Privacy policy
What Vault Tec AI collects, how we use it, who we share it with, and the rights you keep over your data. Plain-English summaries paired with the binding commitments below.
Last updated: 2026-08-04
Account email address and password credentials, handled by better-auth when you create an account or sign in. Signal preferences you opt into on the dashboard (asset classes, exchanges, notification channels). Payment metadata captured during checkout through Stripe, the third-party processor that handles our billing. We do not store full card numbers on our servers.
Server logs (IP, user agent, request timing) used to keep the service healthy and to detect abuse.
To run the service: authenticate you, deliver the signal feed you subscribed to, route trades you choose to execute, send transactional emails (account, billing, security), and show the dashboard state that belongs to your account.
To improve the service: aggregate, de-identified usage trends (e.g., which signals are most-read), and crash/performance telemetry. We do not sell your personal data, and we do not share your account-level activity with third-party advertisers.
Polsia email proxy sends transactional email on our behalf (account notices, billing receipts, security alerts) and is the delivery path for every outbound message. Stripe processes subscription and one-time payments on our behalf under a Connect-style arrangement; card data goes directly to Stripe, and we receive tokenised payment metadata rather than card numbers. Neon DB hosts the Postgres database our Prisma models live on, with stored user and state data on encrypted-at-rest Postgres storage in a US region.
Each processor handles only the data necessary to its role and is bound by its own data-handling commitments. We do not share your account data with any other third party.
Account record and signal preferences: kept for the lifetime of your account. Deleted within 30 days of account closure, except where law requires longer retention (e.g., tax records). Payment metadata is retained as long as Stripe retains it under their retention policy; we retain only what we need for receipts, refunds, and accounting.
Server logs are retained for 90 days, then aggregated or deleted. Backups are encrypted; the oldest retained backup is deleted 35 days after a record is deleted from the primary database.
Access — request a copy of the personal data we hold about you. We respond within 30 days. Deletion — close your account from Settings → Account, or email support. We delete the data described above and confirm the deletion window in writing. Export — request a machine-readable export of your account data, including signal preferences and billing history.
You can also correct your signal preferences and contact details at any time from Settings without contacting support.
Questions about this policy, your data, or a rights request can be sent to vault-tec-ai@polsia.app. Privacy and account-deletion requests are prioritised ahead of general feature support; a human reads every message.
Questions about this policy, your data, or a rights request — email vault-tec-ai@polsia.app. Privacy and account-deletion requests are prioritised ahead of general feature support.