Last updated: March 2026 ยท Effective: March 2026
๐ ClientVault encrypts all credentials with AES-256-GCM before storing them. We never store passwords in plain text and we never sell your data.
ClientVault is a credential management tool built for Chartered Accountant firms in India. It is operated by ClientVault ("we", "our", "us"). For questions, contact us at privacy@clientvault.in.
Account information: When you sign up, we collect your name, email address, and firm name.
Client credentials: Usernames and passwords you store for your clients' government portals. These are encrypted with AES-256-GCM using keys derived from your account before being written to our database. We cannot read them.
Usage data: Autofill events (which portal, which client, when) are logged for your firm's audit trail. This data is only visible to your firm's owner and admins.
Technical data: Browser type, IP address, and error logs collected automatically for security and debugging.
We do not use your data for advertising or sell it to third parties.
All data is stored on Google Cloud (Firebase/Firestore) in the asia-south1 (Mumbai) region.
Client credentials are encrypted client-side with AES-256-GCM before transmission. Encryption keys are derived from your Firebase Auth token and never stored in plain form on our servers.
Access to your firm's data is protected by Firestore security rules โ only authenticated members of your firm can read or write your data.
We share data only with the following sub-processors, strictly to deliver the service:
We never sell, rent, or share your data with any other party.
Your data is retained for as long as your account is active. If you delete your account, all firm data including encrypted credentials and audit logs will be permanently deleted within 30 days.
Audit logs on the Free plan are retained for 1 day. Pro and Enterprise plans retain full history.
To exercise any of these rights, email privacy@clientvault.in.
We use only essential cookies required for authentication (Firebase Auth session). We do not use tracking or advertising cookies.
We may update this policy as the product evolves. We will notify you by email and by posting a notice in the app at least 14 days before material changes take effect.
For privacy questions or data requests: