Privacy Policy
Last updated: September 2026. This policy explains how DeadVault collects, uses, and protects your data.
1. Information We Collect
Account information: Name, email address, firm name, and billing details when you register. We collect this to provide the Service and process payments.
Usage data: We log page views, feature usage, and API calls to improve the Service. This data is aggregated and not linked to individual file contents.
File metadata: File names, sizes, upload timestamps, and access patterns are logged as part of the audit trail. We do NOT access or analyze the contents of your encrypted files.
Client portal data: When clients access drops, we log IP addresses, timestamps, and user agents for security and audit purposes. Clients do not need to create accounts.
2. How We Use Your Information
We use your information to:
- Provide and maintain the DeadVault service
- Process payments through Stripe
- Generate audit trails for your compliance needs
- Send transactional emails (drop notifications, receipts, security alerts)
- Improve the Service based on aggregate usage patterns
- Respond to support requests and security inquiries
We do NOT:
- Sell your personal information to third parties
- Use your data for advertising
- Access the contents of your encrypted files
- Share your client data with other DeadVault users
3. Data Storage & Security
Files are encrypted with AES-256-GCM using per-file encryption keys. Keys are wrapped with a master key and stored in a separate key store, not alongside file data. All data is transmitted over TLS 1.2+. Database contents are encrypted at rest.
Infrastructure is hosted in the United States. We implement industry-standard security measures including rate limiting, security headers, and access controls. See our Security page for detailed technical information.
4. Data Retention & Cryptographic Erasure
Drop contents: Encrypted files and their encryption keys are destroyed when the drop deadline passes. This is cryptographic erasure, the keys are permanently deleted, making the encrypted data mathematically unrecoverable.
Audit trail: Retained for 90 days after drop expiration, then permanently deleted. This retention period exists for compliance purposes (regulatory audits, legal holds).
Account data: Retained while your account is active. After cancellation, account data is deleted within 30 days, except where required by law (tax records, billing history).
Backups: Database backups are rotated on a 30-day cycle. Backup retention does not extend the availability of cryptographically erased files, since the encryption keys no longer exist.
5. Third-Party Services
We use the following third-party services:
- Stripe: Payment processing. Stripe's privacy policy applies to payment data.
- Twilio: SMS delivery (Pro Comm Bundle only). Phone numbers are shared with Twilio for message delivery.
- Email provider: Transactional email delivery. We share email addresses for notification delivery.
- Google Analytics and Microsoft Clarity: Usage analytics, heatmaps and session replay, with on-screen text masked (see Section 7).
We do not share file contents with any third party. Third-party services only receive the minimum data necessary for their function.
6. Your Rights
You have the right to:
- Access your account data and audit trails
- Export your audit trail data (CSV/JSON)
- Correct inaccurate account information
- Delete your account (subject to the retention periods in Section 4)
- Opt out of non-essential communications
Note: Due to cryptographic erasure, we cannot recover files after a drop's deadline has passed. This is the intended behavior of the Service, not a limitation.
California residents (CCPA): You have additional rights including the right to know what data we collect, request deletion, and opt out of data sales (we don't sell data). Contact us to exercise these rights.
7. Cookies & Tracking
We use essential cookies for authentication and session management. We use localStorage to persist user preferences (dark mode, etc.). We do not use advertising trackers.
We use Google Analytics and Microsoft Clarity to understand how people use DeadVault, both on our website and inside the app. Clarity records interactions such as clicks, scrolling, mouse movement and the pages or screens visited, and turns them into heatmaps and session replays that show us where the product is confusing or slow so we can fix it. Clarity is set to mask all text on the screen, so the contents of your account (file names, file contents, client names and messages) are not captured. These tools use first- and third-party cookies to recognize repeat visits. They are not used for advertising, and we do not sell this data. Encrypted file contents are never visible to these tools. Microsoft processes Clarity data under the Microsoft Privacy Statement (https://www.microsoft.com/privacy/privacystatement).
8. Children's Privacy
DeadVault is not intended for use by individuals under 18. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this Privacy Policy with 30 days' notice via email. Continued use after the notice period constitutes acceptance. Material changes will be highlighted in the notification.
10. Contact
For privacy-related questions or to exercise your data rights:
Email: privacy@deadvault.app
General contact: support@deadvault.app
Data Controller: Hunter Creative Media & Design, Aurora, IL, United States.
Questions about this policy? Contact us.
See also: Terms of Service | Security