$ cat legal/privacy-policy.md
Privacy Policy
This policy explains what PingVaults processes, what is published permanently, which providers support the service, and the limits of deletion.
Last updated: September 3, 2026
Who operates PingVaults
PingVaults is operated by Brightcore Technologies LLC. Privacy questions and data requests can be sent to info@pingvaults.com.
Account and authentication data
- Your email address for email-code or Google sign-in and account identification.
- A hashed, single-use email code with a 10-minute application expiry and a limited number of attempts.
- A secure, HTTP-only session cookie; short-lived state and return-path cookies during Google sign-in.
- Plan, Stripe customer, and subscription references when you purchase or manage a paid plan.
Vault and inactivity-switch data
The intended save flow sends encrypted ciphertext, a random salt and IV, the recovery-field schema and language, and storage identifiers. When you enable the inactivity switch, it also stores the emergency-contact email, an optional reminder backup email, schedule settings, status, and activity timestamps.
- The save request is designed not to include your vault plaintext, recovery phrase, or derived encryption key.
- Recovery prompt text and field types are metadata and may reveal context; do not put secrets in a prompt.
- The browser stores the latest exported recovery metadata locally on your device so you can download and test it.
Permanent public storage
Vault ciphertext is uploaded through Irys to Arweave. Arweave records are designed to be permanent and publicly retrievable by transaction ID. PingVaults cannot delete or overwrite an earlier Arweave transaction; editing creates another encrypted transaction.
Earlier PingVaults versions may have added a Base64-encoded account-email identifier to an Arweave transaction tag. Base64 is encoding, not encryption. New uploads no longer include that tag, but any historical Arweave tag cannot be removed by PingVaults. Contact us if you need help understanding whether this affected an earlier upload.
Analytics and operational data
We use Vercel Web Analytics and Speed Insights for aggregate page, performance, and conversion measurement. Custom product events contain only coarse fields such as language, plan, step, and boolean feature state. We do not intentionally include email addresses, transaction IDs, recovery phrases, or vault contents in those events. Hosting and application providers may also process IP addresses, user-agent data, timestamps, and request logs for delivery, security, and troubleshooting.
Service providers
- Vercel for application hosting, delivery, analytics, and performance measurement.
- Amazon Web Services for DynamoDB records, email delivery, and scheduled inactivity processing.
- Google for optional OAuth sign-in.
- Stripe for checkout, subscription, and billing management. PingVaults does not receive full card details.
- Irys and Arweave for permanent ciphertext publication and retrieval.
Retention, deletion, and your choices
Account, vault-index, contact, schedule, and billing records are kept while needed to provide the service, meet legal obligations, resolve disputes, and prevent abuse. You may ask us to delete or correct deletable application records or cancel a subscription by contacting us or using the billing portal. A deletion request cannot remove Arweave transactions or records another provider must retain by law.
Security and children
We use technical and organizational controls appropriate to the service, but no internet service or cryptographic design eliminates every risk. PingVaults is not directed to children under 13. Do not use it to store another person’s data unless you are authorized to do so.
Changes
We may update this policy as the product or providers change. The date above identifies the current version. Material changes will be presented through the site or an account communication when appropriate.