Privacy Policy
Last updated: 2026-08-26
Who we are
VaultMail is an encrypted email and file sharing service operated by Spriggan AI, Inc. (“we”, “us”, or “VaultMail”). This policy explains what information VaultMail collects, how we use it, and how we protect it — including Protected Health Information (PHI) under HIPAA.
HIPAA & Business Associate Agreement
VaultMail is designed to handle Protected Health Information (PHI) under the HIPAA Security Rule. When you sign a Business Associate Agreement (BAA) with Spriggan AI, VaultMail acts as your Business Associate for any PHI you transmit or store through the service. Our infrastructure runs on Google Cloud Platform under a signed GCP Business Associate Agreement.
To request a BAA, email support@spriggan.ai.
Information we collect
Account information
- Email address (for authentication and audit logging)
- Display name (from your OAuth provider, if provided)
- Authentication provider (Google, Microsoft Entra ID, or email)
- Account creation timestamp
Content you encrypt
- Files and messages you submit for encryption. They are transmitted to us over TLS 1.3, encrypted with AES-256-GCM on receipt under keys we manage, and stored only as ciphertext — plaintext is never written to disk. We do not access plaintext except as necessary to provide the service, and object access is recorded in the audit log.
- Metadata about the encrypted object: original filename, size, MIME type, sender email, intended recipient emails, expiration time, and forwarding policy.
Audit log
- Every encryption, decryption attempt, access grant, access denial, and revocation is recorded with:
- Timestamp (UTC)
- Object identifier
- Accessor email
- Action type
- IP address and User-Agent (for security monitoring)
- Outcome (success, unauthorized, expired, revoked)
HIPAA §164.312(b) requires this audit log. On the Vault Ledger plan it is retained for a minimum of six years; on all other plans audit and metadata records are purged together with the content at thirty (30) days.
What we do NOT collect
- Plaintext content at rest (content is encrypted on receipt and stored only as ciphertext)
- Email subject lines (they stay with your email provider and never reach VaultMail)
- Mail you send with encryption off (it never reaches VaultMail at all)
- Behavioral analytics or tracking pixels
- Cross-site tracking cookies
- Marketing cookies
User-controlled encryption
Encryption is applied only to content you submit to VaultMail. The browser extension’s Auto-encrypt toggle can be turned off — that choice persists across messages until you change it — and mail sent with encryption off travels as ordinary email through your provider and is never received by us. In attachments-only mode, only the attached files reach VaultMail; your written message is sent as normal email by your provider. Email subject lines are never encrypted and never reach VaultMail in any mode.
How we use information
- To authenticate users and enforce access controls
- To deliver encrypted content only to the recipients you specify
- To generate audit logs required by HIPAA §164.312(b)
- To send transactional email (magic link sign-in, password resets if applicable)
- To detect and respond to security incidents (rate limiting, brute force protection)
- To comply with legal obligations
We do not sell or rent personal information. We do not share PHI with third parties except sub-processors listed below under a signed BAA.
Sub-processors
VaultMail uses the following sub-processors, each under a signed Business Associate Agreement where PHI may be involved:
- Google Cloud Platform — compute (Cloud Run), storage (Cloud Storage), secrets (Secret Manager), identity (Identity Platform). GCP BAA in place.
- Google Workspace — OAuth sign-in (Google)
- Microsoft Entra ID — OAuth sign-in (Microsoft)
All sub-processors are contractually bound to equivalent or stricter privacy and security obligations.
How we protect your data
Encryption
- At rest: AES-256-GCM with per-object Data Encryption Keys (DEKs), wrapped with per-user Key Encryption Keys (KEKs) via AES Key Wrap.
- In transit: TLS 1.3 enforced. HSTS preload.
- Key management: Master key in Google Secret Manager, access scoped to a dedicated service account.
Access controls
- Recipient allowlists enforced server-side on every decrypt request
- OAuth-based authentication (no password storage for PHI access)
- 15-minute automatic session timeout (§164.312(a)(2)(iii))
- Rate limiting on authentication and encryption endpoints
Integrity & monitoring
- AES-GCM authentication tags detect any tampering with ciphertext
- Immutable audit log with tamper detection
- Incident response plan with 24-hour breach notification
Data retention & deletion
Encrypted content is cryptographically destroyed no later than thirty (30) days after creation, or sooner if you set a shorter expiration, revoke it, delete it, or delete your account.
On the Vault Ledger plan, audit log records are retained for a minimum of six years to comply with HIPAA §164.530(j); on all other plans they are purged with the content at thirty (30) days.
You may request deletion of your account at any time by emailing support@spriggan.ai. We will delete your personal data and encrypted objects within 30 days. Audit log records covering you may be retained for the six-year HIPAA minimum.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate information
- Request deletion of your data
- Request a copy of your audit log
- Object to certain processing
- If you are a patient whose PHI was shared via VaultMail by a covered entity, your rights under HIPAA (access, amendment, accounting of disclosures) apply through that covered entity.
To exercise any of these rights, email support@spriggan.ai.
Chrome extension
The VaultMail Chrome extension integrates the same service directly into Gmail and Outlook Web. Its content scripts run on those mail sites to provide the compose-window integration. Specifically, the extension:
- Adds an “Encrypt & Send” button and encryption controls (Auto-encrypt toggle, encryption scope) to compose windows
- When Auto-encrypt is ON, intercepts files you attach, paste, or drop into a compose window so they are encrypted by VaultMail instead of uploaded to your mail provider
- When you click Encrypt & Send, transmits the message text (unless you selected attachments-only), the attached files, and the recipient addresses to vaultmailapp.com over TLS for encryption, then replaces or amends the compose body with a secure link
- Reads recipient fields and the signed-in account email from the mail page to build the recipient allowlist and check sender identity
- Stores your preferences (e.g., the Auto-encrypt toggle) in Chrome local storage
- Makes authenticated API calls to vaultmailapp.com with your existing session
Mail you send with Auto-encrypt OFF is never transmitted to VaultMail. The extension does not contain any analytics, telemetry, or remote code. It does not read or modify websites other than the supported mail clients.
Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email to registered users at least 30 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision.
Contact us
For privacy questions, HIPAA & BAA requests, or security incidents, email us at support@spriggan.ai