Data we process
- Encrypted secret payload (ciphertext and IV) with expiry and view limits.
- Operational metadata required for security controls like rate limiting.
- Optional analytics events only after consent, with masked page paths.
Privacy and data control
VaultLink is designed to reduce exposure by default. Secrets are encrypted in the browser, we store ciphertext only, and decryption material is kept client-side.
Updated February 7, 2026
Our controls are aligned with data minimization and privacy-by-design principles expected under GDPR and common SOC, PCI, and ISO governance programs. For security reporting or data protection requests, contact us directly.
We use one consent cookie and optional analytics storage. Accept enables privacy-safe GA4 metrics with masked paths; reject keeps analytics disabled.