDF:

ProviderPurposeLocation
SupabaseAuthentication, database, row-level securityEU / US
Dodo PaymentsSubscription billing and payment processingVaries by processor region
ResendTransactional email (invites, receipts, onboarding)US
Hetzner CloudApplication hosting, CDN, and operational logsEU (region-dependent)
Grafana CloudOperational log and container metrics (scrubbed before export)EU / US (region-dependent)
GoogleOptional Google OAuth sign-in (when you choose that method)US / global
SlackOptional job notifications when an admin connects a workspaceUS / global
International data transfers

Some sub-processors are located outside the European Economic Area (EEA), including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and processor agreements that require equivalent protection.

Contact divya@vault-pdf.com for details on transfer mechanisms applicable to your organization.

Cookies and similar technologies

We do not use analytics, advertising, or cross-site tracking cookies in the Vault PDF application. For the Client PDF Risk Check and organic free-tool funnels, we use a random UUID stored in your browser's sessionStorage (not a cookie) for cookie-free first-party funnel measurement. We record the event stage, campaign, source, medium, normalized allowlisted page path, and timestamp for 90 days. If you complete signup, we attach your user and organization IDs on our server so we can measure activation. We do not persist an IP address or hash, user agent, referrer, email, or URL query string for this measurement. We never record PDF bytes, filenames, metadata values, entered phrases, findings, file sizes, or pass/fail results. Embed messages contain only an allowlisted tool ID and event type. Optional Google sign-in may set cookies during the OAuth redirect only when you choose that method:

CookiePurposeDuration
Supabase auth sessionKeeps you signed in securelySession / refresh token lifetime
pending_invite_tokenCompletes team invite flow after sign-upShort-lived; cleared after invite acceptance
Google OAuth (sign-in only)When you choose “Continue with Google”, Google may set cookies during the OAuth redirect to authenticate you. We do not use Google for advertising or analytics.Controlled by Google during the sign-in flow
Deletion receipts

When you complete a job, we store metadata needed to generate a signed deletion receipt. Receipts prove processing happened locally and that we did not retain your PDF. Receipts can be shared via a public verification link without exposing file contents.

Proof metadata and verification remain available for seven calendar years from processing, regardless of trial or subscription status. An owner or admin may revoke a public link without removing the organization's private proof. Authorized account or organization deletion requests may remove proof earlier.

Personal data breaches

If we become aware of a personal data breach affecting your account data, we will notify affected account owners without undue delay and within 72 hours where required by applicable law, including the nature of the breach and steps we are taking.

Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Signed-in users can download an account export or delete their account from Account menu → Privacy & data (/settings/privacy). See our GDPR page for the full list of data subject rights and how to exercise them.

We respond to verified requests within one month, or inform you if an extension is required under applicable law.

United States residents
CCPA/CPRA and similar state privacy laws.

If you are in the United States, you may have additional rights to know, access, delete, and correct personal information, and to opt out of the sale or sharing of personal data. Vault PDF does not sell personal information or use it for cross-context behavioral advertising.

See our US Privacy Notice for categories collected, service-provider disclosures, and how to submit requests. You can also use Privacy & data in your account for exports and account deletion.

Children

Vault PDF is a business service for teams handling confidential client documents. It is not directed at children under 13 in the United States (COPPA) or under 16 in the EU/UK, and we do not knowingly collect personal data from children.

Changes to this policy

We may update this policy when our practices or legal requirements change. Material updates will be reflected by the "Last updated" date at the top of this page. For significant changes, we may also notify account owners by email or in-product notice.

Contact

Not Another Software Company

For privacy, legal, DPA, billing, and general support inquiries, email divya@vault-pdf.com.

Document version 2026-07. Added cookie-free, first-party measurement for the Client PDF Risk Check campaign and its 90-day retention period.

This information is provided for transparency and is not legal advice. Consult qualified counsel for jurisdiction-specific requirements.