Legal

Privacy Policy

Effective September 18, 2026 · version 1.0

VaultKeep is operated by MLI Technologies ("we", "us"), Halifax, Nova Scotia, Canada. This policy explains what personal data we handle when you use vaultkeep.dev and the VaultKeep service, and what your rights are. Questions go to support@vaultkeep.dev.

We have tried to write this in plain language. Where a sentence is precise for legal reasons, we say so.

The two kinds of data

There is an important distinction in how VaultKeep handles data:

What we collect and why

DataWhyLegal basis (GDPR)
Email addressSign-in by magic link; alerts about failed backups and verifications; billing receiptsPerformance of the contract
Organization name, members and roles, invitationsRunning your account and team accessPerformance of the contract
Project name, Supabase project reference, Postgres major version, Storage regionConnecting and identifying your projectsPerformance of the contract
Database connection string and Storage access keysTaking backups and running restores on your instruction. Stored sealed with AES-256-GCM; read only by the backup runner at job time, and every read is loggedPerformance of the contract
Credentials for a storage destination you add (S3, Azure, etc.)Writing backups to your own bucket, if you choose toPerformance of the contract
Backup manifests: table names, row counts, object names and sizes, hashesVerifying that backups restore correctlyPerformance of the contract
Audit log: who did what and when (including credential reads by the runner)Security, and evidence for your own auditsLegitimate interest (security); performance of the contract
Billing details via Stripe: name, email, plan, invoices. Card numbers never reach our serversCharging for paid plansPerformance of the contract; legal obligation (tax and accounting)
Technical logs: IP address, user agent, request path, timestamps, error detailsOperating and securing the service, rate-limiting sign-inLegitimate interest
Emails you send usSupportLegitimate interest

We do not buy data about you, and we do not sell or rent personal data to anyone.

Cookies

We use one cookie, vk_session, which keeps you signed in. It is strictly necessary and contains no tracking. If we add analytics, it will be Cloudflare Web Analytics, which does not use cookies or track individuals. If you enable the optional Turnstile bot check, Cloudflare may set its own cookies on that widget; see Cloudflare's privacy policy.

We do not use advertising cookies or third-party trackers.

Where data is stored and who processes it

VaultKeep runs on Cloudflare's network. Our sub-processors are:

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting (Workers, D1, Containers), backup storage (R2), email delivery, bot protectionGlobal network; data at rest in Cloudflare's storage regions
Stripe, Inc.Payments and invoicingUnited States and EU
Resend, Inc.Transactional email (used where Cloudflare's email service is not enabled)United States

If you configure your own backup destination (for example an Amazon S3 or Azure bucket), that provider processes your encrypted backups under your agreement with them, not ours.

Transfers outside the EEA/UK rely on the providers' standard contractual clauses. We will update this list when a sub-processor changes; email us if you want to be notified of changes.

How long we keep it

DataRetention
BackupsFor the retention period you configure, capped by your plan (7, 30 or 90 days). Expired backups are deleted and their encryption key is destroyed nightly
CredentialsUntil you replace them, remove the project, or delete your organization; then the ciphertext is destroyed immediately
Audit logWhile your organization exists, and for 90 days after you delete it
Account and organization dataUntil you delete your organization. Deletion destroys credentials at once and queues every backup artifact for removal
Billing recordsAs long as tax and accounting law requires (typically 7–10 years), at Stripe and in our exports
Technical logsUp to 30 days
Support emailsUp to 2 years

Security

The short version, with the technical details on the security page: backups are streamed through AES-256-GCM before they are stored; each backup has its own key, wrapped by a master key that the web application cannot read; credentials are sealed the moment they arrive and are only opened by the isolated job runner, with every read written to an append-only audit log; the runner and the web application run in separate trust domains; and restores only ever target an empty database you designate.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you without undue delay and, where required, within 72 hours of becoming aware.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA and similar laws) you can ask us to:

Email support@vaultkeep.dev. We answer within 30 days and never charge for these requests.

Children

VaultKeep is for businesses and developers and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes

When we change this policy we update the effective date above and, for material changes, email account owners at least 14 days before they take effect.

Contact

MLI Technologies · Halifax, Nova Scotia, Canada · support@vaultkeep.dev