Privacy Policy
Last updated: 2026-09-05
Overview
VaultRAG Inc. ("we", "us") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how it is handled.
What We Collect
Email address
When you purchase VaultRAG, we collect your email address through the Stripe checkout process. We use it to send you your license key, download link, and important product updates such as new releases or security notices.
Payment information
Payment is processed entirely by Stripe. We do not collect, store, or have access to your credit card number or billing details. We only receive a confirmation of payment, a transaction ID, and the amount paid.
License activation
When you activate VaultRAG on a device, a cryptographic hash of your device identifier is stored to enforce the two-device activation limit. We do not store your actual device ID or any other information about your hardware.
What We Do Not Collect
- Your name, phone number, or billing address
- The contents of your documents or vault
- Your AI provider API keys
- Your search queries or chat conversations
- IP addresses, cookies, or browsing activity
- Device identifiers in plaintext
The Desktop Application
VaultRAG is a desktop application that processes your documents locally on your machine. When you use cloud AI features such as search or chat with an external provider, the app sends document content to the third-party AI provider you have configured (e.g., models accessed through OpenRouter). This communication happens directly between your device and the provider. We are not involved in that data exchange and do not have access to it.
When you use Local AI features, inference runs on your device using bundled runtimes such as llama.cpp and ONNX Runtime. For those features, VaultRAG does not send your document content to us or to an external AI provider. You may download model files and optional acceleration components from third-party sources; those downloads are subject to the respective owner's terms.
You choose which files to index. The app does not scan or access files outside of your selected vault folder.
Coding agents
When you hand a conversation to a coding agent such as Claude Code, Codex, OpenCode, or an Agent Client Protocol agent, VaultRAG launches the agent software you installed and sends your conversation content to it. That agent then talks to its own vendor under your own account and the vendor's terms; we are not involved and receive nothing. Agents can search your vault only through a read-only interface that is reachable solely from your own machine. Usage and cost analytics for agents are computed from log files on your device and are never uploaded.
Git and GitHub
Git features use the git program on your device. If you sign in to GitHub from VaultRAG, the access token is stored in your operating system's keychain or credential manager and used only to talk to GitHub on your behalf. Repository contents you choose to publish or push go to GitHub under GitHub's terms; we never see them.
Remote control
The optional remote control feature runs a small server on your computer, bound to localhost, and publishes it only on your own Tailscale network. Pairing codes and per-device tokens are generated and stored on your device (tokens as hashes). There is no VaultRAG-hosted relay: your phone and your computer talk directly over your tailnet, and we receive no data from this feature.
Third-Party Services
We use the following third-party services:
- Stripe for payment processing. Stripe's privacy policy is available at stripe.com/privacy.
- AI providers (configured by you) for cloud search and chat features within the desktop app. Review your chosen provider's privacy policy for details on how they handle data.
- Local AI model and runtime providers (selected by you) for model files and optional acceleration components you download for on-device inference. VaultRAG does not receive the content processed by Local AI features.
- Coding agent vendors (Anthropic for Claude Code, OpenAI for Codex, the OpenCode project, and the vendors behind any Agent Client Protocol agent you enable) when you choose to run a conversation through their tools. Each runs under your own account and its vendor's privacy policy.
- GitHub when you sign in to use repository hosting features. GitHub's privacy statement is available at docs.github.com.
- Tailscale when you use remote control, for the private network that connects your phone to your computer. Tailscale's privacy policy is available at tailscale.com/privacy-policy.
Data Retention
We retain your email address and order records for as long as your license is active, and as needed to comply with legal obligations. If you would like your data deleted, contact us and we will remove it.
Contact
For privacy-related questions, contact us at [email protected].