Privacy Policy
Last updated: 10 September 2026
This policy explains what Shanghai Wavetop Information Technology Co., Ltd (“Vaulta”, “we”) collects when you use the Vaulta backup service, why we collect it, and how long we keep it. It applies to usevaulta.app, the web console and the Vaulta agent.
1. What we deliberately cannot see
Backup content is encrypted on your machine with AES-256-GCM before it is uploaded, using a key derived from a BIP39 recovery mnemonic generated on your machine. That mnemonic is never transmitted to us and we have no copy of it.
Backup content is written directly from your machines to object storage in your own cloud account. It does not pass through our servers. As a result we cannot read your file names, file contents, database contents or directory structure, and we cannot produce them in response to a request from anyone — including a lawful one.
2. What we do collect
Account data
- Email address, and a salted hash of your password (Argon2id — we never store the password itself).
- Email verification status and timestamps.
- Plan tier, subscription status and quota usage.
Backup metadata
To schedule work and report status, the control plane stores:
- A name you choose for each protected machine, plus its operating system and CPU architecture.
- Agent online status, last heartbeat time and agent version.
- Backup job definitions: a name, a schedule expression, the workload type, and the source path or database name you entered.
- For each completed backup: an opaque snapshot identifier, byte counts, duration and success or failure status.
- Restore verification results: pass or fail, and the checks that ran.
- Your storage bucket endpoint, region and bucket name, plus storage credentials encrypted at rest with AES-256-GCM.
Note the boundary: we store the path you chose to back up, because we have to tell the agent what to do. We do not store what is inside that path.
Technical data
- Server logs containing IP address, timestamp, request path and response status, for security and debugging.
- Aggregate, cookie-free website analytics. We do not use Google Analytics, advertising trackers or cross-site cookies.
3. Why we process it
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Operating the Service you signed up for | Performance of a contract |
| Billing and tax compliance | Legal obligation / contract |
| Security, abuse prevention, debugging | Legitimate interests |
| Service emails: verification, failure alerts, weekly reports | Performance of a contract |
| Product announcements you can unsubscribe from | Consent |
4. Where it is processed
Vaulta is operated by a company registered in Shanghai, China. The control plane itself runs in Amazon Web Services in the United States (us-east-1). If you are in the UK or EEA, this is an international transfer and we rely on the Standard Contractual Clauses. We plan to offer an EU-hosted control plane; this policy will be updated when it is available.
Your backup data does not move with us. It lives in the bucket and region you choose, under your own cloud account. It never transits our servers and it is encrypted before it leaves your machine.
5. Who else touches it
We use a small number of subprocessors and no more:
| Subprocessor | Purpose | Data |
|---|---|---|
| Amazon Web Services | Hosting the control plane | All control-plane metadata |
| Our payment provider (merchant of record) | Payments, invoicing, tax | Email, billing details — collected by them, not by us |
| Our transactional email provider | Verification and alert emails | Email address, message content |
| Cloudflare | DNS and website hosting | Website request logs |
We do not sell personal data, and we do not share it for advertising. We will disclose data if legally compelled — and note that what we could disclose is metadata, never your file contents.
6. How long we keep it
- Account and backup metadata — for as long as your account is open, then deleted within 30 days of account deletion.
- Server logs — 30 days.
- Billing records — as required by tax law, typically seven years, held by our payment provider.
- Your backup data — controlled entirely by you, in your own bucket, under your own lifecycle rules. Deleting your Vaulta account does not delete it.
7. Your rights
If you are in the UK or EEA you have the right to access, correct, delete, export or restrict processing of your personal data, and to object to processing based on legitimate interests. You also have the right to complain to your local supervisory authority.
To exercise any of these, email [email protected]. We respond within 30 days. Most account data can also be exported directly from the REST API without contacting us.
8. Security
- All traffic to the control plane is HTTPS-only. Our domain is on the browser HSTS preload list, so your browser will never connect to us over plain HTTP — not even on the first request.
- Passwords are hashed with Argon2id.
- Storage credentials are encrypted at rest with AES-256-GCM.
- Backup content is encrypted client-side before it leaves your machine.
- Agents authenticate with a bearer token that is stored hashed, never in plaintext.
Report a vulnerability to [email protected]. We will acknowledge within two business days and will not pursue researchers acting in good faith.
9. Children
The Service is not directed at anyone under 18 and we do not knowingly collect their data.
10. Changes
We will announce material changes to this policy by email at least 30 days before they take effect. The “last updated” date above always reflects the current version.
11. Contact
Shanghai Wavetop Information Technology Co., Ltd
Room 22301-186, Building 14, No. 498 Guoshoujing Road, Shanghai Pilot Free Trade Zone, China
Privacy enquiries — [email protected]