Privacy Policy

United States · MiSalvo Inc. · Effective 6 August 2026*

MiSalvo — Privacy Policy (United States)

* Awaiting counsel sign-off.

Entity: MiSalvo Inc. (Delaware)

1. Short version

MiSalvo is built so that staff cannot read your Vault papers. Documents are encrypted on your device; we store ciphertext and the account / household metadata needed to run the service. Meaningful content is decrypted on your devices (and recovery paths you choose).

We do not sell your personal information. We do not run advertising trackers or ad SDKs in the app. We do not scan your email or messages. We do not use your documents to train MiSalvo AI models.

Most labelling of merchants and document types happens on your device. When a label is unclear, MiSalvo may briefly use a private automated cloud label service under contract (Section 4.10). That service receives only a short text snippet — not your Vault papers, not your keys, and not a chat that reads your life. We do not sell your data or use your documents to train MiSalvo AI models.

This summary is a guide. The full policy below controls.

2. Who we are

This Service is operated by MiSalvo Inc., a Delaware corporation (“MiSalvo,” “we,” “us”).

Contact for privacy requests: in-app Account → Help / support (product contact is in-app; we do not require an email address to use MiSalvo).

Public Privacy Policy URL: https://misalvo.com/privacy

Mailing / registered address: Suite 4910, 1007 N Orange St, 4th Floor, Wilmington, DE 19801, USA

You” means anyone who uses the MiSalvo mobile apps (including on Apple iOS and Google Android platforms) or website (the “Service”).

US launch. This policy addresses a United States launch on major app stores. We may ship on Apple App Store first and Google Play when ready — this policy is written to cover both distribution channels. Rights and notices for UK, EU, Singapore, and other markets will be added as schedules when those storefronts open.

GDPR-aligned design (aim — not a certification claim). MiSalvo is built toward strong European-style data-protection practices associated with the GDPR (and UK GDPR): data minimisation, purpose limitation, security by design, user access/export, and erasure — with ciphertext on our servers, keys on your devices, and no staff plaintext viewer for Vault papers. Hosting today is in the United States (us-east-2). We are not claiming GDPR certification, ICO registration completion, an EU Article 27 representative, or that this US policy alone makes us “GDPR compliant” for UK/EU users. Those steps belong to later market waves. The architecture is intended so those schedules are documentation and registration work, not a rebuild.

3. Our privacy model

Three design choices drive this policy:

1. Encrypted Vault. Papers are sealed on device. Servers hold ciphertext plus operational metadata — not staff-readable document bodies.

2. No email / password login. Day-to-day access uses your device’s biometrics (Face ID / Touch ID) or device passcode path. Recovery uses materials you hold (master phrase, Spare Key). We do not run a password-reset email channel.

3. No staff document viewer. We do not decrypt Vault papers for support, marketing, or “AI convenience.”

Custody is still real. While your account is active, MiSalvo Inc. holds sealed blobs on cloud infrastructure so devices can sync. Encryption means staff cannot read papers — not that nobody holds anything. See Section 10 (deletion) and our Trust Promise for the honest leave story.

Biometrics. We do not collect or store your biometric templates. Unlock uses your device’s built-in biometric / passcode facilities (for example Face ID / Touch ID on Apple devices, or the equivalent on Android). We never receive your biometric templates from the operating system.

4. Information we hold

4.1 Account and profile

Examples:

We do not require an email address or phone number to create or use a MiSalvo account. Product contact is in-app (and optional push if you turn it on).

Optional contact details you choose to save (for example email, postal address, or mobile number for your own records or Salvo slots) are designed to be sealed in your Vault under your keys — the same posture as your papers. MiSalvo staff do not have a tool to read those sealed fields. Coarse account metadata needed to run the Service (ids, plan flags, Circle roles) may remain outside that sealed envelope as described elsewhere in this section.

4.2 Payment

Subscriptions and trials are billed through the Apple App Store and/or Google Play, depending on which store you used. Apple or Google (as applicable) is the merchant of record for that purchase. We receive subscription / entitlement status needed to provide paid features — not your full card number. Apple’s and Google’s privacy terms also apply to payment data they hold.

4.3 Encrypted Vault documents

Captured papers (camera, Photos, Files, Share Sheet, and similar) are encrypted on device and stored as ciphertext with related cryptographic metadata (e.g. IVs). Coarse plaintext fields may exist for product filters (e.g. capture source tag, timestamps, security tier Protected / Fortified, share status). Rich document meaning and sealed provenance detail stay under keys we do not hold in the clear.

We cannot produce readable Vault document content for staff, advertisers, or routine support.

4.4 Circle, Missions, notifications

To run household life-admin we store mission titles, dates, assignees, status, and related coordination data; in-app notification inbox rows; and Circle membership metadata. Mission “place” data you add for Nearby stays subject to your Nearby opt-in; live GPS for Nearby matching is designed to stay on device and is not uploaded for matching by default.

4.5 Salvo packs and sharing

When you prepare or fire a Salvo, we may store pack metadata (path, status, token, expiry, open counts) and sealed pack ciphertext for revocable secure links. We do not keep readable pack letter bodies as a product store (pack_artifact_text is not the model). Recipients who open a link decrypt with material in the URL fragment on their client — that key is not intended for our server logs.

4.6 Device and technical data

Examples: device type, OS version, app version, approximate connection metadata (e.g. IP at request time as processed by our hosts), crash / diagnostic signals we use to keep the Service reliable. Prefer platform crash infrastructure where practical; we do not embed advertising, MMP, or third-party product-analytics SDKs.

4.7 Optional push delivery

If you enable push notifications, we may use a push delivery provider (currently OneSignal) with the platform push service (Apple Push Notification service and/or Firebase Cloud Messaging / Google as applicable). That provider receives a device push token, an opaque account identifier we choose (not your name or documents), and delivery metadata. We do not send Vault contents, Salvo pack bodies, or document text to that provider. Lock-screen text is kept generic; detail stays in the in-app inbox. We do not use this provider for advertising or email/SMS contact.

4.8 First-party product events

We may record allowlisted first-party product events (coarse product usage signals) to improve the Service. These events are designed not to include Vault document bodies, OCR text, or Salvo pack meaning.

4.9 What we do not collect as account fields

4.10 Optional cloud label assist (classify rescue) — launch AI

Product intent for launch: at least one level of paid cloud AI — thin classify rescue only (not chat). Canonical design: docs/MISALVO_AI_LAUNCH_LAW.md. If we later add more AI surfaces, we will update this Privacy Policy and the Terms.

Confidence rule. Your Vault papers, sealed contact fields, encryption keys, master phrase, and Spare Key material are not opened for MiSalvo staff, advertisers, or ordinary third parties. We do not sell your personal information. We do not embed ad or tracking SDKs that siphon document meaning. Cloud label assist, when used, is a narrow, contracted exception: only an allowlisted short text snippet goes to a private automated enterprise cloud label service so a label can come back — not your full document, photo, or PDF, and not your keys.

Most labelling of merchants and document types happens on your device (OCR, catalogs, on-device learned labels). When on-device confidence is low, MiSalvo may send a short text snippet through our Classify Gateway to a contracted enterprise AI provider selected for no-training / no use of your content to improve their models (as stated in that provider’s enterprise terms with us). We do not use that content to train MiSalvo models.

We name the specific provider in our subprocessor / app-store privacy disclosures when the contract is signed. Until then, this policy describes the rules the provider must meet, not a brand name — so choosing among qualifying vendors does not change what you are promised.

Disclosure. You will see a short in-app notice when cloud assist is used (butler, clear language). Caps and a kill-switch may stop cloud assist; the app continues with on-device labelling.

Vendor retention. Exact how long a contracted provider may retain a snippet or related log for abuse, security, or legal compliance is set in that enterprise agreement and will be summarized here when signed. Training on your content remains off under the enterprise posture we require.

Analytics. Durable product analytics for this path use allowlisted reason codes and counts (e.g. why rescue was needed) — not raw OCR, merchant strings, or document identifiers in those dashboards.

Fortified papers. Prefer on-device-only labelling, or a fresh biometric confirm before a snippet leaves, as implemented at ship.

5. Circle and children’s information (COPPA-critical)

5.1 Account holders (18+)

Only adults 18 or older may create and own a MiSalvo account (bill-paying account holder). By creating an account you represent that you are 18+.

5.2 Invited Adults and Seniors

Adults and Seniors invited into a Circle create their own MiSalvo profile / session and accept these Terms and this Privacy Policy themselves. They typically use seats on the bill payer’s plan and do not buy a separate subscription. Each adult member’s Vault is theirs — MiSalvo does not give the bill payer a staff-style back door into another Adult’s Vault.

5.3 Juniors (own minor children only)

The bill-paying account holder may add their own minor children as Juniors, with parental / guardian attestation. Launch posture:

5.4 Admin role

A bill payer may grant Admin (circle ops). Admin is not ambient access to other Adults’ Vaults or ambient Junior papers beyond product rules. See Circle product rules.

6. How we use information

We use what we hold to:

We do not sell personal information. We do not use Vault documents to train MiSalvo models. We do not use personal information for cross-context behavioral advertising.

On-device features (OCR, Ask me, Finance-style summaries) run over content decrypted on your device in session — not as a staff-readable server pipeline.

Cloud label assist (Section 4.10) uses allowlisted short snippets only, to return a structured label, under enterprise / no-train terms. It is not used to train MiSalvo models and is not a Vault chat.

Nothing readable leaves your Vault unless you send it (or a recipient opens a link you fired).

When you share, download, print, AirDrop, email, upload, or Fire a Salvo pack or other export — including to a laptop, employer portal, insurer, tax software, or government site — you are sending that information outside MiSalvo. We do not control those systems. They may log, retain, or track activity under their own policies. MiSalvo is not responsible for privacy or tracking practices of services you choose to send your packs to.

Secure links and PDFs. Secure-link recipients decrypt on their client. Revoking a link affects stored share access we control; it cannot undo screenshots or copies already made outside MiSalvo. A PDF or file you Share via the system share sheet is likewise under the recipient’s (or the channel’s) rules once it leaves the app.

External links (e.g. IRS.gov or other official sites). The app may show links to third-party websites (tax agencies, benefit portals, insurers, and similar). If you tap such a link, you leave MiSalvo and that site’s privacy policy, cookies, and tracking rules apply. We do not control those sites.

8. Service providers (processors)

We use providers to host and operate the Service, including for example:

They process data on our behalf for those purposes.

9. Your rights and choices (US)

Privacy rights vary by state. California residents (CCPA/CPRA) and residents of other comprehensive state privacy laws may have rights to know / access, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising.

MiSalvo does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are commonly understood. We do not run advertising SDKs that would require App Tracking Transparency for that purpose.

How to exercise rights: use in-app Account → data / privacy / leave flows where available, or in-app Help / support. Because we have no email login, identity verification for rights requests may rely on signed-in session and account controls.

Structural note: For Vault ciphertext, you already control keys on device. Download your data (complete export of owned documents) and schedule account deletion are the primary portability and erasure paths (Section 10).

Do Not Sell / Share. Because we do not sell or share for cross-context ads, a “Do Not Sell” link is not used as an advertising opt-out mechanism. If law requires a specific link or signal (e.g. GPC) for other processing,.

10. Export, retention, and account deletion

10.1 Download your data

From Account → data / leave you can run a biometric-gated complete export of documents you own (usable files + index), decrypted with your keys. Large Vaults may use a time-limited laptop download link (key in URL fragment). Export is not emailed to you. Staff cannot open the archive as plaintext.

10.2 Schedule leave / delete account

Apple and Google require in-app account deletion where applicable. Our product path:

1. Confirm you saved your export (data_export_confirmed_at)

2. Schedule account deletion

3. 14-day cooling-off (you can cancel)

4. Hard wipe of account data we control (including storage objects and auth), and local crypto cleanup as designed

Ending a trial or cancelling store billing is not the same as deleting the account.

Circles: scheduling leave leaves Circles quietly first where the product supports that. Remaining members may get an in-app note and time to save shared docs — not a public announcement push about why you left.

After wipe: we do not keep a product “~30-day debug” copy of Vault content for AI or convenience. Cloud backups may lag for a limited time (infrastructure reality). That residual window is custody time, not a staff reader.

10.3 Retention while active

We retain account, Circle, mission, notification, and ciphertext storage while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations.

We comply with valid legal process. Architecture limits what we can produce: we cannot hand over readable Vault document content for which we do not hold the keys. We may provide account metadata, subscription status, operational records, and sealed blobs as held.

12. Security

We use encryption, access controls, and related measures. No system is perfectly secure. Core defence: an attacker who reached our servers would find ciphertext and metadata, not staff-readable Vault papers — subject to the honesty that sealed custody still exists.

If you lose all devices, your master phrase, and Spare Key paths, Vault plaintext may be unrecoverable by design. Keep recovery materials safe.

These controls support our GDPR-aligned design aim (Section 2): minimisation, security by design, export, and erasure — without claiming a GDPR certificate or completed UK/EU formalities.

13. Children and age

The Service is not directed at children under 13 as a standalone audience. Account creation is limited to adults 18+. Children’s participation is only via Junior add by a parent account holder (Section 5).

14. Changes

We may update this policy. We will post the revised version with a new effective date at the Privacy Policy URL and in-app. Material changes will be shown in the app. Continued use after the effective date means you accept the updated policy where permitted by law.

15. Contact

Privacy questions and requests: in-app Account → Help / support.

Legal: