LEGAL

Privacy Policy

Effective: May 12, 2026 · Last updated: May 12, 2026

Contents

  1. What We Collect
  2. What We Do NOT Collect
  3. How We Use Your Data
  4. Third-Party Services
  5. Data Retention
  6. Cookies & Session Storage
  7. Security
  8. Your Rights (GDPR / CCPA)
  9. Contact

What We Collect

TuneVault collects the minimum data required to operate the service.

Category Data Why
Account Email address, name (from Google OAuth or magic-link sign-in) Authentication and communication
Connection metadata Oracle host/port, connection type, proxy URL Establishing database connections
Health check results Check scores, findings, AI analysis text Delivering diagnostic reports and trend tracking
Payment data Order ID, payment status, plan tier (via Razorpay) Subscription management
Usage analytics Page views, feature interactions, hashed IP Product improvement (no cross-site tracking)
Alert configuration Alert email addresses, severity thresholds, schedules Autonomous monitoring and notifications

What We Do NOT Collect

Oracle credentials are never stored in plaintext. Database usernames and passwords exist only in memory during an active connection and are immediately discarded. We never log, cache, or export raw database credentials.

How We Use Your Data

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

Third-Party Services

Service Purpose Data Shared
Razorpay Payment processing Payment amount, order ID (Razorpay handles card data directly)
Google OAuth Sign-in authentication Google profile email and name (with your consent)
Postmark / Polsia email proxy Transactional email (magic links, alerts, receipts) Your email address and alert content
OpenAI (via Polsia proxy) AI-generated summaries of health check results Anonymized check result data — no PII, no raw database content
Cloud Database Provider Database hosting All stored application data (hosted in their cloud)
Cloud Hosting Provider Application hosting Application logs and server telemetry

Each third party processes data under their own privacy policy. We select vendors that meet industry-standard security requirements.

Data Retention

Cookies & Session Storage

TuneVault uses minimal, functional cookies only:

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies (e.g., Google Analytics). No cookie consent banner is required for functional-only cookies under most regulatory frameworks.

Security

Security is core to TuneVault's purpose — we're trusted with access to production Oracle databases. We take that seriously:

For a full security overview, see our Security & Trust page.

Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the following rights:

Right GDPR (EU/UK) CCPA (California)
Access your data YES YES
Request deletion YES YES
Export your data YES YES
Correct inaccurate data YES YES
Opt out of sale N/A (we don't sell data) YES (we don't sell)
Lodge a complaint YES (with your supervisory authority) N/A

To exercise any of these rights, email privacy@tunevault.app. We will respond within 30 days. For account deletion, you may also delete your account directly from your account settings — data deletion follows within 30 days.

Contact

Privacy inquiries: privacy@tunevault.app

General contact: hello@tunevault.app

We may update this policy as the product evolves. Material changes will be communicated via email to registered users. The effective date at the top of this page reflects the latest revision.