FerrVault
FeaturesWhy FerrVaultPricingChangelogDocs
ENFR
Waitlist→

Legal document

Privacy policy: FerrVault

Last updated: May 6, 2026

This policy describes the personal data collected by FerrLabs (Bryan Ferrando, sole proprietor, SIREN 104 243 951) acting as data controller for the FerrVault service, in accordance with the GDPR.

Encryption architecture

FerrVault encrypts your secrets client-side before any transmission to our servers (end-to-end encryption: the data encryption key (DEK) is derived from your master password and is never transmitted in clear text to FerrLabs). FerrVault servers store encrypted data only. FerrLabs cannot technically read the contents of your secrets. Key encryption keys (KEKs) are managed by Google Cloud KMS under our GCP tenant, in the EU region eu-west1. Consequence: if you forget your master password, your secrets are unrecoverable. This is by design.

Data collected

  • Account: email address, master password (never stored: only a verifier derived via Argon2id), display name, timezone, locale.
  • Organization: name, slug, team size, country.
  • Vaults and secrets metadata: vault name, slug, description, owner, members, role assignments. Secret name, version history, last rotation timestamp. The encrypted secret content (opaque ciphertext to FerrLabs).
  • Audit log: every secret access (read, write, rotation, share) with actor, IP address, user-agent, timestamp.
  • Cookies: fl_session (httpOnly, SameSite=Lax, 7-day lifetime), strictly necessary for authentication.
  • Server logs: 30-day retention.

Purposes

  • Authentication and access to the service.
  • Storage and synchronization of your encrypted secrets.
  • Operation, integrity and security of the platform (audit log, abuse detection).
  • Billing of paid subscriptions.
  • Compliance with legal obligations.

Legal bases (GDPR art. 6)

  • Performance of the contract (6.1.b) for accounts, vaults and subscriptions.
  • Legitimate interest (6.1.f) for security, audit log and server logs.
  • Legal obligation (6.1.c) for accounting and tax data.

Sub-processors

  • OVH SAS: primary hosting (France).
  • Google Cloud Platform: Cloud KMS for key wrapping (KEK custody), EU region eu-west1. KMS holds wrapping keys only; encrypted secret content is never sent to GCP.
  • Stripe Inc.: payments (United States, certified under the Data Privacy Framework), active when a paid subscription is activated.
  • Resend: transactional emails, active when transactional emails are sent.

Audit log

FerrVault records every access to a secret in an append-only audit log: actor (user or service token), source IP address, user-agent, timestamp, action (read, write, rotation, share), and the affected secret reference. The audit log records metadata only: never the plaintext content of the secret, which FerrLabs cannot decrypt server-side.

Retention: 90 days, after which entries are purged.

Retention period

DataRetention
Active account, vaults, encrypted secrets For the lifetime of the workspace
Deleted account or workspace30 days, then permanent purge
Audit log90 days
Server logs30 days
Billing data 10 years (art. L.123-22 of the French Commercial Code)

Your rights

Under the GDPR, you have the rights of access, rectification, erasure, portability, objection, and restriction of processing. Important: the right of access only applies to metadata (account details, vault names, audit log entries). It does not extend to the encrypted content of your secrets, which FerrLabs cannot decrypt. Only you, as the holder of the master password, can produce the plaintext.

To exercise your rights: privacy@ferrlabs.com.

You may also lodge a complaint with the CNIL (cnil.fr).

Data Protection Officer (DPO)

FerrLabs has not appointed a DPO. This is not required for a sole proprietorship that does not carry out large-scale processing of sensitive data (GDPR art. 37).

Transfers outside the European Union

Where applicable, transfers occur to sub-processors located in countries with an adequacy decision or certified under the Data Privacy Framework (Stripe Inc., United States). The primary data store (OVH) and key custody (Google Cloud KMS) are both located in the European Union.

Changes

This policy may be updated. The date of the last revision is shown at the top of this page.

FerrVault

Secrets management for product teams. EU-hosted, audited.

← Back to ferrlabs.com
Products
  • FerrVault
  • FerrFlow
  • FerrTrack
  • FerrGrowth
  • FerrFleet
  • FerrLens
Resources
  • Changelog
  • Docs
  • RSS
  • GitHub
Legal
  • Legal notice
  • Privacy
  • Terms
  • Cookies
  • DPA
  • Subprocessors
  • Security
© 2026 FerrLabs. FerrVault is a FerrLabs product.Set in Fraunces, hand-built in Lille, FR