Privacy policy
Draft – as of 24 September 2026. This privacy policy has not yet been reviewed by a lawyer and will be completed before launch.
This English version is a translation for your convenience. In case of doubt, the German version applies. Read the German version
Controller
Ohrlaf GmbHReichholz 187634 ObergünzburgGermanyEmail: post@ohrlaf.com · Questions about WhyVault: hello@whyvault.io
You'll find further details in the legal notice.
In short
- Your notes are stored in Frankfurt. We use them only to run WhyVault – not for advertising and not to train AI models.
- An AI assistant only receives content if you connect it and it fetches that content. The assistant provider's privacy policy then applies to that content.
- Payments are handled by Stripe. We never see card details.
- No advertising or tracking cookies.
Visiting the website
When you visit whyvault.io or the app, our host Vercel processes technically necessary data: IP address, time, requested address, browser and operating system. This is needed to deliver the pages and detect attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). These logs are kept only as long as necessary for that purpose.
For visitor statistics we use Vercel Web Analytics. It sets no cookies and stores no IP addresses. Visits are counted using a hash of the request that is discarded after 24 hours; we only see aggregated numbers, such as how often which pages are viewed. The legal basis is our legitimate interest in improving our service (Art. 6(1)(f) GDPR).
Account and sign-in
For your account we store your email address, optionally a password (only as a hash), a display name, your language and timestamps such as registration and last sign-in. We email you sign-in links. Sign-in runs on Supabase Auth; the data is stored with Supabase in Frankfurt.
The legal basis is our contract with you (Art. 6(1)(b) GDPR). We can't create an account without an email address.
Content of your vault
We store what you put into WhyVault: notes, folders, files and links between notes. For every change we store a version and a history entry – with the time and whether the change came from you or from a connected assistant. Deleted notes go to the trash first. Everything is stored with Supabase in Frankfurt.
We use your content only to run WhyVault. We only look at it if you ask us to, if we are legally required to, or to stop a specific abuse. You can export your vault as a zip at any time.
If your notes contain personal data of other people, you are responsible for it yourself; we only process it to store it for you.
The legal basis is our contract with you (Art. 6(1)(b) GDPR).
Connected AI assistants (MCP)
You can connect AI assistants to your vault via the Model Context Protocol – by signing in (OAuth) or with a personal access key. For each connection we store its name, its type (OAuth or key), its permissions (read, or read and write), and when it was created, last used and, if applicable, revoked. We store access keys only as a hash plus a short prefix so you can recognize them. For OAuth connections we store the assistant's identifier; the sign-in itself runs on Supabase Auth.
A connected assistant reads and writes notes when you ask it to. Whatever it fetches goes to the assistant's provider (e.g. Anthropic or OpenAI). The provider processes that content under its own responsibility and its own privacy policy; we have no influence on this. So only connect assistants you want to entrust with that content, and when in doubt, grant read access only.
If a connection writes an unusual amount in a short time, we stop it and send you an email. The legal basis is our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in protecting your vault from abuse (Art. 6(1)(f) GDPR).
Payment (Pro)
We sell the Pro subscription through Stripe Managed Payments. Stripe is the seller; you pay via Link, a Stripe service. Stripe processes your payment and billing data (such as name, address, payment method, invoices, tax details) as an independent controller under its privacy policy: https://stripe.com/privacy
From Stripe we only receive what we need for your subscription: a customer ID, the subscription ID, status, plan and billing interval, the end of the current period and whether a cancellation is scheduled. We never see card or bank details.
The legal basis is our contract with you (Art. 6(1)(b) GDPR). Stripe issues the invoices and keeps them for the statutory periods. Records we need for our own accounting are kept for the statutory periods (Art. 6(1)(c) GDPR, § 147 German Fiscal Code, § 257 German Commercial Code).
Emails
We send sign-in links, confirmations and emails about your account via Plunk. Plunk stores data in the EU (Hetzner, Germany) and delivers emails via Amazon SES; on their way to the recipient, emails may pass through servers outside the EU. The legal basis is our contract with you (Art. 6(1)(b) GDPR).
Service providers and processors
We work with only a few service providers. We have data processing agreements (Art. 28 GDPR) with all processors.
Supabase
DPA- Purpose
- Database, files and sign-in
- Location
- Supabase Inc., USA; data in Frankfurt (eu-central-1)
- Role
- Processor
Vercel
DPA- Purpose
- Hosting of website and app, server functions, visitor statistics
- Location
- Vercel Inc., USA; server functions in Frankfurt (fra1), delivery via a global network (CDN)
- Role
- Processor
Plunk
DPA- Purpose
- Sending sign-in links and emails about your account
- Location
- Storage in the EU (Germany), delivery via Amazon SES
- Role
- Processor
Stripe
Privacy policy- Purpose
- Sale and billing of the Pro subscription (Managed Payments, Link)
- Location
- EU and USA
- Role
- Independent controller
Supabase, Vercel and Stripe are based in the USA. Where data is transferred to the USA, we rely on the adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses.
How long we keep data
We keep your data as long as you have your account. If you delete your account, we delete your account, your vault with all versions and your connections – except data we must keep longer for legal reasons; we restrict that data until the period expires.
Until you can delete your account yourself in the app, just email us at hello@whyvault.io or post@ohrlaf.com.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20) – for the latter, you can export your vault yourself at any time. Where we process data based on our legitimate interest, you can object on grounds relating to your particular situation (Art. 21).
Just write to us at hello@whyvault.io or post@ohrlaf.com.
You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de
We do not make automated decisions within the meaning of Art. 22 GDPR.
Changes
We update this privacy policy when WhyVault or the legal situation changes. The version published here applies.