Privacy Policy
Last updated: July 15, 2026
1. Data Controller
VaultDrop ("we", "us", "our") is the data controller responsible for your personal data. VaultDrop is operated within the European Union and is committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following categories of personal data:
- Account information: email address and name, plus a hashed password when you register with email. If you choose Google sign-in, we receive your Google account identifier, verified email address, profile name, and profile image.
- Files and metadata: encrypted file contents, file names, sizes, folder paths, and upload timestamps.
- Usage data: IP addresses, browser type, and access timestamps recorded in server logs and audit trails.
- Anonymous transfers: files sent via the anonymous transfer feature are stored temporarily without an account association.
- File requests and receipts: request titles and messages, recipient folder, expiry and status, file receipt details, and an optional submitter email address used to deliver the requested receipt.
3. Legal Basis for Processing
We process your data under the following GDPR legal bases:
- Contract performance: to provide the cloud storage service you signed up for.
- Legitimate interest: to maintain security, prevent abuse, and improve our service.
- Consent: where applicable, such as for optional communications.
4. Where Your Data Is Stored
VaultDrop uses Cloudflare for application execution, metadata, and encrypted file-object storage:
- Application execution: Cloudflare Workers.
- File-object storage: Cloudflare R2, EU jurisdiction.
- Primary database: Cloudflare D1.
Cloudflare also provides network delivery, security, and transactional account email. Stripe processes billing data for paid accounts. If you choose Google sign-in, Google authenticates you and provides only basic identity information; VaultDrop does not request access to Google Drive, Gmail, or other Google account content. These providers may process limited service metadata outside the EU under their applicable data processing terms and transfer safeguards. VaultDrop does not send plaintext file contents to these providers: file contents are encrypted in your browser before upload.
5. Data Retention
- Account data: retained while your account is active. An erasure request immediately disables access and is completed by a retryable background process; invoice records may be retained by Stripe where legally required.
- Files: retained until you delete them. Soft-deleted files are permanently removed within 30 days.
- Anonymous transfers: objects and associated transfer metadata are automatically deleted after 7 days.
- File requests: open request metadata is retained through expiry, revocation, or archival. Received files follow the normal file-retention rules; receipt metadata is retained with the account until account erasure.
- Audit logs: retained for up to 12 months for security purposes.
6. Your Rights
Under the GDPR, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate personal data.
- Erasure: request deletion of your personal data.
- Data portability: receive your data in a structured, machine-readable format.
- Restriction: request limited processing of your data.
- Objection: object to processing based on legitimate interest.
To exercise any of these rights, contact us at privacy@vaultdrop.eu.
7. Cookies and Browser Storage
VaultDrop uses only cookies and browser storage needed to provide the service, protect sign-in, remember interface preferences, and support resumable uploads. We do not use third-party analytics, advertising cookies, tracking pixels, or cross-site profiling. Because these items are strictly necessary for the features you request, they cannot be disabled through VaultDrop without affecting those features.
Google sign-in is optional and uses a redirect to Google only after you choose it. VaultDrop does not embed Google One Tap, Google advertising, or Google analytics scripts. Google may use its own cookies while you are on Google's domain under Google's privacy terms.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| better-auth.session_token | Cookie | Keeps you securely signed in | Up to 30 days |
| better-auth.two_factor | Cookie | Secures a two-factor sign-in challenge | Up to 10 minutes |
| vaultdrop_privacy_notice | Cookie | Remembers that you have seen the privacy notice | 180 days |
| vaultdrop-theme, vaultdrop-view, vaultdrop-tree-expanded | Local storage | Remembers your interface preferences | Until changed or cleared |
| vaultdrop-vault / master-key | IndexedDB | Keeps a non-extractable browser encryption key available between page loads | Until sign-out or 30 minutes of inactivity |
| vaultdrop-upload-resume-v1 | Local storage | Keeps encrypted upload recovery metadata for resumable uploads | Up to 7 days |
| vaultdrop-checkout | Session storage | Carries your selected plan into sign-in and checkout | Until the tab closes or checkout continues |
Authentication cookie names may include a __Secure-prefix in production. You can clear cookies and browser storage through your browser at any time, although doing so may sign you out or reset saved preferences and upload recovery data.
8. Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (TLS), hashed passwords, two-factor authentication, and audit logging of security-relevant actions.
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or a notice on our website. The "last updated" date at the top reflects the most recent revision.
10. Contact
If you have questions about this privacy policy or your personal data, contact us atprivacy@vaultdrop.eu.
You also have the right to lodge a complaint with a supervisory authority in the EU member state where you live or work.