WhyVault

Privacy policy

Draft – as of 24 September 2026. This privacy policy has not yet been reviewed by a lawyer and will be completed before launch.

This English version is a translation for your convenience. In case of doubt, the German version applies. Read the German version

Controller

Ohrlaf GmbHReichholz 187634 ObergünzburgGermany

Email: post@ohrlaf.com · Questions about WhyVault: hello@whyvault.io

You'll find further details in the legal notice.

In short

  • Your notes are stored in Frankfurt. We use them only to run WhyVault – not for advertising and not to train AI models.
  • An AI assistant only receives content if you connect it and it fetches that content. The assistant provider's privacy policy then applies to that content.
  • Payments are handled by Stripe. We never see card details.
  • No advertising or tracking cookies.

Visiting the website

When you visit whyvault.io or the app, our host Vercel processes technically necessary data: IP address, time, requested address, browser and operating system. This is needed to deliver the pages and detect attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). These logs are kept only as long as necessary for that purpose.

For visitor statistics we use Vercel Web Analytics. It sets no cookies and stores no IP addresses. Visits are counted using a hash of the request that is discarded after 24 hours; we only see aggregated numbers, such as how often which pages are viewed. The legal basis is our legitimate interest in improving our service (Art. 6(1)(f) GDPR).

Account and sign-in

For your account we store your email address, optionally a password (only as a hash), a display name, your language and timestamps such as registration and last sign-in. We email you sign-in links. Sign-in runs on Supabase Auth; the data is stored with Supabase in Frankfurt.

The legal basis is our contract with you (Art. 6(1)(b) GDPR). We can't create an account without an email address.

Content of your vault

We store what you put into WhyVault: notes, folders, files and links between notes. For every change we store a version and a history entry – with the time and whether the change came from you or from a connected assistant. Deleted notes go to the trash first. Everything is stored with Supabase in Frankfurt.

We use your content only to run WhyVault. We only look at it if you ask us to, if we are legally required to, or to stop a specific abuse. You can export your vault as a zip at any time.

If your notes contain personal data of other people, you are responsible for it yourself; we only process it to store it for you.

The legal basis is our contract with you (Art. 6(1)(b) GDPR).

Connected AI assistants (MCP)

You can connect AI assistants to your vault via the Model Context Protocol – by signing in (OAuth) or with a personal access key. For each connection we store its name, its type (OAuth or key), its permissions (read, or read and write), and when it was created, last used and, if applicable, revoked. We store access keys only as a hash plus a short prefix so you can recognize them. For OAuth connections we store the assistant's identifier; the sign-in itself runs on Supabase Auth.

A connected assistant reads and writes notes when you ask it to. Whatever it fetches goes to the assistant's provider (e.g. Anthropic or OpenAI). The provider processes that content under its own responsibility and its own privacy policy; we have no influence on this. So only connect assistants you want to entrust with that content, and when in doubt, grant read access only.

If a connection writes an unusual amount in a short time, we stop it and send you an email. The legal basis is our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in protecting your vault from abuse (Art. 6(1)(f) GDPR).

Payment (Pro)

We sell the Pro subscription through Stripe Managed Payments. Stripe is the seller; you pay via Link, a Stripe service. Stripe processes your payment and billing data (such as name, address, payment method, invoices, tax details) as an independent controller under its privacy policy: https://stripe.com/privacy

From Stripe we only receive what we need for your subscription: a customer ID, the subscription ID, status, plan and billing interval, the end of the current period and whether a cancellation is scheduled. We never see card or bank details.

The legal basis is our contract with you (Art. 6(1)(b) GDPR). Stripe issues the invoices and keeps them for the statutory periods. Records we need for our own accounting are kept for the statutory periods (Art. 6(1)(c) GDPR, § 147 German Fiscal Code, § 257 German Commercial Code).

Emails

We send sign-in links, confirmations and emails about your account via Plunk. Plunk stores data in the EU (Hetzner, Germany) and delivers emails via Amazon SES; on their way to the recipient, emails may pass through servers outside the EU. The legal basis is our contract with you (Art. 6(1)(b) GDPR).

Cookies and local storage

We don't use advertising or tracking cookies. When you sign in to the app, we set session cookies so you stay signed in. We also store display settings in your browser, such as the color scheme (light or dark), expanded folders and the state of the sidebar. This data doesn't leave your device.

Both are strictly necessary for the features you use (§ 25(2) no. 2 German TDDDG). No consent is required for this.

Service providers and processors

We work with only a few service providers. We have data processing agreements (Art. 28 GDPR) with all processors.

  • Supabase

    DPA
    Purpose
    Database, files and sign-in
    Location
    Supabase Inc., USA; data in Frankfurt (eu-central-1)
    Role
    Processor
  • Vercel

    DPA
    Purpose
    Hosting of website and app, server functions, visitor statistics
    Location
    Vercel Inc., USA; server functions in Frankfurt (fra1), delivery via a global network (CDN)
    Role
    Processor
  • Plunk

    DPA
    Purpose
    Sending sign-in links and emails about your account
    Location
    Storage in the EU (Germany), delivery via Amazon SES
    Role
    Processor
  • Purpose
    Sale and billing of the Pro subscription (Managed Payments, Link)
    Location
    EU and USA
    Role
    Independent controller

Supabase, Vercel and Stripe are based in the USA. Where data is transferred to the USA, we rely on the adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses.

How long we keep data

We keep your data as long as you have your account. If you delete your account, we delete your account, your vault with all versions and your connections – except data we must keep longer for legal reasons; we restrict that data until the period expires.

Until you can delete your account yourself in the app, just email us at hello@whyvault.io or post@ohrlaf.com.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20) – for the latter, you can export your vault yourself at any time. Where we process data based on our legitimate interest, you can object on grounds relating to your particular situation (Art. 21).

Just write to us at hello@whyvault.io or post@ohrlaf.com.

You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de

We do not make automated decisions within the meaning of Art. 22 GDPR.

Changes

We update this privacy policy when WhyVault or the legal situation changes. The version published here applies.