DomainVault Buddy Privacy Policy
Last updated: July 18, 2026
Overview
DomainVault Buddy is a local-first macOS organizer made by VendStop LLC. This policy describes the native Mac app. A separately hosted online edition needs its own privacy policy based on the hosting configuration chosen by its owner.
Data the app stores
The app stores the website, domain, provider, renewal, email-address, note, document-reference, task, and AI-account information that you enter. The native app stores this information locally in an encrypted vault on your Mac. Its vault encryption key is stored in macOS Keychain.
DomainVault Buddy is not a password manager. It is designed to store the name or location of a credential in Apple Passwords, 1Password, Bitwarden, Keychain, or another trusted password manager, not the password, API key, recovery code, or private key itself.
Data collection and tracking
VendStop LLC does not receive the contents of the native app's local vault. The app does not include advertising, third-party analytics, tracking, or a VendStop account service. VendStop LLC does not sell app data.
User-initiated network requests
When you ask the app to research a public website, check a domain, open webmail, or synchronize with a supported hosting provider, the app connects directly to that website or provider. The app can also refresh public website research after unlock when the optional automatic-research setting is enabled. Those services receive ordinary network information such as your IP address and are governed by their own privacy policies. Provider credentials are stored in macOS Keychain and are sent only to the provider selected by the user.
Generic DNS and email-health checks send public query names and record types to Cloudflare's DNS-over-HTTPS service. Cloudflare receives ordinary network information, the public domain name, and requested record type. The app does not include notes, documents, passwords, provider tokens, or decrypted vault contents in those requests. When a domain advertises MTA-STS, the app also requests that domain's exact public MTA-STS policy file over HTTPS.
The app can load public website favicons for domain covers. The website hosting the favicon can receive an ordinary image request.
DreamHost inbox preview
The optional DreamHost Inbox Preview displays DreamHost Webmail in a temporary, nonpersistent in-app browser. The password and message content are sent to and rendered by DreamHost, not added to the DomainVault organizer. The preview restricts navigation to secure DreamHost Webmail, blocks third-party message images, and requests deletion of its temporary cookies and website data when closed. Users can instead open Webmail in their default browser.
Licensing and checkout
The Mac App Store build does not use external license keys, external license servers, or third-party checkout for app features. Direct-download editions may offer direct-sales license activation; that activation sends the license key and a random app-generated device ID to the configured license server so activation limits and revocation can be checked. License activation does not send vault notes, documents, provider tokens, passwords, or decrypted organizer records.
Notifications
Optional reminders are scheduled locally through the macOS notification system. DomainVault Buddy does not send vault contents to a remote notification service. By default, notification text uses generic wording without saved website, renewal, task, or account names. Users can opt into detailed wording. Notification previews may appear on the Lock Screen according to the user's macOS settings.
Backups and retention
Portable backups are encrypted with a passphrase chosen by the user. VendStop LLC cannot recover that passphrase. Local data remains on the Mac until the user deletes it, erases the vault in Settings, or removes the app's data. Removing the app alone may not remove its Application Support or Keychain data.
Your choices
Users can avoid provider synchronization and website scanning and enter information manually. Users can export an encrypted backup or erase all local vault data from Settings.
Contact
For privacy or support questions about DomainVault Buddy, contact VendStop LLC at support@vendstopllc.com or visit /support/domainvault-buddy/ and use the support request form. Do not include passwords, API keys, recovery codes, private keys, or other secrets in support requests.