Vaulty privacy policy

Effective Date: application release date

Vaulty player (hereinafter referred to as"This player") by its operator (hereinafter referred to as"We""We") to develop and provide services. We attach great importance to your personal information security and privacy rights, this policy is formulated in strict compliance with international data protection principles such as legality, fairness, transparency, purpose limitation, data minimization and integrity confidentiality (e.g. EU GDPR, U.S. CCPA/CPRA, etc.) . This policy sets out in detail how we collect, use, store, protect and transfer your personal information across borders and the rights you enjoy. Please read and fully understand this policy before using this player. You will be deemed to have read, understood and agreed to be bound by this policy if you use this player.

1. General

1.1 scope of Policy Application

1.1.1 this policy applies to all users (hereinafter referred to as"You") who access, download, install or use this player and related services worldwide, covers your data handling behavior when using the player to play local/cloud media files, manage playlists, set playback preferences, use subtitle services, and more.

1.1.2 this policy applies only to services provided by this player. If you use third-party services (such as third-party cloud storage, subtitle providers, advertising services, etc.) through this player, third party privacy policy will be applied separately, we do not assume the privacy liability of third party services.

1.2 policy update mechanism

1.2.1 we reserve the right to update this policy from time to time as required by changes in international data protection regulations, business operations adjustments, technological upgrades or service optimizations.

1.2.2 the updated policy will be posted on the official website (vaultyweb.com ) and will be marked"Last updated". If the content is related to your core rights and interests (such as the expansion of the scope of information collection, use purpose change, etc.) , we will inform you through the player pop-up window, official website announcement and other reasonable ways.

1.2.3 if you continue to use this player after the policy update, you will be deemed to fully understand and accept the revised terms and conditions in their entirety. If you do not accept the revised terms and conditions, you shall immediately cease to use this player and related services.

2. The scope and methods of collecting personal information

2.1 media broadcast and management of relevant information

2.1.1 local media information: for the purposes of playing and managing local media files, we will read your device's local storage media file metadata (such as file name, format, length, resolution, playback progress, cover image, etc.) after you've authorized it, by default, this kind of data is only stored in the local device, which is used to generate the media library list, remember the playback progress and realize the playback control.

2.1.2 play preference data: We'll collect your play setting information (such as volume, play speed, subtitle style, track selection, loop mode, etc.) and play history (such as played file name, play time, completion, etc.) , used to provide you with personalized playback experience and fast recovery playback state.

2.1.3 cloud media related information: if you are using a cloud media player or synchronization service, you need to provide authorization information for your cloud storage account (only for permission verification, no account password stored) , we will collect your authorized access to the cloud media metadata and playback progress, for the realization of cloud media playback and multi-device synchronization.

2.2 account and value-added services related information

2.2.1. Registration information: If You Register for an account and use value-added services, you will need to provide an e-mail address to identify your account and set a login password. We only collect the information necessary for account creation, identity verification and service synchronization.

2.2.2 payment information: if you purchase a payment service, we will collect your payment amount, payment time and other transaction information through a third-party payment channel (not directly collect sensitive payment information such as bank card number) , for settling transactions and providing invoices (if any) .

2.3 equipment and technology information

2.2.1 to ensure the stability, compatibility and security of the player, we automatically collect your device model, operating system version, CPU model, memory capacity, network type (e.g. WI-FI, 4G/5G) , IP address, unique device identifier (e.g. UUID) , player version number and usage log (e.g. crash log, function error message, load speed data) .

2.2.2 this type of data is non-identifying technical data that does not directly relate to the identity of the individual and is used only for technical analysis, troubleshooting and performance optimization.

2.4 collection principles

2.4.1 all information is collected in accordance with the principle of 'necessary minimization' . Only such information as is necessary for the purpose of the service is collected, and no personal information not related to the service is collected without reasonable excuse.

2.4.2 the collection of information relating to access to device storage, microphones (for voice control, if any) , etc. , will be explicitly sought from you prior to the use of the corresponding feature, and you may consent or deny it at your discretion, denying authorization only affects the usage of the corresponding function and does not affect the underlying playback service.

3. Purpose and manner of use of personal information

3.1 provision of core services

3.1.1 based on local media information, we provide you with basic services such as media file retrieval, playback control, playback progress memory, and media library management to ensure the fluency and convenience of local playback functions.

3.1.2 use play preference data to provide personalized play settings synchronization, play history query, recommend similar media content (if enabled) and other services to enhance the user experience.

3.1.3 value-added services such as cloud media playback, playlist synchronization, and verification of paid service rights and interests are implemented through account information and cloud media-related data.

3.2 service optimization and Security

3.2.1 analysis of anonymized and aggregated device and technology data and playback behavior data to optimize player loading speed, format compatibility, playback fluency, and interface operation logic.

3.2.2 use IP addresses, device information, and usage logs to detect abnormal logins, prevent malware attacks, identify and fix player vulnerabilities, and protect your account and device security.

3.3 compliance and notification purposes

3.3.1 send you the necessary service notifications via your registered email address, such as account security alerts, paid service expiration alerts, policy updates, etc. , you can unsubscribe from non-essential notices by setting up your account.

3.3.2 all use of information is strictly limited to the purposes of this policy statement and is not intended to be used beyond its intended purpose without your express consent, nor is it the sole basis for the use of personal information for automated decision-making.

4. Storage and protection of personal information

4.1 storage specifications

4.1.1. Local storage data: your local media metadata, playback preferences, local playback history, etc. are stored on your local device by default, under your control, and we do not actively upload them to the server.

4.1.2 cloud storage data: if you enable cloud services, your account information, cloud playlists, and synchronized playback preferences will be stored on a cloud server that complies with international security standards, the server location follows the data localization and cross-border transmission compliance requirements, and uses AES-256 encryption technology to ensure the security of data transmission and storage.

4.1.3 data retention period: account information stored in the cloud is retained for the duration of your account; data related to paid services is retained until 90 days after the service expires; Synchronized playback data is retained until 90 days after you voluntarily turn off the synchronization function or cancel your account (unless extended by law and regulations) ; device and technical information is retained for only 30 days.

4.1.4 when data expires beyond its retention period or service purpose, we will ensure that the data is no longer personally identifiable through permanent deletion, anonymisation or de-identification.

4.2 safety precautions

4.2.1 establishment of a multi-layered security protection system, including data encryption storage (especially account password, payment information and other sensitive data using separate encryption algorithm) , access classification control, real-time intrusion detection, regular security audit and other technical and management measures, protection against data leakage, tampering or loss.

4.2.2 severely restrict data access by authorizing access to user information only to essential personnel within their functions, who are required to sign strict confidentiality agreements and receive data protection training.

4.2.3 conduct regular security risk assessments and technical upgrades to fix player security vulnerabilities in a timely manner; in the event of security incidents such as data breaches, within 72 hours, we will notify the affected users and the relevant regulatory authorities (if applicable) and take remedial action to mitigate the risk.

5. Data Sharing, transfer and disclosure

5.1 data sharing rules

5.1.1 we will not sell, rent, or share your personal information with any third party without your express written consent.

5.1.2 when working with a third-party service provider (such as a cloud storage provider, a payment service provider, or a subtitle provider) , share only anonymized or aggregated data that is necessary to implement the service, and third parties are required to sign data-handling agreements that promise to comply with the same data-protection standards.

5.2 circumstances under which disclosure is permitted

5.2.1 information may be disclosed to the extent necessary to comply with applicable international laws and regulations, judicial decisions or administrative orders or in response to lawful inquiries by competent authorities.

5.2.2 to the extent reasonably necessary to protect your legitimate rights and interests, maintain the Order of your services, or respond to an emergency of public safety.

5.2.3 in order to protect the legitimate rights and interests of this player, relevant personal information may be transferred to the transferee in the event of a merger, acquisition, transfer of assets, or other change in the property rights of an enterprise, subject to the transferee's compliance with its duty to protect under this policy.

6. Cross-border data transmission

6.1 transmission principles

6.1.1 if you need to transfer your personal information to an offshore server for cloud synchronization, cross-border subtitle services, etc. , we will ensure compliance with cross-border data transfer requirements in the target region (E. G. Standard EU GDPR contract terms, US Privacy Shield framework, etc.) .

6.1.2 cross-border transmissions will be conducted with security safeguards such as encrypted transmission, signing of cross-border data processing agreements and selection of qualified offshore server providers to ensure that the level of data protection is not lower than the standard at the place of origin.

6.2 transparency statement

6.2.1 the name of the recipient of the cross-border data transmission, its location, purpose of transmission and security measures can be described in detail on the official website or by contacting customer service.

7. Users' rights and ways of exercising them

7.1 scope of core rights

7.1.1 access and query right: you can access your local playback history and preferences at any time through the"Settings-privacy and data" function in the player; Through the"Account center" to access the cloud synchronization data and account information.

7.1.2 rights of Correction and supplement: you may directly modify the email and password information associated with your account in the player, and edit and correct the data such as playback preferences. If you find errors in the cloud data, contact customer service to assist with corrections.

7.1.3 deletion and cancellation rights: you can delete your local playback history and clear your playback preferences through the in-player function; you can turn off the cloud synchronization function to stop data uploads, or apply for account cancellation through customer service, all personal information in the cloud will be permanently deleted after logoff (except for those required by laws and regulations) .

7.1.4. Revoke permissions: you can revoke permissions for device storage, microphones, etc. through the device's system settings or the"Permissions management" page in the player. Revoke permissions will only affect the use of the corresponding function, does not affect the underlying playback service.

7.1.5 data portability: you can export playlists, preferences and other data through the"Export data" function in the player. For cloud data, you can apply for a copy of your personal information from customer service, we will provide it in a common format, such as CSV.

7.2 mode of exercise of Rights

7.2.1 the above rights may be exercised autonomously by means of a function in the player or by sending an email to the contact mailbox to submit a written application, which requires the provision of valid authentication information.

7.2.2 upon receipt of the application, we will complete the verification and feedback the results within 15 working days; complex cases can be extended to 30 working days, and you will be informed in advance of the extension.

8. Third-party service announcements

8.1 this player may include the integration of third-party services (e.g. third-party cloud storage, subtitling services, advertising services, payment channels, etc.) with an independent privacy policy.

8.2 we are not responsible for the privacy practices, content, security or legality of third parties. You are required to view and comply with the privacy policies of third parties when using their services at your own risk.

8.3 we only perform security audits on access to third-party services and do not interfere with their internal data processing activities. You should carefully read the third-party's terms of service and privacy statement before authorizing the use of third-party services.

9. Protection of Minors

9.1 this player does not offer services to minors under the age of 18 and does not actively collect personal information of minors. If minor information is found to have been collected by mistake, it will be immediately stopped and permanently deleted.

9.213 minors between the ages of 13 and 18 must use this player with the guidance and express consent of their guardians, who are responsible for authorizing the use of the information. Guardians can contact us to help manage the broadcast data and account information of minors.

10. Contact Us

10.1 if you have questions about this policy, need to exercise your right to personal information, or report information security issues, you may contact us by:

10.1.1 pyretictech01solutions@outlook.com

10.1.2 official website: vaultyweb.com

10.2 we will give you a formal response within 15 working days of receiving your feedback to ensure that your complaint is properly addressed.