Vaulta

Privacy Policy

Last updated: 10 September 2026

This policy explains what Shanghai Wavetop Information Technology Co., Ltd (“Vaulta”, “we”) collects when you use the Vaulta backup service, why we collect it, and how long we keep it. It applies to usevaulta.app, the web console and the Vaulta agent.

The short version: we hold your email, your billing status, and scheduling metadata about your backups. We do not hold your files, and we cannot decrypt them.

1. What we deliberately cannot see

Backup content is encrypted on your machine with AES-256-GCM before it is uploaded, using a key derived from a BIP39 recovery mnemonic generated on your machine. That mnemonic is never transmitted to us and we have no copy of it.

Backup content is written directly from your machines to object storage in your own cloud account. It does not pass through our servers. As a result we cannot read your file names, file contents, database contents or directory structure, and we cannot produce them in response to a request from anyone — including a lawful one.

2. What we do collect

Account data

Backup metadata

To schedule work and report status, the control plane stores:

Note the boundary: we store the path you chose to back up, because we have to tell the agent what to do. We do not store what is inside that path.

Technical data

3. Why we process it

PurposeLegal basis (UK/EU GDPR)
Operating the Service you signed up forPerformance of a contract
Billing and tax complianceLegal obligation / contract
Security, abuse prevention, debuggingLegitimate interests
Service emails: verification, failure alerts, weekly reportsPerformance of a contract
Product announcements you can unsubscribe fromConsent

4. Where it is processed

Vaulta is operated by a company registered in Shanghai, China. The control plane itself runs in Amazon Web Services in the United States (us-east-1). If you are in the UK or EEA, this is an international transfer and we rely on the Standard Contractual Clauses. We plan to offer an EU-hosted control plane; this policy will be updated when it is available.

Your backup data does not move with us. It lives in the bucket and region you choose, under your own cloud account. It never transits our servers and it is encrypted before it leaves your machine.

5. Who else touches it

We use a small number of subprocessors and no more:

SubprocessorPurposeData
Amazon Web ServicesHosting the control planeAll control-plane metadata
Our payment provider (merchant of record)Payments, invoicing, taxEmail, billing details — collected by them, not by us
Our transactional email providerVerification and alert emailsEmail address, message content
CloudflareDNS and website hostingWebsite request logs

We do not sell personal data, and we do not share it for advertising. We will disclose data if legally compelled — and note that what we could disclose is metadata, never your file contents.

6. How long we keep it

7. Your rights

If you are in the UK or EEA you have the right to access, correct, delete, export or restrict processing of your personal data, and to object to processing based on legitimate interests. You also have the right to complain to your local supervisory authority.

To exercise any of these, email [email protected]. We respond within 30 days. Most account data can also be exported directly from the REST API without contacting us.

8. Security

Report a vulnerability to [email protected]. We will acknowledge within two business days and will not pursue researchers acting in good faith.

9. Children

The Service is not directed at anyone under 18 and we do not knowingly collect their data.

10. Changes

We will announce material changes to this policy by email at least 30 days before they take effect. The “last updated” date above always reflects the current version.

11. Contact

Shanghai Wavetop Information Technology Co., Ltd
Room 22301-186, Building 14, No. 498 Guoshoujing Road, Shanghai Pilot Free Trade Zone, China
Privacy enquiries — [email protected]