V
VaultAP
ProductFeaturesPricingSecurityWalkthroughDocs
Log inBook a demo

Privacy Policy

Last updated: August 13, 2026

Introduction

VaultAP (“we,” “our,” or “us”) operates the VaultAP platform (app.vaultap.app), website (vaultap.app), and documentation (docs.vaultap.app). This Privacy Policy explains how we collect, use, store, and protect your information.

By using VaultAP, you agree to the collection and use of information as described in this policy.

Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Organization name
  • Role within your organization

Invoice Data

When you upload invoices to VaultAP, we process:

  • Invoice documents (PDFs, images)
  • Extracted invoice fields (vendor names, amounts, dates, PO numbers)
  • Bank account details (hashed — we store only the last 4 digits in plain text; full numbers are never stored)

Usage Data

We automatically collect:

  • Pages visited and features used within the app
  • Actions taken (uploads, reviews, setting changes)
  • Browser type, device type, and IP address
  • Timestamps of actions

Waitlist and Contact Information

When you join our waitlist or contact us, we collect:

  • Email address
  • Any information you voluntarily provide

How We Use Your Information

We use your information to:

  • Provide and operate the VaultAP service
  • Process and score invoices for fraud risk
  • Generate AI-powered explanations for flagged invoices
  • Maintain audit trails for compliance
  • Send notifications (email, in-app, Slack) about invoice activity
  • Send product updates and communications you've opted into
  • Improve the product and fix issues
  • Respond to your inquiries

We do NOT:

  • Sell your data to third parties
  • Use your invoice data to train AI models
  • Share your data with other VaultAP customers
  • Display advertising in the product

Data Storage and Security

Encryption

  • All data is encrypted at rest using AES-256 encryption
  • All data in transit is protected by TLS 1.3
  • Bank account numbers are hashed before storage; only the last four digits are retained in readable form

Tenant Isolation

  • Your data is isolated from other customers through two enforcement layers: authenticated application middleware, and query-level filtering that scopes every database read to your organization
  • No other customer can access your invoices, vendors, or settings

Infrastructure

Your data is processed and stored using the following services:

  • Database: Neon (PostgreSQL) — hosted in AWS US East (Ohio)
  • File storage: Cloudflare R2 — encrypted at rest
  • Authentication: Clerk — handles login and session management
  • OCR processing: Azure Document Intelligence — processes invoice images for field extraction
  • AI explanations: Anthropic Claude API — generates plain-language explanations for flagged invoices (receives only the minimum fields needed, never full bank account numbers)
  • Email: Postmark (transactional), Resend (marketing/waitlist)
  • Background processing: Inngest

Data Retention

  • Active account data is retained as long as your account is active
  • Audit logs are retained for a minimum of 7 years (configurable per organization)
  • Archived invoices are retained according to your organization's archive settings
  • If you delete your account, we will delete your data within 30 days, except where retention is required by law
  • Waitlist emails are retained until you unsubscribe

Your Rights

You have the right to:

  • Access: Request a copy of all data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data (subject to legal retention requirements)
  • Export: Export your invoices, vendors, and audit logs via the app's built-in export features
  • Opt-out: Unsubscribe from marketing communications at any time

To exercise any of these rights, email us at VaultAP@proton.me.

Cookies

VaultAP uses only essential cookies required for authentication and session management. We do not use advertising cookies or third-party tracking cookies.

We use PostHog for product analytics, which may set a cookie to track anonymous usage patterns. You can opt out of analytics tracking in your browser settings.

Children's Privacy

VaultAP is a business product not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice in the app. The “Last updated” date at the top of this page indicates when the policy was last revised.

Contact Us

If you have questions about this Privacy Policy:

  • Email: VaultAP@proton.me
  • Website: vaultap.app
V
VaultAP

Pre-payment fraud detection for mid-market AP teams.

Product

FeaturesPricingSecurityDocumentationAPI (coming soon)Changelog

Company

AboutBlogCareersContactPrivacy PolicyTerms of Service
© 2026 VaultAP. All rights reserved.Made in Brooklyn