Privacy Policy
Effective July 12, 2026 · Code Vault (thevault.codes)
What Code Vault does
Code Vault gives you a private forwarding address. Emails you choose to send to that address are processed to extract discount codes, which are stored in your personal vault and shown to you at matching stores by our browser extension.
What we collect
- Your account email — used to sign you in (one-time codes; we never store passwords because none exist).
- Emails you forward to your vault address — processed immediately to extract structured code details. The email body is deleted as soon as extraction finishes and is never written to our database. We keep only: sender, subject line, and the time received.
- Extracted code details — merchant name and domain, the code, discount amount, expiration date, and conditions. Visible only to your account.
- Product telemetry — whether a code fill succeeded at checkout, application errors, and bug reports you choose to send. Bug reports include diagnostic state (sync status, recent activity log) but never email content or your codes' values beyond what you type.
- Payments — if you subscribe, payment is handled by Stripe; we never see or store card numbers.
What we never do
- We never connect to, read, or request access to your email inbox. There is no OAuth grant, ever — you forward mail to us, not the other way around.
- We never store email bodies.
- We never sell or share your data with advertisers or data brokers.
- We never crowd-source your codes to other users. Your codes are yours.
- The extension never tracks your browsing: it checks the current site against a code list stored on your device, and does nothing at all on sites where you hold no codes.
The browser extension, specifically
The extension asks for access to web pages for exactly one purpose: to check whether the site you're on matches a store in your vault, using a list synced to your device. On a match, it shows your codes and can fill one into the promo field when you click. On every other site it renders nothing, records nothing, and sends nothing.
Service providers
We use a small set of processors to run the service: Supabase (database and sign-in), Postmark (receiving forwarded email and sending sign-in codes), Anthropic (AI processing of forwarded emails to extract codes — content is processed transiently and not used to train models), Netlify (hosting), and Stripe (payments, when billing launches). Each receives only what it needs to do its job.
Retention
- Codes and vault data: kept until you delete them or your account.
- Email receipt records (sender/subject/time): 90 days.
- Diagnostic events and bug reports: 60 days.
Your choices
You can delete any code from your vault at any time. To delete your account and everything in it, email us — removal cascades through all stored data. You can stop all inbound processing instantly by removing your forwarding rule; we only ever receive what you send.
Contact
Questions or deletion requests: olivia@keiterandco.com
We'll update this policy as the product grows and note the effective date above when we do.