Last updated: 10 April 2026
VaultKeep is published by VaultKeep Ltd (Company No. 17033775), registered in England and Wales. Contact: support@vaultkeep.co.uk
VaultKeep is built on a local-first architecture. All your financial data — accounts, holdings, liabilities, assets, snapshots, settings, and themes — is stored on your device and never transmitted to our servers. There are no user accounts, no analytics, no telemetry, and no tracking.
When you use optional paid features, minimal data processing occurs through our server as described below.
| Data | Purpose | Lawful Basis | Retention |
|---|---|---|---|
| Licence key (SHA-256 hash) | Validate your licence and determine your tier | Contract performance | Until key is deleted or licence expires |
| Email address (SHA-256 hash) | Link licence keys to your purchase (received from LemonSqueezy webhook) | Contract performance | Until key is deleted |
| Device hostname | Register your device activation with LemonSqueezy | Contract performance | Managed by LemonSqueezy |
| IP address (SHA-256 hash) | Rate-limit feedback submissions | Legitimate interests (abuse prevention) | 1 hour |
| Requested ticker symbols | Sent directly from your device to EODHD using your own API key | Legitimate interests (service functionality) | Not stored by VaultKeep (see EODHD's retention policy) |
| Feedback text | Deliver your feature suggestion to our team | Consent (you choose to submit) | Forwarded to Discord, not stored |
| IP address (Cloudflare logs) | Standard web infrastructure (auto-update checks, API requests) | Legitimate interests (security, availability) | Per Cloudflare's retention policy |
Important: We never store raw licence keys or email addresses. All identifiers are SHA-256 hashed before storage. Your financial data (balances, holdings, net worth) never leaves your device.
If you enable the AI assistant, conversations are sent directly from your device to your chosen AI provider (e.g. OpenAI, Anthropic, Google) using your own API key. VaultKeep Ltd does not see, proxy, intercept, or store any part of these conversations. Your API key is stored locally on your device, optionally encrypted using WebCrypto AES-GCM.
We share limited data with the following third parties, only when you use paid features:
| Recipient | What they receive | Why | Their privacy policy |
|---|---|---|---|
| Cloudflare | Hashed licence key, IP address | Infrastructure for licence validation, app updates, and feedback | cloudflare.com/privacypolicy |
| LemonSqueezy | Email, payment details, licence key, device name | Process your purchase and manage licence activations | lemonsqueezy.com/privacy |
| EODHD | Ticker symbols (directly from your device using your API key) | Provide delayed market prices | eodhd.com/privacy-policy |
| Discord | Hashed IP, feedback text, tier info | Deliver feature suggestions and operational alerts | discord.com/privacy |
| Your chosen AI provider | Portfolio context, conversation (BYOK) | Power the AI assistant using your own API key | See provider's policy |
Some of the recipients above are based outside the UK. Where personal data is transferred internationally, we rely on:
Under UK GDPR, you have the right to:
To exercise any of these rights, email support@vaultkeep.co.uk. We will respond within one month.
ICO contact: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Tel: 0303 123 1113. Website: ico.org.uk
VaultKeep is intended for users aged 18 and over. We do not knowingly process data from anyone under 18.
If we change this policy, we will update this page, the “Last updated” date, and notify you via an in-app banner on the next update.
VaultKeep Ltd
United Kingdom
Company No. 17033775
support@vaultkeep.co.uk