Privacy Policy

United States · MiSalvo Inc. · Effective 1 October 2026 · Last updated 16 September 2026

Entity: MiSalvo Inc. (Delaware)

1. Short version

MiSalvo is built so that staff cannot read your Vault papers. Documents are encrypted on your device. We store ciphertext and the account / household metadata needed to run the service. Meaningful content is decrypted on your devices (and recovery paths you choose).

We do not sell your personal information. We do not run advertising trackers or ad SDKs in the app. We do not scan your email or messages. We do not use your documents to train MiSalvo AI models. Optional preferred professionals are not available at launch. If we later offer that path, we may be compensated for intros. Never from money that is yours. See §7.1.

On misalvo.com only, we use Cloudflare Web Analytics for aggregate page views and site performance. It is not in the mobile app, does not read Vault papers, and is not used for advertising or cross-app profiling.

Labelling of merchants and document types happens on your device. Cloud label assist is not on at this launch. If we later turn it on, we will update this policy and our App Store privacy labels first. See Section 4.10.

This summary is a guide. The full policy below controls.

2. Who we are

This Service is operated by MiSalvo Inc., a Delaware corporation (“MiSalvo,” “we,” “us”).

Contact for privacy requests: in-app Account → Help / support (product contact is in-app; we do not require an email address to use MiSalvo).

Public Privacy Policy URL: https://misalvo.com/privacy

Mailing / registered address: Suite 4910, 1007 N Orange St, 4th Floor, Wilmington, DE 19801, USA

“You” means anyone who uses the MiSalvo iOS app or this website (the “Service”). When we launch on Google Play, the Android app is part of the Service too.

US launch. This policy is for a United States launch. The app ships on the Apple App Store first. When we launch on Google Play, this policy also covers that Android app. Rights and notices for UK, EU, Singapore, and other markets will be added as schedules when those storefronts open.

App license and website Terms. Downloading the iOS app is licensed under Apple’s Standard Licensed Application End User License Agreement, unless Apple later shows a custom license for MiSalvo. This Privacy Policy still applies. Our website Terms cover misalvo.com. They are not a second App Store license.

GDPR-aligned design (aim, not a certification claim). MiSalvo is built towards strong European-style data-protection practices associated with the GDPR (and UK GDPR): data minimisation, purpose limitation, security by design, user access/export, and erasure. Ciphertext sits on our servers. Keys sit on your devices. There is no staff plaintext viewer for Vault papers. Hosting today is in the United States (Ohio). UK households, and EU households including Ireland, are designed for a host in Frankfurt, Germany when those stores open. That project is not live. South America is planned for São Paulo, Brazil. Asia-Pacific is planned for Singapore. When we open India, those households will use Mumbai, India. South Africa stays on the United States host until a local option exists. Canada and Mexico stay on the United States host. We are not claiming GDPR certification, ICO registration completion, an EU Article 27 representative, “hosted in Europe,” or that this US policy alone makes us “GDPR compliant” for UK/EU users. Those steps belong to later market waves. The architecture is intended so those schedules are documentation and registration work, not a rebuild. See Section 8.1.

3. Our privacy model

Three design choices drive this policy:

1. Encrypted Vault. Papers are sealed on device. Servers hold ciphertext plus operational metadata. Staff cannot read document bodies.

2. Biometric sign-on. Day-to-day access uses your device’s biometrics (Face ID / Touch ID) or device passcode path. Not an email-and-password login. When we launch on Google Play, Android’s equivalent biometric / passcode path applies. Recovery uses materials you hold: Vault key, optional Spare Key, or another signed-in device (one-time recovery code). We do not run a password-reset email channel. That would require keys we could read.

3. No staff document viewer. We do not decrypt Vault papers for support, marketing, or “AI convenience.”

Custody is still real. While your account is active, MiSalvo Inc. holds sealed blobs on cloud infrastructure so devices can sync. Encryption means staff cannot read papers. It does not mean nobody holds anything. See Section 10 (deletion) and our Security page for the honest leave story.

Biometrics. We do not collect or store your biometric templates. Unlock uses your device’s built-in biometric / passcode facilities (Face ID / Touch ID on Apple devices, and the equivalent on Android when we launch on Google Play). We never receive your biometric templates from the operating system.

4. Information we hold

4.1 Account and profile

Examples:

We do not require an email address or phone number to create or use a MiSalvo account. Product contact is in-app (and optional push if you turn it on).

Optional contact details you choose to save (for example email, postal address, or mobile number for your own records or Salvo slots) are designed to be sealed in your Vault under your keys. Same posture as your papers. MiSalvo staff do not have a tool to read those sealed fields. Coarse account metadata needed to run the Service (ids, plan flags, Circle roles) may remain outside that sealed envelope as described elsewhere in this section.

4.2 Payment and entitlement flags

Subscriptions and trials at this US launch are billed through the Apple App Store. Apple is the merchant of record for that purchase. When we launch on Google Play, Google will be the merchant of record for purchases made there. We receive subscription / entitlement status needed to provide paid features. Not your full card number. Apple’s privacy terms apply to payment data Apple holds. Google’s will apply when that store is live.

We may store plan tier, subscription active flags, and Vault trial end timestamps so the product can enforce freemium rules (for example: Missions free; Vault trial starting when you confirm seats and start the trial on first paper save; Circle invites only while a trial or paid plan is active). These are operational account flags. Not document contents.

4.3 Encrypted Vault documents

Captured papers (camera, Photos, Files, Share Sheet, and similar) are encrypted on device and stored as ciphertext with related cryptographic metadata (for example IVs). Coarse plaintext fields may exist for product filters (for example capture source tag, timestamps, security tier Protected / Fortified, share status). Rich document meaning and sealed provenance detail stay under keys we do not hold in the clear.

We cannot produce readable Vault document content for staff, advertisers, or routine support.

4.4 Circle, Missions, notifications

To run household life-admin we store mission titles, dates, assignees, status, and related coordination data; in-app notification inbox rows; and Circle membership metadata. Mission “place” data you add for Nearby stays subject to your Nearby opt-in. Live GPS for Nearby matching is designed to stay on device and is not uploaded for matching by default.

4.5 Salvo packs and sharing

When you prepare or fire a Salvo, we may store pack metadata (path, status, token, expiry, open counts) and sealed pack ciphertext for revocable secure links. We do not keep readable pack letter bodies on our servers. Recipients who open a link decrypt with material in the part of the URL after the #, on their client. That key is not intended for our server logs.

4.6 Device and technical data

Examples: device type, OS version, app version, approximate connection metadata (for example IP at request time as processed by our hosts), crash / diagnostic signals we use to keep the Service reliable. Prefer platform crash infrastructure where practical. We do not embed advertising, MMP, or third-party product-analytics SDKs.

4.7 Optional push delivery

If you enable push notifications, we may use a push delivery provider (currently OneSignal) with the platform push service. On iOS that is Apple Push Notification service. When we launch on Google Play, that may also include Firebase Cloud Messaging / Google. That provider receives a device push token, an opaque account identifier we choose (not your name or documents), and delivery metadata. We do not send Vault contents, Salvo pack bodies, or document text to that provider. Lock-screen text is kept generic. Detail stays in the in-app inbox. We do not use this provider for advertising or email/SMS contact.

4.8 First-party product events

We may record allowlisted first-party product events (coarse product usage signals) to improve the Service. These events are designed not to include Vault document bodies, OCR text, or Salvo pack meaning.

4.9 What we do not collect as account fields

4.10 Optional cloud label assist (not on at launch)

Most labelling of merchants and document types happens on your device (OCR, catalogs, on-device learned labels). There is no free-form chat with your Vault.

Not on at this launch. We may later add a thin paid cloud label assist when on-device confidence is low. That would be a contracted enterprise service under no-training terms. Not a chat that reads your life. If we turn it on, we will update this Privacy Policy and our App Store privacy labels before it ships. Until then, labelling stays on your device.

If cloud assist later ships, only an allowlisted short text snippet would go to that automated service. Not your full document, photo, or PDF. Not your keys. We would name the provider in this policy and in App Store privacy disclosures when the contract is signed.

What we would send

What we would never send

Disclosure. If cloud assist ships, you will see a short in-app notice when it is used. Caps and a kill-switch may stop cloud assist. The app continues with on-device labelling.

Vendor retention. How long a contracted provider may retain a snippet for abuse, security, or legal compliance would be set in that enterprise agreement and summarized here when signed. Training on your content remains off under the enterprise posture we would require.

Analytics. If this path ships, durable product analytics would use allowlisted reason codes and counts (for example why assist was needed). Not raw OCR, merchant strings, or document identifiers in those dashboards.

Fortified papers. If cloud assist ships, Fortified papers stay on-device only unless you confirm with a fresh biometric before a snippet leaves.

5. Circle and children’s information (COPPA-critical)

5.1 Account holders (18+)

Only adults 18 or older may create and own a MiSalvo account (bill-paying account holder). By creating an account you represent that you are 18+.

5.2 Invited Adults and Seniors

Adults and Seniors invited into a Circle create their own MiSalvo profile / session. They accept this Privacy Policy themselves. On iOS they also accept Apple’s Standard Licensed Application EULA when they download the app. They typically use seats on the bill payer’s plan and do not buy a separate subscription. Each adult member’s Vault is theirs. MiSalvo does not give the bill payer a staff-style back door into another Adult’s Vault.

5.3 Juniors (children under parental or legal guardian responsibility)

The bill-paying account holder may add minor children for whom they have parental or legal guardian responsibility as Juniors, with parental / guardian attestation. Launch posture:

5.4 Admin role

A bill payer may grant Admin (circle ops). Admin is not ambient access to other Adults’ Vaults or ambient Junior papers beyond product rules. See Circle product rules.

6. How we use information

We use what we hold to:

We do not sell personal information. We do not use Vault documents to train MiSalvo models. We do not use personal information for cross-context behavioral advertising.

On-device features (OCR, Ask me, Finance-style summaries) run over content decrypted on your device in session. Not as a staff-readable server pipeline.

Cloud label assist (Section 4.10) is not on at this launch. If we later turn it on, it would use allowlisted short snippets only, to return a structured label, under enterprise / no-train terms. It would not train MiSalvo models and would not be a Vault chat.

Nothing readable leaves your Vault unless you send it (or a recipient opens a link you fired).

When you share, download, print, AirDrop, email, upload, or Fire a Salvo pack or other export, including to a laptop, employer portal, insurer, tax software, or government site, you are sending that information outside MiSalvo. We do not control those systems. They may log, retain, or track activity under their own policies. MiSalvo is not responsible for privacy or tracking practices of services you choose to send your packs to.

Secure links and PDFs. Secure-link recipients decrypt on their client. Revoking a link affects stored share access we control. It cannot undo screenshots or copies already made outside MiSalvo. A PDF or file you Share via the system share sheet is likewise under the recipient’s (or the channel’s) rules once it leaves the app.

External links (for example IRS.gov or other official sites). The app may show links to third-party websites (tax agencies, benefit portals, insurers, and similar). Tapping a link opens that site in a Safari view inside the app so you can tap Back and return to MiSalvo. That site’s privacy policy, cookies, and tracking rules still apply. We do not control those sites. On misalvo.com, official links open in the same tab so your browser’s back arrow returns you to MiSalvo.

7.1 Preferred professionals and partners (future release)

In a future release, some Salvos (for example Estate) may, in some markets, offer an optional way to contact a preferred professional (such as a solicitor or other licensed adviser) or show a partner-powered panel. This feature will not be available at launch. When introduced, that path will be strictly optional. You can always gather and Fire a pack yourself without using it. Preferred panels may be unavailable, demo-only, limited to certain countries, or never ship. The product chrome will say so when a panel is not live.

What we share with partners. We do not give preferred partners your Vault keys or readable Vault papers. Firm / panel rows are business directory metadata (for example firm name, area, contact details). If you choose Contact or a similar intro, you start that outreach (for example by email or another channel you confirm). Coarse attribution for a panel (for example that a contact was started) may be recorded so we and a channel partner can run the panel. Not document contents.

Compensation, and what we never take. If this path later ships, MiSalvo and/or a named channel partner may be compensated when you use a preferred Contact / intro (for example a fee or revenue share with the firm channel). That is separate from your Apple App Store subscription, and from Google Play billing when we launch that store.

We are never compensated from money that is yours. We do not take a cut of tax refunds, benefit payments, claim payouts, reimbursements, estate or inheritance proceeds, or other money you recover or receive. Preferred-partner economics are not a share of your outcome.

Preferred listing is not a MiSalvo endorsement of legal quality. Professionals keep their own tools and terms once you leave MiSalvo.

8. Service providers (processors)

We use providers to host and operate the Service, including for example:

They process data on our behalf for those purposes.

8.1 Regional hosts (intent)

Live today. Sealed Vault copies for TestFlight and the current US backend sit in the United States (Ohio). Households in the United States, Canada, and Mexico use that Americas host. Catalogs and a country picker are not residency.

Design for later storefronts. When those App Stores open, new bill-paying households should land on a regional home. Not Ohio.

One Circle uses one backend. Invitees join the bill payer’s host. We do not dual-write Vault ciphertext across oceans.

Apple, App Store billing, APNs, and optional OneSignal remain separate processors. They may process outside the household’s database region even after we move that database. When we launch on Google Play, Google billing and Android push may do the same.

Picking a city is not GDPR, PIPEDA, LGPD, or DPDP certification. We do not claim “hosted in Europe” while live traffic is in the United States.

9. Your rights and choices

9.1 United States privacy rights

Privacy rights vary by state. California residents (CCPA/CPRA) and residents of other comprehensive state privacy laws may have rights to know / access, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising.

MiSalvo does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are commonly understood. We do not run advertising SDKs that would require App Tracking Transparency for that purpose.

How to exercise rights: use in-app Account → data / privacy / leave flows where available, or in-app Help / support. Because we have no email login, identity verification for rights requests may rely on signed-in session and account controls.

Structural note: For Vault ciphertext, you already control keys on device. Download your data (complete export of owned documents) and schedule account deletion are the primary portability and erasure paths (Section 10).

Do Not Sell / Share. Because we do not sell or share for cross-context ads, a “Do Not Sell” link is not used as an advertising opt-out mechanism. We do not currently honor Global Privacy Control as a separate site signal. If law later requires a specific link or browser signal for other processing, we will update this page.

9.2 European data protection principles (GDPR and UK GDPR design alignment)

The General Data Protection Regulation (GDPR) in the European Union and the UK GDPR set principles for protecting personal data. MiSalvo’s US product is designed around those ideas. This is an architecture aim. It is not a certification.

Scope. The mapping above describes product engineering. Our initial launch is the United States App Store with hosting in the US. We do not claim formal third-party GDPR certification, completed European Data Protection Authority registrations, or an EU Article 27 representative. UK, Ireland, and EU households are designed for a Frankfurt host when those stores open. That host is not live. Dedicated regional schedules and local representative disclosures will be published as UK and European storefronts open.

10. Export, retention, and account deletion

10.1 Download your data

From Account → data / leave you can run a biometric-gated complete export of documents you own (usable files + index), decrypted with your keys. Large Vaults may use a time-limited laptop download link (key in the part of the URL after the #). Export is not emailed to you. Staff cannot open the archive as plaintext.

10.2 Schedule leave / delete account

Apple requires in-app account deletion. Google will require the same when we launch on Google Play. Our product path:

1. Confirm you saved your export

2. Schedule account deletion

3. 14-day cooling-off (you can cancel)

4. Hard wipe of account data we control (including storage objects and auth), and local crypto cleanup as designed

Ending a Vault trial or cancelling store billing is not the same as deleting the account. A free Missions-only account may continue until you schedule leave / delete.

Circles: scheduling leave leaves Circles quietly first where the product supports that. Remaining members may get an in-app note and time to save shared docs. Not a public announcement push about why you left.

After wipe: we do not keep a product “about 30-day debug” copy of Vault content for AI or convenience. Cloud backups may lag for a limited time (infrastructure reality). That residual window is custody time, not a staff reader.

10.3 Retention while active

We retain account, Circle, mission, notification, and ciphertext storage while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations.

We comply with valid legal process. Architecture limits what we can produce: we cannot hand over readable Vault document content for which we do not hold the keys. We may provide account metadata, subscription status, operational records, and sealed blobs as held.

12. Security

Plain-language overview (what we claim and what we do not): Security.

We use encryption, access controls, and defense-in-depth security measures. No system is perfectly secure. Core defence: an attacker who reached our servers would find ciphertext and metadata, not staff-readable Vault papers. Sealed custody still exists.

Our security architecture includes hardware-backed biometric verification, automatic lockdown upon device biometric database modification, emergency remote freeze capabilities across trusted Circle members, cryptographic session revocation, and zero-knowledge key restoration.

If you lose all signed-in devices, your Vault key, and Spare Key paths (and cannot use another device to send a recovery code), Vault plaintext may be unrecoverable by design. Keep recovery materials safe.

Junior recovery is different. A Junior is not required to retain a Vault key or nominate a Spare Key. After a biometric check, the bill payer can issue a fresh private recovery link. Its short-lived, one-time secret is not shown in the message or sent to MiSalvo’s web server. It reconnects the existing Junior Vault and revokes prior Junior sessions.

These controls support our GDPR-aligned design aim (Section 2): minimisation, security by design, export, and erasure. Without claiming a GDPR certificate or completed UK/EU formalities.

13. Children and age

The Service is not directed at children under 13 as a standalone audience. Independent account ownership is limited to adults 18+. A parent or legal guardian may provision a restricted Junior session and custodial Junior Vault under Section 5. The child cannot create that relationship alone.

14. Changes

We may update this policy. We will post the revised version with a new effective date at the Privacy Policy URL and in-app. Material changes will be shown in the app. Continued use after the effective date means you accept the updated policy where permitted by law.

15. Contact

Privacy questions and requests: in-app Account → Help / support.

Legal notices: see Contact, or write to .