In short: we cannot read the contents of your vault. It is encrypted on your device before it reaches us, and we hold no key. Below is a precise account of what we do process — because it is not nothing.
1. Data controller
Me & Max AS, company no. 987 607 882 MVA, Stigerbakken 7, 1348 Rykkinn, Norway. Contact: kontakt@kodovault.no.
2. What we process
- Account: first name, last name, email address, chosen subdomain and language preference.
- Vault contents: stored only as an encrypted blob. We cannot read passwords, cards, IDs or notes.
- Payment: handled by Stripe. We store a customer ID and invoice history, never card numbers.
- Event log: timestamps for sign-ins, failed attempts and changes to the vault. The log records that something happened, never what the vault contains.
- Operations and security: technical logs, including IP address. Bot protection via Cloudflare Turnstile, which also processes IP addresses.
- Usage statistics: Vercel Analytics on kodovault.no — aggregated page-view statistics, no cookies and no profiling of individuals.
- Mailing list: your email address, if you sign up.
3. Stored on your own device
Some things are stored only in your browser and never sent to us:
- Your language preference.
- Passkey (WebAuthn): if you enable Touch ID or Face ID, the credential ID, a salt and an encrypted copy of your master password are stored in your browser’s local storage. That copy is encrypted with AES-256-GCM under a key only your passkey can derive — we use the WebAuthn PRF extension, which yields a secret bound to the passkey inside your device’s security chip (Secure Enclave / TPM). The key is stored nowhere; it is re-derived on every unlock, and only after Touch ID or Face ID has confirmed it is you. The credential ID and salt are not secrets and grant no access on their own. If your browser does not support PRF, we do not offer Touch ID or Face ID at all — we do not fall back to something weaker. The private key never leaves your device, and we register no passkey on the server. The unlock itself is recorded as an event (see section 2), but the key is not.
This storage is strictly necessary for the service to work as you have requested, and therefore requires no consent under the Norwegian Electronic Communications Act § 3-15. We use no cookies for tracking or marketing.
4. Purpose and legal basis
- Providing the service and managing your subscription — contract, GDPR art. 6(1)(b).
- Security, operations, event logging and abuse prevention — legitimate interest, art. 6(1)(f).
- Usage statistics on kodovault.no — legitimate interest, art. 6(1)(f).
- Accounting — legal obligation, art. 6(1)(c).
- Mailing list — consent, art. 6(1)(a). You may withdraw it at any time.
5. Processors
- Upstash — database. Vault data is stored in Frankfurt, with an alternative read path via Dublin.
- Vercel — hosting and operations (Frankfurt and Stockholm). Processes IP addresses in server logs.
- Stripe — payment and invoicing.
- Resend — sending email. Processes your email address and the contents of transactional emails (notices and receipts).
- Cloudflare — bot protection at registration. Processes IP addresses.
6. Transfers to the US — plainly stated
All five providers above are US companies. The fact that Upstash stores data in Frankfurt does not change that the company is subject to US law — that is precisely what the Schrems II debate is about. We say so directly rather than claiming “everything is in the EU”.
What protects you is not the jurisdiction but the mathematics: vault contents are encrypted on your device and are not readable by any of them. What they can process is metadata — email address, name, IP address and payment details — and this may be processed in the US.
Transfers rely on the EU Standard Contractual Clauses (SCC). Several of the providers are, as of September 2026, all certified under the EU–US Data Privacy Framework. Certifications can change or lapse, so the SCC remain the mechanism we rely on. A copy of the standard clauses is available on request.
7. Retention
- Account and vault: until you delete the account yourself, or 28 days after the vault was locked — whichever comes first. The vault is locked when the trial expires or a payment fails, and is deleted automatically 28 days later. You are warned by email 7 days before deletion, and you may export your data throughout that period (see section 10 of the terms).
- Stripe customer ID: until the account is deleted.
- Invoices and accounting records: five years, per the Bookkeeping Act.
- Event log and technical logs: normally up to 30 days.
- Mailing list: until you unsubscribe.
8. Deletion
You can permanently delete your vault and account yourself, from settings. Deletion is final. Accounting records are retained as described above because we are legally required to keep them.
9. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing. You can exercise portability yourself: export the entire vault as an encrypted backup or as CSV, at any time.
If you believe we process data unlawfully, you may complain to the Norwegian Data Protection Authority.
10. Changes
We may update this policy. Material changes are announced by email.
English translation for convenience. In case of conflict, the
Norwegian version governs.