← Back to Home
Privacy Policy
Last Updated: January 21, 2026
Effective Date: January 21, 2026
Welcome to VaultReader. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our ebook protection and distribution platform.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address, name, and password when you create an account
- Payment Information: Processed securely through third-party payment processors (Stripe, PayPal, Gumroad, LemonSqueezy, Paddle)
- Ebook Content: PDFs and related metadata you upload
- Customer Data: Order numbers and email addresses for ebook access verification
- Support Communications: Any information you provide when contacting support
1.2 Automatically Collected Information
- Usage Data: Pages viewed, time spent reading, session duration
- Device Information: Browser type, operating system, device ID
- IP Address: For security and fraud prevention
- Cookies: Essential cookies for authentication and preferences
- Security Logs: Authentication attempts, access logs
1.3 Third-Party Data
- Payment Verification: Transaction data from payment processors
- Analytics: Aggregated usage statistics (no personal identification)
2. How We Use Your Information
Primary Purposes:
- Provide and maintain the VaultReader service
- Verify ebook purchases and manage access
- Prevent fraud and unauthorized access
- Improve our platform and user experience
- Communicate important updates and support
2.1 Service Delivery
- Create and manage your account
- Deliver ebooks to verified customers
- Track reading analytics for publishers
- Process and validate payments
- Generate watermarks for copyright protection
2.2 Security & Fraud Prevention
- Verify user identity through email verification
- Detect and prevent bot activity (CAPTCHA)
- Monitor for suspicious access patterns
- Protect against piracy and unauthorized sharing
2.3 Communication
- Send account verification emails
- Provide customer support responses
- Notify about service updates (essential only)
- Send security alerts when necessary
We do NOT:
- ❌ Sell your personal data to third parties
- ❌ Send marketing emails without explicit consent
- ❌ Track you across other websites
- ❌ Use your data for advertising purposes
3. Data Sharing & Disclosure
3.1 Service Providers
| Provider |
Purpose |
Data Shared |
| Supabase |
Database & Authentication |
Account info, ebook metadata |
| Netlify |
Hosting & Functions |
Technical logs, IP addresses |
| Cloudflare |
CAPTCHA & Security |
Browser data, IP address |
| Payment Processors |
Payment Verification |
Order numbers, email (validation only) |
3.2 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations or court orders
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Enforce our Terms of Service
3.3 Business Transfers
If VaultReader is acquired or merged, your data may be transferred to the new entity. You will be notified of any such change.
4. Cookies & Tracking Technologies
4.1 Essential Cookies
- Authentication: Keep you logged in
- Security: Prevent CSRF attacks
- Preferences: Remember your settings
- License Storage: Save ebook access (30 days)
4.2 Optional Cookies
- Analytics: Understand usage patterns (aggregated only)
- Performance: Improve load times and functionality
You can control cookies through your browser settings or our cookie consent banner.
5. Data Storage & Security
5.1 Where We Store Data
- Primary databases hosted on secure cloud infrastructure (Supabase)
- PDF files stored in encrypted cloud storage
- Backups maintained in geographically distributed locations
- Data centers comply with SOC 2, ISO 27001 standards
5.2 Security Measures
- ✅ TLS/SSL encryption for all data transmission
- ✅ Encrypted database storage
- ✅ Multi-factor authentication support
- ✅ Regular security audits and monitoring
- ✅ Rate limiting and DDoS protection
- ✅ CAPTCHA to prevent automated attacks
- ✅ Content Security Policy (CSP) headers
5.3 Data Retention
| Data Type |
Retention Period |
Reason |
| Account Information |
Until account deletion |
Service provision |
| Ebook Files |
Until publisher deletion |
Content delivery |
| Usage Analytics |
12 months |
Platform improvement |
| Security Logs |
90 days |
Fraud prevention |
| License Cache |
30 days |
User convenience |
6. Your Rights (GDPR & CCPA)
You have the right to:
- ✅ Access: Request a copy of your personal data
- ✅ Rectification: Correct inaccurate information
- ✅ Erasure: Delete your account and data
- ✅ Portability: Export your data in a readable format
- ✅ Objection: Object to certain data processing
- ✅ Restriction: Limit how we process your data
- ✅ Withdraw Consent: Revoke permissions at any time
6.1 How to Exercise Your Rights
- Dashboard: Access account settings to update or delete data
- Email: Contact support@vaultreader.com with your request
- Response Time: We'll respond within 30 days
6.2 Data Export
Request an export of your data in JSON or CSV format. Includes:
- Account information
- Ebook metadata (not the PDFs themselves)
- Usage statistics
- Transaction history
7. Children's Privacy
VaultReader is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we discover that a child has provided us with personal data, we will delete it immediately.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the EU Commission
- Service providers certified under EU-U.S. Data Privacy Framework
- Encryption and security measures meeting international standards
9. Third-Party Links
Our platform may contain links to payment processors, documentation, or other external sites. We are not responsible for the privacy practices of these third parties. Please review their privacy policies separately.
10. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. We will:
- Notify you via email for significant changes
- Display a notice on our website
- Update the "Last Updated" date at the top
- Require re-acceptance for material changes
11. Contact Us
12. Specific Privacy Provisions
12.1 For European Users (GDPR)
- Data Controller: VaultReader
- Legal Basis: Contract performance, legitimate interests, consent
- DPO Contact: dpo@vaultreader.com
- Supervisory Authority: You can lodge complaints with your local data protection authority
12.2 For California Users (CCPA)
- Right to know what personal information is collected
- Right to know if personal information is sold (we don't sell)
- Right to delete personal information
- Right to opt-out of the sale (not applicable)
- Right to non-discrimination for exercising rights
12.3 Do Not Track Signals
We do not track users across third-party websites. Our analytics are limited to our own platform. We honor Do Not Track (DNT) browser settings.