Privacy Policy
Last updated: September 19, 2026
1) Who we are
This policy describes how Tariq Alshara (“Vault”, “we”, “us”) handles personal data when you use the Vault iOS app or try-vault-app.com. Contact: support@try-vault-app.com.
Vault is not a local-only app. Portfolio data can exist on your device and on our servers. We do not sell your personal data. We do not share it for cross-context behavioral advertising. We do not use the App Tracking Transparency prompt or IDFA.
2) Data we collect
Accounts and identity. Clerk accounts. Email address, name, user ID, and sign-in provider (email, Apple, or Google). If you use Sign in with Apple and Hide My Email, we receive Apple’s private relay address, not your personal inbox. Avatars come from the sign-in provider when they supply one. We do not open your photo library for this.
Financial and portfolio data. Holdings, lots, transactions, prices, and portfolio values. This is stored in SwiftData on your device and on Vault’s Supabase backend, including when sync is on. It is financial information.
SnapTrade. If you connect a brokerage, SnapTrade sends Vault read-only holdings and connection status. After you connect, SnapTrade may send later holding-update notices to Vault’s servers so the app can refresh imported lots. Vault does not receive or store your brokerage password.
Ask Vault. A read-only snapshot of the active portfolio is sent through Vault’s Edge Functions to Groq so the model can answer. Chat text stays on your device for the current session only.
Purchases. Subscription status from Apple / RevenueCat so we can unlock Analytics and Ask Vault.
Feedback. Posts, comments, votes, and a display name derived from your profile (or the local part of your email). Other signed-in users can read the public board.
Website waitlist. If you join the waitlist on this site, we store your email in our Supabase waitlist table to tell you when Vault is available.
Crash and diagnostic data. If the iOS app crashes or a server call fails, we send a report to Sentry so we can fix it. That report can include a stack trace, device and app metadata, and your Clerk user id. It does not include email, portfolio names, tickers, balances, holdings, Ask Vault questions or answers, or credentials. Session Replay is off.
Product analytics. The iOS app sends named product events to PostHog so we can see whether onboarding, paywall, and account setup work. After you sign in, those events are tied to your Clerk user id. They can include the step you were on, a tap such as Continue or Skip, and a multiple-choice onboarding answer. They do not include email, portfolio names, tickers, balances, holdings, Ask Vault questions or answers, or credentials. We discard the client IP. Session Replay, Error Tracking, surveys, and advertising identifiers (IDFA) are off.
3) Why we use it
We use this data to run the app: sign you in, store and sync your portfolio, import brokerages you choose, answer Ask Vault questions, process the subscription, operate the feedback board, diagnose crashes, measure which product steps people complete, and send waitlist notes. We do not use this data for third-party advertising. Purposes in Apple’s privacy nutrition labels are App Functionality, and Analytics for Product Interaction and User ID.
4) Legal bases
If GDPR or similar law applies, we process personal data on these bases:
- Contract. Providing the account, storing and syncing the portfolio you asked us to keep, and delivering the paid app and subscription features.
- Consent. Optional brokerage import through SnapTrade, and waitlist emails if you join from this site.
- Legitimate interests. Securing the service, preventing abuse, diagnosing crashes, measuring product usage in PostHog without holdings or advertising identifiers, and understanding traffic on this marketing site through Vercel Analytics and Speed Insights.
- Legal obligation. When the law requires us to keep or disclose information.
5) Processors and other services
Vault uses other companies to provide the product. They process data only as needed for their role:
- Clerk — accounts and sign-in (email, Apple, Google)
- Supabase — database, storage, Edge Functions, waitlist
- SnapTrade — read-only brokerage import and later holding updates
- Groq — Ask Vault model responses
- RevenueCat and Apple — subscriptions
- Google — Sign in with Google, if you choose it
- Massive, CoinMarketCap, Metals.dev — market prices
- Logo.dev — company and crypto logos
- NewsData and PropertyWire — asset news in the app
- Sentry — crash reports, handled failures, and diagnostic logs from the iOS app
- PostHog — product analytics from the iOS app (named events and Clerk user id; not holdings)
- Vercel Analytics and Speed Insights — traffic on this marketing site, not inside the iOS app
Each of those providers has its own privacy policy. Market-data requests send asset identifiers (such as tickers), not your name.
6) Sharing
We share data with the processors above to run Vault, and if the law requires it. We do not sell personal data. We do not share personal data for cross-context behavioral advertising. Feedback you post is visible to other Vault users. SnapTrade, Apple, Google, and Groq see only what that feature needs.
7) Cookies and this website
The Vault iOS app does not use advertising cookies or IDFA. This marketing site uses Vercel Analytics and Speed Insights to measure visits and performance. Those tools may use cookies or similar storage in the browser. They are not used to advertise Vault on other sites. The waitlist form collects the email you submit.
8) Retention and deletion
We keep account and portfolio data while your account exists. Ask Vault chat is session-only on the device. Crash reports in Sentry are kept under Sentry’s retention settings. Product-analytics events in PostHog are kept under PostHog’s retention settings. Signing out resets the local PostHog identity and clears the Clerk user id from the device Sentry SDK. Deleting your account also queues deletion of your PostHog person and associated events; that request can take time to finish. You can delete your account in the app. That deletes your Clerk user and Vault’s server copies of profiles, portfolios, holdings, transactions, SnapTrade connection records, feedback posts, comments, votes, and related quota rows, and it removes profile avatars we stored. Backups may lag for a short time. Apple and RevenueCat keep purchase records under their rules. Waitlist emails stay until you ask us to remove them or we shut the list down.
9) Security
We use HTTPS, access controls on the backend, and device protections provided by iOS. No method of transmission or storage is perfectly secure.
10) Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object or restrict certain processing, and to complain to a supervisory authority. Email support@try-vault-app.com to use them. If GDPR applies to you, those rights include Arts. 15–18, 20, and 21, and the right to lodge a complaint under Art. 77.
If California law applies, we do not sell or share personal information as those terms are used in the CCPA/CPRA. We do not use or disclose sensitive personal information to infer characteristics about you for advertising. You may still email us to access or delete your data.
11) Children
Vault is not directed at children under 13, or under 16 where that is the digital-consent age. We do not knowingly collect personal data from children.
12) International transfers
Our processors may store or process data in the United States and other countries. If you use Vault from elsewhere, you understand that your data may be processed outside your home country.
13) Changes
We may update this policy. The “Last updated” date will change when we do. Material changes will be noticed in the app or by email when practical.