Last updated June 2026

Privacy Policy

How we collect, use, and protect personal data when you use Vault PDF. Core PDF tools never upload your files to our servers.

Who we are

Your Company Ltd("we", "us") operates Vault PDF, a browser-based PDF toolkit with team collaboration features. We are the data controller for personal data described in this policy.

Privacy contact: divya@vault-pdf.com

For GDPR-specific information and Data Processing Agreement (DPA) requests, see our GDPR page.

How PDF processing works
The privacy architecture that keeps client documents off our servers.

PDF processing runs entirely in your browser using permissive open-source libraries (pdf-lib, PDF.js, qpdf). We do not use AGPL-licensed processing modules. Your files are never uploaded to our servers for core PDF tools.

The PDF engine runs as a separate static container. It does not receive uploaded PDF bytes for core tools. Optional Slack notifications, when enabled by your team admin, share privacy-safe job metadata only, never file contents or filenames.

What we collect
Account and operational data needed to run the SaaS shell.
  • Account information (email, display name) via Supabase Auth
  • Team and billing metadata (organization name, subscription status, seat usage, payment provider customer ID)
  • Privacy-safe activity metadata (tool used, file count, compression mode, never filenames or PDF content)
  • Audit log entries for team administration and security events
  • Optional integration data when you connect Slack (encrypted OAuth tokens and channel preferences)
What we do not collect
  • PDF file contents or filenames from core browser-local tools
  • Passwords used to decrypt PDFs in your browser
  • Marketing or advertising tracking cookies
Sub-processors

We use the following services to operate Vault PDF:

ProviderPurposeLocation
SupabaseAuthentication, database, row-level securityEU / US
Dodo PaymentsSubscription billing and payment processingVaries by processor region
ResendTransactional email (invites, receipts, onboarding)US
Hosting providerApplication hosting, CDN, and operational logsUS / EU (region-dependent)
International data transfers

Some sub-processors are located outside the European Economic Area (EEA), including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and processor agreements that require equivalent protection.

Contact divya@vault-pdf.com for details on transfer mechanisms applicable to your organization.

Cookies and similar technologies

We use essential cookies only, no analytics, advertising, or third-party tracking cookies. These are required for authentication and core product functionality:

CookiePurposeDuration
Supabase auth sessionKeeps you signed in securelySession / refresh token lifetime
pending_invite_tokenCompletes team invite flow after sign-upShort-lived; cleared after invite acceptance
Deletion receipts

When you complete a job, we store metadata needed to generate a signed deletion receipt. Receipts prove processing happened locally and that we did not retain your PDF. Receipts can be shared via a public verification link without exposing file contents.

Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. See our GDPR page for the full list of data subject rights and how to exercise them.

We respond to verified requests within one month, or inform you if an extension is required under applicable law.

Children

Vault PDF is a business service for teams handling confidential client documents. It is not directed at children under 16, and we do not knowingly collect personal data from children.

Changes to this policy

We may update this policy when our practices or legal requirements change. Material updates will be reflected by the "Last updated" date at the top of this page. For significant changes, we may also notify account owners by email or in-product notice.

Contact

Privacy questions: divya@vault-pdf.com

General support: divya@vault-pdf.com

This information is provided for transparency and is not legal advice. Consult qualified counsel for jurisdiction-specific requirements.