Privacy Policy

Last updated: August 31, 2026

vvault provides a workspace to upload and manage audio files, create packs and series, share links, send campaigns, track engagement, sell licenses, and manage billing. This policy explains what data we collect and how we use it to operate and secure the service.

1. Who we are

vvault is operated from Belgium by Tom Nsengiyumva (sole proprietor), company number BE 1022.549.155, registered office Zwartleertouwersstraat 40, 8000 Brugge, Belgium ("vvault", "we"). For the personal data described here, vvault is the data controller within the meaning of the EU General Data Protection Regulation (GDPR).

This policy covers the vvault web app, desktop app, iOS app, the public pages we serve on vvault.app and on custom domains, and our emails and support.

For any privacy matter, write to vvaultapp@gmail.com or use the in-app Support page. We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one; that address reaches the operator directly. Because we are established in the EU, we do not need an Article 27 representative.

2. What we collect

What you give us: account details (name, email, handle, avatar, locale), the content you upload (audio, artwork, titles, notes, and metadata such as BPM and key), your contacts and groups, campaign content and recipient lists, messages, marketplace listings and licence terms, support correspondence, and billing details.

What we collect automatically: IP address, device and browser information, server logs, cookies and similar identifiers, approximate region (used to pick your currency and language), and the usage events needed to run, secure and improve the service.

What we collect from your listeners: when someone opens a link you shared, streams, downloads, saves or buys, we record that event and the technical data around it, and we show it to you as analytics.

What we receive from others: identity and profile basics from a sign-in provider if you use one, payment and payout status from Stripe or Apple, files you deliberately import from a cloud provider, and reports about content sent to us by other users or rights holders.

Please do not send us special-category data — health, beliefs, political opinions, biometrics and the like. We do not ask for it and we have no use for it.

3. Legal bases

Contract (Art. 6(1)(b)): running your library, sharing, collaboration, sends, the marketplace and your subscription.

Legitimate interests (Art. 6(1)(f)): security, abuse and fraud prevention, measuring engagement on content you shared, product improvement, defending legal claims. You can object to processing based on legitimate interests at any time.

Consent (Art. 6(1)(a)): non-essential cookies, marketing emails, and connecting a third-party account. You can withdraw consent at any time, without affecting processing already carried out.

Legal obligation (Art. 6(1)(c)): tax and accounting records, lawful requests, and our duties as a hosting provider.

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for that purpose.

4. Engagement tracking

Opens, clicks, plays, play duration, downloads, saves and purchases on content you share are recorded so we can give you analytics. We filter automated scanners to improve accuracy, so figures are approximate.

If you open a vvault-powered email or a shared link, the person who sent it can see those events. If you would rather not be measured that way, do not open the link.

5. Cookies

Essential cookies keep you signed in, remember your preferences and secure the service. They are always on because the product cannot work without them.

With your consent we also use analytics cookies, to understand how the product is used, and marketing cookies, to measure campaigns — including a Meta pixel where enabled. You choose in the cookie banner and can change your mind at any time from the cookie settings link or your browser controls. Declining non-essential cookies does not limit the product.

Some browsers send a "Do Not Track" signal. There is no agreed standard for what a site must do in response, so we do not act on it; use the cookie banner instead, which we do act on.

6. Access levels: what becomes visible, and to whom

You decide what is reachable. Private means only you. Invite only means the people you name. Anyone with the link means whoever holds the link. For sale means reachable and purchasable. A track's own level governs the track's own link; inside a pack, the pack's level governs.

When something is reachable, the people who reach it can see what is on the page: title, artwork, duration, your handle and profile picture, and anything you put in the notes or description. Public items may also be indexed by search engines and cached or copied by others, which we cannot undo for you.

Content shared by link stays reachable to anyone holding that link until you change the level or reset the link. We cannot retrieve a link somebody already has.

7. Collaboration

If you join or are invited to a shared pack, the pack's owner and the other members can see that you are a member, your handle and profile picture, what you add, and activity attributed to you inside that pack — uploads, versions, and edits where editing is enabled.

If you own a pack, the same is true in reverse: what you do there is visible to your collaborators. Removing a member ends their access going forward; it does not recall what they already downloaded.

8. Buying and selling

When a sale happens we process what is needed to complete and evidence it: who bought what, when, for how much, under which licence, and the payment status. A licence document may name the buyer and the seller, because that is what makes it usable as proof of the rights granted.

Sellers see the purchases made from them and the information needed to honour the licence. Buyers see who they bought from. We keep order, licence and payout records as long as Belgian accounting and VAT law requires, and because they evidence the other party's rights.

9. Content moderation

To keep vvault free of illegal and prohibited content (see the Terms of Use), we review content that is reported to us. We do not screen content before it is uploaded, published, sent or shared, and we are under no general obligation to monitor it. You can contest any decision, as described in the Terms.

When we review a report we process the reported content, the report itself, and the identifiers of the people involved. Legal bases: our legitimate interests in keeping the platform safe and lawful (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c)). Reports and the record of what we decided are kept while the account is active, and afterwards where a case, dispute or legal obligation requires it.

Content indicating serious crime, in particular child sexual abuse material, is preserved in a restricted state, is not distributed further, and is reported to the competent authorities as the law requires.

10. Connected accounts and imports

Gmail sending: if you connect Gmail, we store the tokens needed to send email on your instruction. You control the recipients and the message.

Google Drive and Dropbox import: you pick files in the provider's own picker and they transfer into your library. We access only the files you select — for Google Drive, under the drive.file scope — and we do not browse the rest of your storage. vvault's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Desktop folder sync: files in the folders you choose are uploaded from your device and kept in sync.

You can disconnect any of these at any time in Settings. Disconnecting stops future access; it does not undo transfers already made at your instruction.

11. Payments

Subscriptions, purchases, payouts and refunds are processed by Stripe, and by Apple for in-app purchases on iOS. We receive payment status, amounts and related metadata. We never see or store full card numbers. The currency shown is based on your approximate region.

12. Emails we send you

Service emails — verification codes, password resets, receipts, security notices — are necessary to operate your account and have no unsubscribe. Product and marketing emails always do.

13. Who we share data with

Processors, under contract and only to provide their service: hosting and storage (Supabase, on AWS in the EU), email delivery (Resend), payments (Stripe; Apple for iOS purchases), and error and usage monitoring.

Other users, where you chose it: anyone you share with, invite, sell to or buy from, as described in the access, collaboration and marketplace sections above.

Authorities and advisers: where we must comply with a legal obligation or lawful request, and to establish, exercise or defend legal claims. Where we may lawfully tell you first, we will.

A successor: if the business is transferred, merged or sold, or in an insolvency, data may pass to the acquirer, who remains bound by this policy or one no less protective. We will tell you if that happens.

Advertising and measurement partners, with your consent only: if you accept marketing cookies, we send Meta events about actions you take on our marketing pages — including a hashed version of your email address, a hashed user identifier, your IP address and your user agent — so we can measure whether our advertising works. Hashing means Meta does not receive your address in readable form, but this is still a sharing of personal data with an advertising platform, and it happens only if you consent. Withdraw consent in the cookie settings and it stops.

With your consent we also use Google Analytics 4 and Vercel Analytics to understand how the product is used.

We do not sell your personal data.

14. Transfers outside the EEA

Your content is hosted in the EU. Some providers may nevertheless process limited data outside the European Economic Area — for example support or monitoring operations in the United States.

Where that happens we rely on a transfer mechanism the GDPR recognises: an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified), or the European Commission's Standard Contractual Clauses with the additional measures the circumstances require. Write to us if you want to know which one applies to a specific provider.

15. How long we keep things

Account data is kept while your account is active. Deleted tracks and packs pass through a recoverable state before permanent removal.

When you delete your account we delete or anonymise your personal data within a reasonable period, apart from what we must keep: order, licence and payout records, which Belgian accounting and VAT law requires us to hold for up to ten years and which also evidence the other party's rights. Backups expire on their own cycle. Engagement events may be kept in aggregated, de-identified form, which we do not attempt to re-identify. Moderation records are kept as described above.

16. Security

Audio lives in private storage and is served through signed links that expire. Traffic is encrypted in transit, data is encrypted at rest, and direct messages carry additional safeguards. We apply technical and organisational measures appropriate to the risk.

No system is perfectly secure. Where the GDPR requires it, we notify the competent authority and, where the risk to you is high, you.

17. Your rights

You can ask us to give you access to your data, correct it, delete it, give you a portable copy, restrict how we process it, or object to processing based on legitimate interests — including a straightforward right to object to direct marketing at any time. Where processing rests on consent, you can withdraw it at any time without affecting what came before.

Write to vvaultapp@gmail.com. We answer within one month, and tell you if we need longer or if we cannot act on a request and why. We may ask for information to confirm it is really you.

You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.dataprotectionauthority.be), or to the supervisory authority where you live or work.

18. Children

vvault is not for children under 16, and we do not knowingly process their data. If you believe a child has given us personal data, contact us and we will delete it.

19. Changes and contact

We post changes here and update the date above. For material changes we tell you in the app or by email. Questions: vvaultapp@gmail.com, or Zwartleertouwersstraat 40, 8000 Brugge, Belgium.

Terms of Use →