Privacy policy

The Vault is operated by Business Masters Enterprises Inc.. Effective August 2026.

Who we are

Business Masters Enterprises Inc. operates The Vault at yourvault.cloud. For anything in this policy, write to support@help.yourvault.cloud.

What we store

Account data: your email address, your name if you give one, and which projects and accounts you belong to. Vault data: the credentials you choose to store — a label, the service, an optional username and URL, notes, an expiry date, and the secret value itself. Activity data: an append-only record of who added, changed, revealed, revoked or shared each credential, and when.

We do not sell any of it, we do not use it for advertising, and we do not train models on it.

How credentials are protected

Every secret value is encrypted with AES-256-GCM before it is written to storage, with keys scoped per project. Reading a secret is a deliberate, logged action taken by a person or by an agent connection you authorised. Our staff accounts are separate identities from customer accounts and have no path to read your stored secrets.

Who can see your data

People you have invited to a project, at the role you gave them. Agent connections you created, limited to the credentials you marked as available to AI, for as long as you leave that connection active. Nobody else — access is enforced in the database, not only in the interface.

Service providers

We rely on infrastructure providers for hosting, the database, and sending email. They process data on our instructions in order to run the service and for no other purpose.

Email we send you

Account email only: invitations, sign-in and password messages, and warnings that a stored credential is about to expire. We never email you asking for a password, a key, or any credential — and we never ask you to reply with one.

How long we keep it

Credentials and project data are kept until you delete them or close the account. Deleting a credential removes its stored value; the audit record that it existed and was deleted remains, because an audit trail you can edit is not an audit trail.

Your choices

You can edit or delete any credential, revoke any agent connection, remove any member, change your email, and turn on two-factor authentication from your settings. To request an export or full deletion of your account, email support@help.yourvault.cloud.

Reporting a security issue

Send security reports to support@help.yourvault.cloud. We would rather hear about a problem than not.

Changes

If we change this policy in a way that materially affects you, we will say so by email to the address on your account before it takes effect.

See also the security model and the terms of service.