In short

We collect as little as we can. For an account that means your email address and a hashed password. We run no advertising or analytics trackers, and we never sell your data.

Who is responsible

VantageVault is operated by Zyntex (“we”). For any privacy question or request, email privacy@vantagevault.dev.

What we collect

  • Account data: your email address, a hash of your password (never the password itself), an internal user ID and the creation date.
  • Session data: sign-in cookies that keep you logged in (see Cookies below).
  • Technical data: IP address and request details, processed by our hosting and security providers to deliver the site, block abuse and apply rate limits.
  • Messages: if you email us, we keep your message and our reply.

Cookies

We use only strictly necessary cookies: the sign-in cookies. They are marked HttpOnly and Secure, so scripts on a page cannot read them, and they are shared across *.vantagevault.dev so one login works across our services. They are removed when you log out. We set no analytics, advertising or tracking cookies.

How we use your data

  • To create and secure your account and keep you signed in.
  • To send essential emails such as email confirmation and password reset.
  • To detect and prevent abuse of our services.
  • To answer your messages and meet legal obligations.

We do not use your data for advertising or profiling, and we do not sell it.

Service providers

Two providers process data on our behalf. Supabase hosts our database and authentication, and stores your account data. Cloudflare provides hosting, DNS, network security and the gateway that handles sign-in. Essential emails are sent through our authentication provider. We share data with no one else, except where the law requires it.

How we protect it

  • HTTPS on every page and request.
  • Passwords are hashed by our authentication provider and never stored in plain text.
  • Database access rules limit every account to its own data.
  • Sign-in cookies are HttpOnly, and a strict content security policy limits what scripts can run.
  • Security reports are welcome at security@vantagevault.dev.

No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authorities where the law requires it.

Encryption: today and goal

Client-side, zero-knowledge encryption is the design goal for VantageVault Storage. It does not apply to the account system on this site, and we will not describe a service as zero-knowledge until it is.

Retention and deletion

We keep account data while your account exists. You can delete your account yourself from the Account page, which removes the account and its profile data. Copies may remain in provider backups for a limited time before they are overwritten, and providers keep short-lived technical logs under their own policies.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or export it. If you are in the EU/EEA, the UK or Switzerland, these rights come from the GDPR, UK GDPR and Swiss data protection law, and you may also complain to your local supervisory authority. Email privacy@vantagevault.dev; we aim to reply within 30 days.

Children

Our services are not intended for children under 16.

Changes

If we change this policy we will update this page and its date. For significant changes affecting how we use your data, we will also email account holders.