Privacy Policy
Last Updated: September 2026 · Effective Date: September 2026
1. Commitment to Privacy
Vaultsink AI (“Vaultsink”, “we”, “our”, “us”) is committed to protecting the privacy, confidentiality, and data sovereignty of our platform users, customers, and their website visitors.
This Privacy Policy outlines how we collect, use, disclose, and safeguard personal information when you access our website (vaultsink.dev), our web builder, our dashboard, and our hosting services. We adhere to global data protection frameworks, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
2. Information We Collect
We collect personal information that you provide directly to us, information collected automatically during your use of our platform, and information from third-party integrations:
A. Account & Authentication Data
Full name, email address, password hash (encrypted with bcrypt), session tokens, and OAuth identifiers if you choose to sign in via Google.
B. Prompt Content & Website Project Data
Business descriptions, service lists, industry selections, brand color choices, custom uploaded imagery or logos, domain names, and conversational revision prompts transmitted during website creation.
C. Billing & Payment Information
Payment transactions are processed directly by our merchant-of-record and payment processor (Polar). Vaultsink never stores or has access to your full credit card numbers, CVVs, or bank account credentials; we only receive transactional confirmation tokens, billing tier, and renewal timestamps.
D. Technical, Log & Edge Telemetry Data
IP addresses, browser user agent, device operating system, request timestamps, referring URLs, CDN cache metrics, and error telemetry necessary to maintain infrastructure security and DDoS defense.
3. Legal Bases for Processing (GDPR)
Under GDPR Article 6, we process personal information under the following legal grounds:
- Performance of a Contract: To provide website synthesis, in-place AI editing, deployment, and customer support as requested under our Terms of Service.
- Legitimate Interests: To secure our network, prevent fraud and abuse on subdomains, debug compiler errors, and enhance platform performance.
- Compliance with Legal Obligations: To comply with tax, financial reporting, and statutory law enforcement requests.
- Consent: Where you have granted explicit consent for optional marketing communications.
4. AI Processing & Third-Party Sub-Processors
Vaultsink utilizes reputable third-party cloud infrastructure and AI model providers to deliver automated site generation. When you prompt our AI engine, business details are transmitted strictly via secure, enterprise API endpoints:
- AI Model Inference: Google Gemini API, OpenAI, and Anthropic are utilized for copywriting and layout AST compilation. We access these services via standard commercial APIs where provider terms confirm customer inputs are not used to train foundation models.
- Cloud Infrastructure & Database: Supabase and Neon (PostgreSQL database hosting), Cloudflare (Edge CDN, Workers routing, and R2 static asset storage), and Vercel (Edge serverless runtime).
- Payment Processing: Polar.sh for subscription billing and tax compliance.
- Curated Stock Photography: Unsplash API for retrieving relevant business category photography.
Vaultsink AI does not sell, rent, or trade your personal data, business prompts, or customer lists to third-party data brokers or behavioral advertising networks.
5. California Consumer Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act provides you with specific rights regarding your personal information:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you over the past 12 months.
- Right to Delete: You have the right to request deletion of your personal data, subject to certain legal exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: Vaultsink does not “sell” or “share” personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.
- Right to Non-Discrimination: We will never discriminate against you for exercising your CCPA/CPRA privacy rights.
To exercise any of these rights, contact us at privacy@vaultsink.dev.
6. Your European Privacy Rights (GDPR / UK GDPR)
If you reside in the European Economic Area (EEA) or United Kingdom, you possess statutory rights under Articles 15-22 of the GDPR:
- The right to access, update, or rectify inaccurate information;
- The right to erasure (“Right to be Forgotten”) of your account and generated websites;
- The right to restrict or object to our processing of your personal data;
- The right to data portability (exporting your website AST JSON and static code bundles);
- The right to withdraw consent at any time without affecting the lawfulness of prior processing;
- The right to lodge a complaint with an authorized EU/UK Data Protection Authority.
7. Cookies & Local Storage
Vaultsink AI utilizes strictly necessary cookies and local storage tokens solely to maintain authenticated user sessions (via Better Auth), preserve unsaved website generation drafts, and record UI theme preferences. We do not deploy third-party advertising tracking cookies. For more information, read our Cookie Notice.
8. Data Retention & Security Safeguards
We retain account information and generated website projects for as long as your account remains active. Upon receiving an account deletion request, your projects and personal identifiers will be permanently removed from our active databases within thirty (30) days, except where retention is required by law (e.g. tax records).
We implement industry-standard administrative, physical, and technical safeguards, including TLS 1.3 encryption in transit, HttpOnly secure cookies, bcrypt password hashing, and isolated database query boundaries. Learn more on our Security Page.
9. Children's Privacy (COPPA)
Vaultsink AI is strictly intended for business founders, creators, and commercial professionals. Our services are not directed to or intended for children under the age of thirteen (13) (or sixteen (16) in the EU). We do not knowingly collect personal information from children. If we discover that a child has provided us with personal information, we will immediately delete it.
10. Contact Our Privacy Officer
For privacy inquiries, data subject access requests, or deletion requests, contact our designated Data Protection Officer:
Vaultsink AI Privacy Office
Data Protection Officer: privacy@vaultsink.dev
Legal Inquiries: legal@vaultsink.dev