infovault, operated from Slovenia, is the data controller for the personal data described here. Contact: support@infovault.app.
All content and account data is stored in the EU (Frankfurt, Germany).
We use a small number of service providers ("processors") strictly to run infovault, each bound by a data processing agreement:
A detailed processor list is available on request via support@infovault.app.
When you connect your own AI assistant (e.g. Claude) via the infovault connector, your queries and matching document excerpts flow to that assistant under your agreement with its provider — that connection exists only because you set it up, and you can disconnect it at any time.
Essential cookies: pak_session (sign-in), pak_theme (appearance), pak_consent (remembers your analytics choice). Google Analytics cookies (_ga) are set only after you accept the cookie banner; declining is remembered and respected. Server-side usage events use internal pseudonymous IDs and contain no personal details. We do not run ads and never sell data.
Performing our contract with you (accounts, content, billing), legitimate interest (security, service usage measurement with pseudonymous IDs), and consent (analytics cookies).
Content: until you delete it (deleting a document or workspace purges its files, index entries, and vectors). Account data: while your account exists. Analytics: 14 months. Operational logs: weeks, not months.
You can access, correct, export, or delete your data, object to processing, and withdraw consent at any time — most of it directly in the app (delete documents/workspaces, change password, cookie banner), the rest via support@infovault.app, including full account deletion. You may lodge a complaint with the Slovenian Information Commissioner (IP-RS) or your local supervisory authority.
Where a provider processes data outside the EU, transfers rely on the EU Standard Contractual Clauses and equivalent safeguards.
We'll announce material changes to this policy by email or in the dashboard before they take effect.