Trust Center
You're trusting LuxeVault HQ with the things that matter most to your family — passports, insurance cards, your budget, your kids' schedules. This page explains, in plain language, how we protect that trust. For the full legal detail, see our Privacy Policy.
What LuxeVault protects
Everything you store or organize inside LuxeVault HQ: identity documents (birth certificates, passports, insurance cards), medical and school records, your household budget and bank connection, family calendars and schedules, chores and lists, thoughtful notes and cards you send, and — if you use Family Hub — parenting schedules and shared records between households.
How your data is secured
- Encrypted, always. Your data is encrypted both while it travels to and from the app, and while it's stored — this is handled by Google Cloud, the infrastructure LuxeVault runs on.
- Your family's data is walled off from every other family's. No other household using LuxeVault can see your bills, documents, calendar, or anything else — this is enforced at the database level, not just hidden in the app's interface.
- We don't store your bank login. Bank connections go through Plaid; LuxeVault never sees or holds your banking credentials.
- Protected against loss. Your family's data lives in Google Cloud, automatically replicated across multiple secure data centers as you use the app — and nothing is ever permanently deleted without your explicit say-so.
- No secrets live in our app's code. Every key or credential our systems use to talk to outside services (email delivery, AI features) is stored in a locked-down secrets vault, not written into the codebase itself.
- Locked by default — and tested from the outside. Our database rules deny every request that isn't explicitly allowed. In July 2026 we verified this against the live app itself: requests made with no login, the way a stranger or a bot would try, are refused by the running system — not just on paper.
- App integrity screening. Firebase App Check is registered for our web and iOS apps, giving our systems a way to tell real LuxeVault apps apart from scripts and bots as an added layer on top of the rules above.
- Dependencies are monitored and patched. Automated scanning (GitHub Dependabot and secret scanning) watches the building blocks our code is made from. As of July 28, 2026, our backend has zero known vulnerabilities in its dependencies.
- Strict browser protections. The app ships with hardened security headers (including a Content Security Policy) that limit what code is even allowed to run on the page.
How permissions work
Inside your family, not everyone sees everything by default:
- Financial data and the Document Vault are visible only to members marked as parents/guardians.
- Kids' accounts see calendars, chores, and lists appropriate to their role — not bills, bank connections, or documents.
- Family Hub connections (for co-parenting across two households) share only what's explicitly sent through a request or record — never your full account, and never anything outside that one connection.
How AI uses your family's data
- AI features (like the Daily Briefing, budgeting suggestions, and document/gift photo recognition) only receive the specific facts needed to do that one task — for example, a bill's name and amount, not your entire account.
- Your family's data is never used to train AI models.
- Voice notes sent to Brain Dump are converted to text and the audio is discarded — it isn't kept.
- Your data is never sold, and never shared with anyone for advertising.
Data ownership
Your family's data belongs to you — not to us. You can delete your own account and everything tied to it at any time from inside the app (Family Members → Delete my account). We don't hold your data hostage, and we don't make it hard to leave.
Security contact & responsible disclosure
If you notice something that seems wrong, or you're a security researcher who's found an issue, please tell us directly before disclosing it publicly: security@luxevaulthq.com. We'll acknowledge reports promptly and won't take legal action against good-faith security research. We also publish a standard security.txt file so researchers can always find this channel.
Where we are on formal certification — honestly
We'd rather tell you exactly where things stand than imply more than is true. LuxeVault HQ itself has not yet completed a formal, independent security certification. Here's what's true today:
Built entirely on Google Cloud, which itself holds SOC 2 Type II and ISO 27001 certification at the infrastructure level. LuxeVault inherits that foundation — it is not the same as LuxeVault itself being independently certified.
A July 2026 pre-launch security review of the application itself: live verification that the database refuses requests from anyone outside your family, dependency patching to zero known vulnerabilities, app-integrity screening (Firebase App Check), and a standing responsible-disclosure channel (security.txt). This was our own engineering review, verified against the running app — not a third-party certification.
Independent grades anyone can verify: an A+ from SSL Labs — the highest grade given — for how the site encrypts your connection, and an A+ from Mozilla's HTTP Observatory (10 of 10 checks passed) for the browser security protections the app ships with.
LuxeVault HQ