Legal document
ChemVault Privacy Policy
Effective date: 20 July 2026
Last updated: 20 July 2026
1. Scope and Application
This Privacy Policy explains how ChemVault collects, receives, uses, stores, discloses, transfers, retains, and deletes information in connection with the ChemVault website and associated services, including ChemVault Mail, the User System, Docs, the File System, the Notification System, Molecule Model and Molecule Studio, Extract and other artificial-intelligence-assisted scientific data services, Apple native applications and TestFlight builds, application programming interfaces, integrations, and related support or administrative functions (collectively, the Services).
This Privacy Policy applies to visitors, account holders, authorized users of an organization, developers using ChemVault APIs, and persons who communicate with ChemVault. A separate written agreement, order form, enterprise agreement, data processing addendum, deployment notice, or product-specific notice may supplement this Privacy Policy. If a separate agreement validly establishes different data-handling terms for a particular organization or deployment, that agreement will govern to the extent of the conflict.
Third-party websites, systems, applications, repositories, or services that link to or integrate with the Services are governed by their own privacy practices. This Privacy Policy does not apply to information processed independently by those third parties.
2. Identity of the Responsible Entity
ChemVault is the name used for the Services. Where an order form, enterprise agreement, service notice, or other written contract identifies the legal entity responsible for a particular deployment or contracted service, that entity is responsible for the processing governed by that instrument.
The current contact channel for controller-identity questions, privacy inquiries, and data-rights requests is contact@chemvault.science. ChemVault will provide additional controller, representative, or data protection officer information through an applicable agreement or service notice where required by law.
3. Definitions
For purposes of this Privacy Policy:
- Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household, as defined by applicable law.
- User Content means information, files, messages, records, prompts, instructions, datasets, references, and other materials submitted to, stored in, generated through, or transmitted using the Services by or on behalf of a user or organization.
- Service or Asset Management Database means a user-controlled or third-party structured or unstructured collection used to administer services, assets, equipment, facilities, inventory, maintenance, support, operations, or related workflows. Reference data a user chooses to submit, attach, link, or connect from such a database may include database records, asset registers, equipment details, identifiers, ownership or custody information, service requests, incidents, tickets, work orders, change records, maintenance histories, status records, notes, photographs, attachments, logs, and linked metadata.
- Service Management Reference means material used to inform or support a service or asset-management activity, including manuals, standard operating procedures, maintenance instructions, service histories, vendor materials, safety information, knowledge articles, diagrams, specifications, checklists, and other reference documents.
- Organization means a business, university, laboratory, institution, or other entity that provides or manages access to the Services for its authorized users.
- Processor or Service Provider means a third party that processes information on ChemVault's behalf to provide infrastructure, communications, storage, security, support, AI, payment, or other operational services.
4. Information We Collect or Receive
The categories of information processed depend on the Services selected, the applicable deployment, organization settings, user choices, and enabled integrations.
4.1 Account and Profile Information
ChemVault may process names, display names, email addresses, institutions, organizations, roles, fields of interest, websites, avatars, account status, memberships, permissions, preferences, and related account settings.
4.2 Authentication and Security Information
ChemVault may process password hashes, OAuth or single sign-on identifiers, session tokens and token hashes, app-password records, connected-service records, API-key identifiers and hashes, IP addresses, user-agent information, timestamps, login history, device information, and security or authentication events.
ChemVault does not intend to store plain-text account passwords. Password, token, API-key, and OAuth implementations remain subject to technical and security review, and no method of authentication or storage can be guaranteed to be completely secure.
4.3 Email and Communication Information
ChemVault Mail may process sender and recipient addresses, subjects, message bodies, HTML content, headers, attachments, delivery status, mailbox paths, routing details, message identifiers, spam or abuse indicators, app-password activity, audit events, and mail-account settings.
When a person contacts ChemVault, joins a waitlist, requests enterprise access, submits a form, or requests support, ChemVault may process the person's name, email address, organization, role, team information, interests, message content, attachments, and related communication metadata.
Contact, commercial-interest, and lead submissions may be stored in D1-backed form or lead records. Relevant fields may include the submitter's name, email address, organization, role, team size, interests, message, submission category, status, timestamps, and related request metadata.
If the contact or lead API is unavailable, the website may store the complete submitted payload in browser local storage as a delivery fallback. This fallback can hold up to 50 submissions and does not apply an automatic expiration period. A person with access to the browser profile may be able to view that stored information, and the user can remove it by clearing the relevant website data in the browser. Users should not submit secrets or highly sensitive information through an ordinary form.
4.4 Files and General User Content
The Services may process uploaded files, file names, file sizes, media or MIME types, storage identifiers, checksums, folder and project metadata, sharing links or tokens, preview data, download or access records, activity logs, and other information contained in or associated with a file.
Files and User Content may contain Personal Information or confidential, proprietary, scientific, or regulated information. Users must evaluate whether the relevant Service, deployment, provider configuration, and contract are suitable before submitting such information.
4.5 Service or Asset Management Database and Service Management Reference Data
Only where an applicable feature or integration is enabled and a user or Organization chooses to submit, attach, link, or connect the material, the Services may process reference data from a Service or Asset Management Database and Service Management References. These materials may include Personal Information about employees, contractors, customers, suppliers, asset custodians, requestors, approvers, support personnel, or other individuals.
Only in that context, ChemVault may process database schema information, source-system identifiers, object relationships, record history, tags, field mappings, import status, validation results, access-control metadata, and integration logs necessary to receive, organize, display, search, analyze, secure, troubleshoot, or export those records and references.
These definitions identify categories and sources of User Content only. They do not represent that ChemVault provides a configuration management database, IT service management or IT asset management system, asset discovery, database synchronization, maintenance scheduling, monitoring, or an authoritative system-of-record function.
Section 8 contains additional terms that apply specifically to these materials.
4.6 Scientific, Molecular, and AI Information
ChemVault Extract and other AI-assisted or scientific features may process uploaded papers and documents, extracted text and document chunks, tables, metadata, prompts, user instructions, model inputs and outputs, citations, review decisions, correction history, exports, cost or usage records, molecule identifiers, SMILES strings, PDB identifiers, spectra, generated molecular structures, and job or provider-response metadata.
AI output may be incomplete, inaccurate, non-deterministic, or unsuitable for scientific, medical, legal, regulatory, financial, operational, or safety-critical use without independent human review.
4.7 Notification, API, and Integration Information
ChemVault may process notification content, push-subscription endpoints and keys, device or browser details, project messages, message-read status, webhook payloads and delivery results, API usage, API-key prefixes and hashes, integration configuration, connected-service identifiers, and related activity or audit logs.
4.8 Device, Browser, Usage, and Log Information
ChemVault may automatically receive IP addresses, browser and device type, operating system, app version, language or region settings, request metadata, route or feature access, timestamps, errors, diagnostics, performance information, service-usage records, entitlement checks, security events, and infrastructure, operational, or audit logs.
Apple native applications may store information such as language settings, cached region selection, API base URLs, authentication tokens in Keychain, local molecule-library entries, and other local app state. Apple may separately process TestFlight participation, device information, diagnostics, crash information, or app analytics depending on the applicable Apple settings and app configuration.
For region detection or service routing, an Apple application may request the user's public IP address or approximate country or region from ipapi.co, ipwho.is, ipinfo.io, or Cloudflare trace services, depending on availability and configuration. Those providers receive network request information, including the requesting IP address, and process it under their own terms.
4.9 Cookies and Local Technologies
ChemVault may use cookies, local storage, session storage, Keychain, UserDefaults, and similar technologies to authenticate users, maintain sessions, remember preferences, secure the Services, cache app state, and support product functions.
Depending on the feature, browser local storage may also contain usage counters, saved research items, research notes, and the contact or lead fallback submissions described in Section 4.3. This information remains associated with the relevant browser profile until the Service removes it or the user clears the website's stored data.
Any deployment of non-essential analytics, advertising, marketing cookies, cross-site tracking, session replay, or similar technology must be reflected in an updated notice and, where required, an appropriate consent or opt-out mechanism.
The current website application code covered by this Policy does not include a third-party analytics SDK. Infrastructure providers, platform settings, deployed configurations, diagnostics, or later releases may involve additional telemetry, which must be reflected in this Policy where it materially changes the processing described here.
4.10 Payment and Subscription Information
If billing is enabled, a payment provider may process payment-card and transaction information under its own privacy terms. ChemVault may process provider customer or subscription identifiers, plan and status information, checkout or portal references, billing-event metadata, metered usage, entitlement information, and reconciliation records. ChemVault does not intend to store full payment-card numbers.
5. Sources of Information
ChemVault may obtain information:
- directly from a user, including through registration, forms, files, messages, prompts, imports, and support requests;
- from an Organization, account administrator, project owner, or another authorized user;
- automatically from browsers, devices, applications, APIs, cookies, local technologies, logs, and security systems;
- from connected services and systems selected or authorized by the user or Organization, including email, identity, storage, repository, service management, asset management, and other enterprise systems;
- from infrastructure, communications, AI, payment, authentication, app-distribution, and other Service Providers; and
- from public, licensed, institutional, or third-party sources identified or supplied by a user.
Where information originates from a third party, the user or Organization supplying or connecting that information is responsible for ensuring that it has the rights, permissions, notices, consents, contracts, and lawful basis necessary for ChemVault to process the information as instructed.
When a user performs a scientific or compound search, ChemVault may send the search term, identifier, or related query parameters to PubChem, PubMed, NCBI, or another source selected or configured for that search. Those services receive network and query information and process it under their own terms.
6. Purposes of Processing
ChemVault may process information to:
- provide, operate, maintain, support, and improve the Services;
- create and administer accounts, sessions, roles, memberships, permissions, and entitlements;
- authenticate users, protect accounts, and manage connected services;
- send, receive, route, store, display, search, and administer email and other communications;
- store, preview, organize, search, share, download, transform, and export files and User Content;
- only where an applicable feature or integration is enabled and the user submits or connects the material, import, map, validate, index, search, analyze, relate, report on, and export reference data from a Service or Asset Management Database and Service Management References;
- process scientific documents, molecular information, AI-assisted tasks, extraction results, review workflows, and exports;
- deliver notifications, webhooks, transactional messages, security alerts, and service communications;
- provide support, diagnose errors, respond to inquiries, and administer enterprise or commercial-interest requests;
- measure capacity, performance, reliability, feature usage, and service integrity;
- maintain security, operational, and audit records;
- detect, prevent, investigate, and respond to fraud, spam, abuse, unauthorized access, safety risks, and security incidents;
- enforce applicable agreements, policies, and usage restrictions;
- comply with law, preserve legal claims, respond to lawful requests, and protect the rights, safety, and property of ChemVault, users, Organizations, Service Providers, and the public; and
- carry out another purpose disclosed at collection or authorized by the user or Organization.
ChemVault will not treat access to the Services as authorization to use User Content for an unrelated purpose. Before materially changing the purpose for which Personal Information is processed, ChemVault will provide additional notice and obtain authorization where required by applicable law or contract.
7. Legal Bases for Processing
Where applicable law requires a legal basis, ChemVault may rely on one or more of the following:
- performance of a contract, where processing is necessary to provide requested Services or administer the user or Organization relationship;
- legitimate interests, including operating and improving the Services, maintaining security and reliability, preventing abuse, supporting users, protecting legal rights, and administering business operations, where those interests are not overridden by applicable privacy rights;
- consent, where ChemVault requests and receives valid consent for a particular activity;
- compliance with legal obligations, including responding to binding legal process and meeting accounting, security, or regulatory requirements; and
- protection of vital interests or other bases recognized by law, in the limited circumstances in which they apply.
The applicable legal basis depends on the context, jurisdiction, relationship, and requested processing. An Organization may be the controller or business for Personal Information that it submits to the Services, with ChemVault acting as its processor or service provider under the applicable contract. These roles must be confirmed for each enterprise deployment.
8. Service or Asset Management Database and Service Management Reference Data
8.1 User and Organization Ownership
Where a user submits or connects reference data from a Service or Asset Management Database or submits a Service Management Reference, as between ChemVault and the user or Organization, the user or Organization retains its rights, title, and interest in that material and other User Content, subject to any rights held by third-party licensors, source-system operators, individuals, or other owners. ChemVault does not acquire ownership of those materials merely because they are submitted to or processed through the Services.
Only where the user submits or connects the material through an applicable enabled feature or integration, the user or Organization grants ChemVault and its authorized Service Providers a limited right to host, reproduce, transmit, index, convert, map, analyze, display, and otherwise process it as necessary to provide, secure, support, maintain, and improve the requested Services, follow documented instructions, comply with applicable law, and enforce applicable agreements.
8.2 Processing Purpose and Scope
If a user submits the reference data, or if a compatible function or connection is made available and enabled, ChemVault may process the records and references to perform user-directed import, normalization, field mapping, validation, deduplication, relationship analysis, search, reporting, classification, summarization, AI-assisted analysis, workflow support, export, troubleshooting, and audit functions. ChemVault will limit processing to the enabled Services and purposes selected or reasonably expected by the user or Organization, except where additional processing is required by law or separately authorized.
8.3 Confidentiality and Access
Reference data submitted or connected from a Service or Asset Management Database and submitted Service Management References will be treated as User Content and may be confidential where their nature or the circumstances reasonably indicate confidentiality. Access may be provided to the user, authorized members and administrators of the relevant Organization, personnel or contractors who require access to operate or support the Services, and authorized Service Providers subject to appropriate obligations.
ChemVault may access such materials when reasonably necessary to provide support requested by the user or Organization, investigate security or abuse, maintain service integrity, comply with law, or exercise or defend legal rights. Users must not submit passwords, private keys, recovery codes, unprotected credentials, or specially regulated information unless the applicable Service and written agreement expressly authorize that use.
No transmission, storage, or access-control method is completely secure. A confidentiality commitment in a signed agreement may impose additional or more specific requirements and will govern to the extent of a conflict.
8.4 Disclosure and Sharing
ChemVault may disclose these records and references:
- to infrastructure, storage, database, security, communications, support, AI, and integration providers to the extent necessary to provide enabled functions;
- to persons and systems designated, connected, or authorized by the user or Organization;
- to Organization administrators who control the relevant workspace, account, or deployment;
- in connection with a merger, financing, acquisition, reorganization, insolvency, sale of assets, or similar transaction, subject to applicable confidentiality and legal requirements;
- to comply with law, regulation, court order, or other binding legal process; or
- where reasonably necessary to protect rights, safety, service integrity, or security, or to investigate fraud, abuse, or unlawful activity.
An AI provider will receive relevant records or references only where an AI-enabled function is selected, configured, or otherwise used in a manner that requires provider processing. Users should review the notice presented for the relevant AI feature and avoid submitting information that the active provider terms and configuration are not authorized to process.
8.5 Retention, Deletion, and Export
ChemVault retains these records and references for no longer than reasonably necessary for the purposes described in this Privacy Policy, taking account of account status, Organization instructions, feature configuration, contractual requirements, security and audit needs, dispute preservation, and legal obligations. Retention periods vary across Services and deployments, so no single fixed period applies to every record or reference.
A user or Organization may request deletion or export using available account controls or by contacting ChemVault. ChemVault may verify identity and authority before acting on a request. Deletion may be limited or delayed where information must be preserved for security, fraud prevention, legal compliance, dispute resolution, audit integrity, or the establishment, exercise, or defense of legal claims.
Residual copies may remain temporarily in backups, disaster-recovery systems, caches, immutable security records, or logs until they are overwritten or removed under applicable operational schedules. ChemVault may retain information that has been aggregated or de-identified so that it no longer identifies an individual or reveals the confidential source record, subject to applicable law and contract.
Deleting information from ChemVault does not delete the original record in a connected source system or copies previously exported, disclosed, or shared at the user's or Organization's direction. Users and Organizations are responsible for managing those systems and recipients separately.
8.6 Third-Party Sources and User Responsibilities
Users and Organizations are responsible for:
- having the authority to access, copy, connect, upload, analyze, share, and instruct ChemVault to process the relevant records and references;
- complying with source-system terms, database rights, intellectual property rights, confidentiality obligations, employment or monitoring rules, procurement restrictions, and applicable data-protection law;
- providing required notices and obtaining required consents or other lawful bases from individuals whose Personal Information appears in the materials;
- configuring permissions, field selection, sharing, integrations, and retention settings appropriately;
- maintaining the accuracy, quality, legality, and relevance of submitted information;
- avoiding the submission of secrets, credentials, excessive Personal Information, or specially regulated information that is not necessary and expressly authorized; and
- reviewing outputs, mappings, classifications, recommendations, and exports before relying on or distributing them.
ChemVault does not independently verify that a user or Organization owns or is authorized to use third-party records. ChemVault may suspend processing, restrict access, or remove materials where reasonably necessary to address a credible rights, privacy, security, or legal concern.
9. AI and Automated Processing
Where a user invokes or enables an AI-assisted function and submits or connects the relevant material, ChemVault may transmit documents, text, prompts, molecular information, reference data from a Service or Asset Management Database, Service Management References, or other inputs to an AI provider or internal AI system to generate extraction results, summaries, classifications, embeddings, structured data, relationships, or other outputs.
Provider handling of those inputs and outputs depends on the provider, contract, account settings, deployment, region, and feature configuration. ChemVault does not promise that a provider will not retain, review, or use submitted information unless the active provider terms and configuration support that statement.
AI output is provided to assist human review. It must not be treated as verified scientific, medical, legal, regulatory, financial, operational, security, or safety advice. Users remain responsible for validating outputs and for decisions made using them.
ChemVault will disclose and obtain authorization where required before using Personal Information to make a decision that produces legal or similarly significant effects solely by automated means. The presently described AI features are intended as assistive tools, not as a substitute for qualified professional judgment.
10. Disclosure to Third Parties
ChemVault may disclose information to:
- Cloudflare or other providers used for hosting, routing, databases, object storage, security, logs, and edge infrastructure;
- Resend, SMTP, DNS, or other providers used for email sending, receiving, and routing;
- OpenAI or other AI providers used for enabled AI and extraction features;
- PubChem, PubMed, NCBI, or other scientific information sources selected or configured for a search;
- Apple for App Store, TestFlight, Sign in with Apple, diagnostics, and developer services;
- ipapi.co, ipwho.is, ipinfo.io, or Cloudflare trace services where an Apple application uses them for public-IP or approximate region detection;
- OAuth or identity providers, such as Apple, Google, GitHub, or Microsoft, where enabled;
- GitHub for source-control, workflow, issue, or repository functions where applicable;
- Supabase or other database and notification providers where configured;
- Stripe or another payment provider if billing is enabled;
- professional advisers, auditors, insurers, and contractors subject to appropriate obligations;
- an Organization and its administrators for accounts managed by that Organization;
- authorities, courts, regulators, or other parties where disclosure is required or permitted by law; and
- a successor or relevant counterparty in a corporate transaction, subject to applicable protections.
The specific provider list may change as the Services evolve. ChemVault will update this Privacy Policy or provide another appropriate notice where a provider change materially affects the processing described here and additional notice is required. Depending on the integration, a third party may act as a Processor for ChemVault or may process information independently under its own terms, configuration, and privacy notice.
ChemVault may also disclose information at a user's direction, including through sharing links, exports, webhooks, connected applications, repositories, email recipients, or Organization workspaces. The user is responsible for reviewing the destination, permissions, and consequences before directing such disclosure.
11. International Processing and Transfers
ChemVault and its Service Providers may process information in more than one country or region. The applicable locations and transfer mechanisms depend on the deployed infrastructure, provider settings, contract, Organization instructions, and user location.
ChemVault does not promise a particular data-residency location or legal transfer mechanism unless it is expressly stated in a written agreement and supported by the active technical configuration. Where applicable law requires safeguards for an international transfer, ChemVault and the relevant Organization must confirm and implement an appropriate mechanism before the affected processing occurs.
12. Retention of Other Information
ChemVault retains Personal Information and User Content only for as long as reasonably necessary to provide the Services, maintain accounts, secure and audit systems, prevent abuse, resolve disputes, enforce agreements, meet contractual requirements, and comply with law.
Retention may vary by information category, feature, Organization instruction, provider setting, account status, and legal requirement. Closed, non-security submissions stored through the forms service use a configurable retention setting with a current default of 90 days and an allowed configuration range of 30 to 730 days. This setting does not establish the retention period for open submissions, security reports, separate lead or newsletter records, billing records, audit records, privacy-rights requests, browser fallback copies, provider records, or backups.
No single product-wide retention period applies to account data, mail, files, AI inputs and outputs, logs, backups, audit records, notifications, push subscriptions, API keys, webhooks, payment or usage records, security reports, lead or newsletter records, and rights requests. ChemVault therefore does not state one fixed period for those categories in this Policy.
When information is no longer required, ChemVault will delete, de-identify, or otherwise dispose of it in accordance with the applicable operational process, contract, and law. Information may remain in backups, provider systems, security records, or legal archives until removal is technically feasible or the applicable preservation requirement ends.
13. Security and Confidentiality
ChemVault uses technical and organizational measures intended to protect information, which may include authentication, role and permission checks, token hashing, encryption for certain secrets, access controls, audit logging, infrastructure security services, and restricted secret handling.
The safeguards applied depend on the Service and deployment. ChemVault cannot guarantee that unauthorized access, disclosure, alteration, loss, provider failure, vulnerability, or configuration error will never occur. Users are responsible for protecting their credentials, using appropriate access settings, maintaining secure devices and connected systems, and promptly reporting suspected unauthorized activity.
Information submitted through ordinary contact channels should not include passwords, API keys, private keys, recovery codes, or other authentication secrets. Security or abuse reports should use the published reporting channel where available.
14. Privacy Rights and Choices
Depending on the person's location, relationship with ChemVault, and applicable law, the person may have rights to:
- request access to or a copy of Personal Information;
- request correction of inaccurate Personal Information;
- request deletion of Personal Information;
- request restriction of or object to certain processing;
- request portability of information in an applicable format;
- withdraw consent for future processing where consent is the applicable basis;
- opt out of certain targeted advertising, sale, sharing, profiling, or marketing activities if such processing applies and the law grants that right;
- appeal a decision concerning a privacy request where applicable; and
- lodge a complaint with a competent data-protection or consumer-protection authority.
Requests may be submitted through available account deletion or export functions or by email to contact@chemvault.science. The deletion and export entry points record a pending request; they do not establish that deletion or export is completed immediately or automatically across every ChemVault service. ChemVault may require identity and authority verification, administrator review, and manual or service-specific processing before completing a request.
Rights are not absolute. A request may be limited or denied where permitted by law, including to protect other persons, preserve security and audit integrity, comply with legal obligations, prevent fraud or abuse, protect confidential information, or establish, exercise, or defend legal claims. ChemVault will not discriminate against a person for exercising a privacy right where prohibited by law.
For an Organization-managed account, the Organization may control the account and submitted information. ChemVault may refer the request to that Organization or act on its documented instructions where the Organization is responsible for the processing.
15. Children and Specially Regulated Information
The Services are not intended to be directed to children, and ChemVault does not knowingly invite children to create accounts without authorization required by applicable law. If ChemVault learns that Personal Information was submitted by a child without required authorization, ChemVault may restrict the account and take reasonable steps to delete the information, subject to legal and technical limitations.
Users must not submit protected health information, patient records, clinical-care data, regulated submissions, GxP records, export-controlled information, controlled-substances records, payment-card data, school records, children's data, biometric data, government identifiers, or other specially regulated information unless a separate written agreement and the applicable deployment expressly authorize that processing.
Use by minors, schools, universities, healthcare entities, regulated laboratories, government bodies, or other regulated Organizations may require additional notices, agreements, safeguards, permissions, or legal review.
16. Organization Accounts and Administrators
An Organization that provides access to the Services may administer accounts, control permissions, configure integrations, access Organization workspaces and User Content, establish retention or export settings, and receive account or activity information. Users should direct questions about an Organization's independent privacy practices to that Organization.
ChemVault processes Organization-managed information according to the applicable agreement and documented instructions, subject to legal, security, and service-integrity requirements.
17. Changes to This Privacy Policy
ChemVault may update this Privacy Policy to reflect changes in the Services, providers, legal requirements, contracts, or information-handling practices. The revised policy will state its effective date and last-updated date.
Where required by law or contract, ChemVault will provide additional notice of a material change through reasonable means, which may include a website notice, in-product notice, account communication, email, or release note. Continued use after an update will have only the effect permitted by applicable law and agreement.
18. Contact
Questions, privacy requests, and concerns may be directed to:
ChemVault
Email: contact@chemvault.science
Security or abuse reports may also be submitted through forms.chemvault.science/security-report where that channel is available.
To help ChemVault identify the relevant account, service, or Organization, a request should include sufficient non-sensitive context. Do not send passwords, API keys, private keys, recovery codes, or other authentication secrets through ordinary email or contact forms.