Privacy Policy
Total Vault (the “Service”) is operated by Total Weddings LLC (“we”, “us”). This page describes what we collect about you, how we use it, and the choices you have.
1. Who this applies to
This policy covers anyone who signs in to or uploads files through Total Vault. If you’re a guest using a scoped upload link — a second shooter, a client, a family member — the customer who invited you is the controller of the resulting data; we process it on their behalf under the same protections described here.
2. What we collect
We collect three categories of information:
Account information. Your email address (used as your identifier), an optional display name and avatar image, your role within an organization, the date you joined, and timestamps recording when you last signed in. Depending on how you sign in, we also store a password hash (if you set a password), the identity details returned by Google or Microsoft single sign-on (your subject identifier, email, and name), short-lived two-factor codes, and a hashed token for any device you ask us to remember.
Content you upload.The files you put in Total Vault — photos, videos, RAWs, and anything else you choose to store — along with their filenames, sizes, MIME types, and any embedded metadata (EXIF, capture time, camera, lens, ISO, GPS). We also keep a cryptographic checksum, computed in your browser at upload, which we use to confirm the file arrived intact and to keep double-checking it over time. To power browsing and search, we store data we derive from your visual files — thumbnails, auto-generated tags, a short caption, any text we can read in the image, and a numeric “embedding” used for similarity search.
Activity data.A record of actions you take in the Service: uploads completed, files moved or renamed, folders created or trashed, files double-checked, shares created, and the natural-language search queries you type. We retain a per-org audit log so administrators can answer “who did what when.”
3. What we don't collect
- Browser-fingerprinting data or third-party advertising identifiers. We don’t track you across other sites or build an ad profile.
- Plaintext passwords. If you set a password, we store only a salted, hashed form of it — never the password itself.
- File contents for AI training. Anthropic and Cohere are configured not to use your data to train their general models.
- Anything from minors. The Service is not intended for anyone under 18.
4. How we use it
- To operate the Service — store, retrieve, verify, search, and present your files.
- To send you transactional emails: sign-in verification codes and password-reset links, receipts and notifications when a project finishes processing, share invites you send, and security alerts about your account.
- To keep double-checking your files. When a file lands we confirm it arrived intact, then continuously monitor its storage-level integrity, and on a rolling schedule (and on demand) we re-read the file in full and re-compare its checksum to detect silent corruption or bitrot. Results are recorded on the file’s row.
- To generate derived assets — thumbnails, EXIF extracts, and AI embeddings — to power browsing and search. Only thumbnails and structured metadata are sent to AI providers; full-resolution originals never leave our storage.
- To diagnose problems, prevent abuse, and improve the Service in aggregate.
- To comply with legal obligations (subpoena, audit, tax records).
We do not use your data for advertising, profile-based marketing, or any purpose beyond providing the Service.
5. Where it lives
File contents are stored in Backblaze B2 (US data centers), with derived video assets on Cloudflare R2. The database that tracks file metadata, checksums, folders, and activity runs on Neon Postgres (US-East). The web application is hosted on Vercel (US edge with US-East origin). Background jobs run on Inngest. Email is sent via Resend.
A complete list of third parties we share data with, what they receive, and where they operate is on our subprocessors page. We update it whenever we add or remove a vendor.
6. Cookies and similar technologies
Total Vault uses only the cookies it needs to sign you in and keep you signed in. The main one is vault_session, which holds your signed session token; it’s HTTP-only, Secure in production, SameSite=Lax, and expires 30 days after sign-in. If you ask us to remember a device, we set a long-lived vault_devicecookie (also 30 days). During a Google/Microsoft sign-in or a cloud-import connection we set a few short-lived cookies (about 10 minutes) to keep the round-trip secure, then clear them. We also use your browser’s local storage to let an interrupted upload resume. We do not use third-party advertising or cross-site tracking cookies.
7. How long we keep it
- Active files stay in Total Vault as long as the owning organization’s account is open.
- Soft-deleted files (Trash) stay recoverable for 30 days before permanent deletion from both the database and Backblaze.
- Account and activity records are retained for the lifetime of the account and for up to 12 months after closure, then purged.
- Password-reset links expire 15 minutes after issue, and sign-in verification codes expire after 10 minutes; both are destroyed once used.
- Residual copies in our database provider’s point-in-time backup window expire automatically within that recovery window.
8. How we protect it
- Every file gets a cryptographic checksum in your browser before upload, and our storage provider confirms the bytes it received match it — so a file is double-checked the moment it lands. We also re-read files in full and re-compare the checksum on a rolling schedule to catch any later drift.
- Files are stored encrypted at rest in Backblaze B2, and all in-transit traffic uses TLS.
- Database access is over TLS to a per-environment Neon endpoint; credentials live in encrypted secrets and never in code.
- You sign in with your email and password plus a single-use code we email you, or with Google or Microsoft single sign-on. You can trust a device for 30 days to skip the emailed code on that browser. Any password is stored only in salted, hashed form.
- Access to your data inside our team is limited to staff who need it and is logged.
- If we ever detect that a file’s checksum no longer matches the one recorded at upload, we flag it, surface it prominently in your dashboard, and notify the account owner by email.
9. Your rights
You can ask us to:
- Access a copy of everything we hold about you, in machine-readable form.
- Correctinformation that’s wrong.
- Delete your account and the files associated with it. When you delete an account or workspace, we promptly remove the database rows and purge the file bytes from object storage in a background job; any residual copies in our backup window expire on their own shortly after.
- Exportyour files. You can download originals individually or, for whole projects, request a streaming ZIP. We don’t lock you in.
- Opt outof any AI-powered feature on a per-project basis (we’ll keep the metadata; we just won’t generate embeddings or tags for those files).
To exercise any of these, email support@totalvault.ai. We respond within 30 days; usually faster.
10. Sharing
We share your data only as needed to provide the Service: with the subprocessors listed on the subprocessors page, with people you explicitly invite (guests, members of your organization, share-link recipients), and where compelled by law. We will challenge any government request that appears overbroad. We will not sell, rent, or trade your data, ever.
11. International transfers
The Service operates from the United States. If you upload from outside the US, your data will be transferred to and stored in the US. We rely on standard contractual clauses with vendors who process EU/UK personal data on our behalf.
12. Changes to this policy
When this policy changes, we’ll update the “Effective” date at the top and email account owners if the changes are material. Older versions stay available on request. Continuing to use the Service after a change means you accept the new policy.
13. Google user data
When you connect a Google account to import files, you grant Total Vault read-only access to your Google Drive (the drive.readonly scope). We use that access solely to let you browse the folders and files in your Drive and to copy the items you choose into your vault. We never create, modify, or delete anything in your Google Drive, and we request read-only access for exactly this reason.
Total Vault’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, that means:
- We do not use Google user data for advertising.
- We do not sell, rent, or trade Google user data.
- We do not use Google user data to train generalized or non-personalized AI or machine-learning models.
- We transfer Google user data only as necessary to provide or improve the import feature you requested, to comply with applicable law, or as part of a merger or acquisition.
- No human reads your Google user data except where you give explicit consent, where it is necessary for security or to comply with applicable law, or in aggregated, anonymized form for internal operations.
Your OAuth refresh token is encrypted at rest. You can disconnect a connected Google account at any time, which revokes our access, and you can revoke it directly from your Google Account permissions page.
14. Contact
Questions about this policy, requests under it, or anything else: support@totalvault.ai.
