Privacy Policy
Effective date: July 26, 2026
This Privacy Policy explains what information Recovery Vault AI collects, how it is used, and the limited third parties that help us operate the service. This policy describes the current Founding Member Beta implementation. If you have questions, contact recoveryvault.ai@gmail.com.
1. Information we collect
- Account data: first name, last name, email address, phone number, and a hashed password.
- Recovery-interview and profile data: disaster type, phase, state/county, occupancy, insurance status, dates, and other answers you enter during onboarding or edit later.
- Property and inventory data: property records, room notes, and item descriptions you add to the Property Inventory (a paid feature).
- Documents and evidence: files you upload to the Evidence Vault (photos, receipts, PDFs) and any drafts you create in the Document Writer.
- Recovery Passport fields: sensitive identifiers you choose to store (for example policy numbers) are stored encrypted at rest.
- Billing data: subscription status, plan, renewal dates, refund/dispute audit entries. We do not store your payment card number. Card details are collected and stored by Stripe.
- Consent records: the versions of Terms, Privacy, and Refund Policy you accepted and the UTC timestamp.
- Technical and log data: authentication cookies, request logs, IP addresses (short-lived), device/user-agent information, and error traces used to diagnose and improve the service.
2. How we use your information
- To operate the service: authenticate you, save your recovery plan, generate deterministic document drafts, export Recovery Packet PDFs, run the Evidence Vault, and produce Dashboard summaries.
- To process paid subscriptions (via Stripe) and to send transactional emails such as password resets.
- To keep the service secure and to investigate abuse or fraud.
- To communicate with you about your account, service changes, and support requests.
We do not use your personal recovery data to train AI models, and we do not sell your personal information. AI-assisted suggestions currently rendered in the Dashboard are generated from the answers you have already given us; features labeled Coming soon (Recovery Circle, AI Recovery Assistant, AI drafting) are not enabled.
3. Service providers we use
- Emergent: application hosting and preview/production infrastructure.
- MongoDB: primary database.
- Stripe: subscription billing, checkout, and customer portal. Card data is entered on Stripe’s pages and stored by Stripe.
- Resend: transactional email delivery (password reset and account notifications).
- Cloudflare: DNS, edge TLS termination, and www→apex redirect for recoveryvault.ai.
- Google Trust Services: TLS certificate issuance.
4. Cookies and authentication
We use one server-set, HTTP-only, Secure, SameSite=Lax cookie to keep you signed in. It contains a signed session token — no personal information is stored in the cookie itself. We do not use third-party advertising cookies.
5. Retention
Your account data and recovery content are retained while your account exists. Billing audit records (refunds, disputes, payment failures) are retained for at least seven (7) years to satisfy financial record-keeping expectations. If you delete your account, we will remove your recovery content and associated files within a reasonable period, subject to lawful record-keeping obligations.
6. Your choices and rights
You may access and update most of your data from within the app (Profile, Settings, Passport, Vault). To request export or deletion of your account and data, email recoveryvault.ai@gmail.com. Depending on your jurisdiction, you may have additional rights (for example under the California CCPA or the EU GDPR) — we will honor lawful requests where they apply.
7. Security
We use industry-standard practices: HTTPS everywhere, HTTP-only session cookies, hashed passwords, encryption at rest for designated Passport fields, and access controls. We do not claim HIPAA compliance, government endorsement, or absolute security. No online service can be made completely immune to attack. If a security incident affects your data, we will notify you as required by applicable law.
8. Children
Recovery Vault AI is not directed to children under 13. Do not create an account or upload information about minors without appropriate consent. If we learn that we have collected personal information from a child under 13 without parental consent, we will delete it.
9. Changes to this policy
We will update this policy as the service evolves. Material changes will be announced in-app and by a new effective date. You may be asked to re-consent to the updated policy before continuing to use paid features.
Contact: recoveryvault.ai@gmail.com