Privacy Policy
How we collect, use, and protect personal data when you use Vault PDF. Core PDF tools never upload your files to our servers.
Not Another Software Company("we", "us") operates Vault PDF, a browser-based PDF toolkit with team collaboration features. We are the data controller for personal data described in this policy.
Registered address: 150, Greenfields Soc., Palodia, Gandhinagar, India 382115
Vault PDF is offered to business teams in the United States, the EU/UK, and other international markets. We do not currently market or tailor the service to customers in India.
For GDPR-specific information and Data Processing Agreement (DPA) requests, see our GDPR page, US Privacy Notice, and DPA page. Contact details are in the Contact section below.
PDF processing runs entirely in your browser using permissive open-source libraries (pdf-lib, PDF.js, qpdf). We do not use AGPL-licensed processing modules. Your files are never uploaded to our servers for core PDF tools.
The PDF engine runs as a separate static container. It does not receive uploaded PDF bytes for core tools. Optional Slack notifications, when enabled by your team admin, share privacy-safe job metadata only, never file contents or filenames.
- Account information (email, display name) via Supabase Auth
- Team and billing metadata (organization name, subscription status, seat usage, payment provider customer ID)
- Privacy-safe activity metadata (tool used, file count, compression mode, never filenames or PDF content)
- Audit log entries for team administration and security events
- Optional integration data when you connect Slack (encrypted OAuth tokens and channel preferences)
- PDF file contents or filenames from core browser-local tools
- Passwords used to decrypt PDFs in your browser
- Marketing or advertising tracking cookies
To create an account and use Vault PDF, you must provide an email address and authentication credentials (password or Google sign-in). Without this information we cannot provide the service, manage your subscription, or support your workspace.
PDF files processed in browser-local tools are not transmitted to our servers, so no upload is required for those operations.
Usage and activity metadata
Our interest: Operating the service, showing team activity, generating deletion receipts, and demonstrating compliance to your clients
We collect metadata only (tool, file count, timestamps), never PDF content or filenames. You may object via our privacy contact.
Audit and security logging
Our interest: Detecting abuse, securing accounts, and maintaining an accountability trail for team administration
We store administrative actions and HMAC-hashed IP addresses for security events, retained for 90 days with export available to org admins.
| Purpose | Legal basis | Retention |
|---|---|---|
| Client PDF Risk Check campaign measurement Anonymous session UUID, event stage, campaign, source, medium, normalized page path, timestamp, and - after authenticated signup only - server-attached user and organization IDs | Legitimate interests: understanding whether this educational campaign helps firms reach product activation (Art. 6(1)(f)) | 90 days (automated purge); no IP address, IP hash, user agent, referrer, email, or query string is persisted |
| Account creation and authentication Email, display name, password hash (via Supabase Auth) | Contract (Art. 6(1)(b)) | While account is active, plus up to 90 days after deletion for security and billing reconciliation |
| Team and subscription management Organization name, role, seat usage, subscription status | Contract (Art. 6(1)(b)) | While subscription is active, plus up to 7 years for billing and tax records where required by law |
| Usage and activity metadata Tool ID, file count, timestamps, compression mode (no filenames or PDF content) | Legitimate interests: service operation, team visibility, and compliance receipts (Art. 6(1)(f)) | 90 days for activity and audit logs (automated purge); receipt, certificate, and review-manifest proof metadata retained for seven calendar years from processing, unless an authorized deletion request removes it earlier |
| Audit and security logging Administrative actions, hashed IP address for security events | Legitimate interests: security, fraud prevention, and accountability (Art. 6(1)(f)) | 90 days (automated purge); export available to org admins before expiry |
| Transactional email Email address, invite tokens, billing notifications | Contract (Art. 6(1)(b)) | Per email provider logs; typically up to 30 days operational retention |
| Optional Slack integration OAuth tokens (encrypted), channel selection, privacy-safe job notifications (may include actor email) | Consent / contract, enabled only when an admin connects Slack (Art. 6(1)(a)/(b)) | While integration is connected; tokens removed on disconnect |
| Optional Google sign-in Email and profile name from Google when you choose OAuth | Contract (Art. 6(1)(b)) | While account is active; Google may set cookies during the OAuth redirect |
We use the following services to operate Vault PDF:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, row-level security | EU / US |
| Dodo Payments | Subscription billing and payment processing | Varies by processor region |
| Resend | Transactional email (invites, receipts, onboarding) | US |
| Hetzner Cloud | Application hosting, CDN, and operational logs | EU (region-dependent) |
| Grafana Cloud | Operational log and container metrics (scrubbed before export) | EU / US (region-dependent) |
| Optional Google OAuth sign-in (when you choose that method) | US / global | |
| Slack | Optional job notifications when an admin connects a workspace | US / global |
Some sub-processors are located outside the European Economic Area (EEA), including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and processor agreements that require equivalent protection.
Contact divya@vault-pdf.com for details on transfer mechanisms applicable to your organization.
We do not use analytics, advertising, or cross-site tracking cookies in the Vault PDF application. For the Client PDF Risk Check and organic free-tool funnels, we use a random UUID stored in your browser's sessionStorage (not a cookie) for cookie-free first-party funnel measurement. We record the event stage, campaign, source, medium, normalized allowlisted page path, and timestamp for 90 days. If you complete signup, we attach your user and organization IDs on our server so we can measure activation. We do not persist an IP address or hash, user agent, referrer, email, or URL query string for this measurement. We never record PDF bytes, filenames, metadata values, entered phrases, findings, file sizes, or pass/fail results. Embed messages contain only an allowlisted tool ID and event type. Optional Google sign-in may set cookies during the OAuth redirect only when you choose that method:
| Cookie | Purpose | Duration |
|---|---|---|
| Supabase auth session | Keeps you signed in securely | Session / refresh token lifetime |
| pending_invite_token | Completes team invite flow after sign-up | Short-lived; cleared after invite acceptance |
| Google OAuth (sign-in only) | When you choose “Continue with Google”, Google may set cookies during the OAuth redirect to authenticate you. We do not use Google for advertising or analytics. | Controlled by Google during the sign-in flow |
When you complete a job, we store metadata needed to generate a signed deletion receipt. Receipts prove processing happened locally and that we did not retain your PDF. Receipts can be shared via a public verification link without exposing file contents.
Proof metadata and verification remain available for seven calendar years from processing, regardless of trial or subscription status. An owner or admin may revoke a public link without removing the organization's private proof. Authorized account or organization deletion requests may remove proof earlier.
If we become aware of a personal data breach affecting your account data, we will notify affected account owners without undue delay and within 72 hours where required by applicable law, including the nature of the breach and steps we are taking.
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Signed-in users can download an account export or delete their account from Account menu → Privacy & data (/settings/privacy). See our GDPR page for the full list of data subject rights and how to exercise them.
We respond to verified requests within one month, or inform you if an extension is required under applicable law.
If you are in the United States, you may have additional rights to know, access, delete, and correct personal information, and to opt out of the sale or sharing of personal data. Vault PDF does not sell personal information or use it for cross-context behavioral advertising.
See our US Privacy Notice for categories collected, service-provider disclosures, and how to submit requests. You can also use Privacy & data in your account for exports and account deletion.
Vault PDF is a business service for teams handling confidential client documents. It is not directed at children under 13 in the United States (COPPA) or under 16 in the EU/UK, and we do not knowingly collect personal data from children.
We may update this policy when our practices or legal requirements change. Material updates will be reflected by the "Last updated" date at the top of this page. For significant changes, we may also notify account owners by email or in-product notice.
Not Another Software Company
For privacy, legal, DPA, billing, and general support inquiries, email divya@vault-pdf.com.
Document version 2026-07. Added cookie-free, first-party measurement for the Client PDF Risk Check campaign and its 90-day retention period.
This information is provided for transparency and is not legal advice. Consult qualified counsel for jurisdiction-specific requirements.