cairnvault.app

Legal

Privacy Policy

Effective date: June 28, 2026

Also see our .

The short version

We collect your email address and the encrypted ciphertext of your vault. We cannot read your vault contents — they are encrypted on your device before they reach us, and we do not hold the key. We do not sell your personal data. You can delete your account (and your stored data) at any time by contacting us.

1. Who We Are

CairnVault is operated by CairnVault. If you have any questions about this Privacy Policy, you can reach us at support@cairnvault.app.

2. What We Collect

We collect a small amount of information to operate the service:

  • Email address. The email you provide when you create your account. We use this to identify your account, send transactional messages (such as verification and release-notification emails), and contact you about your account.
  • Encrypted vault ciphertext and a public salt. The encrypted blob your device sends to our servers for storage. The ciphertext is unreadable to us (see Section 3). The public salt is a non-secret value used in the key-derivation process on your device — it does not reveal your password or Secret Key.
  • Operational and security logs. Standard server logs — IP addresses, request timestamps, error events — that we use to monitor uptime, diagnose problems, and detect abuse. These are retained for a limited period and are not linked to your vault contents.
  • Invite and referral counts. When you invite a contact or family member, we record aggregate, server-side counts — such as how many invites were sent and whether a new account was referred by an existing planner — to measure product metrics like invite activity and referral rate. These are operational counts tied to your account and its invites, not a behavioral profile, and are never shared with third parties.

On our public marketing pages we use a privacy-respecting, cookieless analytics counter to measure aggregate page views — it sets no cookies, does not track you across sites, and records no information that identifies you personally. Apart from that, we run no advertising pixels, cross-site trackers, or behavioral profiling of any kind, and the invite and referral counts above are the only usage metrics tied to your account, kept on our servers for internal product measurement only.

CairnVault offers two optional paid items: a one-time setup fee and an optional annual maintenance subscription. We do not currently collect, store, or transmit payment card data; when paid plans go live, payment will be handled by a third-party payment processor, and CairnVault itself will not store your full card number.

3. What We Cannot Access — Your Vault Contents

Your vault is encrypted on your device before it leaves your browser. The encryption key is derived from your master password and Secret Key, neither of which is ever transmitted to our servers. CairnVault stores only the encrypted ciphertext and has no ability to decrypt or read the contents of your vault. This is true even for CairnVault staff, and it holds regardless of any legal demand — we cannot hand over what we cannot read.

This zero-knowledge design is a core architectural commitment, not a policy option we could switch off. The privacy of your vault contents is structural.

4. How We Use Your Information

We use the information we collect only to:

  • Create and maintain your account.
  • Store and return your encrypted vault ciphertext.
  • Send transactional emails related to your account (such as verification emails and vault-release notifications to your designated contacts).
  • Operate, monitor, and improve the service.
  • Respond to your support requests.
  • Detect, prevent, and address fraud, security incidents, or abuse.

We do not use your email address for marketing or promotional messages without your consent, and we do not profile your behavior for advertising purposes.

5. Sub-processors

We rely on the following third-party service providers to operate CairnVault. Each processes data only as necessary to provide their service:

  • Google Cloud / Firebase (Google LLC) — cloud hosting, database (Firestore), and authentication infrastructure. Your encrypted vault ciphertext and account metadata are stored in Firebase/Firestore. Google’s data-processing terms apply. Data is stored in the United States.
  • Resend (Resend Inc.) — transactional email delivery. We share your email address with Resend solely to send account-related and vault-release emails on our behalf.

We do not share your information with any other third parties, and we do not sell your data.

6. Data Retention

We retain your account data (email address and encrypted vault ciphertext) for as long as your account is active. Operational logs are retained for a limited period (typically 90 days) and then deleted. If you delete your account (see Section 7), your email address and encrypted vault ciphertext are removed from our systems.

7. Account Deletion

You can delete your CairnVault account at any time by emailing support@cairnvault.app with your request. When we delete your account, we remove your email address and your stored encrypted vault ciphertext from our systems. Operational logs may persist for their standard retention period (typically 90 days) before being purged.

Note: because the vault is zero-knowledge, deleting your account also means the encrypted vault data is deleted — there is no way to recover it afterward.

8. No Sale of Personal Data

CairnVault does not sell, rent, or trade your personal information to any third party for their own marketing or commercial purposes. We do not monetize your data in any form. The only reason we have your email address is to operate your account and send you service-related messages.

9. Children

CairnVault is not intended for anyone under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us at support@cairnvault.app and we will delete the account promptly.

10. Security

We take reasonable technical and organizational measures to protect the information we hold. Your vault ciphertext is encrypted before it reaches us and cannot be read by anyone without your credentials. That said, no internet-based service can be guaranteed to be perfectly secure, and we encourage you to use a strong master password and to safeguard your Secret Key carefully.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised policy at cairnvault.app with a new effective date. If you continue to use the service after a change takes effect, you accept the updated policy. For material changes, we will take reasonable steps to notify you — for example, by emailing the address associated with your account.

12. Contact

Questions, requests, or concerns about this Privacy Policy? Reach us at support@cairnvault.app.