Skip to content
Vaulant
How it works Pricing Security FAQ
Sign in
Privacy

Privacy Policy

Effective 13 July 2026 · Vaulant, Inc.

The short version.
  • Your vault items are encrypted on your device before they reach us. We cannot read them.
  • We can see your email, billing status, whether you check in on time, and roughly how much you store, not what you store.
  • Information you give us about other people (a successor's name and email, a custodian's identity, a handoff greeting) is not encrypted. We can read that, and we use it to run the succession feature.
  • We don't sell your data. We use a small number of infrastructure providers, listed below.

1. Who we are

Vaulant is operated by Vaulant, Inc., a Delaware corporation ("we", "us"). We are the controller of the personal information described here. For any privacy question, or to exercise the rights in section 11, write to privacy@vaulant.com.

2. Beta notice

Vaulant is currently offered as an invite-only beta. The service and this policy may change as we build; we will post updates here and, for material changes, notify you by email (see section 14).

3. Information we collect

We collect only what we need to run the service:

  • Account information: your email address, the display name you give, and (if you add one) a phone number.
  • Authentication data: sign-in events and, if you use them, passkey public keys. We use email one-time codes, Google sign-in, and passkeys; we never receive a password you know.
  • Your encrypted vault contents: the items, files and attachments you store arrive already encrypted. We hold them only as opaque ciphertext (see section 4).
  • Vault metadata: how many items are in a vault and their approximate size, your check-in and activity status, and technical attributes needed to operate the vault. Not their contents.
  • Succession and relationship data: the names, email addresses and phone numbers you enter for successors, co-owners and custodians, and any plain-text handoff message you write. This is not encrypted and we can read it (see section 5).
  • Billing information: handled by our payment processor, Stripe. We receive your subscription status and limited billing metadata; we do not store full card numbers.
  • Support communications: the content of emails you send us.
  • Diagnostics and logs: server logs (including IP address and request metadata) and privacy-preserving error reports. Error reports are scrubbed and never include your item contents.

4. What we cannot see

  • Anything you store as an item, file or attachment, it is encrypted on your device before it reaches us.
  • Your unlock passphrase, your Safety Envelope recovery phrase, or your device passkey secret. These never leave your device.
  • The contents of a Letter to a successor, or items you label "Funeral Wishes" or similar, the same encryption applies.

This is a cryptographic property, not just a promise: while you are using your vault, we hold no key that can decrypt your items.

5. Two things we can read, and want to be clear about

Relationship data. To deliver items to the right people, we necessarily hold your successors', co-owners' and custodians' contact details, and any handoff greeting you write, in a form we can read. Please don't put passwords or secret codes in a handoff message. Store those as encrypted items instead.

Succession (your choice). With the default succession option, Vaulant holds a key that can unlock what you leave behind, but only after a time-gated waiting period triggered by a Recovery Request, never while you are responsive, and never for your everyday use of the vault. If you choose a custodian option instead, even that stays beyond our reach: the key is split between us and your custodian, and neither can act alone. We disclose the tradeoff when you choose.

6. How we use your information

  • To provide, secure and operate your vault and the succession feature.
  • To send transactional messages: sign-in codes, check-in prompts, invitations and, at succession, notifications to the people you named.
  • To process your subscription and prevent abuse.
  • To diagnose errors and improve reliability.
  • To comply with law and enforce our Terms.

We do not use your information for advertising, and we do not sell it.

7. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to run the service); our legitimate interests (to secure the service and prevent abuse); your consent (where specifically requested); and compliance with legal obligations.

8. Who we share it with

We use a small set of infrastructure providers ("sub-processors"):

  • Amazon Web Services (AWS): hosting, storage, identity (Amazon Cognito) and email delivery, in the United States.
  • Stripe: subscription billing.
  • Sentry: privacy-preserving error monitoring (scrubbed; never your item contents).

We choose providers that don't need to read user content, and in our case they couldn't anyway, because your items are encrypted before they reach them. We may also disclose information if required by valid legal process, or to protect our rights and users' safety. For the items in your everyday vault we hold no keys, so we could not produce their contents even if compelled; the succession key you assign to us is the one exception, released only under the time-gated process above.

9. International transfers

We operate in the United States (AWS us-east-1). If you access Vaulant from outside the US, your information is processed in the US. Where required, we rely on appropriate safeguards such as the Standard Contractual Clauses.

10. How long we keep it

  • Account and vault data: for as long as your account is active.
  • Encrypted item and file contents: until you delete them, or until the vault is deleted or fully handed off, after which the ciphertext is permanently removed (subject to short grace and safety windows).
  • Security audit records: retained in an immutable, write-once export for up to seven years for integrity and compliance.
  • Waitlist and support emails: kept only as long as needed for the purpose collected.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, export or object to the processing of your personal information, and (for California residents) to know what we collect and to opt out of "sale", which we do not do. To exercise a right, email privacy@vaulant.com. Note that because your items are encrypted with keys only you hold, we can act on the data we can see (account, billing, relationship data), but we cannot decrypt or export your item contents for you. You do that from your own device.

12. Security

End-to-end encryption of your items, isolated and audited AWS accounts, least-privilege access, and an append-only audit log. More detail is on our Security page. No system is perfectly secure, but the design ensures a breach of our servers does not expose your item contents.

13. Children

Vaulant is not intended for anyone under 18, and we do not knowingly collect information from children.

14. Changes to this policy

We may update this policy from time to time. We will change the effective date above and, for material changes, notify you by email or in the app before they take effect.

15. Contact

Vaulant, Inc. · privacy@vaulant.com. The plain-language commitments behind this policy are also visible on our Security and wind-down pages, and the legal terms of the service are in our Terms of Service.

Vaulant

Private storage for the things your family will need.

Product

  • How it works
  • Pricing
  • Security
  • FAQ

Company

  • Contact
  • Privacy
  • Terms
  • If we go away
© 2026 Vaulant. Your items are encrypted on your device, by design.