← Back

Privacy Policy

Last Updated: 26 May 2026

1. Introduction

Welcome to Rune Vault (“we,” “our,” or “us”). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we look after your personal data when you use our application. Rune Vault is an independent third-party tool and is not affiliated with or endorsed by Jagex Ltd.

2. Data We Collect

We only collect data necessary to provide you with the best experience. This includes:

  • Account Information: If you create an account, we store your email address and securely hashed password (via Supabase, hosted in the EU).
  • App Data: Your created profiles, RuneScape username(s), item watchlists, portfolio quantities, and Grand Exchange trade history are securely synced to our cloud to provide cross-device support.
  • Subscription Status: Your account identifier (Supabase user UUID) and subscription entitlement status are shared with RevenueCat (see Section 5) to manage Pro access.
  • Feedback Submissions: When you voluntarily submit a bug report or suggestion, we attach your device platform, OS version, app version, and approximate portfolio size (item count and profile count) to help us reproduce and diagnose issues. This is disclosed in the feedback form before you submit.
  • Crash and Error Data: If the app crashes or encounters an unhandled error, diagnostic information is automatically sent to Sentry (see Section 5). This includes a stack trace, device model, OS version, and an anonymized session identifier. We do not intentionally include personally identifiable information in crash reports.
  • Product Analytics: We collect anonymized product usage events (e.g., app opens, portfolio exports, feature interactions) via PostHog (see Section 5). These events are linked to your Supabase user UUID so we can understand how features are used across sessions.

3. How We Use Your Data

We use your data solely to provide the services within the Rune Vault app, including syncing your portfolio across devices, calculating Grand Exchange margins, managing your subscription, and improving reliability and usability. We do not sell your personal data to third parties.

4. Legal Bases for Processing (EU / UK Users)

Under GDPR, we process your personal data on the following bases:

  • Contract performance — account data, app data, and subscription status are necessary to deliver the service you signed up for.
  • Legitimate interests — crash reporting and product analytics help us maintain and improve a reliable product. These interests are balanced against your privacy rights; the data is minimised and, where possible, anonymised.
  • Consent — feedback submissions are voluntary and include an in-form disclosure of the metadata attached.

5. Third-Party Data Processors

We use the following sub-processors. Each receives only the data described and is bound by their own privacy programme.

Supabase

Our primary database and authentication provider. Stores account credentials, app data, and feedback submissions. Data is hosted in the EU (eu-west-1). Privacy policy: supabase.com/privacy.

Sentry (crash reporting)

Receives crash diagnostics when an unhandled error occurs: stack trace, device model, OS version, app version, and an anonymized session ID. Your IP address may be transiently processed by Sentry's ingestion pipeline but is not stored in the event payload. Sentry servers are located in the United States. To opt out of crash reporting, you can uninstall the app. Privacy policy: sentry.io/privacy.

PostHog (product analytics)

Receives anonymized product usage events linked to your Supabase user UUID (not your email). Events include actions such as app opens, portfolio exports, and feature interactions — no free-text content or item names are sent. Our PostHog instance is hosted in the EU (EU Cloud). To opt out of analytics, you can uninstall the app. Privacy policy: posthog.com/privacy.

RevenueCat (subscription management)

Receives your Supabase user UUID and subscription entitlement status to manage Pro access across platforms. RevenueCat servers are located in the United States. RevenueCat does not receive your email address or portfolio data. Privacy policy: revenuecat.com/privacy.

6. Data Retention and International Transfers

Account and app data is retained for as long as your account exists. Crash reports in Sentry and analytics events in PostHog are retained per each processor's default retention policy (typically 90 days). Feedback submissions are retained indefinitely to track recurring issues but contain no sensitive personal data beyond what you choose to write.

Sentry and RevenueCat are based in the United States. Transfers from the EU/EEA to these processors are made under Standard Contractual Clauses or equivalent transfer mechanisms provided by each processor.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — delete your account and all associated data. You can do this directly from the app under Settings → Delete Account, without contacting support.
  • Portability — export your portfolio data as a CSV file (available to Pro subscribers from the app or web dashboard).
  • Object / Restrict — object to processing based on legitimate interests (e.g., analytics). The practical opt-out for analytics and crash reporting is to uninstall the app.

California residents: Rune Vault does not sell or share personal information as defined under the CCPA / CPRA. You may contact us at the address below to exercise any applicable rights.

8. Contact Us

If you have any questions about this Privacy Policy or wish to exercise a data subject right, please contact us at support@vaultek.co.