Privacy Policy

Last updated: 2026-08-21

This Privacy Policy explains how Vaultry, Inc. ("we", "us", "our") collects, uses, shares, and protects your personal information when you use Vaultry.

By using the service you agree to the practices described here.

1. What we collect

We collect the following categories of information:

From Google when you sign in (Google OAuth):

  • Your email address (used as your account identifier).
  • Your name and profile picture, if your Google account has them.
  • A Google user ID we use to link future sign-ins to your account.
  • We do not receive your Google password and we do not see your Google contacts, calendar, Drive, or any other Google data.

Information you create in the app ("Your Content"):

  • Item records (name, serial, condition, location, value, dates, notes, custom-field values).
  • Photos you upload.
  • Locations, sub-locations, and custom lookups you define.
  • Audit sessions, custom field definitions, item relationships.
  • Backups and exports you generate.

Billing information (only if you subscribe):

  • A Stripe customer ID and subscription metadata (tier, status, renewal date).
  • We do not store full payment card numbers, CVV codes, or bank details. Stripe handles all of that directly.

Activity and security logs:

  • Records of significant actions you take (item create/update/delete, login/logout, exports, backups, lock-field overrides, etc.) — see the in-app Activity Log page for the full list.
  • Session metadata: when sessions are created, last-used time, IP address of the most recent use.

Technical information:

  • Your IP address (recorded with sessions and in CloudFront access logs).
  • Browser type, operating system, and request paths (CloudFront / WAF logs).
  • A single httpOnly, Secure, SameSite=Lax session cookie. No tracking cookies, no advertising cookies, no third-party analytics cookies.

2. How we use this information

We use your information to:

  • Provide the service: store and serve your inventory, photos, exports, audits, and reports.
  • Authenticate you: confirm your identity at each request via the session cookie.
  • Bill you (paid tiers only): pass minimal information to Stripe to create and manage your subscription.
  • Send transactional email: account welcome, payment-failed, trial-ending, subscription-cancelled, and account-deleted notifications via Amazon SES. We do not send marketing email.
  • Operate and improve the service: diagnose bugs, plan capacity, detect abuse, review error reports.
  • Comply with legal obligations and respond to valid legal process.

We do not:

  • sell your personal information,
  • share your personal information for cross-context behavioral advertising,
  • use your photos or item data to train machine-learning models,
  • share your data with any third party for that third party's own marketing.

3. Who we share with

Your information is shared only with the limited set of service providers we need to operate Vaultry:

| Provider | Purpose | Data shared | |---|---|---| | Amazon Web Services (AWS) | Hosting, database, photo storage, transactional email (SES) | All Your Content (encrypted in transit; tenant-isolated in the database; private S3 buckets) | | Stripe | Subscription billing | Email address, subscription tier, plus payment data you enter directly into Stripe's checkout | | Google | Sign-in (OAuth identity provider) | Your authentication request only; Google sees that you signed in to Vaultry |

Each provider is bound by its own privacy and security commitments. We use them under standard commercial terms.

We may also disclose your information:

  • In response to valid legal process (court order, subpoena, search warrant). We will notify you of the request unless legally prohibited from doing so.
  • To protect rights and safety if we believe disclosure is necessary to investigate or prevent fraud, abuse, or imminent harm.
  • In connection with a corporate transaction (merger, acquisition, asset sale). You will be notified before your information is transferred under new ownership, and the new owner will be bound by terms no less protective than this Policy.

4. Where your data lives

Vaultry is hosted on Amazon Web Services in the United States (region: us-east-1). If you access the service from outside the United States, your information is transferred to and processed in the US.

5. How long we keep your data

| Category | Retention | |---|---| | Your Content (items, photos, notes, etc.) | As long as your account is active | | Activity log entries | As long as your account is active | | Sessions | 4 hours of inactivity, or 7 days absolute (whichever comes first) | | Backups | Per your tier (Starter ~5 weeks, Unlimited ~26 weeks); local downloads you save are entirely under your control | | Stripe billing records | Stripe retains per its own policy; we hold subscription metadata while your account is active and for the period required by tax / accounting law (typically ~7 years) | | Closed accounts | We delete your data within 30 days of account closure, except for backups already taken (which expire per the tier schedule) and records we are legally required to retain | | CloudFront / WAF access logs | 90 days |

You can download a complete export of Your Content (CSV + photos as ZIP) at any time from the import/export tools in the app. We encourage you to take regular exports.

6. Your rights

You have the following rights regarding your personal information:

  • Access: download all your data via the in-app export tools at any time.
  • Correction: edit any field of any item directly in the app. Use the audited override flow for identity fields like serial / VIN / certification number.
  • Deletion: delete individual items at any time, or delete your entire account from Settings (subject to the retention window above).
  • Portability: the export is in standard CSV + JSON, designed to be imported into any other tool or kept as a personal archive.
  • Object / restrict processing: contact us at the address below.

To exercise any of these rights, contact us at the address below. We will respond within the timeframe required by applicable law.

7. Security

We apply industry-standard practices to protect your data:

  • Tenant isolation enforced at both the application layer (explicit WHERE tenant_id = ? in every query) and the database layer (PostgreSQL Row-Level Security policies on every multi-tenant table).
  • Encryption in transit: HTTPS for every browser-to-server request. Internal AWS traffic is also encrypted in transit between CloudFront, the load balancer, and the API service.
  • Hashed session tokens at rest (SHA-256). The raw token only exists in your cookie.
  • No password storage: authentication is via Google OAuth; we never see or store your password.
  • Secrets in AWS Secrets Manager, not in source code or environment files.
  • Audit logging of significant account actions for forensic review.
  • Rate limiting to mitigate brute-force and abuse attempts.

No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security and you use the service at your own risk.

If we become aware of a security incident affecting your data, we will notify you in accordance with applicable law.

8. Children

Vaultry is not directed at children under the age of 18 and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, please contact us and we will delete the account.

9. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you in-app and by email at least 30 days before the changes take effect. The "Last updated" date at the top of this document reflects the most recent change.

Your continued use of the service after the effective date of an update constitutes acceptance of the updated Policy.

10. Contact

Questions about this Privacy Policy or your data? Contact us at:

Vaultry, Inc. Email: support@vaultry.app


Firearms-specific note

If you record firearms in Vaultry, you should know:

  • Your firearm records — including serials, photos, locations, and notes — are stored under the same tenant-isolation and security controls as every other item type. They are not flagged or treated specially in any database query, log, or report.
  • We will not proactively share your firearm records with any government agency, law-enforcement body, insurance company, or other third party.
  • We will respond to valid legal process (subpoena, warrant, court order). We will notify you of any such request unless we are legally prohibited from doing so.
  • Vaultry is not an FFL bound-book or A&D record system, and we make no commitment to retain or surrender records in any format defined by ATF regulations. See the Terms of Service for the full disclaimer.