Privacy policy
Last updated: 29 September 2026
Privacy at a glance
- ✓The contents of your vault are encrypted on your device before they reach us: we cannot read them. Your password never leaves your browser.
- ✓Some data is needed for the service to work and we can see it, for example your email and the expiry dates of your documents for reminders. We list all of it under “What we can and cannot see”.
- ✓Your data stays in the European Union: servers and database in Frankfurt, Germany.
- ✓No advertising, no profiling, no selling of data, no social network pixels. We do not use your data to train artificial intelligence models.
- ✓LifeVault Sense, the assistant, runs in your browser: questions, data and answers are not sent to external AI services.
- ✓You can ask to see, correct, export and delete your data by writing to privacy@lifevault.it.
1. Who the data controller is
The controller of your personal data is Marco Salatin, sole proprietorship, based at 31015 Conegliano (TV), Italy, VAT number IT05634040264.
For any privacy matter, write to privacy@lifevault.it.
2. What we can and cannot see
LifeVault is designed so that our server cannot read the contents of your vault: they are encrypted on your device with keys derived from your password, which we do not have. “Zero-knowledge”, however, covers the contents, not everything: for the service to work, some data remains readable by the server. We list it here, because you have a right to know exactly what it is.
We cannot read (encrypted on your device)
- The document files you upload
- Titles, notes and all document fields
- People profiles: names, dates of birth, tax codes, contact details
- Cash Manager data: accounts, transactions, bank statements, budgets
- Your password, recovery phrase and encryption keys
- The questions you ask LifeVault Sense and its answers
We can read (needed for the service to work)
- Account data: email and country of residence. We do not store your first and last name: they are kept encrypted in your vault
- Who belongs to each vault and with which role; open invitations (invited email, role, expiry); for children's vaults, which child account they relate to
- For each document: category (for example “Health”), reference year and month, expiry date (for reminders), file size and fingerprint (to verify its integrity), creation and modification dates, who created or modified it
- The activity log: who did what and when (for example “shared a vault”), without contents
- Technical connection data in server logs: IP address, browser, request times
3. Why we process data and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: account, encrypted archive, vault sharing, expiry reminders | Performance of a contract (art. 6.1.b) |
| Account of a child invited by the parent, from the minimum age stated in section 10 | Performance of the contract the child accepts (art. 6.1.b), within the age limits of art. 8 |
| Service emails: account verification, recovery, security and invitation notices, changes to the terms | Performance of a contract (art. 6.1.b) |
| Security, prevention of abuse and fraud, technical logs | Legitimate interest (art. 6.1.f) |
| Website visit statistics, anonymous and cookie-free | Legitimate interest (art. 6.1.f) |
We do not process your data for advertising, profiling or automated decision-making, and we do not sell it.
4. Who we rely on
To provide the service we use these providers, who act as data processors under a written agreement (DPA) and receive only what they need for their task:
| Provider | What it does | Where | What it receives |
|---|---|---|---|
| Amazon Web Services | Application servers, storage of encrypted files, service emails (Amazon SES) | EU: Frankfurt, Germany | Encrypted data, data listed in section 2, email |
| Neon | Database | EU: Frankfurt, Germany | Encrypted data and data listed in section 2 |
| Amazon CloudFront | Delivery of the website files and of the LifeVault Sense model | Global network | No vault data: only requests for public files (IP address, time) |
| Cloudflare | Visit statistics, cookie-free | USA | Pages visited, technical browser data; no vault data |
| Seeweb | Domain DNS | Italy | No personal data of users |
5. Where the data is and transfers outside the EU
Your account and vault data are stored in the European Union, in Frankfurt.
The only processing outside the EU concerns visit statistics (Cloudflare, USA) and the delivery of the website's public files (CloudFront). Amazon and Cloudflare participate in the EU-US Data Privacy Framework; transfers take place on this basis and on the European Commission's standard contractual clauses included in their agreements.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and vault contents | As long as the account is active. You delete it yourself in Settings → Delete account: the account and contents are deleted immediately, and from backups within 30 days. If you own a shared vault, first remove the people in it. You can also ask at privacy@lifevault.it |
| Activity log | 24 months |
| Technical server logs (IP address, times) | 30 days |
| Service emails | We do not keep a copy. Verification and recovery links expire (7 days and 1 hour) and are then deleted |
| Invitations to a vault | The encrypted invitation key is deleted when the invitation is used, cancelled or expires (7 days) |
7. What we store in your browser
- Technical sign-in cookies: access_token (30 minutes) and refresh_token (7 days), not readable by the page's scripts.
- The key that opens your vault during the session, in non-exportable form: it is valid for at most 12 hours and is deleted on logout and after 30 minutes of inactivity.
- Preferences: language, selected vault, Cash Manager display settings, LifeVault Sense activation.
- If you use LifeVault Sense: the model (about 600 MB, the same for everyone) and its configuration, without any of your data. “Remove from this device” deletes them.
We only use technical cookies and storage, necessary for the service you requested: these do not require consent and we do not show a banner. No profiling or advertising cookies.
8. LifeVault Sense
The LifeVault assistant uses a language model that runs in your browser. The model receives only your question and chooses which search or analysis to perform; the data is read and computed by the page's code, after being decrypted on your device. Questions, data and answers are not sent to external AI services. For questions about accounts and spending, the page downloads the encrypted accounting records from our server, just as the Cash Manager does.
9. Who else can see your data
- The people you invite to a vault, according to the role you assign. You can change their role or remove their access at any time; someone who is removed can no longer download anything, but whatever they had already downloaded remains on their device.
- For children's vaults: the parent who creates them, the people the parent invites to manage them together and, from the minimum age stated in section 10, the child themselves if the parent invites them.
- The authorities, if the law requires us to. In that case we can only hand over the encrypted data, which we cannot decrypt, and the data listed in section 2.
10. Minors
Children's vaults are created and managed by a parent or by whoever has parental responsibility. Until the minimum age of the country where the parent lives, the child does not have an account: their vault is opened by the parent.
- Minimum age: the higher of 14 years and the digital age of consent of the country (art. 8 GDPR; in Italy art. 2-quinquies of the Italian Privacy Code). For example: Italy and Spain 14, France 15, Germany and the Netherlands 16; in countries not on our list, 16.
- From that age the parent can invite the child to have their own access. The parent declares that the child has reached the minimum age: we cannot check it, because the date of birth stays encrypted in the vault and we do not see it.
- The child chooses their own password, receives their own recovery phrase and accepts the Terms and the Privacy Policy. We store their email, for sign-in and service communications, as for every account.
- The vault remains the parent's, who chooses the child's role and can remove their access at any time. The child cannot create a vault of their own while they are linked to the parent's vault.
- The rights in section 12 can be exercised by the child and, while the child is a minor, also by the parent.
11. How we protect data
AES-256-GCM encryption on the device, key derivation from the password with Argon2id, one key for every vault and for every document, sign-in without the password ever reaching the server, digital signatures on vault invitations. The details are on the Security page.
12. Your rights
You have the right of access, rectification, erasure, portability, restriction and objection, and you can lodge a complaint with the supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it). Write to privacy@lifevault.it: we reply within 30 days. Note: without your password or recovery phrase we cannot recover the encrypted contents, not even at your request.
13. Changes to this policy
If we change this policy in a significant way, we will notify you by email 30 days before the changes take effect.
14. Contact
Marco Salatin · 31015 Conegliano (TV), Italy · VAT IT05634040264 · privacy@lifevault.it