VaultMailVaultMail

Privacy Policy

Last updated: 2026-04-09

Who we are

VaultMail is an end-to-end encrypted file sharing service operated by Spriggan AI (“we”, “us”, or “VaultMail”). This policy explains what information VaultMail collects, how we use it, and how we protect it — including Protected Health Information (PHI) under HIPAA.

HIPAA & Business Associate Agreement

VaultMail is designed to handle Protected Health Information (PHI) under the HIPAA Security Rule. When you sign a Business Associate Agreement (BAA) with Spriggan AI, VaultMail acts as your Business Associate for any PHI you transmit or store through the service. Our infrastructure runs on Google Cloud Platform under a signed GCP Business Associate Agreement.

To request a BAA, email support@spriggan.ai.

Information we collect

Account information

  • Email address (for authentication and audit logging)
  • Display name (from your OAuth provider, if provided)
  • Authentication provider (Google, Microsoft Entra ID, or email)
  • Account creation timestamp

Content you encrypt

  • Files and messages you upload are encrypted client-bound with AES-256-GCM before they are stored. We cannot read the plaintext contents.
  • Metadata about the encrypted object: original filename, size, MIME type, sender email, intended recipient emails, expiration time, and forwarding policy.

Audit log

  • Every encryption, decryption attempt, access grant, access denial, and revocation is recorded with:
    • Timestamp (UTC)
    • Object identifier
    • Accessor email
    • Action type
    • IP address and User-Agent (for security monitoring)
    • Outcome (success, unauthorized, expired, revoked)

HIPAA §164.312(b) requires this audit log. We retain it for a minimum of six years.

What we do NOT collect

  • Plaintext file contents (we can only see ciphertext)
  • Plaintext message contents
  • Behavioral analytics or tracking pixels
  • Cross-site tracking cookies
  • Marketing cookies

How we use information

  • To authenticate users and enforce access controls
  • To deliver encrypted content only to the recipients you specify
  • To generate audit logs required by HIPAA §164.312(b)
  • To send transactional email (magic link sign-in, password resets if applicable)
  • To detect and respond to security incidents (rate limiting, brute force protection)
  • To comply with legal obligations

We do not sell or rent personal information. We do not share PHI with third parties except sub-processors listed below under a signed BAA.

Sub-processors

VaultMail uses the following sub-processors, each under a signed Business Associate Agreement where PHI may be involved:

  • Google Cloud Platform — compute (Cloud Run), storage (Cloud Storage), secrets (Secret Manager), identity (Identity Platform). GCP BAA in place.
  • Google Workspace — OAuth sign-in (Google)
  • Microsoft Entra ID — OAuth sign-in (Microsoft)

All sub-processors are contractually bound to equivalent or stricter privacy and security obligations.

How we protect your data

Encryption

  • At rest: AES-256-GCM with per-object Data Encryption Keys (DEKs), wrapped with per-user Key Encryption Keys (KEKs) via AES Key Wrap.
  • In transit: TLS 1.3 enforced. HSTS preload.
  • Key management: Master key in Google Secret Manager, access scoped to a dedicated service account.

Access controls

  • Recipient allowlists enforced server-side on every decrypt request
  • OAuth-based authentication (no password storage for PHI access)
  • 15-minute automatic session timeout (§164.312(a)(2)(iii))
  • Rate limiting on authentication and encryption endpoints

Integrity & monitoring

  • AES-GCM authentication tags detect any tampering with ciphertext
  • Immutable audit log with tamper detection
  • Incident response plan with 24-hour breach notification

Data retention & deletion

Encrypted objects are retained until (a) their expiration time passes, (b) you explicitly revoke them, or (c) you delete your account.

Audit log records are retained for a minimum of six years to comply with HIPAA §164.530(j).

You may request deletion of your account at any time by emailing support@spriggan.ai. We will delete your personal data and encrypted objects within 30 days. Audit log records covering you may be retained for the six-year HIPAA minimum.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information
  • Request deletion of your data
  • Request a copy of your audit log
  • Object to certain processing
  • If you are a patient whose PHI was shared via VaultMail by a covered entity, your rights under HIPAA (access, amendment, accounting of disclosures) apply through that covered entity.

To exercise any of these rights, email support@spriggan.ai.

Chrome extension

The VaultMail Chrome extension is an alternative interface to the same service. It does not collect any additional data beyond what the web application collects. Its permissions are scoped to:

  • Reading your current tab URL (to detect Gmail/Outlook Web and surface the “Pull from tab” option)
  • Reading recipient email fields from Gmail/Outlook Web compose windows (only when you explicitly click “Pull from tab”)
  • Inserting share links into Gmail/Outlook Web compose bodies (only when you click “Insert into this tab’s email”)
  • Storing your saved recipient groups in Chrome local storage (never transmitted to VaultMail servers)
  • Making authenticated API calls to vaultmailapp.com with your existing session cookie

The extension does not contain any analytics, telemetry, or remote code. It does not read or modify any other websites.

Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated via email to registered users at least 30 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision.

Contact us

For privacy questions, HIPAA & BAA requests, or security incidents, email us at support@spriggan.ai