Last updated: September 25, 2026
This policy explains what data ReactVault collects, why we collect it, who we share it with, and what you can do about it. We've written it in plain language because you should actually be able to understand it.
Account information. Email address, display name, and avatar when you sign up. You can sign up with an email and password, or sign in with Google, Apple, Discord or Twitch. If you use one of those, we receive your name, email address and profile photo (Apple doesn't share a photo, and only shares your name the first time), plus a permanent account ID from that service so we can recognise you next time even if your email there changes. Nothing else. If you choose Apple's "Hide My Email", we receive a private relay address instead of your real one. Each service's own privacy policy governs how it handles your data.
Payment information. Processed entirely by Stripe. We never see or store your card number, bank details, or billing address. We store transaction records (what you bought, when, how much, and Stripe's transaction ID) for payout calculations, dispute resolution, and tax compliance.
Watch history. Which videos you watch, how long you watch them, and where you left off. This powers the Continue Watching feature, calculates All-Access revenue splits (your subscription money goes to the creators you actually watch), and prevents replay-based exploits.
Unlock and spending history. Which videos you've unlocked, how many Keys you spent, and whether they were purchased Keys, sign-up and referral Keys, or Keys earned from offers. This determines creator payouts and lets you see your own spending in Wallet.
Offerwall activity. Offers are supplied by third-party networks. We fetch their catalogue to our own servers and filter it before showing you anything, so browsing offers on ReactVault sends nothing to the provider. Once you start an offer you're on their site under their terms, and they tell us when you finish: we receive a completion notification containing your anonymous ReactVault user ID, the number of Keys to award, the transaction ID, and the revenue amount. We don't receive your survey answers, game progress, or app usage.
Offers you open. When you tap into an offer we record which one, so the Offers page can show what you've started and how far along it is. This is browsing history rather than a financial record, and it's deleted when you delete your account. Offers you open and never complete drop off the list after a week.
Time zone and last activity. Your browser's time zone, so dates and payout times read correctly rather than in UTC, and the date you were last active, so we can tell when an account has lapsed. Neither is shared with anyone.
Editor access. If you give someone editor access to your catalogue, or accept access to someone else's, we store that link, who created it, and a record of every change they make to a video — what changed, from what, to what, and when. Both of you can see it. Notes written on a draft are visible to both of you and are deleted with the draft. If access is granted by invite link, we store the link, when it expires, and which account accepted it.
Referral data. If you sign up through a referral link, we record who referred you so both of you can receive your bonus — the person who invited you is rewarded once you make your first purchase, so we check whether you have. We use device and account signals to detect referral fraud (self-referrals, fake accounts).
Comments and interactions. Anything you post (comments, reactions, poll votes, tips with messages) is stored and visible to other users as part of normal platform use. If you mark a comment as a spoiler, we store that too. If a creator removes your comment from their video, it's hidden from everyone but kept for our moderation review, and you're notified.
Creator data. If you're a creator, we store your uploaded videos (hosted by Mux), profile information, earnings history, payout records, and Stripe Connect account ID.
Creator access requests. If you ask for creator access, we store the channel links and any note you send, along with when you asked, so we can review your request. If we dismiss a request, the links and note are cleared.
Visit counts. To see how the site is used (which pages people visit, where they arrive from, how many go on to sign up) we count page views ourselves, without cookies and without any third-party analytics service. Each count records the page, the site you came from, whether you're on a phone or a computer, and whether you're signed in. Instead of storing your IP address, we store an anonymous code made from it and your browser type with a secret that changes every day, so a visit can't be traced back to you or linked to your visits on other days. These counts are only looked at in total, and are deleted after 13 months.
Technical data. IP address, browser type, device type, and general location (country/region level) for security, fraud prevention, rate limiting, and debugging. We don't sell this data or use it for ad targeting.
We share data only with the services needed to run the platform:
Stripe — payment processing and creator payouts. Stripe receives your email and payment details directly (we never see card numbers). Creators complete identity verification directly with Stripe. Stripe's privacy policy
Mux — video hosting, encoding, and streaming. Mux processes uploaded video files on our behalf and serves them to viewers. Mux receives playback requests but not your account information. Mux's privacy policy
Resend — transactional email delivery (verification emails, payment receipts, notifications you've opted into). Resend receives your email address and the message content. Resend's privacy policy
Render — cloud hosting for our servers and database. Your data is stored on Render's infrastructure in the United States. Render's privacy policy
Offerwall partners (Lootably and others) — if you choose to complete offers, your anonymous ReactVault user ID is shared so they can credit your account. They don't receive your email, name, or other personal information from us. The offers themselves are provided by third-party advertisers with their own privacy policies.
Google Fonts — the site's typefaces are loaded from Google's font servers. When a page loads, your browser requests the font files directly from Google, which means Google receives your IP address and browser information for that request. Google does not receive your ReactVault account information. Google's privacy policy
Sentry — error monitoring. When something breaks on our servers, or the site hits an error in your browser, a report is sent to Sentry so we can fix it. Reports may include the URL you were on, your IP address, browser type, and technical details of the error. They never include passwords or payment information. Sentry's privacy policy
Law enforcement — only when legally required (valid subpoena, court order, or to prevent imminent harm). We'll notify you unless legally prohibited.
We don't share your data with anyone else.
We use a small number of strictly functional cookies:
That's it. No third-party tracking cookies, no advertising cookies, no analytics cookies. All of these are essential to the service working, so there's no cookie consent banner — there's nothing optional to consent to.
Your data is stored on servers in the United States. We use industry-standard security: encrypted connections (HTTPS), encrypted database storage, rate limiting, and access controls. Payment data is handled entirely by Stripe, which is PCI DSS Level 1 certified.
No system is perfectly secure. If we discover a data breach that affects your personal information, we'll notify you by email within 72 hours of confirming it.
Active accounts: data is kept as long as your account exists.
Deleted accounts: we remove your personal data, comments, and profile. Videos are unpublished and removed from Mux. We retain anonymized transaction records and moderation history as required by law (typically 7 years for financial records).
Creators: content is removed when you delete your account or when we remove it for policy violations. Earnings records are retained for tax compliance.
Access. You can view your account data, watch history, unlock history, and transaction history in Account settings. You can also download a complete export of your data from Account settings → Data & account.
Correction. Update your display name, avatar, and profile information anytime from Account settings.
Deletion. Delete your account from Account settings → Data & account. This removes your personal data from our systems. Certain records (payment history, moderation logs, DMCA notices) may be retained as required by law. Creators with pending earnings must have those paid out before deletion.
Portability. The data export includes your profile, transaction history, unlocks, watch progress, and uploads in JSON format.
Objection. If you're in a jurisdiction with additional data rights (EU/UK under GDPR, California under CCPA), email support@reactvault.tv and we'll honor your request within 30 days.
California residents. We don't sell personal information as defined by the CCPA. You have the right to know what data we collect, request deletion, and not be discriminated against for exercising these rights.
ReactVault is for adults 18 and over. We don't knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we'll close it and delete its data, apart from records we're required to keep by law, such as payment records. If you believe someone under 18 is using ReactVault, email support@reactvault.tv.
We can update this policy. Significant changes will be communicated through the platform at least 14 days before they take effect. The "last updated" date at the top shows the most recent revision.
Questions about your data? Email support@reactvault.tv.