Privacy Policy

Application: My LifeVault (Android)  ·  Publisher: VMH Digital  ·  Contact: mylifevaultapp@gmail.com

Effective / Last Updated: July 28, 2026

1. Who we are and what this policy covers

This Privacy Policy explains how VMH Digital ("we", "us", "our") — the developer and publisher of the My LifeVault Android application (the "App") — handles information in connection with the App and this website (vmhdigital.com/mylifevault).

For the personal records you create inside the App, you are the person in control: the data stays in the App's private storage area on your device and, if you choose to enable backup, in your own Google Drive account. We are the data controller only for the limited information described in sections 3 and 7, and for any message you voluntarily send to our support address.

By installing or using My LifeVault, you agree to this Privacy Policy. If you do not agree, please do not use the App.

2. What My LifeVault does with your information

Information you create in the App ("vault content")

This includes document and ID scans, generated PDFs, family member profiles (names, relationships, dates of birth, identity document numbers, clothing and shoe sizes), medical information (blood group, allergies, conditions, medications, health journal entries), emergency contacts, notes, tasks and reminder dates.

We do not collect, receive, transmit to ourselves, view, analyse, profile or sell your vault content. It is written to the App's private application directory on your device. There is no My LifeVault account, no login to our systems, and no automatic upload of your records to us.

Information we do not collect

The App does not contain analytics or crash-reporting SDKs that report your vault content to us, does not read your contacts, messages, call logs or browsing history, and does not track your location.

Information handled by third parties

The App is not entirely network-free, and we want to be precise about that. Two things involve the internet, and both are described in full below: (a) the optional Google Drive backup you may choose to enable (section 3), and (b) Google AdMob advertising and Google Play Billing in the free tier (section 7). Aside from these, the App's features — including scanning, OCR, search, PDF generation and reminders — function with your device offline.

3. Optional Google Drive backup and Google user data

Because your vault is stored only on your device, losing or resetting that device would mean losing your records. To protect against this, My LifeVault offers an optional, opt-in backup feature that stores an encrypted backup file in your own Google Drive.

What we ask for, and why

Access requestedWhy My LifeVault needs it
Sign in to your Google Account (basic profile / email address) To identify which Google Drive account the backup should be written to and read from, and to display the connected account in the App's Settings screen so you always know which account is linked.
Access to files in your Google Drive that were created by My LifeVault To upload your encrypted vault backup file, list the previous backups the App has made so you can pick one, download a backup during restore, and delete old backup files at your request.

What we cannot do

My LifeVault's Drive access is limited to files the App itself created. The App cannot browse, list, open, read, modify or delete any other file in your Google Drive, and it has no access to Gmail, Google Photos, Google Contacts, Google Calendar or any other Google service.

How your Google data is used and stored

  • The backup file is encrypted on your device with AES-256 using a password you choose, before it is uploaded. Neither VMH Digital nor Google can read its contents without that password.
  • The connection to Google is made directly between the App on your device and Google's servers. The backup file never passes through, and is never stored on, any server operated by VMH Digital.
  • OAuth access tokens issued by Google are stored only in secure storage on your device so the App can refresh your backup without asking you to sign in each time. They are not transmitted to us.
  • Your email address and Google profile information are used only for the on-device purpose described above. They are not stored on our systems, added to a mailing list, used for advertising, or shared with anyone.

It is optional

Every feature of My LifeVault other than Drive backup works without signing in to a Google Account. You may instead export your encrypted backup file to local device storage or any folder you choose. If you never enable Drive backup, no Google user data is accessed by the App at all.

4. Google API Services Limited Use disclosure

My LifeVault's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we affirm that data obtained through Google APIs is:

  • used only to provide and improve the user-facing backup and restore feature described in section 3;
  • never transferred to any third party, except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition with the user's consent;
  • never used for serving advertisements, including personalised, retargeted or interest-based advertising;
  • never sold to anyone, and never used to build user profiles or for creditworthiness or lending purposes;
  • never read by humans — no employee or contractor of VMH Digital reads your Google user data, other than (i) with your explicit consent for a specific support issue you have raised, (ii) where required for security purposes such as investigating abuse, or (iii) where required by applicable law. In practice the encrypted backup file is unreadable without your password in any case.

5. Encryption and security

  • On-device protection. Vault data is held in the App's private storage area, which the Android operating system isolates from other applications. Access to the App can be locked behind your device's biometric credential or a PIN you set.
  • Backup encryption. Exported backups (whether saved locally or to your Google Drive) are encrypted with 256-bit AES using a password you choose.
  • No password recovery. Because we operate no account system and hold no copy of your password, we cannot recover your backup password or reset it. If you lose it, that backup file cannot be decrypted by us, by Google, or by anyone else. Please store it somewhere safe.
  • Transport security. Communication with Google's APIs uses HTTPS/TLS.
  • Your responsibility. The security of your records also depends on your device: keep your operating system updated, use a screen lock, and avoid rooted or malware-infected devices. No method of electronic storage is completely secure, and we cannot guarantee absolute security.

6. Device permissions we request

My LifeVault requests only the Android permissions it needs to function. Each is used solely for the stated purpose, and never to collect data for us:

  • Camera — to scan and photograph documents inside the App and crop their borders. No image is uploaded anywhere by the App.
  • Biometrics / Fingerprint / Face unlock — invoked through the standard Android BiometricPrompt API to lock and unlock the App. We never receive your biometric data; it never leaves the secure hardware of your device.
  • Photos, media and files — to import scans you already have in your gallery, to save exported PDFs and backup files where you choose, and to receive files shared to the App from other apps.
  • Notifications — to deliver LifePulse expiry and task reminders. These are generated locally on your device by a local scheduler, not pushed from a server.
  • Internet / network access — required to display advertisements in the free tier, to process purchases through Google Play Billing, and to perform the optional Google Drive backup if you enable it.

You may deny or revoke any of these permissions in Android Settings; the corresponding feature will simply be unavailable.

7. Advertising, purchases and other third-party services

Google AdMob

The free tier of My LifeVault displays advertisements served by Google AdMob. To serve and measure ads, AdMob may collect and process device-level information such as your Android Advertising ID, IP address, device model, operating system version, and ad interaction events. This processing is carried out by Google as described in Google's Privacy Policy and the AdMob policies.

No vault content, document, family profile, medical entry, note or Google Drive data is ever shared with AdMob or used for advertising. You can reset or delete your Advertising ID, and opt out of ad personalisation, in Android Settings → Privacy → Ads. Purchasing the premium tier removes advertisements.

Google Play Billing

Premium upgrades are processed by Google Play Billing. Your payment details are handled entirely by Google — we never see or store your card number, billing address or payment credentials. We receive only the anonymous purchase token needed to confirm your entitlement.

On-device processing components

Text recognition uses Google ML Kit text recognition, which runs its models locally on your device; the images it processes are not sent to Google or to us.

This website

This website is static informational content. It sets no advertising or tracking cookies of our own. It does load web fonts from Google Fonts and an icon stylesheet from Cloudflare's CDN, and those providers may log your IP address as part of serving those files. Standard server access logs may be retained by our hosting provider for security and diagnostics.

We do not sell or share personal information with data brokers, and we run no third-party analytics on this site.

8. Data retention, revoking access and deletion

Your vault

Vault content remains on your device until you delete individual items, clear the App's data, or uninstall the App. Uninstalling My LifeVault removes its private storage, which permanently deletes your vault from that device — make a backup first if you want to keep your records.

Your Google Drive backups

Backup files remain in your Google Drive until you remove them. You can delete them in three ways:

  1. Inside the App: Settings → Backup & Restore, where you can delete individual backup files the App created.
  2. In Google Drive directly: open drive.google.com and delete the My LifeVault backup file, then empty the Trash.
  3. By revoking access: visit myaccount.google.com/permissions and remove My LifeVault. This immediately invalidates the App's access tokens. Note that revoking access stops future backups but does not itself delete files already in your Drive — delete those using method 1 or 2.

Disconnecting your Google Account

You can sign out of Google inside the App at any time from Settings → Backup & Restore → Disconnect account. This deletes the stored OAuth tokens and the cached account email from your device.

Support correspondence

If you email us, we retain that correspondence for as long as needed to resolve your issue and for a reasonable period afterwards for reference, and then delete it. You may ask us to delete it sooner at any time.

9. Children's privacy

My LifeVault is intended for adults managing a household's records and is not directed to children. We do not knowingly collect personal information from children under 13 (or the minimum age of digital consent in your jurisdiction, which may be higher). A parent or guardian may of course store their child's documents and medical details in their own vault; that information stays under the parent's control on the parent's device, and is not transmitted to us. Advertising in the App is not configured to target children.

10. Your privacy rights

Because your vault stays in your possession, you already hold direct rights of access, correction, export and erasure over it — you can view, edit, export and delete any record inside the App at any time, without asking us.

To the extent applicable law (including the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable laws elsewhere) gives you rights over information we or our providers process, you have the right to:

  • request access to, correction of, or deletion of personal information we hold about you;
  • object to or restrict certain processing, and withdraw consent you have given (for example, by disconnecting Google Drive backup);
  • opt out of personalised advertising, as described in section 7;
  • not be discriminated against for exercising these rights;
  • lodge a complaint with your local data protection authority.

Where we process the limited data described in this policy, our legal bases are your consent (Google Drive backup; personalised advertising where required), the performance of our agreement with you (providing the App's features), and our legitimate interests (securing the App, preventing abuse, funding the free tier through advertising).

We do not sell your personal information and we do not "share" it for cross-context behavioural advertising in the sense defined by the CPRA. To exercise any right, email mylifevaultapp@gmail.com and we will respond within the time required by applicable law.

11. International data transfers

We do not operate servers, so we do not transfer your vault anywhere. Where you enable Google Drive backup, or where advertising and billing are processed, the relevant data is handled by Google and may be stored and processed on Google's infrastructure in the United States and other countries, subject to Google's own safeguards and transfer mechanisms as described in Google's Privacy Policy. Your backup file is encrypted before it leaves your device, so its contents remain unreadable regardless of where the file is stored.

12. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to the App, to our practices, or to legal requirements. The "Last Updated" date at the top of this page always shows the current version. Material changes — for example, adding a new Google API scope or a new third-party service — will be announced on this page and in the App's release notes before or when they take effect. Continuing to use My LifeVault after an update means you accept the revised policy.

13. How to contact us

For privacy questions, data rights requests, or anything else about this policy:

We aim to respond to every privacy enquiry within 30 days.