Privacy Policy
Last updated: 2 October 2026
This policy explains what personal data VaultPulse Cloud Systems (“VaultPulse”, “we”, “us”) collects when you use vaultpulse.cloud and the VaultPulse GitHub App, why we collect it, and the choices you have. Your backup archives are stored in your own Amazon S3 bucket or Azure Blob Storage container; VaultPulse processes temporary working copies but does not retain your source code.
1. Who we are
VaultPulse is the data controller for the account and usage data described in this policy. For the repository contents you back up, you remain the controller; VaultPulse acts as a processor on your behalf. You can reach us at support@vaultpulse.cloud.
2. Data we collect
- Account data: your name, email address, profile image, linked Google or GitHub user ID, a hashed password (if you use email/password signup), two-factor authentication settings and team membership. GitHub sign-in uses your verified primary email; its OAuth access token is used temporarily to retrieve your profile and email and is not stored.
- GitHub installation data: the GitHub account or organization name and ID, installation ID, repository names, IDs, visibility, default branch and the backup selection you configure.
- Storage configuration: your chosen provider, storage location, prefix and authentication method. For S3, we store the bucket name and region, plus the IAM role ARN and generated External ID or encrypted IAM access keys. For Azure Blob Storage, we store the account and container names, Entra tenant and client IDs, and an encrypted client secret. Access keys and client secrets are not returned by the API.
- Backup and restore metadata: run status, timestamps, snapshot sizes, object keys, error messages and restore history.
- Billing data: your plan and subscription status. Card details are collected and stored by Stripe; we never see your full card number.
- Support enquiries: the name, email, company and message you send through our contact form.
- Analytics and logs: if you consent, anonymised usage analytics via Google Analytics; plus standard server and security logs (IP address, user agent, request path) kept for security and troubleshooting.
3. Your source code
When a backup runs, VaultPulse uses a short-lived GitHub installation token to mirror-clone the repository and uploads the snapshot into your own S3 bucket or Azure Blob Storage container. S3 access uses a temporary cross-account IAM role or the IAM access keys you provide; Azure access uses an Entra service principal with the client secret you provide. Working copies exist only in temporary storage for the duration of the job and are deleted when it finishes. We do not retain copies of your code, and GitHub tokens are never persisted.
4. How we use your data
- To provide the service: run scheduled and on-demand backups, restores and the health dashboard.
- To authenticate you and secure your account.
- To process payments and manage your subscription.
- To respond to support requests and send essential service emails.
- To understand usage and improve the product (only with your consent for analytics).
Our legal bases under UK GDPR are performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and your consent for analytics cookies.
5. Third-party services
We share data only with the providers needed to run VaultPulse:
- Amazon Web Services: application hosting, database and email delivery (Amazon SES) in eu-west-2, London; access to your S3 bucket in its configured region if you choose S3 storage.
- Microsoft Azure: service-principal authentication through Microsoft Entra and access to your Blob container if you choose Azure storage.
- GitHub: optional sign-in with GitHub and repository access through the separate VaultPulse GitHub App installation.
- Stripe: payment processing and subscription billing.
- Google: optional sign-in with Google, and Google Analytics with anonymised IPs (only with your consent).
We do not sell your personal data.
6. Data location and transfers
Our infrastructure is hosted in the AWS London (eu-west-2) region. Some providers (such as Stripe, GitHub and Google) may process data outside the UK; where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum or Standard Contractual Clauses. Your backups stay in whichever region you choose for your S3 bucket or Azure storage account, subject to your cloud provider's replication configuration.
7. Retention
- Account, installation and backup metadata are kept while your account is active and deleted within 30 days of account closure, except where we must keep billing records for legal reasons.
- If you uninstall the GitHub App, we stop all backups immediately and mark the installation as removed.
- Backup snapshots live in your S3 bucket or Azure Blob container. VaultPulse applies configured retention while the connection is active, subject to your storage policies; deleting your VaultPulse account does not delete stored snapshots.
8. Security
We use TLS encryption in transit, a private, non-public database network, application-level AES-256 encryption for stored credentials, a web application firewall, short-lived scoped GitHub and IAM role credentials, cross-account roles with unique External IDs, optional two-factor authentication and least-privilege access controls.
9. Your rights
Under UK GDPR you can request access to, correction of, deletion of or a copy of your personal data, and you can object to or restrict processing. You can withdraw analytics consent at any time by clearing your cookie preference. To exercise any right, email support@vaultpulse.cloud. You may also complain to the UK Information Commissioner's Office (ico.org.uk).
10. Cookies
We use essential storage to keep you signed in, and Google Analytics cookies only if you accept them in the cookie banner.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and, for material changes, notify account holders by email.