← Vaultwell

Vaultwell for Webflow: Privacy Policy

Effective date: October 1, 2026 Vaultwell is made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA ("we"). Contact: hello@greatwork.company. This policy covers the Vaultwell app for Webflow (the Designer Extension and our backend at addons.greatwork.company).

What Vaultwell does with your data

Vaultwell keeps snapshots of your site's CMS so you can see what changed and put it back. A snapshot reads every collection on the site (its fields) and every item (drafts and archived included, every locale) through Webflow's API, and stores a compressed, encrypted copy on our server. Between snapshots, Webflow tells Vaultwell when an item is created, changed or deleted, and Vaultwell keeps the item as Webflow describes it. When you restore, Vaultwell writes saved values back through Webflow's API, only after you confirm a preview.

Your CMS content can contain personal data (for example names or emails in a collection). Vaultwell stores it only as part of the snapshots described here, only for your site, and only for your plan's retention.

What we store, and for how long

WhatWhyHow long
Webflow access token for your site (encrypted, AES-256-GCM)to take snapshots and restore through Webflow's APIuntil you remove Vaultwell, uninstall it, or revoke access
Snapshots: each collection's fields and items, as they were (compressed, encrypted)the backup itself; unchanged items are stored onceyour plan's retention: 90 days on Standard and Workspace, 1 year on Pro; the oldest go first if you reach your plan's storage (1 GB Standard, 5 GB Pro)
Captured changes: items as Webflow reported them between snapshots (encrypted)the item historysame as snapshots
Pro: copies of the images and files your items use (encrypted)so a restore works after an asset was removedsame as snapshots
Item names, slugs, status, Webflow's last-updated time and updated-by user id, per saved versionto list and search historysame as snapshots
Restore log: when, what kind, counts, and a report (encrypted)so you can see what a restore did90 days
Schedule settings, site name, site ID, workspace ID, locale list, the email of the signed-in Webflow userto run your schedule, identify the site for billing and send receiptswhile you use Vaultwell; billing records as tax law requires

When a trial or plan ends, new snapshots stop and the saved data is kept 30 days so you can export it, then deleted. Server logs record the time, method, path and status of each request for 30 days. They never include tokens, OAuth codes, query strings, file links, request bodies, or your CMS content.

Who processes data (every third-party domain the app contacts)

DomainWhoWhat for
webflow.com, api.webflow.comWebflow, Inc.OAuth sign-in, reading and writing your CMS, item webhooks
cdn.prod.website-files.com (and other Webflow asset hosts on website-files.com)Webflow, Inc.Pro only: downloading the images and files your items use, to keep copies
addons.greatwork.companyGreat Work LLC (our server, hosted by DigitalOcean in New York, USA)runs the backend, stores snapshots, licensing; serves one-time links to our image copies when Webflow needs them during a restore
checkout.stripe.com, billing.stripe.comStripe, Inc.payments and billing (we never see card numbers)
greatwork.companyGreat Work LLCproduct, documentation, privacy and terms pages

We don't sell personal data, don't use your content for advertising or to train AI models, and don't use advertising or analytics trackers in the app. No person at Great Work looks at your snapshots unless you ask us to help with a specific problem and give us permission, or the law requires it.

Deletion

  • Remove Vaultwell from this site (Settings) deletes our webhooks, every snapshot, captured change, image copy and log entry for the site, and revokes and deletes our Webflow token.
  • Uninstall or revoke: when Webflow tells us the authorization is gone (any request answered "unauthorized", plus a daily check, because Webflow sends no uninstall notice), we delete the token and all data for its sites, usually within 24 hours.
  • After a lapse: 30 days after a trial or plan ends without a new plan, all saved data for the site is deleted.
  • Your Webflow CMS is never changed by removal or deletion.

Your rights

You can ask for a copy of your data, correction or deletion at hello@greatwork.company; you can also export any snapshot as CSV or JSON yourself. If you are in the EU or UK you can also complain to your data protection authority. Where your content contains other people's personal data, you are the controller and we process it for you (see the terms for a data processing agreement).

Security

Tokens and all saved content are encrypted at rest with keys kept outside the database; each piece of saved content is bound to its site, so it can't be opened as another site's. The backend runs under its own unprivileged user on a hardened server, behind TLS. The Designer Extension never receives a Webflow token.

Changes

We'll post changes here and update the date; material changes are announced in the app.