The Vault
Legal

Privacy Policy

Last updated 14 September 2026

The Vault ("we", "us", "our") is a personal relationship manager operated by Luke Farrow. This policy explains what information we collect when you use The Vault at vaultprm.com, why we collect it, and the choices you have. It applies to everyone who uses The Vault, whether you signed up directly or joined the waitlist.

1. Information we collect

Account information. Your name, email address, and either a password (stored as a salted hash, never in plain text) or an OAuth identity if you sign in with Google.

The data you enter about your contacts. This is the core of the product: names, companies, job titles, emails, phone numbers, locations, notes, tags, interests, dates, tasks, reminders, and event history for the people you choose to track. This is your data about your network, not ours - we store it so the app works, and access to it is scoped strictly to your account.

Ask Vault conversations. If you use the built-in AI assistant, your messages and the relevant contact details needed to answer them are processed to generate a response (see "Third parties" below). Conversation history is stored so you can revisit it, and you can clear it at any time from within the app.

Google data, only if you connect it. If you choose to connect a Google account from the Integrations page, we request access to specific, limited scopes - currently your Google Contacts (read-only) and Google Calendar (to read your events, bring existing Google Calendar events into The Vault, and, where you choose to use it, create Vault events on your Google Calendar and manage their attendees). We never request access beyond what a given feature needs, and each capability is requested separately. Access and refresh tokens are encrypted at rest.

Apple data, only if you connect or import it. Apple Calendar works differently to Google: there's no OAuth available for it, so if you choose to connect it from the Integrations page, you provide your Apple ID and an app-specific password (generated at appleid.apple.com, never your actual Apple account password), which we use to read and write your iCloud Calendar over CalDAV. That password is encrypted at rest, the same as a Google refresh token. Apple Contacts has no equivalent connection available to third-party apps at all, so bringing those in is a one-time file you export from the Contacts app yourself and upload to the Import page - it's processed once and isn't an ongoing, stored connection to your Apple account.

Usage analytics. On our public marketing pages, we log anonymous page views and clicks (tied to a random per-visit session identifier, not your account) to understand what's working. Your IP address is used only transiently, to resolve an approximate country/city, and is not stored.

Cookies. We use a single session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.

2. How we use your information

To provide and operate The Vault: authenticating you, storing and displaying your contacts and their data, powering features like the world map, weekly digest, and reminders, and responding to support requests.

To power Ask Vault: your request and the relevant contact context are sent to our AI provider to generate a response. Ask Vault never writes a change to your data without first showing you exactly what it plans to save and waiting for your confirmation.

To keep the product secure and working: rate-limiting abusive requests, debugging errors, and maintaining backups.

We do not sell your data, or the data of the contacts in your network, to anyone.

3. Google user data

The Vault's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: Google Contacts and Calendar data is used only to power the specific features you've connected them for (contact syncing, meeting matching, and two-way event sync) inside your own account. It is never used to train AI models, never used for advertising, and never shared with anyone other than the AI provider used for Ask Vault when you actively use it on a contact whose information originated from a Google sync. You can disconnect Google access at any time from the Integrations page, which deletes the stored tokens immediately.

4. Apple user data

If you connect Apple Calendar, your Apple ID and app-specific password are used solely to authenticate to iCloud's CalDAV service and read/write your calendar events on your behalf - they are never used for any other purpose, never shared with anyone (including the AI provider used for Ask Vault), and are encrypted at rest. You can disconnect Apple Calendar at any time from the Integrations page, which deletes the stored password immediately.

Apple Contacts data only ever enters The Vault through a vCard file you choose to export and upload yourself - there is no ongoing connection, no credential stored, and nothing is read from your Apple account beyond that one file at the moment you import it.

5. Third parties we work with

We use a small number of external services to operate The Vault, each only for the specific job listed:

  • Anthropic (Claude API) - to generate Ask Vault's responses. Only invoked when you actively use the assistant.
  • Google (People API, Calendar API) - only if you connect a Google account, and only for the scopes you've granted.
  • Apple / iCloud (CalDAV) - only if you connect Apple Calendar, authenticated with the app-specific password you provide.
  • OpenStreetMap / Nominatim - to resolve a contact's town or country into map coordinates for the World Map feature.
  • Mapbox - to render the map itself.
  • Resend - to send transactional emails, such as a password reset link.
  • Railway - our hosting provider, running the application and database.

Each of these processes data under its own terms, and only receives the minimum needed to do its job.

6. Data retention

We keep your account and contact data for as long as your account is active. You can permanently delete your account and everything in it yourself at any time from the Integrations page ("Delete account") - this happens immediately and can't be undone. If you'd rather we handle it, contact us (below) and we'll action it for you.

7. Your rights

You can view, edit, or delete any contact's data at any time from within the app. You can export your entire contact list to CSV whenever you like, so your data is never locked in. You can request a copy of your account data, or full account deletion, by contacting us.

8. Security

Every request is checked against your account before anything is read or written, so your data is never visible to another account. Connections to The Vault are encrypted in transit. Passwords are stored as salted hashes, never in plain text. Google OAuth tokens and your Apple app-specific password (if you connect Apple Calendar) are encrypted at rest.

9. Children's privacy

The Vault is not directed at, and is not intended for use by, anyone under 16. We don't knowingly collect data from children.

10. Changes to this policy

If we make a material change to this policy, we'll update the date at the top of this page. Continued use of The Vault after a change means you accept the updated policy.

11. Contact us

Questions about this policy, your data, or a deletion request? Email lukefarrow2005@icloud.com and we'll get back to you.