For business/compliance accounts: your clients' business details (name, contact person, phone/email) and compliance-related documents (GST, TDS, ROC, FSSAI, and other regulatory filings) that you or your clients share via WhatsApp or the web
Usage data: pages visited, actions taken (no third-party analytics in V1)
2. How we use it
To provide the core service: tracking expiry dates and deadlines, and sending reminders
For business/compliance accounts: to identify documents required for a given filing, flag what's missing, and — with your direction — send requests to your clients (via WhatsApp or email) on your behalf
To send reminder and request emails from reminders@usevaultly.com
We do not sell your data to anyone, ever
We do not use your documents to train AI models
3. How we store it
Documents stored in Cloudflare R2 (encrypted at rest)
Database hosted on Neon (PostgreSQL, encrypted at rest)
Authentication handled by Clerk (SOC 2 Type II certified)
We use Anthropic's Claude API for document processing — including date extraction and, for compliance accounts, comparing documents against standard filing requirements. Documents sent to Claude are subject to Anthropic's data handling policy (anthropic.com/privacy)
Document requests may be sent via WhatsApp or email. Where WhatsApp is used, messages are processed through WhatsApp's Business Platform, subject to their own data handling terms.
4. Your rights
You can delete any document at any time from your dashboard
You can delete your account and all associated data from Settings
For business/compliance accounts: you are responsible for having appropriate authorization from your clients before sharing their information through Vaultly
5. Cookies
We use session cookies for authentication only (via Clerk)