Privacy Policy
Last updated: July 27, 2026
VaultAlts is an unofficial fan made companion app for World of Warcraft players. This Privacy Policy explains how we collect, use, and protect your data.
1. Information We Collect
When you use VaultAlts, we collect:
- Email address (for account login)
- Battle.net OAuth token (only with your consent, used to read your WoW character data)
- Character data from Blizzard's public API (item level, vault progress, achievements, and so on)
- Optional push notification token
- Subscription data, if you buy VaultAlts Premium: a RevenueCat customer id stored on your account, whether the subscription is currently active, and when the paid period ends. Payment itself is handled by the store, so your card details never reach us.
- Anonymous error reports (via Sentry) to fix bugs
2. How We Use Your Data
Your data is used solely to:
- Display your character information in the app
- Send notifications you have enabled (reset reminders, vault alerts)
- Improve app stability via crash reports
We never sell your data to third parties.
3. Data Storage and Retention
Your data is stored on Supabase (EU region, hosted in Frankfurt, Germany). Battle.net OAuth tokens are kept on access controlled servers and never shared with third parties.
- Active accounts: data is retained as long as your account exists.
- After deletion: deleting your account deletes your data at once, not on a schedule. The delete runs from your login outward through every table that hangs off it, so your characters, weekly rows, Mythic+ runs, PvP rows and stored tokens all go in the same operation. Anonymous aggregate analytics may be kept up to 90 days for service health monitoring and fraud prevention.
- Backups: automated database backups are retained for 7 days, then deleted. This is the one place a copy of a deleted account can outlive the deletion, and never by more than those 7 days.
- Push notification token: cleared the moment you sign out or delete your account. If you uninstall the app, it is cleared automatically as soon as the next notification to that device comes back undeliverable. Turning individual notification types off in Settings stops those notifications but leaves the token in place.
- Battle.net OAuth tokens: deleted the moment you disconnect Battle.net or delete your account.
- Crash reports (Sentry): sent with no account identifier attached, so a report is not tied to your account, and kept by Sentry under its own retention schedule.
You can delete your account and all associated data at any time from Settings, then Delete Account.
4. Third Party Services
We use these services to operate the app. Each has its own privacy policy.
- Blizzard / Battle.net API. Reads your WoW character data with your consent (privacy.blizzard.com)
- Supabase. Database, authentication, file storage. Hosted in EU. (supabase.com/privacy)
- Railway. Backend server hosting. (railway.app/legal/privacy)
- Vercel. Hosting for this website, and Vercel's own cookieless analytics on it, which counts page views and records the page, the site you arrived from, your country and the type of device and browser. Every page here loads it, including this one. It sets no cookie and builds no profile of you, and it is the website only: the mobile app makes no request to Vercel. (vercel.com/legal/privacy-policy)
- Sentry. Anonymous error monitoring (no personal data in stack traces). (sentry.io/privacy)
- Expo Push. Push notification delivery (push token only). (expo.dev/privacy)
- RevenueCat. Subscription management for VaultAlts Premium. Receives your account identifier and the state of your purchase, so the app can tell whether a subscription is active, and returns a customer id we store on your account. (revenuecat.com/privacy)
- Google AdMob. Banner and full screen ad delivery in the ad supported app. Banners sit on the dashboard, the tools tab and the character sheet; the full screen ad can appear when you open a character from the dashboard, and it is capped at one every two minutes and five in any hour. Ads stop as soon as the app has confirmed that Premium is active, so a subscriber sees none in normal use; on a fresh install that check lands a moment after the first screen, and a single ad can be requested before it does. May use the device advertising ID to personalise ads, which you control through the first launch prompts, through your device advertising settings, and, wherever the Google consent form applies, through the Ad Privacy Options row in Settings. Section 5 sets that out in full. (policies.google.com/privacy)
We do not sell, rent, or share your personal data with any other third parties.
5. Cookies, Local Storage and Ad Tracking
The mobile app uses on device storage (AsyncStorage / SecureStore) to:
- Remember your login session
- Cache character data for offline viewing
- Store your preferences (notifications, haptics)
None of that storage is used to profile you, and VaultAlts sets no advertising cookies of its own and follows you into no other app.
On this website the picture is just as short. Signing in at vaultalts.com keeps your session in your browser's own storage, the page view counting named in section 4 sets no cookie, and there are no advertising cookies and no advertising scripts here at all.
Advertising in the app is the exception, and it works as set out in section 4. While the ad supported app is serving ads, Google AdMob may read the device advertising identifier and personalise the ads you see, and that personalisation can draw on your activity in other apps and on the web. The identifier is used by Google, not by us, and it never reaches our servers. The app asks first, in this order, and starts Google's ads SDK after it:
- On iOS. Apple's App Tracking Transparency prompt is shown first, and declining it withholds the advertising identifier from AdMob.
- Where local law requires it, such as the EU and the UK. Google's certified consent form asks separately, and your answer decides whether the ads you see are personalised.
- Everywhere else. Personalisation follows your device advertising settings.
One qualification, because an absolute promise here would not be true. A question that cannot be put to you still has to end somewhere, and in this app it ends in ads rather than in an app that stops earning: if the consent check fails or times out, if that part of Google's software is missing from the build, or if Google publishes no consent form for your region, ads are requested anyway. What never happens is an answer being invented for you. Personalisation still follows whatever you have already answered on an earlier launch and whatever your device advertising settings say, and on iOS a tracking prompt you have not accepted keeps the advertising identifier away from AdMob. The one case where every ad is held back is the case that counts: when Google's form has told the app that consent is required where you are and you have not given it, no ad is requested at all until you answer, either from Ad Privacy Options or the next time you open the app.
You can change your answer at any time, with the same effort it took to give it. Wherever the Google consent form applies, the app carries an Ad Privacy Options row in Settings, under Legal, and that row reopens the form. Your device settings work anywhere: on iOS, Settings, then Privacy and Security, then Tracking; on Android, Settings, then Google, then Ads. Withdrawing consent does not remove ads, it makes them non personalised.
VaultAlts Premium is what removes ads outright. Once the app has confirmed Premium is active it requests no ads, asks no consent question and reads no advertising identifier. If you answered the Google consent form before you subscribed, the Ad Privacy Options row stays where it is, so you can still change or withdraw that answer; if you never answered it, there is nothing to reopen and no row appears. On a fresh install the Premium check lands a moment after the first screen, exactly as described in section 4.
6. Your Rights (GDPR, CCPA)
If you reside in the EU, UK, or California, you have the right to:
- Access: view all data we hold (visible in app, or use Settings, then Export My Data, for a JSON dump).
- Rectification: correct inaccurate data (in Settings or by contacting support).
- Erasure (the right to be forgotten): Settings, then Delete Account.
- Portability: Export My Data returns a machine readable JSON of your data.
- Object to processing: disconnect Battle.net, disable notifications, opt out of personalized ads (Settings, then Ad Privacy Options, wherever the Google consent form applies, and your device advertising settings anywhere).
- Withdraw consent: any time, with the same effort as giving it.
To exercise these rights, contact support@vaultalts.com. We respond within 30 days.
7. Children's Privacy
VaultAlts is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from minors below those ages. If you believe a child has created an account, contact us at support@vaultalts.com and we will delete it immediately.
8. Security
We use HTTPS for all network traffic. Passwords are hashed with industry standard algorithms (bcrypt via Supabase Auth). Battle.net OAuth tokens are kept on access controlled servers, scoped read only (wow.profile), and can be revoked at any time via account.battle.net, then Connections. Despite our efforts, no online service is fully secure, so please use a strong, unique password.
9. International Data Transfers
Your data may be processed in the EU (Supabase) and the US (AdMob, Sentry, RevenueCat, and Vercel for this website). Where data crosses borders, we rely on Standard Contractual Clauses approved by the European Commission to protect your data.
10. Changes to This Policy
We may update this policy occasionally, and the date at the top of this page is always the version in force. When a change affects how we handle data we already hold, we announce it via in app notification or email, and it takes effect at least 14 days after that announcement. A change that only describes something you have to opt into before it touches you, such as a subscription you have not bought, or that only clarifies existing wording, applies from the day it is published.
11. Contact
For privacy questions, requests, or complaints: support@vaultalts.com. EU users may also lodge a complaint with their local data protection authority.
How to Delete Your VaultAlts Account
You can delete your VaultAlts account and all associated data at any time:
Option 1 · In app (instant)
- Open the VaultAlts app and sign in
- Go to the Settings tab
- Scroll to the bottom and tap Delete Account
- Confirm. Your account and all data are immediately and permanently removed.
Option 2 · By email (7 days)
Email support@vaultalts.com from the address registered to your account, with the subject Delete my account. We process all deletion requests within 7 days.
What gets deleted
- Email address and password hash
- Linked WoW characters and their sync history
- Weekly Great Vault progress, Mythic+ runs, PvP ratings, and the world boss and weekly quest rows
- Push notification token
- Battle.net OAuth token
What is retained
Aggregated, anonymized analytics events for 90 days, used solely for fraud prevention and service health monitoring. No personally identifiable information remains.
Trademark Notice
World of Warcraft® and Battle.net® are trademarks of Blizzard Entertainment, Inc. VaultAlts is an unofficial fan made companion app and is not affiliated with, endorsed, sponsored, or specifically approved by Blizzard Entertainment.