Privacy Policy
United States · MiSalvo Inc. · Effective 1 October 2026 · Last updated 16 September 2026
Entity: MiSalvo Inc. (Delaware)
1. Short version
MiSalvo is built so that staff cannot read your Vault papers. Documents are encrypted on your device. We store ciphertext and the account / household metadata needed to run the service. Meaningful content is decrypted on your devices (and recovery paths you choose).
We do not sell your personal information. We do not run advertising trackers or ad SDKs in the app. We do not scan your email or messages. We do not use your documents to train MiSalvo AI models. Optional preferred professionals are not available at launch. If we later offer that path, we may be compensated for intros. Never from money that is yours. See §7.1.
On misalvo.com only, we use Cloudflare Web Analytics for aggregate page views and site performance. It is not in the mobile app, does not read Vault papers, and is not used for advertising or cross-app profiling.
Labelling of merchants and document types happens on your device. Cloud label assist is not on at this launch. If we later turn it on, we will update this policy and our App Store privacy labels first. See Section 4.10.
This summary is a guide. The full policy below controls.
2. Who we are
This Service is operated by MiSalvo Inc., a Delaware corporation (“MiSalvo,” “we,” “us”).
Contact for privacy requests: in-app Account → Help / support (product contact is in-app; we do not require an email address to use MiSalvo).
Public Privacy Policy URL: https://misalvo.com/privacy
Mailing / registered address: Suite 4910, 1007 N Orange St, 4th Floor, Wilmington, DE 19801, USA
“You” means anyone who uses the MiSalvo iOS app or this website (the “Service”). When we launch on Google Play, the Android app is part of the Service too.
US launch. This policy is for a United States launch. The app ships on the Apple App Store first. When we launch on Google Play, this policy also covers that Android app. Rights and notices for UK, EU, Singapore, and other markets will be added as schedules when those storefronts open.
App license and website Terms. Downloading the iOS app is licensed under Apple’s Standard Licensed Application End User License Agreement, unless Apple later shows a custom license for MiSalvo. This Privacy Policy still applies. Our website Terms cover misalvo.com. They are not a second App Store license.
GDPR-aligned design (aim, not a certification claim). MiSalvo is built towards strong European-style data-protection practices associated with the GDPR (and UK GDPR): data minimisation, purpose limitation, security by design, user access/export, and erasure. Ciphertext sits on our servers. Keys sit on your devices. There is no staff plaintext viewer for Vault papers. Hosting today is in the United States (Ohio). UK households, and EU households including Ireland, are designed for a host in Frankfurt, Germany when those stores open. That project is not live. South America is planned for São Paulo, Brazil. Asia-Pacific is planned for Singapore. When we open India, those households will use Mumbai, India. South Africa stays on the United States host until a local option exists. Canada and Mexico stay on the United States host. We are not claiming GDPR certification, ICO registration completion, an EU Article 27 representative, “hosted in Europe,” or that this US policy alone makes us “GDPR compliant” for UK/EU users. Those steps belong to later market waves. The architecture is intended so those schedules are documentation and registration work, not a rebuild. See Section 8.1.
3. Our privacy model
Three design choices drive this policy:
1. Encrypted Vault. Papers are sealed on device. Servers hold ciphertext plus operational metadata. Staff cannot read document bodies.
2. Biometric sign-on. Day-to-day access uses your device’s biometrics (Face ID / Touch ID) or device passcode path. Not an email-and-password login. When we launch on Google Play, Android’s equivalent biometric / passcode path applies. Recovery uses materials you hold: Vault key, optional Spare Key, or another signed-in device (one-time recovery code). We do not run a password-reset email channel. That would require keys we could read.
3. No staff document viewer. We do not decrypt Vault papers for support, marketing, or “AI convenience.”
Custody is still real. While your account is active, MiSalvo Inc. holds sealed blobs on cloud infrastructure so devices can sync. Encryption means staff cannot read papers. It does not mean nobody holds anything. See Section 10 (deletion) and our Security page for the honest leave story.
Biometrics. We do not collect or store your biometric templates. Unlock uses your device’s built-in biometric / passcode facilities (Face ID / Touch ID on Apple devices, and the equivalent on Android when we launch on Google Play). We never receive your biometric templates from the operating system.
4. Information we hold
4.1 Account and profile
Examples:
- Opaque account / user identifiers (including what the product may show as a Vault-related id)
- Display name you choose
- Market code (e.g. United States) and app language preference
- Circle / household membership, roles (e.g. bill payer, Admin, Adult, Senior, Junior), and related timestamps
- Plan / trial / subscription status flags we need to run the product
- Notification preferences; optional Nearby-missions preference (boolean)
- Help-ticket text you submit in-app and related metadata
We do not require an email address or phone number to create or use a MiSalvo account. Product contact is in-app (and optional push if you turn it on).
Optional contact details you choose to save (for example email, postal address, or mobile number for your own records or Salvo slots) are designed to be sealed in your Vault under your keys. Same posture as your papers. MiSalvo staff do not have a tool to read those sealed fields. Coarse account metadata needed to run the Service (ids, plan flags, Circle roles) may remain outside that sealed envelope as described elsewhere in this section.
4.2 Payment and entitlement flags
Subscriptions and trials at this US launch are billed through the Apple App Store. Apple is the merchant of record for that purchase. When we launch on Google Play, Google will be the merchant of record for purchases made there. We receive subscription / entitlement status needed to provide paid features. Not your full card number. Apple’s privacy terms apply to payment data Apple holds. Google’s will apply when that store is live.
We may store plan tier, subscription active flags, and Vault trial end timestamps so the product can enforce freemium rules (for example: Missions free; Vault trial starting when you confirm seats and start the trial on first paper save; Circle invites only while a trial or paid plan is active). These are operational account flags. Not document contents.
4.3 Encrypted Vault documents
Captured papers (camera, Photos, Files, Share Sheet, and similar) are encrypted on device and stored as ciphertext with related cryptographic metadata (for example IVs). Coarse plaintext fields may exist for product filters (for example capture source tag, timestamps, security tier Protected / Fortified, share status). Rich document meaning and sealed provenance detail stay under keys we do not hold in the clear.
We cannot produce readable Vault document content for staff, advertisers, or routine support.
4.4 Circle, Missions, notifications
To run household life-admin we store mission titles, dates, assignees, status, and related coordination data; in-app notification inbox rows; and Circle membership metadata. Mission “place” data you add for Nearby stays subject to your Nearby opt-in. Live GPS for Nearby matching is designed to stay on device and is not uploaded for matching by default.
4.5 Salvo packs and sharing
When you prepare or fire a Salvo, we may store pack metadata (path, status, token, expiry, open counts) and sealed pack ciphertext for revocable secure links. We do not keep readable pack letter bodies on our servers. Recipients who open a link decrypt with material in the part of the URL after the #, on their client. That key is not intended for our server logs.
4.6 Device and technical data
Examples: device type, OS version, app version, approximate connection metadata (for example IP at request time as processed by our hosts), crash / diagnostic signals we use to keep the Service reliable. Prefer platform crash infrastructure where practical. We do not embed advertising, MMP, or third-party product-analytics SDKs.
4.7 Optional push delivery
If you enable push notifications, we may use a push delivery provider (currently OneSignal) with the platform push service. On iOS that is Apple Push Notification service. When we launch on Google Play, that may also include Firebase Cloud Messaging / Google. That provider receives a device push token, an opaque account identifier we choose (not your name or documents), and delivery metadata. We do not send Vault contents, Salvo pack bodies, or document text to that provider. Lock-screen text is kept generic. Detail stays in the in-app inbox. We do not use this provider for advertising or email/SMS contact.
4.8 First-party product events
We may record allowlisted first-party product events (coarse product usage signals) to improve the Service. These events are designed not to include Vault document bodies, OCR text, or Salvo pack meaning.
4.9 What we do not collect as account fields
- Email / phone as login identity
- Advertising IDs for cross-app tracking
- Live GPS for Nearby when Nearby is off
- Biometric templates
- Free-form “chat with my Vault” transcripts (not a product)
4.10 Optional cloud label assist (not on at launch)
Most labelling of merchants and document types happens on your device (OCR, catalogs, on-device learned labels). There is no free-form chat with your Vault.
Not on at this launch. We may later add a thin paid cloud label assist when on-device confidence is low. That would be a contracted enterprise service under no-training terms. Not a chat that reads your life. If we turn it on, we will update this Privacy Policy and our App Store privacy labels before it ships. Until then, labelling stays on your device.
If cloud assist later ships, only an allowlisted short text snippet would go to that automated service. Not your full document, photo, or PDF. Not your keys. We would name the provider in this policy and in App Store privacy disclosures when the contract is signed.
What we would send
- A short merchant / payee string (normalized)
- A few OCR text lines already extracted on your phone (not the image by default)
- A small list of candidate labels our allowlist expects
- Opaque request metadata needed for rate limits (for example account id, day bucket). Not full document meaning beyond the snippet
What we would never send
- Your Vault files or sealed profile fields as readable papers
- Full page / PDF / photo bytes as the default path
- Vault encryption keys, Vault key, Spare Key material
- Free-form chat turns or user essays
- Salvo pack / cover-letter prose for the model to “improve”
- Content for advertising, data brokers, or MiSalvo model training
- Server-side embeddings of Vault meaning for search or training
Disclosure. If cloud assist ships, you will see a short in-app notice when it is used. Caps and a kill-switch may stop cloud assist. The app continues with on-device labelling.
Vendor retention. How long a contracted provider may retain a snippet for abuse, security, or legal compliance would be set in that enterprise agreement and summarized here when signed. Training on your content remains off under the enterprise posture we would require.
Analytics. If this path ships, durable product analytics would use allowlisted reason codes and counts (for example why assist was needed). Not raw OCR, merchant strings, or document identifiers in those dashboards.
Fortified papers. If cloud assist ships, Fortified papers stay on-device only unless you confirm with a fresh biometric before a snippet leaves.
5. Circle and children’s information (COPPA-critical)
5.1 Account holders (18+)
Only adults 18 or older may create and own a MiSalvo account (bill-paying account holder). By creating an account you represent that you are 18+.
5.2 Invited Adults and Seniors
Adults and Seniors invited into a Circle create their own MiSalvo profile / session. They accept this Privacy Policy themselves. On iOS they also accept Apple’s Standard Licensed Application EULA when they download the app. They typically use seats on the bill payer’s plan and do not buy a separate subscription. Each adult member’s Vault is theirs. MiSalvo does not give the bill payer a staff-style back door into another Adult’s Vault.
5.3 Juniors (children under parental or legal guardian responsibility)
The bill-paying account holder may add minor children for whom they have parental or legal guardian responsibility as Juniors, with parental / guardian attestation. Launch posture:
- Parental or guardian responsibility only. For children under 18 in your care (including biological children, stepchildren, adopted children, and children under your legal guardianship). Not unrelated third parties’ children. Not a free-floating Junior invite code for strangers’ kids.
- Consent-by-ownership. The parent or legal guardian who consents is the account owner. The child does not separately accept this Privacy Policy or the app license.
- Parent-issued setup. After a biometric check, the parent creates the Junior seat and may send a short setup message plus a private one-tap link. The short-lived, one-time secret stays in the part of the link after the #. It is not shown in the message or sent to MiSalvo’s web server. The link opens only the Junior setup path in MiSalvo. This is not a peer Circle invitation.
- Junior custodial Vault. A Junior with a supported device may receive a restricted session and save papers into a distinct Junior Vault. The Junior does not share the parent’s Vault or receive the parent’s Vault keys.
- Parent access at launch. The bill payer can open and manage every paper in that Junior Vault. “No private Junior space” means no Junior paper is hidden from that parent, not that the Junior has no Vault. Admins and other Circle members do not receive this custodial access.
- Lost or replaced phone. After a biometric check, the parent can issue a fresh private one-tap recovery link for a replacement device. Its short-lived, one-time secret stays in the part of the link after the #, same as setup. The replacement reconnects to the same Junior Vault and keys, and prior Junior sessions are revoked. The Junior does not need to retain a Vault key or nominate a Spare Key.
- Adult transition. At 18, the product is designed to re-key the Junior Vault into an independent Adult Vault and end future parental access.
- MiSalvo does not use children’s documents to train AI or for advertising
5.4 Admin role
A bill payer may grant Admin (circle ops). Admin is not ambient access to other Adults’ Vaults or ambient Junior papers beyond product rules. See Circle product rules.
6. How we use information
We use what we hold to:
- Provide, sync, secure, and improve the Service
- Run Circle, Missions, notifications, and Salvos
- Process subscription status via Apple. When we launch on Google Play, via Google as well
- Respond to in-app help tickets
- Prevent abuse, enforce the app license and website Terms, and comply with law
- Produce allowlisted product analytics (no Vault bodies)
We do not sell personal information. We do not use Vault documents to train MiSalvo models. We do not use personal information for cross-context behavioral advertising.
On-device features (OCR, Ask me, Finance-style summaries) run over content decrypted on your device in session. Not as a staff-readable server pipeline.
Cloud label assist (Section 4.10) is not on at this launch. If we later turn it on, it would use allowlisted short snippets only, to return a structured label, under enterprise / no-train terms. It would not train MiSalvo models and would not be a Vault chat.
7. When information leaves MiSalvo (sharing / Fire / export / external links)
Nothing readable leaves your Vault unless you send it (or a recipient opens a link you fired).
When you share, download, print, AirDrop, email, upload, or Fire a Salvo pack or other export, including to a laptop, employer portal, insurer, tax software, or government site, you are sending that information outside MiSalvo. We do not control those systems. They may log, retain, or track activity under their own policies. MiSalvo is not responsible for privacy or tracking practices of services you choose to send your packs to.
Secure links and PDFs. Secure-link recipients decrypt on their client. Revoking a link affects stored share access we control. It cannot undo screenshots or copies already made outside MiSalvo. A PDF or file you Share via the system share sheet is likewise under the recipient’s (or the channel’s) rules once it leaves the app.
External links (for example IRS.gov or other official sites). The app may show links to third-party websites (tax agencies, benefit portals, insurers, and similar). Tapping a link opens that site in a Safari view inside the app so you can tap Back and return to MiSalvo. That site’s privacy policy, cookies, and tracking rules still apply. We do not control those sites. On misalvo.com, official links open in the same tab so your browser’s back arrow returns you to MiSalvo.
7.1 Preferred professionals and partners (future release)
In a future release, some Salvos (for example Estate) may, in some markets, offer an optional way to contact a preferred professional (such as a solicitor or other licensed adviser) or show a partner-powered panel. This feature will not be available at launch. When introduced, that path will be strictly optional. You can always gather and Fire a pack yourself without using it. Preferred panels may be unavailable, demo-only, limited to certain countries, or never ship. The product chrome will say so when a panel is not live.
What we share with partners. We do not give preferred partners your Vault keys or readable Vault papers. Firm / panel rows are business directory metadata (for example firm name, area, contact details). If you choose Contact or a similar intro, you start that outreach (for example by email or another channel you confirm). Coarse attribution for a panel (for example that a contact was started) may be recorded so we and a channel partner can run the panel. Not document contents.
Compensation, and what we never take. If this path later ships, MiSalvo and/or a named channel partner may be compensated when you use a preferred Contact / intro (for example a fee or revenue share with the firm channel). That is separate from your Apple App Store subscription, and from Google Play billing when we launch that store.
We are never compensated from money that is yours. We do not take a cut of tax refunds, benefit payments, claim payouts, reimbursements, estate or inheritance proceeds, or other money you recover or receive. Preferred-partner economics are not a share of your outcome.
Preferred listing is not a MiSalvo endorsement of legal quality. Professionals keep their own tools and terms once you leave MiSalvo.
8. Service providers (processors)
We use providers to host and operate the Service, including for example:
- Cloud database / auth / storage / functions: Supabase (backend currently in the United States, Ohio)
- Website hosting / CDN: Cloudflare (Pages, DNS, security). Web Analytics on misalvo.com. Aggregate page views and performance only. Not in the app.
- App distribution and billing: Apple App Store. Google Play when we launch that store.
- Optional push: OneSignal, plus Apple APNs. Firebase Cloud Messaging when we launch on Android.
- Optional cloud label assist: not on at launch. Named here if we later turn it on.
They process data on our behalf for those purposes.
8.1 Regional hosts (intent)
Live today. Sealed Vault copies for TestFlight and the current US backend sit in the United States (Ohio). Households in the United States, Canada, and Mexico use that Americas host. Catalogs and a country picker are not residency.
Design for later storefronts. When those App Stores open, new bill-paying households should land on a regional home. Not Ohio.
- United States, Canada, Mexico: Ohio, United States. Live.
- UK: Frankfurt, Germany. Design. Project not created.
- EU, including Ireland: Frankfurt, Germany. Design. Project not created.
- Chile (later Brazil / others): São Paulo, Brazil. Named slot. No project until that store is real.
- Australia, New Zealand, Singapore: Singapore. Named slot. No project until that store is real.
- India: Mumbai, India. Named slot. No project until that store is real. Singapore is not India’s host.
- South Africa: United States until a local option exists. Our current database host does not currently sell an Africa region.
One Circle uses one backend. Invitees join the bill payer’s host. We do not dual-write Vault ciphertext across oceans.
Apple, App Store billing, APNs, and optional OneSignal remain separate processors. They may process outside the household’s database region even after we move that database. When we launch on Google Play, Google billing and Android push may do the same.
Picking a city is not GDPR, PIPEDA, LGPD, or DPDP certification. We do not claim “hosted in Europe” while live traffic is in the United States.
9. Your rights and choices
9.1 United States privacy rights
Privacy rights vary by state. California residents (CCPA/CPRA) and residents of other comprehensive state privacy laws may have rights to know / access, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising.
MiSalvo does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are commonly understood. We do not run advertising SDKs that would require App Tracking Transparency for that purpose.
How to exercise rights: use in-app Account → data / privacy / leave flows where available, or in-app Help / support. Because we have no email login, identity verification for rights requests may rely on signed-in session and account controls.
Structural note: For Vault ciphertext, you already control keys on device. Download your data (complete export of owned documents) and schedule account deletion are the primary portability and erasure paths (Section 10).
Do Not Sell / Share. Because we do not sell or share for cross-context ads, a “Do Not Sell” link is not used as an advertising opt-out mechanism. We do not currently honor Global Privacy Control as a separate site signal. If law later requires a specific link or browser signal for other processing, we will update this page.
9.2 European data protection principles (GDPR and UK GDPR design alignment)
The General Data Protection Regulation (GDPR) in the European Union and the UK GDPR set principles for protecting personal data. MiSalvo’s US product is designed around those ideas. This is an architecture aim. It is not a certification.
- Data minimisation. Processing is limited to what is necessary for the product to function. MiSalvo does not collect email addresses or mobile numbers to create accounts, does not stream continuous background GPS coordinates, does not scrape user inboxes, and does not store plaintext document contents on servers.
- Integrity and confidentiality (security by design). Personal records and Vault documents are encrypted on your device using AES-256-GCM with device-held keys. MiSalvo servers hold sealed ciphertext and operational coordination flags only. MiSalvo staff have no technical keys, backdoors, or viewers to decrypt or read your Vault documents. Related controls include automatic lockdown if the device biometric database is tampered with, remote emergency freeze across trusted Circle members, cryptographic session revocation, and recovery via Vault keys or blind Spare Key holders.
- Purpose limitation. Information is used to deliver the life-admin features you choose (Vault, Missions, Circle, and Salvo packs). We do not run third-party advertising SDKs, sell personal data, or use your documents to train MiSalvo machine learning models.
- Storage limitation and erasure. When an account is closed, our scheduled deletion workflow runs a hard wipe of server-held ciphertext and account records following the 14-day cooling window. We do not keep a post-leave shadow archive of user documents for testing, debugging, or analytics.
- Data portability and access. You can access and extract your records. Our biometric-gated data export provides usable, client-side decrypted original files (PDF, JPEG, PNG) and an indexed summary before account deletion can be scheduled.
- Transparency. We disclose what information is held, how encryption operates, and the boundary between device-held meaning and server-held ciphertext.
Scope. The mapping above describes product engineering. Our initial launch is the United States App Store with hosting in the US. We do not claim formal third-party GDPR certification, completed European Data Protection Authority registrations, or an EU Article 27 representative. UK, Ireland, and EU households are designed for a Frankfurt host when those stores open. That host is not live. Dedicated regional schedules and local representative disclosures will be published as UK and European storefronts open.
10. Export, retention, and account deletion
10.1 Download your data
From Account → data / leave you can run a biometric-gated complete export of documents you own (usable files + index), decrypted with your keys. Large Vaults may use a time-limited laptop download link (key in the part of the URL after the #). Export is not emailed to you. Staff cannot open the archive as plaintext.
10.2 Schedule leave / delete account
Apple requires in-app account deletion. Google will require the same when we launch on Google Play. Our product path:
1. Confirm you saved your export
2. Schedule account deletion
3. 14-day cooling-off (you can cancel)
4. Hard wipe of account data we control (including storage objects and auth), and local crypto cleanup as designed
Ending a Vault trial or cancelling store billing is not the same as deleting the account. A free Missions-only account may continue until you schedule leave / delete.
Circles: scheduling leave leaves Circles quietly first where the product supports that. Remaining members may get an in-app note and time to save shared docs. Not a public announcement push about why you left.
After wipe: we do not keep a product “about 30-day debug” copy of Vault content for AI or convenience. Cloud backups may lag for a limited time (infrastructure reality). That residual window is custody time, not a staff reader.
10.3 Retention while active
We retain account, Circle, mission, notification, and ciphertext storage while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations.
11. Legal requests
We comply with valid legal process. Architecture limits what we can produce: we cannot hand over readable Vault document content for which we do not hold the keys. We may provide account metadata, subscription status, operational records, and sealed blobs as held.
12. Security
Plain-language overview (what we claim and what we do not): Security.
We use encryption, access controls, and defense-in-depth security measures. No system is perfectly secure. Core defence: an attacker who reached our servers would find ciphertext and metadata, not staff-readable Vault papers. Sealed custody still exists.
Our security architecture includes hardware-backed biometric verification, automatic lockdown upon device biometric database modification, emergency remote freeze capabilities across trusted Circle members, cryptographic session revocation, and zero-knowledge key restoration.
If you lose all signed-in devices, your Vault key, and Spare Key paths (and cannot use another device to send a recovery code), Vault plaintext may be unrecoverable by design. Keep recovery materials safe.
Junior recovery is different. A Junior is not required to retain a Vault key or nominate a Spare Key. After a biometric check, the bill payer can issue a fresh private recovery link. Its short-lived, one-time secret is not shown in the message or sent to MiSalvo’s web server. It reconnects the existing Junior Vault and revokes prior Junior sessions.
These controls support our GDPR-aligned design aim (Section 2): minimisation, security by design, export, and erasure. Without claiming a GDPR certificate or completed UK/EU formalities.
13. Children and age
The Service is not directed at children under 13 as a standalone audience. Independent account ownership is limited to adults 18+. A parent or legal guardian may provision a restricted Junior session and custodial Junior Vault under Section 5. The child cannot create that relationship alone.
14. Changes
We may update this policy. We will post the revised version with a new effective date at the Privacy Policy URL and in-app. Material changes will be shown in the app. Continued use after the effective date means you accept the updated policy where permitted by law.
15. Contact
Privacy questions and requests: in-app Account → Help / support.
Legal notices: see Contact, or write to .