Privacy Policy

Invisivault encrypts file contents and names in your browser before upload. We keep encrypted account keys so that you can recover access through your email. This is service-assisted recovery, not zero-knowledge storage.

Data categories

  • Account data: email address, account identifiers, created timestamps.
  • Sign-in data: protected passwords and records of security activity.
  • File information: locked names and file types, storage references, sizes, and dates.
  • Technical information: IP address, browser information, and security logs.

What we can and cannot read

We store encrypted file contents, file names, folder names, and file types. We also store encrypted account keys protected by a separate service key. This gives the service the technical ability to recover keys and decrypt data; we do not claim that access by the service is cryptographically impossible.
We can read information needed to run the service, including file sizes, dates, storage references, account details, billing status, and security logs.

Purposes

  • Provide secure storage and account access.
  • Prevent abuse and maintain security.
  • Comply with legal obligations.

Retention

We keep encrypted files until you delete them. Security logs are kept for a limited period and removed automatically. After account deletion, encrypted files and temporary backup copies are removed according to the normal deletion and backup schedules. A minimal account-deletion record may be retained for a limited time to prevent abuse.

Cookies and browser storage

Necessary storage is used for sign‑in and security. Optional analytics is off by default and only enabled with your consent. A secure, HttpOnly cookie remembers each approved browser for up to 180 days since its last sign-in. It contains no file key. Account keys are loaded into page memory while signed in, and that in-memory copy is removed on sign-out. Older browser-key records may remain in browser storage until you clear them.

Subprocessors

We use service providers to run Invisivault, including Scalingo for application hosting, Hetzner for encrypted file storage, Stripe for payments, Resend for email, and Cloudflare for automated-abuse protection. Contact us for current details.

Policy change log

  • 2026-09-10: Added email-confirmed browsers and service-assisted account-key recovery. Older files require migration with their original keys.
  • 2026‑02‑10: Initial privacy policy published.

Your rights

You can request data export or account deletion in Settings. For other requests, contact info@coliberant.com.

You may also have the right to complain to your local data-protection authority.