THE VAULT FX
Trust & Security

How we protect your account and data

This page is maintained by the team behind The Vault FX to answer common security and privacy questions. It is editable project content and is not an independent certification or audit.

Accounts & access

Accounts are protected by email and password sign-in. Each request is authenticated server-side before any account data is returned, and administrative actions are restricted to a separate admin role rather than being inferred from the client.

You can reset your password at any time from the sign-in screen. We recommend using a unique, strong password and keeping the email on your account up to date.

Data in transit & at rest

Traffic between your device and our servers is encrypted in transit over HTTPS/TLS. Account data, bot sessions, deposits, withdrawals, and referral records are stored in our managed backend with row-level access rules so that each user can only read and modify their own data.

Proof-of-deposit uploads are kept in a private storage bucket. They are not publicly browsable and are only viewed by admins during transaction review.

What we collect and why

We collect the information you provide when you register (such as display name, email, optional phone number, and an optional referral code), and the records needed to operate the service: deposits, withdrawals, bot sessions, referral earnings, and support tickets.

We do not sell personal information. Data is used to run your account, process transactions, calculate referral bonuses, provide support, and send service emails related to your activity.

Hosting & subprocessors

The Vault FX is hosted on the Lovable platform, which provides our application runtime, managed database, authentication, and file storage. Describing an underlying platform capability is not a claim of certification by that platform.

If we add additional subprocessors (for example, an email delivery provider or analytics tool), we will update this page.

Shared responsibility

Security is shared. We are responsible for the application's access rules, server-side validation, and how we handle the data you give us. You are responsible for keeping your password confidential, securing the email account tied to your login, and reviewing the wallet addresses and amounts you submit for deposits and withdrawals before confirming them.

Reporting a security concern

If you believe you have found a security issue, or you notice suspicious activity on your account, please open a support ticket from inside the app. Include a clear description and steps to reproduce when possible. We will review every report and respond as soon as we can.

Last updated: July 28, 2026.