Axiom Data Integrity
Your data is protected by the **Axiom Protocol**. VaultedAI LLC ("Vaulted", "we", "us") operates a zero-trust, high-concurrency architecture that ensures your compliance documents are encrypted and managed with enterprise-grade security.
1. Information We Collect
We collect personal and operational data necessary to deliver permit tracking services:
- Account Information: Name, email address, and authentication credentials.
- Business Location Data: Business names, trade names, entity/LLC names, physical addresses, and jurisdiction details.
- Permit & Document Data: File contents (PDFs, images), permit numbers, expiration dates, issuing authorities, and status notes.
- Employee & Staff Certification Data: If you use our staff compliance features, we collect the name, position, and (if provided) contact information of your employees, along with their certification records — certification type, certification/card numbers, issuing body, expiration dates, and uploaded photos of certification documents. This data is submitted by you, the account holder, on behalf of your staff. See Section 9 ("Employee & Third-Party Data; Your Responsibilities") for your obligations when submitting this information.
- AI Extraction Metadata: Extracted metadata parsed by Google Gemini AI during Snap & Vault ingestions.
- Payment Data: Billing details processed securely through Stripe via the web platform only. Vaulted does not store full payment card numbers.
- Phone Numbers & SMS Communications: If you provide a mobile phone number for alert delivery, we use it solely to send the text message notifications you've opted into. See Section 4 ("Text Message (SMS) Communications & Consent").
- Biometric Security (Mobile Only): AppLock utilizes native device biometrics (Face ID/Fingerprint). All biometric verification occurs exclusively inside your device's local hardware secure enclave. Vaulted never receives or stores biometric templates.
2. How We Use Information
We process your data strictly to:
- Provide and optimize compliance tracking workflows, expiration notifications, and form pre-filling.
- Perform AI document parsing and intelligent renewal form field mapping via Google Gemini AI.
- Send essential email and SMS notifications (expiration reminders, MFA codes, billing receipts) that you have opted into.
- Comply with statutory tax, accounting, and legal obligations.
3. Children's Privacy
Vaulted is a business compliance tool intended for use by individuals who are at least 18 years old, acting on behalf of a business entity. The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 18 (or the age of majority in your jurisdiction, if higher). If we become aware that we have inadvertently collected personal data from a minor, we will take reasonable steps to delete it promptly. If you believe a minor has provided us with personal information, contact us at support@vaultedai.app.
4. Text Message (SMS) Communications & Consent
If you choose to provide a mobile phone number and opt in to SMS alerts, you agree to the following:
- Consent Is Opt-In and Separate From Account Creation: Providing a phone number and enabling SMS alerts is optional. We only send text messages to numbers you have affirmatively opted in to receive them at.
- Message Purpose: SMS messages are limited to operational alerts you've requested — permit and certification expiration reminders, critical compliance escalations, and account security codes. We do not send marketing text messages.
- Message Frequency: Message frequency varies based on your account's permit and certification activity and the alert preferences you configure.
- Message & Data Rates: Message and data rates may apply based on your mobile carrier and plan.
- Opting Out: You may withdraw SMS consent at any time by replying STOP to any message, or by disabling SMS alerts in Account Settings. Reply HELP for assistance, or contact support@vaultedai.app.
- Carriers Not Liable: Carriers are not liable for delayed or undelivered messages.
5. Cookies, Analytics & Tracking Technologies
We use essential storage and privacy-focused performance analytics:
- Vercel Analytics: Anonymous, privacy-preserving website performance telemetry without cross-site tracking or persistent user profiling.
- Google Fonts: Web fonts loaded via Next.js font optimization to ensure crisp, fast typography.
- Essential Session Storage: Supabase authentication tokens used to maintain secure signed-in state.
- Device Trust Tokens: Local storage security flags (`mfa_trust_`) to verify trusted devices for 72 hours and reduce MFA friction.
6. Active & Post-Deletion Data Retention Schedule
- Active Accounts: We retain your personal data and uploaded permits for as long as your account remains active and in good standing.
- Financial & Tax Records: Subscription transaction logs and billing receipts are retained for up to 7 years to satisfy statutory tax and financial reporting requirements.
- Account Deletion & Purge: Upon receiving an account deletion request or subscription termination, all stored permit files, employee certification records, metadata, and user profile data are permanently purged from our primary database and encrypted cloud storage within 30 days.
- Transient AI Logs: Document content sent to Google Gemini AI API is processed in-memory and not stored beyond the active API response lifecycle.
7. Data Breach Notification
In the event we become aware of a security breach that compromises the confidentiality, integrity, or availability of your personal data, we will notify affected account holders without undue delay and, where required by applicable law, within the timeframe mandated by the relevant state or federal breach notification statute (for example, Texas requires notification as soon as practicable and generally no later than 60 days after discovery). Notifications will be sent to the email address associated with your account and will describe the nature of the breach, the data involved, and steps we are taking in response.
8. Consumer Privacy Rights (GDPR, CCPA/CPRA & US State Laws)
Whether located in the EU, UK, California, Texas, or other jurisdictions, you hold the following statutory rights:
- Right to Access / Know: Request a copy of the personal data and permit records we hold about you.
- Right to Deletion: Request the deletion of your personal data and uploaded document files.
- Right to Correction: Request correction of inaccurate account or location details.
- Right to Data Portability: Export your permit records and documents in a structured, machine-readable format.
- Right to Opt-Out of Sale or Sharing: Vaulted DOES NOT SELL, rent, share, or monetize your personal data or document content to third parties or data brokers.
- Right to Non-Discrimination: Exercising your privacy rights will never result in service denial, price increases, or degraded platform quality.
- Right to Appeal: If we decline action on a privacy request, you may appeal within 30 days by emailing support@vaultedai.app.
9. Employee & Third-Party Data; Your Responsibilities
Our staff compliance features allow you to submit personal data belonging to your employees or other individuals who are not Vaulted account holders ("Third-Party Data"). When you submit Third-Party Data, you represent and warrant that you have the legal right and any necessary consent to provide that data to us for processing, and that you have informed the relevant individual how their information will be used consistent with this Privacy Policy. Vaulted acts as a data processor with respect to Third-Party Data you submit; you, the account holder, remain the data controller responsible for your underlying legal basis for collecting and sharing it. Our Data Processing Agreement, available within your account under Settings → Legal or by request at support@vaultedai.app, governs the terms of this processing relationship in greater detail.
10. International & Cross-Border Data Transfers
Vaulted infrastructure is hosted primarily in secure U.S.-based data centers (Supabase on AWS and Vercel Edge Network). For international users transferring data from the EU, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) and robust technical measures (AES-256-GCM encryption at rest and TLS 1.2+ in transit) to ensure adequate data protection safeguards.
11. Sub-processor Directory
We share data only with authorized sub-processors necessary for platform operations:
- Supabase: Encrypted PostgreSQL database & document storage.
- Google Gemini AI: Automated document metadata extraction.
- Stripe: Payment processing for web subscriptions.
- Resend: Email notification delivery.
- Amazon Web Services (SNS): SMS text message delivery for opted-in alert notifications.
- Vercel: Web application hosting & anonymous performance telemetry.
12. Contact Us
To exercise your privacy rights or contact our Data Protection Officer, email support@vaultedai.app.