Last updated: September 4, 2026 · Controller: VaultAPI · Contact: vaultapi.support@gmail.com
This Privacy Policy explains what personal data we collect, why, and your rights. It covers the VaultAPI website and platform (the "Service").
1. Who we are
VaultAPI operates the VaultAPI AI gateway. For data submitted through the Service on behalf of an organization, we generally act as a processor; for account and billing data, we act as a controller.
2. Data we collect
- Account data: name, email, password (hashed), and organization details.
- Provider credentials: third-party LLM API keys stored encrypted; only a masked hint is displayed.
- Billing data: plan selection and payment identifiers. Card details are handled by Stripe and Razorpay, not stored by us.
- Request metadata and logs: provider, model, token counts, cost, latency, status, timestamps, and related metadata.
- Technical data: IP address, device/browser information, and security or audit events.
Prompt content is sent directly to the third-party provider you select. Request metadata and usage statistics are retained for observability and billing according to your plan.
3. Why we use data
We use data to provide routing, authentication, tooling, billing, security and abuse prevention, support, product improvement, and communications, on the legal bases applicable to those activities.
4. Sharing & subprocessors
We share data with service providers that help operate the Service, including cloud infrastructure providers, managed Redis cache providers, payment processors (Stripe and Razorpay), and the LLM providers you choose. We do not sell personal data. We may disclose data when required by law.
5. International transfers
Data may be processed in global cloud infrastructure regions. Where required, we use appropriate transfer safeguards, such as Standard Contractual Clauses.
6. Retention
- Account and billing data: for the account lifetime plus any legally required period.
- Request logs: per plan retention window (7 to 365 days), then pruned automatically.
- Encrypted provider keys: until deleted or the account closes.
7. Security
Our measures include encrypted stored provider keys, hashed passwords and refresh tokens, access controls, and audit logging. No method of transmission or storage is 100% secure.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, portability, or restriction; object to certain processing; or withdraw consent. Contact vaultapi.support@gmail.com. You may also complain to the applicable data protection authority.
9. Children
The Service is not directed to children under 18, and we do not knowingly collect their data.
10. Cookies
We use necessary cookies, including authentication cookies, and may use analytics cookies where applicable.
11. Changes
We will post updates here and, for material changes, notify you through the Service or email.
12. Contact
Data protection contact: vaultapi.support@gmail.com.