Privacy Policy

Last updated: 25 July 2026

This policy explains what personal data FeatherVault collects, why we collect it, and the rights you have over it.

Who we are

FeatherVault is operated by Brandon Flick, the data controller for the personal data described here.

5 Brayford SquareLondonE1 0SGUnited Kingdom

Data protection enquiries: privacy@feathervault.io

What we collect

Account data. Your name and email address, and a password (stored only as a hash) or, if you sign in with Google, GitHub, or Discord, the identifier and profile image that provider returns.

Connection settings. The panels and storage buckets you connect: names, URLs, regions, and bucket names. The API keys and storage credentials themselves are encrypted before they are stored and are never displayed back to you or exported.

Operational records. A history of your backup and restore runs — server names, timestamps, sizes, status, and any error message — plus your schedules and notification preferences.

Billing data. Your subscription status and the customer identifier assigned by our payment processor. Card details are collected by Stripe and never reach FeatherVault.

What we do not collect

We do not store the contents of your backups. Backups are written directly from your panel to a storage bucket you own and control. FeatherVault holds only the metadata and manifest needed to list and replay them. We cannot read your server files or databases.

We do not use analytics, advertising, or third-party tracking of any kind. There are no marketing cookies, no pixels, and no session recording. Web fonts are served from our own servers, so loading a page does not disclose your IP address to a font provider.

Why we use it, and our legal basis

To provide the service — creating your account, connecting your panels, running backups and restores, and sending the notifications you configure. Legal basis: performance of our contract with you (Art. 6(1)(b) UK/EU GDPR).

To take payment — managing subscriptions and issuing invoices. Legal basis: performance of a contract, and compliance with a legal obligation for tax and accounting records (Art. 6(1)(c)).

To keep the service secure and working — diagnosing failures, preventing abuse, and enforcing plan limits. Legal basis: our legitimate interests in operating a reliable service (Art. 6(1)(f)).

Cookies

FeatherVault sets only cookies that are strictly necessary to deliver the service you asked for, so no consent banner is required. We set no analytics or advertising cookies. Full details are on our cookie policy.

Who we share it with

We do not sell personal data or share it for advertising. We use a small number of processors who act on our instructions:

  • StripeSubscription payments, invoicing, and fraud prevention (United States / Ireland)
  • Hetzner Online GmbHHosting for the application, database, authentication service, and job runners (Germany (EU))

The current list, with the safeguards that apply to each, is on our sub-processors page. Note that the storage bucket you connect belongs to you: your provider is not our sub-processor, and your agreement with them governs it.

Where your data is stored

FeatherVault's application, database, and authentication service run on infrastructure located in Germany (EU). Where a processor transfers data outside the UK/EEA, that transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard.

How long we keep it

Account data is kept while your account is open. When you delete your account it is erased immediately.

Run history is kept for 90 days. After that, failed and cancelled runs are deleted, and successful runs have their diagnostic detail removed while the record needed to restore the backup is retained.

Billing records are retained by our payment processor for as long as tax and accounting law requires, which is why cancelling an account does not delete past invoices.

Backups in your own bucket are unaffected by any of this — their lifecycle is governed by the retention setting on your schedule and by your storage provider.

How we protect it

Panel API keys, storage credentials, and notification channel configuration are encrypted at rest with AES-256-GCM; they are decrypted only inside the isolated container that runs your job. Access to production systems is restricted, all traffic is served over TLS, and each backup or restore runs in a short-lived container that is destroyed when the job ends.

Your rights

Under UK/EU data protection law you have the right to access your data, correct it, erase it, restrict or object to how we use it, and receive it in a portable format.

Two of these are built into the product: you can download everything we hold about you, and delete your account outright, from Settings → Account. For anything else, email privacy@feathervault.io and we will respond within one month.

If you think we have handled your data improperly you can complain to the Information Commissioner's Office (ICO) (https://ico.org.uk), though we would appreciate the chance to put it right first.

Changes to this policy

If we make a material change we will update the date at the top of this page and notify account holders by email before it takes effect.