Privacy Policy
Last updated: August 11, 2026
vvault provides a workspace to upload and manage audio files, create packs and series, share links, send campaigns, track engagement, sell licenses, and manage billing. This policy explains what data we collect and how we use it to operate and secure the service - and where we act not on our own behalf but on yours, which is set out first, in Section 2.
1. Who We Are
vvault is operated from Belgium by Tom Nsengiyumva (sole proprietor, not a company), enterprise and VAT number BE 1022.549.155, registered office Minderbroedersstraat 10, 8000 Brugge, Belgium ("vvault", "we").
For any privacy matter, including a request to exercise your rights, contact privacy@vvault.app or use the in-app Support page. For other legal questions, legal@vvault.app. For copyright notices, copyright@vvault.app.
We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one. privacy@vvault.app reaches the operator directly.
2. Our Two Roles: Controller and Processor
vvault does two different things with personal data, and the GDPR treats them differently. For everything we decide ourselves - your account and profile, authentication, billing and subscriptions, marketplace orders and invoices, fraud prevention, security logging, content moderation, and our own analytics measuring how vvault is used - we are the controller within the meaning of Article 4(7) GDPR. This policy describes that processing.
For the data you bring with you and use vvault to reach, we are your processor: the contacts you import or create, the groups and segments you build, the campaigns and series you send, and the engagement events recorded on the links, packs and pages you share. There you decide who is contacted, why, and on what legal basis; we only execute. That relationship is governed by our Data Processing Agreement at /homepage/dpa, which forms part of the Terms of Use, applies automatically and needs no signature.
The practical consequence for recipients: if you received an email sent through vvault, or opened a link someone shared with you, the person who sent it is the controller of that data and can correct or delete it in the product in seconds. Write to them first. If you write to us instead, we will not answer on their behalf, but we will identify the sender where we can and forward your request to them without undue delay.
Where a single feature involves both roles, each part is governed by the document that covers it: this policy for our part, the Data Processing Agreement for yours.
3. Information We Collect
Information you provide directly: account details (name, email, handle, avatar, locale), uploaded content (audio files, covers, metadata such as BPM and key), your contacts and groups, campaign content and recipients, direct messages, marketplace listings and license terms, support messages, and billing-related information.
Information collected automatically: IP address, device and browser data, server logs, cookies and similar identifiers, approximate region (used for currency and language), and usage events needed to run, secure, and improve the service.
Information from recipients and visitors of your shared content: when someone opens a link, streams, downloads, or interacts with content you shared, we record those events (including technical data) and show them to you as engagement analytics. For that processing we act as your processor, as described in Section 2.
Seller information: if you sell on the marketplace, our payment provider collects the identity and bank details that anti-money-laundering law requires of it. We receive the onboarding status, the payout records and the transaction metadata; we do not receive or store your full bank credentials or card numbers.
4. Legal Bases
We process data on the following GDPR bases: performance of our contract with you, Article 6(1)(b) (running your library, sends, analytics, marketplace, subscriptions); our legitimate interests, Article 6(1)(f) (service security, abuse and fraud prevention, product improvement, measuring engagement on shared content); your consent, Article 6(1)(a), where required (non-essential cookies and advertising measurement, marketing communications, connecting third-party accounts); and compliance with legal obligations, Article 6(1)(c).
The legal obligations are concrete, not decorative: Belgian accounting and VAT law fixes how long we must keep orders, invoices and payout records, and that obligation is what prevents us from deleting them on request. See Section 14.
Where we rely on our legitimate interests, you have the right to object under Article 21 GDPR, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
5. Engagement Tracking
Opens, clicks, plays, play duration, downloads, and saves on content you share are recorded to provide your analytics. We apply protections to filter automated scanners and improve metric quality. If you receive a vvault-powered email or open a shared link, the sender can see these engagement events.
These events are processed on the sender's instructions, not for our own purposes. We do not use them to build a profile of you, and we do not sell or share them with advertising networks.
7. Content Moderation
To keep vvault free of illegal and prohibited imagery (see the Terms of Use, Prohibited Content), we review content that is reported to us and we may screen uploaded images - cover art, profile pictures and banners, video thumbnails, and images used in emails - with automated tools. Where automated screening is used, it may be performed by a specialised service provider acting under contract as our processor, and you can contest any moderation decision (see the Terms, and Section 8 below).
Legal bases: our legitimate interests in keeping the platform safe and lawful (Art. 6(1)(f) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR). Records of moderation decisions are kept for up to 12 months, or longer where a specific case, dispute, or legal obligation requires it. Content indicating serious crime, in particular child sexual abuse material, is preserved and reported to the competent authorities.
8. Automated Screening and Automated Decisions
Article 13(2)(f) GDPR requires us to tell you where automated processing decides something about you, and to explain the logic. We use it in three places. First, images you upload are screened by automated classifiers that estimate the likelihood that an image falls into a prohibited category; above a threshold the image is flagged and may be restricted pending review. Second, engagement events are filtered by automated rules that try to exclude bots, security scanners and link previewers, so that the analytics shown to a sender reflect people; this affects numbers only. Third, security and anti-abuse rules - rate limits, duplicate sign-up signals, and the fraud checks our payment provider runs on its own account as an independent controller - can refuse a request, a sign-up or a payment.
The logic is threshold-based rather than a profile of you as a person: a classifier or a rule produces a score or a match, and that score is compared to a threshold. The possible consequences are that content is restricted, or that an action is refused. Automated processing never changes your licence terms, your pricing, or what you are owed.
You always have the right to human intervention. If automated screening restricts your content, or an automated check blocks you, write to privacy@vvault.app: a person re-examines the case, you can express your point of view and contest the outcome, and we explain the result. Moderation decisions can also be contested through the route set out in the Terms of Use, within six months, with the same guarantee of human re-review.
Outside these cases we do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. We do not use special categories of personal data for automated screening, and we do not carry out profiling for advertising beyond the consent-based measurement described in Section 6.
9. Connected Accounts and Imports
Gmail sending: if you connect Gmail, we store the tokens needed to send emails on your instruction. You control recipients and message content.
Google Drive and Dropbox import: if you import beats, you pick files in the provider's own picker and the files are transferred directly into your library. We only access the specific files you select (for Google Drive, under the drive.file scope), and we do not browse the rest of your storage.
vvault's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Desktop folder sync: if you use the desktop app's sync, files in folders you choose are uploaded to your library and kept in sync from your device.
10. Payments
Subscriptions, purchases, marketplace payouts, and refunds are processed by Stripe, and by Apple for in-app purchases on iOS. We receive payment status, amounts, and related metadata; we never store full card details. Currency shown is based on your approximate region.
Marketplace purchases are concluded with vvault rather than directly with the seller, and vvault issues the invoice. That is why the order and invoice record sits with us, and why it is subject to the retention obligations in Section 14.
11. Sharing and Public Pages
When you publish or share packs, tracks, folders, series, your profile, or a link-in-bio page, they can be reached through public or tokenized links according to your settings, including expiry and usage limits where configured. Anyone with access can view, stream, or download based on your configuration and license rules. Custom domains you connect serve the same content under your domain.
12. Emails We Send You
We send service emails (verification codes, password resets, receipts, security notices) and product emails such as onboarding tips or feature updates. Product and marketing emails include an unsubscribe option; service emails are necessary to operate your account.
13. Service Providers and Transfers
We rely on service providers to run vvault. Each processes personal data under contract, on our instructions, and only as needed to provide its service. The current providers are: Supabase (database, authentication and file storage, in the European Union); Vercel (application hosting, edge delivery, and request and error logs); Resend (transactional email and campaign delivery); Stripe (payments, seller onboarding and identity verification, payouts and invoicing); Apple (in-app purchases on iOS); Google (sign-in, Gmail sending, Drive import and analytics, each only where you use it); Dropbox (import, only where you use it); and Meta (advertising measurement, only with your consent to marketing cookies, as described in Section 6).
The complete and current list - what each provider does, where it processes, and under which transfer mechanism - is published at /homepage/subprocessors. That page forms part of our Data Processing Agreement, and we give at least thirty (30) days' notice before adding or replacing a provider that touches personal data.
Where a provider processes data outside the European Economic Area, we rely on safeguards recognized by the GDPR: an adequacy decision of the European Commission where one covers the recipient (including the EU-US Data Privacy Framework where applicable), or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional technical and organisational measures.
Stripe, Apple and Meta act as independent controllers for parts of their processing - in particular fraud prevention, their own regulatory obligations, and the profiles Meta maintains. For those parts their own privacy policies apply alongside this one, and we cannot instruct them.
14. Data Retention
Account and profile data, your library, your contacts, your messages and your settings are kept for as long as your account exists. When you delete your account we remove them from our live systems, and the deletion propagates to encrypted backups within thirty (30) days. Items you delete inside the product - tracks, packs, projects - first move to a recoverable state so that a mistake can be undone, and are permanently removed within thirty (30) days of that deletion.
Engagement events, and the technical data attached to them, are kept in identifiable form for twenty-four (24) months from the event, so that a sender can compare a campaign to one sent a year earlier. After that we keep only aggregated or de-identified counts, which are no longer personal data. If the underlying link, pack or campaign is deleted sooner, the events go with it.
Records of moderation decisions, including the reason and the outcome of any appeal, are kept for twelve (12) months, or longer where a specific case, dispute, or legal obligation requires it, as described in Section 7.
Server, request and security logs, including IP addresses, are kept for up to twelve (12) months for security, abuse investigation and debugging, and for a shorter period where a provider's own retention is shorter. Authentication and administrative events are kept for the same period. Support correspondence is kept for twenty-four (24) months.
Orders, invoices, payout records and issued licence documents are kept for seven (7) years for accounting purposes and ten (10) years for VAT purposes, counted from the end of the year concerned, as Belgian accounting and VAT law requires. This retention rests on Article 6(1)(c) GDPR and is expressly preserved by Article 17(3)(b), so deleting your account does not delete it. It has one further consequence we want to state plainly rather than leave you to discover: a buyer who paid for a licence keeps the order, the invoice and the licence document even if the seller leaves vvault, and a seller keeps the sales record even if the buyer leaves. Neither side of a transaction can erase the other side's proof of it.
These records are kept for that purpose only. They are not used for marketing, analytics or product development, and the personal data in them is limited to what the accounting and VAT obligations actually require.
Where a claim, dispute, investigation or legal obligation requires it, we keep the specific records concerned until it is resolved and any applicable limitation period has expired; under Belgian law contractual claims generally prescribe after ten (10) years.
15. Security
Audio files live in private storage and are served through signed, expiring links. Access to the service is over encrypted connections, and direct messages use additional encryption safeguards. We apply technical and organizational measures appropriate to the risk; no system can guarantee absolute security, and we will notify you and the competent authority of breaches where the GDPR requires it.
16. Your Rights
Under the GDPR you can ask for access to your data, correction, erasure, restriction of processing, and a copy in a structured, commonly used and machine-readable format. You can object to processing based on our legitimate interests, and you can withdraw consent at any time without affecting processing already carried out. You can also ask for human intervention in an automated decision, as described in Section 8.
You can export your data yourself from your account settings at any time, without contacting us, and we recommend doing so before deleting your account. For anything else, write to privacy@vvault.app; we answer within one month, extendable by two further months for complex or numerous requests, in which case we tell you within the first month and explain why.
Erasure has limits, and we would rather state them than let a request fail quietly: we keep the transaction, invoice and licence records described in Section 14 for as long as Belgian accounting and VAT law requires, and we keep the licence documents that prove what a buyer bought. Article 17(3)(b) GDPR expressly permits this. Everything outside those carve-outs is deleted.
You can also lodge a complaint with the Belgian Data Protection Authority (Autorite de protection des donnees / Gegevensbeschermingsautoriteit, www.dataprotectionauthority.be) or your local supervisory authority. You do not have to go through us first, though we would like the chance to fix it.
17. Children
vvault is not directed at children under 16, and we do not knowingly process their data. If you believe a child provided us personal data, contact privacy@vvault.app and we will delete it.
18. Changes and Contact
We will post any changes to this policy here and update the date above; for material changes we will notify you in the app or by email before they take effect.
Questions about this policy or about your data: privacy@vvault.app. Other legal matters: legal@vvault.app. Copyright notices: copyright@vvault.app.