EverLucent Vault LLC ("we," "us," or "our") operates the EverLucent Vault platform. We act as the data controller for personal information processed through the Service. This notice explains what we collect, why, who we share it with, and your rights.
1. Information we collect
- Account information — name, email, password hash, professional credentials (e.g., NPI), notification preferences.
- Compliance records you upload — license numbers, DEA registrations, certifications, CME activities, malpractice policies, credentialing data, collaborative agreements, telehealth registrations, and related files.
- Practice content — templates, drafts, notes, and other documents you create within the Service.
- Usage and device data — log entries, IP address, browser type, pages viewed, feature interactions, error reports.
- Support and coaching communications — messages, scheduling data, and notes from any coaching sessions you book.
- Financial account data — if you choose to link a bank or card, the account and transaction information we receive through Plaid, described in Section 4.
Payment card information is collected and processed by Stripe, Inc.. We do not see or store your full card number.
2. Why we use your information
- To provide, maintain, and improve the Service (contract performance).
- To send renewal reminders, security notices, and important account messages (contract performance, legitimate interest).
- To detect and prevent fraud, abuse, and security incidents (legitimate interest, legal obligation).
- To respond to support requests and deliver booked coaching sessions (contract performance).
- To meet legal, tax, and accounting obligations (legal obligation).
- To send product updates and marketing where you have opted in (consent; you can withdraw at any time).
3. Who we share with
- Service providers / subprocessors — cloud hosting, database, email delivery, error monitoring, analytics, AI model providers, and customer-support tooling.
- Payment processor — Stripe, Inc., for subscription billing, payment processing, tax compliance, refunds, and invoicing.
- Scheduling — Cal.com (and your selected video provider, e.g., Zoom) for coaching bookings.
- Financial data connectivity — Plaid Inc., only where you choose to link a financial account, to establish and maintain that connection (see Section 4).
- Professional advisers — legal, accounting, and insurance providers, where reasonably necessary.
- Authorities — where required by law, subpoena, or court order, or to protect rights and safety.
- Successors — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections.
We do not sell personal information.
4. Bank account connections (Plaid)
EverLucent Vault uses Plaid Inc. ("Plaid") to gather your data from financial institutions. By using the Service to link a financial account, you grant EverLucent Vault and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.
Linking a bank is optional and is never required to use the Service. You enter your online banking credentials directly with Plaid or with your bank — EverLucent Vault never receives, sees, or stores your banking username, password, or one-time passcodes.
Once you link an account, the information we receive through Plaid and store is:
- Account information — institution name, account name, account type and subtype, and the last four digits of the account number.
- Transaction information — date, amount, direction, pending status, merchant or payee name, transaction description, and Plaid's spending category.
- Connection tokens — the encrypted access token that keeps the connection active, plus sync status and error information from Plaid.
We use this information only to populate your Money ledger — categorizing income and expenses, reconciling invoices and payouts, estimating taxes, and surfacing the alerts and reports you configure. Connections are read-only: we cannot and do not move money, initiate payments or transfers, or change anything at your financial institution. We do not sell this information, use it for advertising, or share it with third parties for their own purposes.
You can disconnect a bank at any time from Money → Accounts. Disconnecting revokes the access token with Plaid, stops all future syncing, and deletes the stored connection. Transactions already imported into your ledger remain until you delete them, and you can delete them individually or remove the account entirely. You may also review and revoke the connections Plaid holds for you at my.plaid.com, and you can request deletion of your data by contacting us using the details in the Contact section below.
5. AI processing and automated decision-making
When you use AI features, the prompts you submit (and limited context) are transmitted to AI providers solely to generate the requested output. You are responsible for not submitting PHI or other protected information; see our Acceptable Use Policy.
No automated decision-making. EverLucent Vault does not use AI or any automated system to make decisions that produce legal or similarly significant effects about you (such as decisions about employment, credit, housing, insurance, healthcare access, or essential goods and services). AI outputs in the Service are drafts and educational summaries that require independent review by a licensed clinician before any clinical, regulatory, or business use, and are not used by us to evaluate, score, profile, or take action against you or any patient.
6. Retention
We retain your account and records for as long as your account is active and for a reasonable period afterward to meet legal, tax, and accounting requirements, then delete or anonymize them. Backup copies may persist for a limited additional period before automatic expiry.
7. Security and breach notification
We use encryption in transit and at rest, Row Level Security so each user can only access their own records, access controls, and audit logging. No system is perfectly secure; you are responsible for the security of your devices and credentials.
Breach notification. If we confirm a security incident that has compromised the confidentiality, integrity, or availability of your personal information, we will notify affected users by email without undue delay and no later than seventy-two (72) hours after confirmation, except where law enforcement requests a delay. Our notice will describe, to the extent then known, the nature of the incident, the categories of information involved, the steps we have taken in response, and recommended steps you can take to protect yourself. We will also notify regulators and other parties where required by applicable law.
8. Your rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, or port your personal information, to object to certain processing, and to withdraw consent. To exercise these rights, contact privacy@everlucentvault.com. You may also lodge a complaint with your local data-protection authority.
7a. Your California privacy rights
This section applies to California residents and supplements the rest of this notice. Under the California Consumer Privacy Act, as amended ("CCPA"), you have the right to (a) know the categories and specific pieces of personal information we have collected about you; (b) know the categories of sources, business purposes, and third parties with whom we share that information; (c) request deletion of your personal information; (d) request correction of inaccurate personal information; (e) limit the use and disclosure of sensitive personal information; and (f) not be discriminated against for exercising these rights.
We do not "sell" or "share" personal information as those terms are defined under the CCPA, and we have not done so in the preceding twelve (12) months. We do not knowingly sell or share the personal information of minors under 16. We do not use sensitive personal information for any purpose that would trigger the right to limit under the CCPA.
The categories of personal information we collect are described in Section 1, the purposes are described in Section 2, and the categories of recipients are described in Section 3 and on our Subprocessors page. We retain personal information as described in Section 6. To exercise any California right, email privacy@everlucentvault.com with the subject line "California Privacy Request." We will verify your request using information already associated with your account. You may use an authorized agent; we may require written proof of authorization. We will not discriminate against you for exercising these rights.
9. International transfers; U.S.-only Service
The Service is offered to, and intended for use by, licensed healthcare professionals located in the United States. We do not market, target, or make the Service available to users in the European Union, European Economic Area, United Kingdom, or other jurisdictions outside the U.S., and the Service is not designed to comply with EU/UK data-protection or AI-specific regulations (including the EU AI Act). Our infrastructure is operated primarily in the United States. If you nevertheless access the Service from outside the U.S., your information will be transferred to and processed in the U.S., and you do so at your own risk and responsibility.
10. Cookies
We use cookies and similar technologies that are strictly necessary for authentication, session management, security, and core functionality. We may use limited analytics cookies to understand feature usage and improve the product. You can manage cookies through your browser settings; disabling strictly necessary cookies will break the Service.
11. Children
The Service is not intended for individuals under 18. We do not knowingly collect personal information from children.
12. Changes
We may update this notice from time to time. When we do, we will post the revised version with a new effective date and, for material changes, notify you by email or in-app.
13. SMS communications and consent
EverLucent Vault may send text messages to the mobile number you provide for appointment reminders, care-team notifications, intake follow-ups, billing alerts, license/CME renewal reminders, and other service-related updates. Message frequency varies with your use of the Service. Standard message and data rates from your carrier may apply.
Opt-in. You consent to receive SMS messages by providing your mobile number in your account settings, on an intake or booking form, or by texting a practice-specific keyword to our number. We do not send marketing texts without your explicit consent.
Opt-out. You can stop receiving text messages at any time by replying STOP to any message. Reply HELP for help, or contact us at support@everlucentvault.com. Carriers are not liable for delayed or undelivered messages.
14. Contact
EverLucent Vault LLC · privacy@everlucentvault.com
