Privacy Policy
Sentinel Vault is operated by JLM Solutions. This policy explains what we collect, why, and how you can exercise your rights.
Last reviewed: August 2026
1. Who we are
Sentinel Vault (the "Service") is provided by JLM Solutions ("we", "us"), the data controller for account-level information and the data processor for credentials your organization stores in the Service. For data-processing terms, see the Data Processing Addendum.
2. Data we collect
Account data
- Email address, display name, and hashed authentication credentials.
- Organizations you belong to and your role within them.
Vault data
- Item metadata (name, username, URL, notes, tags) and the encrypted ciphertext of secret fields (AES-256-GCM at rest).
- Vault, folder, and sharing structure created by you.
Operational data
- Audit events (reveals, edits, shares, member status changes, invites).
- Standard server request metadata (IP address, user agent, timestamps) used for reliability, rate limiting, and abuse prevention.
3. How we use it
- To provide the Service (authentication, encryption, sharing, audit).
- To secure the Service (fraud, abuse, and account-takeover detection).
- To send transactional email you have asked for (invites, verification, security notifications) from
notify.sentinelvault.app. - To meet legal obligations and enforce our Terms.
We do not sell your data, do not use vault contents to train models, and do not run behavioral advertising.
4. Legal bases (GDPR)
- Contract — to deliver the Service you signed up for.
- Legitimate interests — to keep the Service secure and reliable.
- Legal obligation — where required by law.
- Consent — for optional communications you opt in to.
5. Subprocessors
We rely on a small number of vetted providers to host and deliver the Service. The current list, purpose, and hosting region are published on the Subprocessors page.
6. Retention
- Vault items: retained until you delete them or delete your organization.
- Audit events: retained for at least 12 months for security review.
- Account data: retained while your account is active and up to 30 days after deletion.
- Backups: encrypted database backups may retain deleted records for up to 30 days before rotation.
7. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA, and similar) you have the right to access, correct, export, restrict processing of, or delete your personal data, and to lodge a complaint with a supervisory authority. Email privacy@sentinelvault.app and we will respond within 30 days.
8. International transfers
Data is hosted on our managed infrastructure provider. Where data crosses jurisdictions we rely on Standard Contractual Clauses or equivalent safeguards.
9. Security
Encryption, access controls, and audit practices are described in the Security Overview and in our Trust Center. No system is perfect; we disclose material breaches promptly as required by law.
10. Cookies
We use strictly necessary cookies for authentication and session management. We do not run third-party advertising or cross-site tracking cookies.
11. Children
Sentinel Vault is a workplace product and is not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes
We will update this page for material changes and adjust the "Last reviewed" date above. Continued use of the Service after changes constitutes acceptance.
13. Contact
JLM Solutions — privacy@sentinelvault.app
