Draft — unreviewed
This document has not been reviewed by counsel. Do not treat it as final. It is published here so operators can see the shape while the review is in flight.
Privacy Policy
Draft — last updated 2026-08-25
What this document is
VaultAI is a sports-card analysis tool. This document describes what data we collect from you, what third parties that data flows through, and how long we keep it. It reflects the state of the product at the draft date above; when we change the vendor stack or the data flow we’ll update this page and note it in the last-updated line.
What we collect from you directly
- Account: email address and password (the password is stored hashed; we cannot see it in plaintext).
- Portfolio and watchlist: the cards you mark as owned or watched, along with any cost basis, horizon, or strategy notes you enter for them.
- Grading submissions: when you tell the app you sent a card to a grader, we record the card, the service, the date, and the returned grade. This is the submissions ledger you can see on the /submissions page.
- Card scans: when you use the scanner or pre-grader, the image you upload is sent to our AI provider (below) for card identification and grading estimation. We do not train a model on your images.
- Chat queries: anything you type into the VaultAI drawer is sent to our AI provider (below) so the assistant can respond.
- Payment information: when subscriptions open, your card details are handled by Stripe directly. We do not see or store card numbers; we store the Stripe customer id and subscription status.
- Preferences: your grading-cost inputs (grading fee, shipping, eBay fee percentage) are stored in your browser’s local storage. They never leave your device.
Third parties your data flows through
We use the following vendors to run VaultAI. Each row lists what data reaches that vendor.
Supabase
Auth + database + hosting for our Postgres tables.
Email address, password hash, portfolio/watchlist rows, submissions, cost-basis notes. Every card and comp record the app reads.
Stripe
Subscription billing (when public access opens).
Email, subscription status. Payment card details are entered on Stripe’s hosted forms — we never see the card number.
Anthropic (Claude API)
AI narration, chat drawer, card scanner / pre-grader.
Your chat queries and uploaded card images. Anthropic’s API terms apply to the request; we do not opt in to any training-data usage program.
Card Hedger
Pricing and sales-history source for the catalog.
Outbound only — we send card identifiers. No user account or portfolio data leaves the app for Card Hedger.
GemRate
PSA / BGS / CGC population data.
Outbound only — card identifiers. No user data.
DataForSEO
Google Trends search-interest data.
Outbound only — player names as search terms. No user data.
Sentry
Error tracking.
Browser errors, stack traces, and enough context to reproduce a bug. In some paths this can include your email (if the error happens after sign-in). We keep this to the default Sentry retention window.
Vercel
Hosting the web app.
Standard web-server access logs: IP address, request path, timestamp. Retained per Vercel’s platform defaults.
Inngest
Background job scheduling (the daily comps / gemrate / trends crons).
Job payloads are catalog-wide operations — no user account data is passed to Inngest jobs.
What we do NOT collect
- Analytics fingerprints, marketing pixels, or ad-network trackers.
- Contact-list or social-media access.
- Location data beyond what a normal server log contains.
- Your uploaded card images beyond the immediate identification + grading round-trip. Images are not retained for training.
How long we keep it
- Account data: until you delete your account. Contact us at info@thevaultai.app to request deletion.
- Portfolio and watchlist rows: until you remove them, or until your account is deleted.
- Grading submissions: retained after account deletion in de-identified form so aggregate accuracy statistics stay meaningful. Individual-record deletion available on request.
- Server + error logs: per Vercel and Sentry platform defaults (roughly 30 to 90 days depending on the service).
- Payment records: retained by Stripe per their terms; we retain the Stripe customer id.
Your rights
- Access: request a copy of the data we hold on you.
- Correction: most fields you enter yourself can be edited directly in the app; anything else, contact us.
- Deletion: request account deletion at info@thevaultai.app. We’ll process within 30 days.
- Export: we can export your portfolio, watchlist, and submissions history on request.
Contact
Questions about this policy, or requests under it, go to info@thevaultai.app.
This page is a first-cut draft. It has not been reviewed by counsel. Vendors and data flows described here are accurate as of the last-updated date at the top; if you spot a discrepancy between this page and the running product, the running product is the ground truth and the page is what needs correcting.