vault.

Privacy

Last updated: September 2026. Vault is a link-in-bio platform: your page, your domain, your links. We collect as little as possible.

What we store

  • Account details: email and a securely hashed password (Argon2id). Passwords are never stored in readable form.
  • Page content you create: profile, links, social links, themes and custom domains.
  • Billing records processed by Stripe. We never see or store card numbers.

Analytics

  • Page views and link clicks are counted in aggregate (visitors, views, clicks, sources, devices, browsers, countries).
  • Raw events are kept for a short window (7 days by default) for aggregation, then deleted. Aggregates contain no IP addresses.
  • We do not sell analytics data or use third-party tracking cookies on creator pages.

Cookies

  • A strictly-necessary session cookie keeps you signed in.
  • Anonymous visitor keys may be stored so repeat visits are not double-counted. No advertising identifiers.

Your rights

  • Export everything from your account at any time via the app API (/api/v1/me/export).
  • Delete your account at any time from Account settings. Deletion removes your workspace, page, links, domains, media, analytics and sessions.
  • Contact us about access, correction or deletion requests and we will respond within 30 days.

Processors

Hosting infrastructure (PostgreSQL, Redis), Stripe for payments, your configured email provider for transactional mail, S3-compatible storage for images, and your domain registrar for purchases. Each processes only what its job requires.

Retention

Account data is kept while your account is active. Backups rotate on the infrastructure schedule. Raw analytics events auto-delete after the retention window.