Privacy Policy
Last updated: 11 July 2026
1. Who we are
Vaulis is operated by Hindle Consultants Pty Ltd (ABN 44 608 435 972), Hope Island QLD 4212, Australia. References to "Vaulis", "we", "us", or "our" in this policy mean Hindle Consultants Pty Ltd.
Contact: ian@hindle.biz
2. The short version
Vaulis is a zero-knowledge password vault.
- We cannot read your vault data. It is encrypted on your device before it reaches our servers.
- We store ciphertext. You hold the only decryption key — your passphrase.
- We do not sell your data to anyone, ever.
- We do not serve advertising.
- We collect the minimum information necessary to operate the service.
3. Information we collect
3.1 Information you provide
- Email address — used for account identification, security notification emails (new device logins, org invitations), and billing correspondence. Not used for marketing without your consent.
- Auth verifier — a cryptographic derivative of your passphrase, computed on your device using Argon2id. Used to verify your identity at login. Cannot be used to decrypt your vault or recover your passphrase.
- Encrypted vault data — your passwords, cards, notes, and other items stored as ciphertext. We cannot read this data. It is encrypted end-to-end with keys that never leave your device.
- Billing information — collected and processed by Stripe, Inc. We do not store credit card numbers or payment details on our servers. See Stripe's privacy policy at stripe.com/privacy.
- Organisation and sharing data — names of organisations you create, membership relationships, and collection structures. Item content within shared collections remains encrypted.
3.2 Information collected automatically
- Audit log entries — we record security-relevant events: login timestamps, new device logins, plan changes, 2FA enable/disable, and emergency access requests. We do not log the content of your vault.
- Device information — when you log in, we record a device identifier and the device name your browser reports. This is used to show you active sessions and send login notifications.
- IP addresses — logged as part of server infrastructure (Vercel) for rate limiting and abuse prevention. Not linked to your vault contents.
4. How we use your information
- To provide, maintain, and improve the Vaulis service
- To authenticate you and protect your account from unauthorised access
- To send transactional emails — security alerts, invitation emails, payment receipts. We do not send marketing emails without your explicit consent.
- To process billing and manage subscriptions via Stripe
- To enforce our Terms of Service and prevent abuse
- To comply with legal obligations
5. What we cannot see
Due to the zero-knowledge architecture of Vaulis, we are technically unable to access:
- Your passphrase or master key
- The content of any vault item — passwords, card numbers, notes, documents, SSH keys, or any other stored data
- Credentials you autofill using the browser extension or mobile app
This is enforced by cryptographic design, not policy alone. Even if compelled by law, we cannot produce plaintext vault data we do not possess.
6. Information sharing and disclosure
We do not sell, trade, or rent your personal information. We may share limited information with:
- Stripe — payment processing. Subject to Stripe's privacy policy.
- ClickSend — transactional email delivery (security notifications, org invitations). Only your email address and the email content are shared.
- Vercel — application hosting and deployment. Subject to Vercel's privacy policy. Infrastructure logs (including IP addresses) are processed by Vercel.
- Neon — database hosting on AWS infrastructure in the Sydney region. Your encrypted data at rest is held on Neon's servers.
- Legal requirements — we may disclose information if required by Australian law, court order, or to protect against serious harm. As noted above, vault content is technically inaccessible to us.
7. Data storage and security
- Location — database hosted on AWS in the ap-southeast-2 (Sydney) region. Application hosted on Vercel's global edge network.
- Encryption at rest — your vault data is encrypted before it reaches us (client-side). Storage-level encryption is also applied by our hosting providers.
- Encryption in transit — all data is transmitted over TLS 1.2 or higher.
- Security measures — rate limiting, CORS restrictions, httpOnly cookies, Argon2id password hashing, two-factor authentication, and audit logging.
8. Data retention
- Account data is retained while your account is active.
- If you detonate your vault, all vault data and account credentials are deleted immediately. Your email address is retained briefly for notification purposes, then deleted.
- Audit log entries are retained for 12 months.
- Billing records may be retained for up to 7 years as required by Australian tax law.
- You may request deletion of your account at any time by contacting ian@hindle.biz.
9. Cookies and local storage
Vaulis uses minimal cookies and browser storage, strictly for functionality:
- Refresh token cookie — httpOnly, secure, SameSite=Strict. Used to maintain your login session without storing the session token in JavaScript-accessible storage. Expires after 30 days or on logout.
- Admin session cookie — httpOnly, secure. Admin panel only. Expires after 8 hours.
- Session storage — access tokens and decrypted vault key summaries are stored in browser sessionStorage for the duration of your session. Cleared on tab close or browser restart.
We do not use advertising cookies, analytics cookies, or tracking pixels.
10. Browser extension and mobile app
The Vaulis browser extension and mobile app:
- Do not read or transmit the content of pages you visit beyond what is necessary to detect login forms.
- Only send form field data (usernames, passwords) to the Vaulis API when you explicitly save a credential.
- Store decrypted credential summaries in
chrome.storage.session(extension) or app memory (mobile) for the duration of your session. These are never written to persistent storage in decrypted form. - Do not collect browsing history or track which sites you visit.
11. Your rights
Under the Australian Privacy Act 1988 (Cth) and applicable state legislation, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate personal information
- Request deletion of your account and associated data
- Opt out of non-essential communications
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Privacy Act
To exercise any of these rights, contact us at ian@hindle.biz. We will respond within 30 days.
12. Children
Vaulis is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
13. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated by email to registered users and by updating the "Last updated" date above. Continued use of Vaulis after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions or requests: