1. Scope
This Privacy Policy applies to Vautera's public website, apps, local Memory Vault, live messaging, calls, community, marketplace, dating, Status, backup, support, and related services.
It does not control third-party services you choose to use, such as an app store, phone-verification provider, external link, or backup destination. Those services handle data under their own policies.
2. The main data boundaries
- Local import
- A WhatsApp export, imported messages, local search index, and Memory Vault files are processed on your device unless you take a separate action that sends or backs them up.
- Live services
- Registration, messaging, calls, public features, marketplace, dating, support, moderation, and backups use Vautera's servers and collect the data needed to provide those features.
- Device and safety
- Linked-device records, push tokens, app and operating-system details, IP address, integrity signals, and activity timestamps support delivery, security, and abuse prevention.
- Product telemetry
- Vautera records bounded feature and action events. The telemetry contract rejects message text, payloads, phone numbers, tokens, private filenames, and local paths.
- Public website
- The public site does not embed advertising pixels or third-party analytics scripts. If you email Vautera, the message and sender information are received to answer you.
3. Local Memory Vault data
When you select a supported export, the app can read and process its messages, participants, timestamps, attachments, and other included records on your device. It can create an encrypted local vault, a local search index, local media storage, and local sidecar settings such as names, favorites, or reactions.
Importing, searching, or viewing that history does not by itself send the imported history to the live-messaging database. Vautera's account and messaging services are a separate data plane.
If you intentionally use export, sharing, restore, Vautera Cloud backup, or another backup destination, the selected encrypted artifact and related metadata may leave your device. A server-hosted backup can include an encrypted backup object and, depending on the backup mode you choose, recovery key material. External destinations receive data according to the option you select.
Removing an account from Vautera's server does not automatically erase local Memory Vault files or backups held by a destination. Those copies must be removed on the relevant device or service.
4. Data Vautera receives
Account and profile data
This can include your phone number, one-time-code challenge records, username, display name, bio, avatar, city, country, settings, account status, and the date your account was created. Raw device bearer tokens and one-time codes are not stored in the primary database; their hashes are stored for authentication and verification.
Contacts and discovery
If you grant contacts permission and use contact discovery, the app can read selected address-book entries on your device and send normalized phone-number hashes to find matching Vautera accounts. The server can store account-to-account contact relationships used for discovery, privacy audiences, and safety controls.
Live messages, calls, and delivery
Connected messaging features send the content and metadata needed to route messages, media, receipts, calls, and device-specific delivery. Pending messages can remain in a delivery queue until linked devices acknowledge them or server cleanup removes them. Scheduled messages remain server-side until they are sent or cancelled.
Vautera uses encrypted network transport. This policy does not make a blanket claim that every message, call, backup, or product feature is end-to-end encrypted. Feature-specific notices in the app describe the protection available in the build you use.
Feature content
When you use connected features, Vautera receives the information you provide to them. Depending on the feature, this can include group membership, Status posts and audiences, City Hub posts and comments, marketplace listings and leads, dating profile details and preferences, reports, blocks, support tickets, media, backup metadata, and social-profile links.
Device, network, and safety data
This can include a linked-device identifier and label, push-notification token and platform, device model, operating system and version, app version, locale, timezone, network type, carrier information, IP address, last-seen time, official-client status, and available platform-integrity or number-risk signals. Vautera uses these records for account security, delivery, fraud prevention, and support.
Location data
Features based on place or distance can receive a city, user-provided location, or device location when you grant permission and use that feature. Dating, marketplace, community, and map features can use location differently, and the relevant screen controls what you submit or share.
Product telemetry
Authenticated product events can include the account and device identifiers, platform, feature, action, surface, a related record identifier, and small bounded metadata values. The telemetry schema is designed not to accept message bodies, ciphertext, payloads, phone numbers, sender names, credentials, push tokens, filenames, or local paths.
Website and direct communications
The public website is static and does not include advertising trackers or third-party analytics scripts. Standard hosting records may still include technical request information such as IP address, requested path, time, and browser headers. Vautera receives the content and sender details of email or support communications you initiate.
5. How Vautera uses data
Vautera uses data to:
- register accounts, verify phone ownership, and maintain linked devices;
- route messages, calls, notifications, receipts, media, and backups;
- provide profiles, discovery, groups, Status, community, marketplace, dating, and support features;
- apply privacy settings, audience rules, blocks, reports, and moderation decisions;
- detect spam, fraud, compromised devices, abuse, and service attacks;
- measure feature adoption, diagnose failures, maintain reliability, and plan improvements;
- respond to requests and enforce the Terms of Service; and
- comply with applicable law and protect users, Vautera, and the public.
6. When data is shared
Vautera can disclose data in these circumstances:
- With people you choose. Recipients, group members, viewers, buyers, sellers, matches, or community participants receive content and profile details according to the feature and your settings.
- With service providers. Hosting, database, storage, phone-verification, push-notification, communications, security, and support providers process data needed to perform their services.
- With destinations you select. An export, share action, link, or backup destination sends data to the service or person you choose.
- For safety and legal reasons. Vautera may preserve or disclose information when reasonably necessary to respond to lawful process, prevent harm, investigate abuse, protect rights, or secure the Services.
- During an organizational change. Data may be transferred as part of a financing, acquisition, reorganization, or sale, subject to applicable law and continued protection.
7. Visibility, reports, and other users
Your username and selected profile fields may be discoverable. Public posts, listings, comments, reactions, and other public-facing records are visible according to the feature. Contacts-only, private, group, and dating audiences use separate controls; review each audience before publishing.
Reports can include content or context needed for authorized moderators to review the issue. Other people can copy, capture, forward, or report information they receive. Vautera cannot erase copies outside its control.
8. Storage and retention
Retention varies by data type, feature, account state, safety need, and legal requirement. Delivery records are designed to clear after device acknowledgement, expiry, cancellation, or scheduled cleanup. Account, public-content, moderation, audit, support, backup, and safety records can remain while needed to provide the feature, maintain integrity, resolve disputes, enforce rules, or meet legal obligations.
Account deletion removes account-linked server records through the in-app deletion flow, subject to records that must be preserved or cannot be removed immediately. Local files, recipient copies, and external backups are outside that server deletion and require separate action.
Vautera does not promise a fixed retention period for every category in this policy. The product and infrastructure can evolve, and applicable legal obligations can require different treatment.
9. Security
Vautera uses technical and organizational safeguards intended to protect data, including encrypted network transport, hashed authentication secrets, access controls, rate limits, device revocation, audit records, and encrypted local vault and backup formats where supported.
No storage or transmission method is risk-free. Keep your device, email, phone number, backup destinations, and operating-system account secure; install updates; review linked devices; and promptly revoke access you do not recognize.
10. Your choices and controls
- Grant or withdraw device permissions such as contacts, notifications, camera, microphone, and location through the app or operating-system settings.
- Control supported profile visibility, Status audiences, read receipts, last-seen visibility, call privacy, blocks, notification scopes, and linked devices.
- Use the in-app account data export to receive supported operational account data.
- Use the in-app account deletion control to delete your account and account-linked server data.
- Delete local Memory Vault files, exports, and backup copies from the device or destination where they are stored.
- Contact Vautera to ask a privacy question or exercise rights available under applicable law.
Vautera may need to verify your identity before completing a request. Some information may be exempt from a request where applicable law permits or requires it.
11. Age-limited features
Dating features are limited to adults aged 18 or older. Other age restrictions may apply under local law or app-store rules. Do not use an age-limited feature if you do not meet its requirements.
12. International processing
Vautera and its service providers may process data in countries other than the one where you live. Privacy and data-access rules can differ across those locations. Vautera applies safeguards required by applicable law when transferring personal data.
13. Changes to this policy
Vautera may update this policy as the product, providers, or legal requirements change. The effective date at the top identifies the current version. Material changes will receive additional notice when reasonably practicable.
14. Contact
Privacy questions and requests can be sent to hello@vautera.app.