Skip to main content
MystSafe
No Password No Account No Cloud Quantum Safe Family Friendly FAQ Get MystSafe

Legal archive

MystSafe Terms of Use

Effective date
August 9, 2026
Version
1.8

This is an archived version. View the current document.

On this page

  1. 1. Agreement and scope
  2. 2. Eligibility and minors
  3. 3. What MystSafe provides
  4. 4. App license and platform terms
  5. 4.1 License for non-Apple distributions
  6. 4.2 Apple App Store copies
  7. 4.3 Other distribution platforms
  8. 4.4 Mixed licensing
  9. 5. Personal, Family Plan, and individual professional use
  10. 6. Your Vault Data and Family Shared Data
  11. 7. Device security, backups, and recovery
  12. 8. Free and Pro plans
  13. 8.1 Features included in both plans
  14. 8.2 MystSafe Free
  15. 8.3 MystSafe Pro
  16. 8.4 Family Plan and Family Shared
  17. 9. Apple auto-renewable subscriptions
  18. 9.1 Subscription options, duration, price, and included service
  19. 9.2 Billing and automatic renewal
  20. 9.3 Cancellation and paid-through access
  21. 9.4 Purchase restoration
  22. 9.5 Refunds, billing failures, revocations, and chargebacks
  23. 10. Expiration, downgrade, and migration
  24. 11. MystSafe License Identity and subscription service
  25. 12. Share Once
  26. 12.1 How Share Once works
  27. 12.2 Expiration choices and allowances
  28. 13. Optional synchronization and provider choice
  29. 13.1 Provider choice and common terms
  30. 13.2 GitHub authorization and synchronization
  31. 13.3 Google Drive authorization and synchronization
  32. 14. Provider credential handling
  33. 14.1 Shared GitHub credentials
  34. 14.2 Device-local Google credentials
  35. 14.3 Family provider credentials
  36. 15. Provider-specific pairing and Family Plan enrollment
  37. 15.1 Temporary public GitHub pairing repository
  38. 15.2 Google Drive pairing
  39. 15.3 Family Plan enrollment
  40. 15.4 Pairing Service alternate direction
  41. 16. Deletion and disconnection
  42. 17. Device permissions and local authentication
  43. 18. Third-party services
  44. 19. Acceptable use
  45. 20. Privacy and communications
  46. 21. Support
  47. 22. Intellectual property and feedback
  48. 23. Website and security information
  49. 24. Plan and feature changes
  50. 25. Updates, compatibility, and availability
  51. 26. Suspension, discontinuation, and termination
  52. 27. Disclaimer of warranties
  53. 28. Limitation of liability
  54. 29. Indemnification
  55. 30. Export controls and sanctions
  56. 31. Changes to these Terms
  57. 32. Governing law and disputes
  58. 33. General provisions
  59. 34. Contact information

1. Agreement and scope

These Terms of Use ("Terms") are a binding agreement between you and MystSafe LLC ("MystSafe," "we," "us," or "our").

These Terms govern your access to and use of:

  • the MystSafe applications made available for supported platforms (collectively, the "Apps");
  • mystsafe.com and its related pages (the "Website");
  • any MystSafe-operated Share Once browser viewer, relay, install bridge, subscription service, and Pairing Service described in these Terms; and
  • MystSafe support, communications, and related services.

The Apps, Website, and related services are collectively the "Services."

By selecting "Agree," installing or using an App, purchasing or restoring a MystSafe subscription, or accessing or using the Website after these Terms are presented or linked to you, you agree to these Terms and acknowledge the MystSafe Privacy Policy.

If you have not reached the age of legal majority where you live, your parent or legal guardian must review and accept these Terms before permitting you to use the Services. By accepting these Terms for a minor, the parent or legal guardian represents that they have authority to act for the minor, accepts these Terms on their own behalf and on the minor's behalf, authorizes the minor's use, and agrees to supervise that use. References to "you" include the minor and the accepting parent or legal guardian where the context requires.

If the required parent or legal guardian does not agree, the minor must not use the Services. If you otherwise do not agree, do not use the Services.

If applicable law gives you rights that cannot be waived by contract, these Terms do not limit those rights.

2. Eligibility and minors

The Apps are intended to be suitable for people age 4 and older. No person under age 4 may use the Services.

The "4+" designation describes the intended age suitability of the App's content. It does not mean that a child can independently enter into a binding agreement, consent to processing where parental authorization is required, make a purchase, or use a third-party service whose rules require an older user.

A user who has not reached the age of legal majority where the user lives may use the Services only with the authorization and supervision of a parent or legal guardian who has accepted these Terms as described in Section 1. The adult who authorizes a purchase is responsible for that purchase and for managing its renewal through the applicable store.

A child under 13 may use only App features that do not require the child to provide personal information directly to MystSafe or independently maintain an ineligible third-party account. A child under 13 must not submit the Website support form or contact MystSafe directly. A parent or legal guardian may communicate with MystSafe on the child's behalf using the adult's own contact information.

Connected services and app stores may impose higher minimum ages. You may use a connected feature or make a purchase only if you independently satisfy the applicable service's account, age, permission, and legal requirements. Parent or guardian permission does not override those requirements.

You may not use the Services where their use is prohibited by applicable law.

3. What MystSafe provides

MystSafe is local-first encrypted vault software. It allows you to create and use an encrypted personal vault on supported devices, optionally participate in an in-App Family Plan with separate personal vaults for every participant, and deliberately share selected secrets through the separate Family Shared collection. MystSafe can synchronize encrypted personal-vault and Family Shared payloads and signed or encrypted synchronization and security data through either a GitHub repository associated with the Family Plan Owner's or vault user's GitHub account or MystSafe data associated with the selected Google Drive account. Each connected personal vault or Family Plan is bound to one provider; Google Drive and GitHub do not depend on or automatically fall back to one another.

MystSafe uses narrow services for specific functions:

  • share.mystsafe.com provides the first-party browser viewer for Share Once;
  • relay.mystsafe.com provides short-lived encrypted coordination for Share Once;
  • open.mystsafe.com provides a fragment-free install and launcher bridge;
  • subscription.mystsafe.com maintains pseudonymous subscription entitlement, billing-provider state, linked-device and Family Plan authorization, and Share Once allowance state; and
  • pairing.mystsafe.com provides short-lived, end-to-end-encrypted rendezvous for supported alternate-direction device and Family Plan pairing.

Those services are not customer-vault synchronization or backup services. They are separate from the Google Drive or GitHub provider that remains authoritative for vault and Family Plan membership and synchronization state. Their roles and limitations are described in Sections 11, 12, and 15 and in the Privacy Policy.

MystSafe does not provide:

  • a conventional MystSafe user account;
  • a MystSafe-operated central customer vault;
  • a memorized master-password recovery system;
  • access to your decrypted vault contents during normal operation;
  • possession of the cryptographic keys necessary to decrypt your vault during normal operation; or
  • a guarantee that an inaccessible vault can be recovered.

The pseudonymous MystSafe License Identity described in Section 11 is not a conventional user account and is not a claim that use is anonymous or produces no metadata.

MystSafe is not a custodian, bank, money transmitter, cryptocurrency wallet provider, fiduciary, investment adviser, financial adviser, legal adviser, identity-recovery provider, or emergency-access service.

Storing passwords, financial credentials, cryptocurrency recovery phrases, private keys, identity records, professional information, or other sensitive information in MystSafe does not create a custodial, advisory, fiduciary, or recovery relationship between you and MystSafe.

4. App license and platform terms

4.1 License for non-Apple distributions

For an App obtained outside Apple's App Store, and subject to these Terms and any applicable distribution-platform rules, MystSafe grants you a limited, nonexclusive, nontransferable, non-sublicensable, revocable license to install and use the object-code version of the App on devices you own or control for lawful personal use and individual professional or work use.

The App is licensed, not sold. Except where applicable law or a separate software license expressly permits otherwise, you may not:

  • rent, lease, lend, sell, redistribute, sublicense, or commercially host the App;
  • make the App available for simultaneous use by unrelated users through a hosted or managed service;
  • circumvent technical protections, plan controls, allowance controls, or security restrictions;
  • copy, modify, reverse engineer, decompile, disassemble, or attempt to derive the source code of proprietary portions of the App; or
  • remove proprietary notices from the App or related materials.

These restrictions apply only to the extent permitted by law and do not limit rights granted under an applicable open-source or source-review license.

4.2 Apple App Store copies

If you obtain MystSafe through Apple's App Store, Apple's Standard Licensed Application End User License Agreement ("Apple Standard EULA") governs the license to that copy of the App.

These Terms govern your use of the MystSafe Services and supplement the Apple Standard EULA. They do not replace the Apple Standard EULA or constitute a custom Apple EULA. If these Terms conflict with the Apple Standard EULA regarding the scope or conditions of the App Store license, the Apple Standard EULA controls for that issue.

Apple and its subsidiaries are third-party beneficiaries of the Apple Standard EULA and may enforce it as provided there. Apple is not responsible for MystSafe support, maintenance, warranties, product claims, intellectual-property claims, or claims arising from the Apps except to the extent Apple expressly accepts responsibility under its own terms or applicable law.

4.3 Other distribution platforms

Apps obtained through Google Play, the Microsoft Store, or another distribution platform may also be subject to that platform's terms and usage rules. Those terms apply between you and the applicable platform provider. These Terms continue to govern your use of MystSafe and its Services.

4.4 Mixed licensing

The compiled MystSafe Apps, MystSafe branding, and materials are proprietary except for components explicitly distributed under separate open-source or source-review licenses. Those separate licenses control their respective components, and exact notices will appear in Third-Party Notices or the applicable source distribution.

5. Personal, Family Plan, and individual professional use

You may use MystSafe for personal purposes and for your own individual professional or work activities, provided that you are authorized to store and use the information involved and comply with applicable law and applicable employer or client policies.

MystSafe Free and MystSafe Pro ("Pro") each support an in-App Family Plan. The person who creates and administers a Family Plan is the "Family Plan Owner." Each person enrolled by the Owner is a "Family Member." Family Member allowances exclude the Owner.

Each Owner and Member keeps a separate personal vault. The Owner has no App capability or authority under these Terms to decrypt, enumerate, search, edit, or recover a Member's personal vault. Members do not gain access to one another's or the Owner's personal vaults merely by participating in a Family Plan.

A Family Plan is not a Team, Enterprise, shared organizational account, or managed-organization service. It does not provide centralized employee provisioning, organization-wide administration, organizational audit controls, enterprise recovery, regulatory certifications, a data-processing agreement, service-level commitments, or organization-wide support.

Your individual professional use does not create an enterprise agreement between MystSafe and your employer, client, or other organization. An organization requiring enterprise commitments, a data-processing agreement, regulatory assurances, administrative controls, or negotiated terms must obtain a separate written agreement from MystSafe.

6. Your Vault Data and Family Shared Data

"Vault Data" means the credentials, notes, records, files, and other content you place in a MystSafe personal vault. "Family Shared Data" means Vault Data that a participant deliberately creates, copies, or moves into the separate Family Shared collection.

As between you and MystSafe, you retain your rights in your Vault Data. These Terms do not transfer ownership of your Vault Data to MystSafe.

You represent and warrant that you have all rights, permissions, and lawful authority necessary to store and use your Vault Data and to disclose any Family Shared Data to Family Plan participants. You are responsible for the accuracy, legality, appropriateness, and use of that data.

By placing information in Family Shared, you direct the Apps and the selected provider to make it available to every current active Family Plan participant and to later Members admitted while that information remains in Family Shared. Family Shared does not offer per-secret recipient selection. Do not place information there unless every such participant is authorized to receive it.

You must not use MystSafe to obtain, retain, disclose, or use another person's credentials, personal information, trade secrets, confidential information, or other protected material without authorization.

7. Device security, backups, and recovery

You are responsible for:

  • securing your devices and operating-system accounts;
  • protecting device passcodes, biometric settings, Google and GitHub credentials, Family Plan invitations, pairing QR codes, Share Once links, and License Identity authorization material;
  • installing important operating-system and MystSafe security updates;
  • retaining enough trusted devices or other lawful backup methods to tolerate loss or failure;
  • verifying that synchronization, pairing, deletion, disconnection, purchase restoration, and plan-transition operations complete as intended; and
  • understanding the backup and retention behavior of your devices, operating systems, selected synchronization-provider account, app store, and other third-party services.

When the user is a minor, the accepting parent or legal guardian is responsible for determining whether the App is appropriate for the child, supervising the child's use, protecting device access and authentication methods, managing any subscription, and maintaining backups or recovery arrangements appropriate for the child's data.

MystSafe generally cannot reset a vault password, reconstruct a private key, recreate lost cryptographic material, or recover an inaccessible vault. Losing the only usable trusted device or necessary cryptographic material may result in permanent loss of Vault Data.

Do not use MystSafe as the only copy of information whose loss could cause serious personal, financial, professional, legal, or operational harm.

Encryption, local authentication, hardware-backed storage, and similar safeguards reduce risk but do not eliminate it. A compromised device, operating system, Google or GitHub account, shared Family provider credential, software dependency, License Identity authorization, pairing QR code, Share Once link, or unlocked MystSafe session may expose or alter information.

8. Free and Pro plans

The plan terms in this Section apply while MystSafe makes the corresponding plan or feature available.

8.1 Features included in both plans

MystSafe Free and Pro include:

  • a local encrypted vault and unlimited secrets;
  • Google Drive or GitHub synchronization;
  • import and export;
  • local access to existing Vault Data;
  • cryptographic, compatibility, and security updates;
  • no advertising or behavioral tracking in the Apps;
  • trusted-device viewing, removal, revocation, and replacement;
  • an in-App Family Plan and the Family Shared collection; and
  • personal and individual professional or work use.

Both plans use the same security-critical cryptography and receive the same security updates. Pro does not provide stronger vault encryption than Free.

8.2 MystSafe Free

MystSafe Free is a permanent, no-charge plan that does not expire and is not a trial. Here, "permanent" means the plan has no scheduled time limit or trial conversion; it does not guarantee that MystSafe will distribute or operate every Service indefinitely, and Sections 24 through 26 still apply. Free includes:

  • Google Drive or GitHub synchronization for a maximum of two active trusted devices belonging to the plan holder or Family Plan Owner;
  • one active Family Member, excluding the Owner, and one active trusted device for that Member;
  • one active Owner-created Family Shared secret and one active Family Shared secret created by the included Member, giving each active Family Plan participant one Free creation allowance; retained former-Member content continues to occupy the Member allowance;
  • removal, revocation, and replacement of trusted devices without requiring Pro;
  • five successfully created Share Once links per week across linked MystSafe devices, each with a fixed five-minute expiration;
  • import and export; and
  • Standard support.

Pending Family Plan invitations reserve a Member allowance. Removed, revoked, or departed Members and devices do not consume the corresponding allowance. The active-device limits control admission and synchronization; they do not delete Vault Data held locally on an additional device.

8.3 MystSafe Pro

MystSafe Pro is an optional paid plan for the subscriber, that person's linked MystSafe devices, and the Family Plan the subscriber owns. It includes everything in Free plus:

  • up to six active Family Members, excluding the Owner;
  • unlimited active trusted devices for the Owner and for each active Member, meaning Pro imposes no commercial numeric plan limit, subject to technical, security, acceptable-use, provider, and platform constraints;
  • unlimited Family Shared secrets, meaning Pro imposes no commercial secret-count limit, subject to technical, security, acceptable-use, provider, and platform constraints;
  • unlimited successfully created Share Once links across linked MystSafe devices;
  • Share Once expiration choices of 5 minutes, 10 minutes, 30 minutes, 1 hour, 8 hours, and 24 hours; and
  • Premium priority support on a best-effort basis without a service-level agreement or guaranteed response or resolution time.

Pro is offered as monthly and annual auto-renewable subscriptions as described in Section 9. There is no introductory trial and no lifetime purchase in the initial offer.

8.4 Family Plan and Family Shared

Family Shared is a fixed, flat system collection that is separate from every participant's personal vault. It is provisioned when the first Family Member becomes active. It cannot be renamed, moved, deleted as an ordinary folder, or contain subfolders. Only secrets deliberately created, copied, or moved into Family Shared are shared.

Every active Family Plan participant may view, reveal, copy, save a private copy of, and use Share Once with every Family Shared secret. A Member may change or delete only a secret that Member created. The Owner may change or delete any Family Shared secret. Creator attribution remains associated with the original creator after an Owner edit. Family Shared has no ownership-transfer feature, selective-recipient list, shared Trash, or restore workflow.

A newly activated Member receives access to all existing Family Shared Data and later accepted updates. Before activation, the Owner is shown the number of existing Family Shared secrets that will become available to the new Member. If the last Member leaves or is removed, Family Shared remains available to the Owner; a later Member receives the retained content after the required disclosure.

The Owner's validated plan tier governs the Family Plan. A Member does not receive an independent in-App purchase or upgrade action while governed by that Family Plan and may be directed to ask the Owner to upgrade.

9. Apple auto-renewable subscriptions

9.1 Subscription options, duration, price, and included service

The Apple App Store Pro subscription options are:

  • MystSafe Pro monthly subscription: one month, auto-renewing monthly. The advertised United States price is US$2.99 per month.
  • MystSafe Pro annual subscription: one year, auto-renewing annually. The advertised United States price is US$19.99 per year.

Each option provides the Pro features listed in Section 8.3 throughout each active paid subscription period. The annual amount shown in Apple's purchase flow is the total annual charge; any monthly equivalent displayed for comparison is informational only.

The App Store displays the final localized price, currency, taxes where applicable, subscription duration, and billing terms for your Apple Account country or region before you confirm a purchase. The terms and amount shown in Apple's purchase confirmation control over an advertised U.S. price or currency conversion.

Before asking you to subscribe, the App identifies the subscription option, duration, full renewal price, and included Pro features and provides accessible links to these Terms and the MystSafe Privacy Policy.

9.2 Billing and automatic renewal

Apple processes the purchase and charges the payment method associated with your Apple Account when you confirm the transaction. MystSafe does not process checkout on the Website.

Monthly and annual Pro subscriptions automatically renew for successive periods of the same duration until canceled. Apple determines the renewal date and processes each renewal at the price and on the terms it displays or otherwise communicates to you, including any notice or consent required for a price change. Taxes may be included in or added to the displayed price as determined by Apple and applicable law.

No introductory free trial or discounted introductory period is included in the current subscriptions. No lifetime purchase is offered.

9.3 Cancellation and paid-through access

You can manage or cancel an Apple-billed subscription through your Apple Account subscription settings. Deleting the App, deleting a local vault, disconnecting Google Drive or GitHub, deleting a License Identity, or contacting MystSafe does not by itself cancel Apple billing.

Canceling automatic renewal prevents a future renewal but ordinarily does not end Pro immediately. Unless Apple applies a refund, revocation, or other adjustment, Pro remains available through the paid-through expiration date in Apple's entitlement record. To avoid an unwanted renewal, cancel before Apple processes the renewal and follow any timing instructions Apple presents for your country or region.

Cancellation does not delete your secrets. Local vault access and export remain available, subject to device access, App compatibility, these Terms, and applicable law. Section 10 explains what happens after natural expiration.

9.4 Purchase restoration

The Apps provide a way to request restoration of eligible Apple purchases. Restoration is subject to Apple's transaction records, the Apple Account used for the purchase, StoreKit availability, and successful linkage to your MystSafe License Identity. Restoration does not reconstruct a lost vault, recover missing vault keys, restore third-party provider data, or replace the device-pairing or Family Plan enrollment process.

Pro applies across a subscriber's linked MystSafe devices on supported platforms and governs the in-App Family Plan owned by that subscriber. MystSafe Family Plan membership is separate from Apple's Family Sharing feature. Enrolling a MystSafe Family Member does not add that person to an Apple family group or transfer an Apple purchase. Apple Family Sharing applies only if MystSafe enables it for the applicable subscription and Apple recognizes the family member's entitlement under Apple's settings and records.

MystSafe does not promise that a future purchase through a different store can be restored on a completely new or unlinked device without an existing linked device or another recovery method that MystSafe may introduce.

9.5 Refunds, billing failures, revocations, and chargebacks

Apple administers charges, billing retries, refunds, and App Store transaction reversals under Apple's terms and applicable law. You may request an eligible App Store refund from Apple. MystSafe does not promise that Apple will grant a refund and generally cannot issue or control an Apple-billed refund.

A refund, transaction revocation, chargeback, unresolved billing failure, fraud determination, or correction of an invalid or duplicated transaction may cause Apple or MystSafe to correct, suspend, or end the associated Pro entitlement. MystSafe may require purchase restoration or other reasonable verification before restoring access. These actions do not authorize MystSafe to delete local Vault Data or Family Shared Data, but they may end paid features and cause the plan-transition consequences described in Section 10. A migration period promised only after natural expiration may not apply when an entitlement is revoked for fraud, refund, chargeback, legal requirement, or material breach.

Nothing in this Section limits refund, cancellation, conformity, cooling-off, or other rights that cannot be waived under applicable law.

10. Expiration, downgrade, and migration

This Section applies to a Pro subscription and its Family Plan after the paid entitlement ends.

Turning off renewal does not itself downgrade Pro before the paid-through date. When a valid Pro subscription reaches its natural paid-through expiration, MystSafe provides a 30-day migration period for the limited purpose of selecting which two Owner or plan-holder devices will remain synchronization-active under Free and managing configurations that exceed Free allowances.

The migration period is not an additional free month of Pro. During it, MystSafe may constrain new configurations, new Member or device admission, new Family Shared creation, or other operations that would exceed Free allowances while allowing the transition functions identified above.

At or after expiration, as the applicable transition is completed:

  • Share Once returns to Free's limit of five successfully created links per week and a fixed five-minute expiration;
  • you may select the two Owner or plan-holder devices that remain synchronization-active under Free;
  • synchronization may pause on additional Owner or plan-holder devices, while those devices retain local access to Vault Data already held on them;
  • Google Drive and GitHub synchronization remain available under Free;
  • existing Family Members and their devices are not automatically removed, and no personal vault is erased, solely because of the downgrade; new Member and device admissions are blocked while the applicable Free allowance is met or exceeded;
  • every existing Family Shared secret remains available for display, reveal, copy, role-authorized editing or deletion, and synchronization, but new Family Shared creation is blocked when the creating participant's applicable Free Owner or Member allowance is already occupied;
  • Google Drive and GitHub data are not automatically deleted by MystSafe merely because Pro expires;
  • local vault access and export remain available; and
  • renewal or successful purchase restoration restores Pro capabilities without requiring you to rebuild a personal vault or Family Shared collection, subject to the availability and integrity of local and provider data.

You remain responsible for preserving needed data, completing the transition within the migration period, selecting the Free synchronization devices, and separately managing data held by GitHub or Google. MystSafe does not guarantee that a third-party provider will retain data or access throughout a transition.

11. MystSafe License Identity and subscription service

MystSafe uses a pseudonymous MystSafe License Identity to coordinate plan entitlement and allowance controls across linked MystSafe devices and an Owner's Family Plan. A License Identity is not a conventional MystSafe user account, does not contain your Vault Data or Family Shared Data, and does not make your use anonymous or invisible to MystSafe, Apple, a network provider, or another service involved in a request.

The subscription service at subscription.mystsafe.com maintains the limited state needed for:

  • pseudonymous Free or Pro entitlement;
  • Apple billing-provider and transaction status needed to validate entitlement;
  • authorization and linkage of entitlement devices;
  • Family Plan tier and the authorization or allowance proofs needed for Owner and Member devices;
  • purchase restoration and entitlement correction; and
  • Share Once allowance counting across linked MystSafe devices.

The subscription service is separate from vault synchronization and the Share Once relay. It is not designed to receive vault plaintext, vault keys, Google or GitHub credentials, or Share Once ciphertext. The Privacy Policy explains the commercial and operational information it processes, why it is processed, how long it is retained, and available privacy rights.

You may use a Pro entitlement only for yourself, your own linked MystSafe devices, and the Family Plan Members and devices admitted through the authorized in-App enrollment flow. You must not sell, transfer, share outside that flow, duplicate, forge, tamper with, or use another person's License Identity or entitlement authorization. You are responsible for protecting devices and authorization material used to link an entitlement.

Pro is designed to follow you across linked MystSafe devices. MystSafe supports iPhone, iPad, and Mac. Android and Windows are planned. No public release date, regional price, billing method, feature parity, or cross-store restoration mechanism has been announced for those platforms.

12. Share Once

12.1 How Share Once works

Share Once lets a sender create an encrypted, time-limited link that one valid native-App or first-party browser recipient can claim before it expires. These terms apply whenever you use Share Once. Share Once is a single-valid-claim protocol, not a promise of one-time human viewing.

The complete link normally opens the first-party browser viewer at share.mystsafe.com. It includes bootstrap material in its URL fragment, which a compatible browser or MystSafe App processes locally. The fragment is not sent to the viewer or relay as part of an ordinary HTTP path or query. Loading the page, fetching and verifying the signed offer, displaying the countdown, opening the non-consuming save options, or generating a link preview does not claim the share.

The recipient does not need a MystSafe App to view the secret. Explicitly selecting View securely in browser begins the browser claim. Selecting Copy to clipboard is also an explicit browser claim and places a plaintext-equivalent MystSafe secret envelope on the recipient's clipboard after successful verification. The optional Save in MystSafe choices can help the recipient copy or later import the secret into MystSafe. Choosing to install the App opens the fragment-free bridge at open.mystsafe.com/install; opening that installation destination does not claim the share and does not send it the Share Once fragment.

The browser viewer performs claim validation and decryption locally using the same production cryptographic protocol as a compatible native recipient. It is designed to keep bootstrap material, recipient private keys, and decrypted secret data in volatile browser memory and not to persist them in cookies, local storage, session storage, IndexedDB, a cache, or a service worker. Browser and operating-system behavior, extensions, accessibility software, screenshots, clipboard use, memory paging, backups, or a person with access to the device may nevertheless expose or retain information outside MystSafe's control.

After creating a link, the sender may close the Share Once screen, but MystSafe must remain running in the foreground with the vault unlocked while the App encrypts the snapshot specifically for the successful recipient. Backgrounding or locking the sender App, canceling the share, delivery completion, or expiry ends the flow.

The relay at relay.mystsafe.com provides short-lived encrypted coordination, server-enforced expiration, and first-valid-claim state. The relay receives bounded operational metadata and encrypted protocol envelopes needed for that coordination, but is not designed to receive plaintext or a relay-held decryption key. It is not a vault, backup, synchronization provider, subscription service, or user-account service.

The first valid native or browser claimant wins. Later claimants cannot replace the successful claimant through the normal protocol. Under the current protocol assumptions, the relay can deny, interrupt, delay, or fail to coordinate service, but cannot decrypt the share or silently substitute a different valid recipient. MystSafe does not guarantee that a share will be claimed, delivered, decrypted, acknowledged, or available continuously.

A final acknowledgement can be lost after a recipient successfully reveals the information, so a sender may not always receive conclusive delivery confirmation. A recipient who reveals information can copy, save, photograph, screen-capture, memorize, or further disclose it. You are responsible for choosing the recipient, transmission channel, information, and expiration and for complying with law and any confidentiality duty.

12.2 Expiration choices and allowances

Free includes five successfully created Share Once links per week across linked MystSafe devices, each with an expiration fixed at five minutes. Pro includes unlimited successfully created Share Once links across linked MystSafe devices and permits expiration choices of 5 minutes, 10 minutes, 30 minutes, 1 hour, 8 hours, or 24 hours.

The Free weekly allowance resets Monday at 00:00 UTC. The App may display the equivalent time in your local time zone. A Free link counts against the allowance only after successful server-side creation. Expiration, successful consumption, sender cancellation, or revocation does not refund or restore that allowance. Unused Free allowance does not roll over unless MystSafe expressly states otherwise.

MystSafe may reject an unsupported expiration, an over-limit request, an invalid or revoked License Identity, or a request that fails security or protocol validation. Allowances are plan limits, not stored value, currency, property, or a guarantee of successful delivery.

13. Optional synchronization and provider choice

13.1 Provider choice and common terms

Synchronization is optional. A connected personal-vault identity has one provider origin: either Google Drive or GitHub. A Family Plan is separately bound to the provider selected by the Owner and uses opaque namespaces distinct from every participant's personal-vault data. The providers are independent; a Google Drive-backed vault or Family Plan does not require or automatically fall back to GitHub, and a GitHub-backed vault or Family Plan does not require or automatically fall back to Google Drive.

The provider origin cannot be migrated or retargeted in place. An explicit personal-vault provider disconnection may retire the device from the connected vault and preserve its local contents under a new independent vault identity. That new local identity may connect to an available provider from scratch, but the operation is not a migration of the prior connected identity. The Owner cannot disconnect the provider bound to an active Family Plan, revoke required Family administration state, or delete the last Owner device while active or pending Members remain.

Under the plan controls described in Section 8, Google Drive and GitHub synchronization are included in Free and Pro on iPhone, iPad, and Mac. Platform availability and feature details may change as described in Section 25.

Synchronization providers are transport and coordination services, not permanent vault storage or backup services. Every device retains its own encrypted local personal vault, and Family Shared uses a separate encrypted local store and provider collection. A Google or GitHub account alone cannot decrypt or recover a personal vault or Family Shared Data without the necessary device-held cryptographic material.

13.2 GitHub authorization and synchronization

GitHub synchronization is optional and is available in Free and Pro. Establishing a GitHub-backed personal vault or Family Plan requires a GitHub account and authorization or installation of the MystSafe GitHub App by the vault user or Family Plan Owner.

GitHub currently requires users to be at least 13 and may require a higher minimum age in some countries. A user who does not independently satisfy GitHub's requirements may not enable or use GitHub synchronization or GitHub-based device pairing.

When you enable synchronization, the App communicates with GitHub and may request the GitHub permissions needed to establish and operate synchronization, including repository Contents read/write, Metadata read, and Administration read/write permissions.

The App creates or uses a dedicated private GitHub repository named mystsafe-vault-sync-data to hold encrypted and signed synchronization and control data.

You authorize the App to use the GitHub credentials and permissions you approve for operations you request, including:

  • reading and writing encrypted synchronization data;
  • obtaining account, installation, repository, and permission information;
  • creating or administering the dedicated repository;
  • pairing trusted devices and enrolling Family Members;
  • maintaining Family Plan control, membership, and Family Shared objects in opaque namespaces;
  • cleaning up temporary pairing material; and
  • performing deletion or disconnection operations you initiate.

You are responsible for reviewing the permissions presented by GitHub and maintaining your GitHub account and repositories in good standing.

GitHub is an independent third-party service that MystSafe does not control. GitHub may observe information such as your GitHub account and repository identity, network address, request timing, opaque repository paths, object sizes and counts, request counts, access patterns, and the fact that Family Plan or Family Shared objects exist even when Vault Data and Family Shared Data are encrypted.

Your use of GitHub is governed by GitHub's own terms and privacy policy. MystSafe is not responsible for GitHub outages, account restrictions, policy changes, security incidents, retention practices, backups, or loss or corruption of GitHub-hosted data.

13.3 Google Drive authorization and synchronization

Google Drive synchronization is optional. It requires a Google Account that satisfies Google's applicable account, age, permission, and legal requirements. Eligible younger children may be able to use a parent-managed Google Account through Family Link, subject to Google's rules. The App's 4+ age suitability designation does not override Google's requirements.

When you connect Google Drive, the App uses Google Sign-In and requests access to MystSafe's application-specific data through the https://www.googleapis.com/auth/drive.appdata scope. That permission allows the App to create, list, read, write, and delete MystSafe-specific objects in Google Drive's hidden application-data folder.

When an Owner connects Google Drive for Family Plan enrollment, the App also requests the https://www.googleapis.com/auth/drive.file scope. That scope permits the App to create and manage files that MystSafe creates or that the user expressly opens with MystSafe; it does not authorize MystSafe to list, read, modify, or delete arbitrary ordinary Google Drive files. MystSafe uses it to create and clean up the exact temporary enrollment file described in Section 15.3.

You authorize the App to use the Google credentials and permissions you approve for operations you request, including:

  • establishing and verifying the Google account binding;
  • reading and writing encrypted personal-vault and Family Shared payloads and signed or encrypted synchronization and security objects;
  • maintaining device and Family Plan membership, control, and synchronization state;
  • pairing trusted devices without transferring a Google credential;
  • enrolling Family Members through the separate Family credential-transfer process described in Sections 14.3 and 15.3;
  • cleaning up temporary pairing and synchronization objects; and
  • performing deletion or disconnection operations you initiate.

The application-data folder may contain encrypted personal-vault and Family Shared payloads; signed control, device-membership, Family Plan membership, and security records that are not necessarily encrypted; encrypted and signed temporary pairing objects; pseudonymous account, vault, Family Plan, Member, collection, and device identifiers; public cryptographic material; and operational metadata such as opaque file identifiers, object types, versions, sizes, modification times, and change-tracking state.

Google may observe the Google account connection, network address, device or user-agent information, request timing, file identifiers, object sizes and counts, API operations, access patterns, the existence of a Family Shared collection, and the contents and metadata stored in the application-data folder or temporary Family enrollment file. MystSafe does not operate an intermediary synchronization server that receives Google credentials or Google Drive synchronization objects.

Your use of Google Drive and Google Sign-In is governed by Google's own terms and privacy policy. MystSafe is not responsible for Google outages, account or administrator restrictions, policy changes, security incidents, retention practices, backups, app-data deletion, or loss or corruption of Google-hosted data.

14. Provider credential handling

14.1 Shared GitHub credentials

MystSafe's pairing architecture provides each paired device with a copy of the same GitHub App user access token used by the personal vault or Owner-managed Family Plan.

That token is a bearer credential. A person who obtains it may be able to act through GitHub within the permissions associated with the token and the GitHub App.

The token used by the current MystSafe architecture is configured not to expire automatically. It may remain usable until it is revoked, invalidated, or replaced.

Removing a device from MystSafe's trusted-device list or removing a Family Member does not, by itself, individually revoke a copied GitHub credential. Revoking or rotating the shared GitHub authorization may interrupt synchronization for every affected personal-vault or Family Plan device and may require the remaining devices to be reauthorized.

You are responsible for revoking the MystSafe GitHub App through GitHub if you believe the shared credential or a paired device has been compromised.

14.2 Device-local Google credentials

For ordinary personal-vault device pairing, each device in a Google Drive-backed vault separately authorizes the same Google Account. Google OAuth access and refresh tokens, token expiration and scope information, the stable account binding, a derived one-way account hash, and related authorization state are stored locally using protected device storage. They are not placed in the ordinary device-pairing QR code, pairing object, synchronized vault object, or another device's personal vault and are not transferred through ordinary device pairing. Family Plan enrollment uses the separate credential process described in Section 14.3.

Google credentials can expire, be revoked, or become unusable because of a provider, administrator, account, device, or policy action. Reauthorization may be required. Removing a trusted device or deleting one device's local credential does not revoke credentials separately issued to other devices.

Disconnecting Google Drive removes the local Google credential and signs the App out on that device, but it does not automatically revoke the Google-level connection shown in your Google Account. Use Google's third-party connection controls if you also want to revoke that grant. Revoking the connection or deleting MystSafe's Google app data may interrupt synchronization for affected devices.

14.3 Family provider credentials

Successful Family Plan enrollment securely transfers an exact Family-scoped GitHub or Google provider credential from the Owner's Family Plan to the Member device. The Member does not sign in to, select, or receive the password for the Owner's provider account. The transferred bearer credential and its provider, account, scope, and epoch binding are authenticated, staged in protected device storage during enrollment, validated against the exact Family backend, and promoted for normal use only after membership becomes Active.

A transferred Family credential may be shared across Owner and Member devices and may not be independently revocable for one Member device. Removing a Member advances authenticated membership and collection-key state so compliant Apps reject the removed Member's later Family writes and do not provide future Family Shared keys or content. Removal does not recall a credential or encrypted package already copied, revoke the underlying GitHub token or Google grant, or prevent a holder of an extracted bearer credential from observing provider-level metadata or attempting denial of service. Revoking or replacing the shared provider authorization may interrupt the entire Family Plan and require Owner reconnection or reauthorization.

15. Provider-specific pairing and Family Plan enrollment

15.1 Temporary public GitHub pairing repository

MystSafe's current device-pairing method temporarily creates a cryptographically random public GitHub repository. That repository contains an encrypted credential package needed by the new device to join the vault. The App permits the package to be retrieved without GitHub authentication and then attempts to delete the temporary repository.

By initiating device pairing after the App presents its pairing notice, you direct the App to create this temporary public repository and acknowledge that:

  • the encrypted package and public-repository metadata are publicly accessible while the repository exists;
  • third parties may copy the encrypted package;
  • deleting the repository does not guarantee erasure of copies, caches, logs, or backups;
  • GitHub and other parties may retain metadata or copies under their own practices;
  • a person who obtains a still-valid pairing QR code may be able to retrieve and decrypt the pairing package;
  • the pairing package includes the shared GitHub bearer credential; and
  • a copied package could remain a security risk if its cryptographic protection or associated pairing secret is compromised.

Treat every live pairing QR code as a sensitive security credential. Pair only devices you own or expressly trust. Do not publish, transmit, screenshot, or display a live pairing QR where an unauthorized person could obtain it.

If you suspect that a pairing QR, pairing package, shared GitHub token, or paired device has been compromised, stop pairing and revoke the MystSafe GitHub App authorization through GitHub.

Pairing sessions expire within 10 minutes.

15.2 Google Drive pairing

Ordinary Google Drive device pairing uses temporary encrypted and signed objects in MystSafe's hidden Google Drive application-data folder rather than a public repository. Each device separately authorizes the same Google Account. Google credentials are never transferred through the ordinary device-pairing QR code, temporary objects, synchronization data, or another device's personal vault.

The pairing QR code and temporary objects contain account- and session-bound identifiers, opaque Drive file identifiers, public cryptographic material, and encrypted and signed pairing messages. They do not contain a Google access token, refresh token, authorization code, ordinary Google Drive file, vault master key, or device private key.

Pairing sessions expire within 10 minutes. The Apps attempt to delete temporary objects after pairing, cancellation, expiration, or recovery cleanup, but network interruption or provider unavailability can delay cleanup. Google may retain logs, backups, or security records under its own practices.

Treat every live pairing QR code as sensitive. Pair only a device you own or expressly trust, protect the QR code from unauthorized access, and verify the comparison words shown by both devices before approving pairing. If the account binding, object identifiers, signatures, expiry, or comparison checks fail, the Apps are designed to reject the pairing attempt.

15.3 Family Plan enrollment

Family Plan enrollment is QR-only. The default and recommended direction has the Owner display a time-limited QR code and the Member scan it. The alternate direction has the Member display a public-only QR code and the Owner scan it. The Owner assigns an Owner-local alias to the Member, and both devices display the same five comparison words. Only the Owner can approve or reject the comparison and activate membership. Pending invitations reserve a Member allowance until they complete, expire, or are canceled.

Default-direction GitHub enrollment uses an exact temporary public repository containing an authenticated encrypted Family bootstrap. Default-direction Google Drive enrollment uses an exact temporary ordinary Drive file with a non-discoverable public-reader capability containing an authenticated encrypted Family bootstrap. The Member retrieves the object without signing in to the Owner's provider account, authenticates it, stages and validates the transferred Family provider credential, and attempts to delete and verify unavailability of the exact temporary object before activation can complete.

The Apps attempt exact cleanup after enrollment, cancellation, expiration, or recovery, but provider or network failure can delay cleanup. A person with a live invitation QR may retrieve the encrypted package while the capability remains available. Cleanup or cryptographic expiry cannot recall bytes or a bearer credential already copied. Treat every live Family Plan invitation QR as sensitive, share it only with the intended Member or Owner, and verify the five comparison words before the Owner approves membership.

15.4 Pairing Service alternate direction

The alternate direction uses pairing.mystsafe.com as a short-lived rendezvous before the selected Google Drive or GitHub provider becomes authoritative for Pending, Active, Family control, credentials, and normal synchronization. The service receives a public high-entropy session identifier, bounded operational and network metadata, and end-to-end-encrypted, authenticated, write-once protocol envelopes. It is not designed to receive vault plaintext, Family Shared plaintext, a provider account identity, or a usable provider credential outside the encrypted bootstrap intended for the authenticated Member device. It has no vault, provider API, account, search, or roster capability.

Service loss, expiration, or purge can delay or end an unfinished pairing session but does not reverse a Family membership already made Active through the selected provider and cannot recall a decrypted credential or plaintext already obtained.

16. Deletion and disconnection

MystSafe provides controls with different scopes:

  • Delete Local Vault removes the selected local personal vault, local device keys, local settings, and local provider configuration from that device. It does not delete the separate Family Shared provider collection, connected data stored through Google Drive or GitHub, cancel an app-store subscription, or necessarily delete License Identity or service records.
  • Erase All Vault Data also attempts to delete the selected personal vault's connected synchronization objects from the selected provider. It does not delete the separate Family Shared provider collection, a GitHub repository, ordinary Google Drive files, unrelated vault namespaces, provider logs or backups, or signed terminal-removal and security evidence that the protocol retains.
  • Disconnect GitHub removes the local GitHub credential and synchronization configuration from the selected device when the Family Plan lifecycle permits it. It does not delete remote GitHub data, revoke credentials held by other paired or Family Plan devices, or cancel Pro.
  • Disconnect Google Drive retires the selected device from the shared Google Drive-backed vault, attempts to clean up transient objects as the protocol permits, preserves signed terminal-removal security evidence, and keeps the vault contents on that device under a new independent local vault identity. It removes the local Google Drive provider origin and credential and signs the App out of Google on that device. It does not revoke Google credentials separately issued to other devices or automatically revoke the Google-level grant in your Google Account.

An explicit provider disconnection is not an in-place provider migration. The new independent local vault identity may later connect to an available provider from scratch.

The Owner may remove a Member, and a Member may leave, through the Family Plan lifecycle. An authenticated terminal transition ends that participant's authorization to receive future Family Shared keys or content and to publish later accepted Family changes through compliant Apps. It advances the membership and collection-key epochs, rejects later offline writes that were not accepted before the removal barrier, and erases the departed device's local Family Shared cache, pending journal, and collection keys after the terminal state is authenticated.

Removal or departure does not delete the former Member's separate personal vault, remotely wipe an uncontrolled device, erase information the person already revealed, copied, saved, exported, photographed, memorized, or otherwise retained, or individually revoke a copied Family provider bearer credential. Secrets created by the former Member remain in Family Shared for the active participants unless an authorized participant deletes them. The Owner retains Family Shared after the last Member leaves, and a later Member receives retained content after the disclosure described in Section 8.4.

You may separately manage or delete repositories and revoke the MystSafe GitHub App through GitHub, and manage MystSafe's app data or third-party connection through Google Account and Google Drive controls. Revoking the shared GitHub authorization may affect every paired GitHub-backed device. Revoking a Google connection or deleting MystSafe's Google app data may stop synchronization for affected devices.

Encrypted Google Drive synchronization snapshots expire after 30 days and are normally deleted sooner after verified acknowledgement. Temporary Google Drive pairing objects expire within 10 minutes. Signed membership, pruning, checkpoint, and terminal-removal evidence may remain when the synchronization protocol needs it to verify security state. Provider logs, caches, backups, and security records may also remain under the provider's practices.

Uninstalling an App does not necessarily delete:

  • Google Drive or GitHub remote synchronization data;
  • data on other paired devices;
  • device or cloud backups;
  • App Store, Google Play, or Microsoft Store records;
  • License Identity, subscription, entitlement, or Share Once service records;
  • support or launch-notification communications;
  • security logs, caches, or backups maintained by third parties; or
  • copies previously made by another person, including a current or former Family Plan participant.

You are responsible for selecting the appropriate deletion option and verifying that it achieved the result you intended. MystSafe cannot delete information that it does not possess or control. The Privacy Policy explains how to request deletion of eligible MystSafe-controlled information.

17. Device permissions and local authentication

Depending on the platform and feature you choose, an App may request:

  • camera access to scan a pairing QR code;
  • Face ID, Touch ID, device-passcode, Windows authentication, or another operating-system authentication method to protect local access; and
  • network access to communicate with Google Drive, GitHub, MystSafe-operated services and legal pages, app stores, or other services you request.

The operating system performs supported biometric matching. MystSafe is designed to receive the authentication result rather than your fingerprint, facial template, or other raw biometric data.

You are responsible for deciding which people may enroll biometrics or know the passcode on a device used with MystSafe.

18. Third-party services

The Services may link to or interoperate with third-party services, including GitHub, Apple, Google, Microsoft, Cloudflare, operating-system providers, email providers, and social platforms.

MystSafe does not control those services. They may require separate accounts, permissions, fees, or agreements and may process information under their own privacy policies.

MystSafe is not responsible for third-party availability, functionality, security, content, data practices, account decisions, billing decisions, or acts or omissions. A reference to a future integration does not promise that the integration will be released.

19. Acceptable use

You must not use, or help another person use, the Services:

  • in violation of applicable law or another person's rights;
  • to access, collect, retain, test, disclose, or distribute credentials or secrets without authorization;
  • to facilitate fraud, theft, phishing, malware, stalking, harassment, exploitation, surveillance, or other harm;
  • to attack, probe, overload, disrupt, or bypass the security of MystSafe, Google, GitHub, a device, or another system without express authorization;
  • to publish or intentionally expose a live device-pairing or Family Plan QR code, Share Once link, or pairing material to an unauthorized person;
  • to interfere with deletion of a temporary pairing repository, Google Drive pairing object, or Family enrollment object;
  • to evade a plan limit, Share Once allowance, device limit, entitlement decision, suspension, or security control;
  • to forge, share, sell, transfer, duplicate, or tamper with a License Identity, purchase record, entitlement, protocol message, or authorization;
  • to introduce malicious code or exploit a vulnerability for harmful purposes;
  • to submit passwords, vault exports, Vault Data, Family Shared Data, private keys, recovery information, Google or GitHub credentials, License Identity authorization material, live device or Family pairing QR codes, or complete Share Once or pairing links through a Website or support form;
  • to submit unlawful, threatening, harassing, abusive, defamatory, obscene, malicious, deceptive, or spam content through a Website or support form;
  • to impersonate another person or misrepresent your authority;
  • to infringe intellectual-property, privacy, confidentiality, or contractual rights; or
  • in a manner that exposes MystSafe or another person to sanctions, export-control violations, or other legal liability.

You may conduct security research only when authorized by applicable law and the system owner and in a manner that avoids harm, unauthorized access to other users' data, privacy violations, and service disruption.

Report suspected MystSafe vulnerabilities privately through mystsafe.com/support/ or to help@mystsafe.com, and allow a reasonable period for investigation and remediation before public disclosure.

20. Privacy and communications

The MystSafe Privacy Policy explains how MystSafe handles personal information in connection with the Services, including Family Plan and Family Shared state, Pairing Service coordination, subscription and transaction state, the License Identity, linked-device authorization, Share Once coordination and allowance state, support requests and correspondence, existing launch-notification records, and third-party providers.

The Website support form submits the information you choose to provide to MystSafe for support, security, privacy, feedback, or another selected request category. The form's plan selection is self-declared, and you must not use the form to submit the prohibited secrets or abusive content described in Sections 19 and 21.

New launch-notification registrations are closed. Existing registrations remain limited to the one product-availability notice previously requested and are not converted into newsletters, offers, recurring updates, or general marketing. You may cancel an outstanding request or ask MystSafe to delete it before the notice is sent by contacting info@mystsafe.com from the registered address.

A child under 13 must not submit the support form or contact MystSafe directly. A parent or legal guardian may communicate on the child's behalf using the adult's own contact information. MystSafe may still send responses you separately request or legally necessary, security-related, subscription-related, purchase-related, or other transactional communications.

21. Support

Free includes Standard support. Pro includes Premium priority support on a best-effort basis while its entitlement is active. The same public knowledge base and support-request form are available to Free and Pro users. Pro support requests receive priority queue handling; Premium support does not provide stronger cryptography or security assistance.

All support is best effort. MystSafe does not guarantee a response time, resolution time, outcome, data recovery, continuous staffing, or service-level agreement. A self-declared Pro selection in the Website form affects initial queue classification but is not a verified entitlement assertion.

Support cannot decrypt your personal vault or Family Shared Data, reconstruct lost keys, restore third-party data, override Apple billing records, or guarantee recovery. Do not submit Vault Data, Family Shared Data, vault exports, private keys, passwords, recovery information, Google or GitHub credentials, License Identity authorization material, live device or Family pairing QR codes, complete Share Once or pairing links, encrypted pairing packages, or other secrets in a support request. Do not submit unlawful, threatening, harassing, abusive, malicious, deceptive, or spam content.

22. Intellectual property and feedback

Except for your Vault Data and components governed by separate licenses, MystSafe and its licensors own all rights, title, and interest in the Services, Website content, software, designs, documentation, names, logos, and other materials.

"MystSafe" and associated branding may not be used in a manner that suggests endorsement, affiliation, or authorization without MystSafe's written permission.

If MystSafe makes source code available for review, that availability does not grant rights beyond the license accompanying the source. In particular, public visibility alone does not grant unrestricted redistribution, commercial reuse, competing-product rights, or a right to publish MystSafe releases.

If you voluntarily provide feedback, ideas, suggestions, or bug reports, you grant MystSafe a worldwide, perpetual, irrevocable, royalty-free, transferable, and sublicensable right to use, reproduce, modify, distribute, and commercialize that feedback for any lawful purpose without compensation or obligation to you.

Do not include Vault Data, Family Shared Data, vault exports, passwords, recovery information, private keys, Google or GitHub credentials, License Identity authorization material, live device or Family pairing QR codes, complete Share Once or pairing links, encrypted pairing packages, or other secrets in feedback or support requests.

MystSafe will not publicly identify you as the source of feedback without your permission.

23. Website and security information

Website content is provided for general information. It may describe design goals, technical architecture, future plans, or features that are not available on every platform.

Website content is not legal, financial, investment, cybersecurity, or other professional advice. You should independently evaluate information before relying on it.

Descriptions of encryption, local-first architecture, post-quantum methods, authentication, or other safeguards are explanations of design and implementation. They are not warranties that the Services are unhackable, error-free, formally verified, independently audited, suitable for every threat model, or guaranteed to prevent unauthorized access or data loss.

MystSafe may correct or update Website content at any time.

24. Plan and feature changes

The Free and Pro offer boundaries are stated in Sections 8 through 12. MystSafe will not charge you for a purchase without presenting the applicable price and obtaining authorization through an appropriate purchase flow.

MystSafe may prospectively add, remove, or change plans, features, allowances, prices, or technical limits, subject to paid-through commitments, notice, consent, refund, and other requirements imposed by Apple or applicable law. A change will not retroactively shorten a valid paid subscription period or authorize deletion of local Vault Data or Family Shared Data. If MystSafe discontinues a paid service, it will honor the applicable paid term or provide a remedy as required by Apple and applicable law.

25. Updates, compatibility, and availability

MystSafe may release updates, patches, or new versions. Updates may change features, security requirements, file formats, device compatibility, Google Drive or GitHub behavior, StoreKit integration, or other third-party integrations. A security or compatibility update may be necessary for continued use or synchronization.

MystSafe does not promise that:

  • every App will be available on every platform or device;
  • every platform version will have identical features;
  • the Services will always be available or uninterrupted;
  • the Apps will remain compatible with every operating-system version;
  • a third-party integration will remain available; or
  • every existing feature will be maintained indefinitely.

App stores, operating systems, Google, GitHub, service providers, export restrictions, sanctions, legal requirements, and other dependencies may affect availability.

Where applicable law requires continued support, notice, conformity, remedies, or other consumer protections, those requirements control.

26. Suspension, discontinuation, and termination

You may terminate these Terms at any time by stopping use of the Services and uninstalling the Apps. Stopping use or uninstalling does not cancel an app-store subscription, delete remote data, or necessarily delete MystSafe service records. You remain responsible for canceling billing and deleting local and provider-hosted data you no longer want.

MystSafe may suspend or limit a MystSafe-operated feature, correct or revoke an entitlement, discontinue distribution, or terminate access to a service MystSafe controls when reasonably necessary to:

  • address abuse, fraud, a chargeback, an invalid or refunded transaction, or a security threat;
  • enforce a plan, allowance, device, or protocol limit;
  • comply with law, an app-store decision, or a platform requirement;
  • protect MystSafe, users, or third parties;
  • respond to a material breach of these Terms; or
  • discontinue a product or integration subject to Section 24.

When reasonably practicable, MystSafe will tailor a suspension to the affected service or entitlement. Because MystSafe is local-first, MystSafe may be unable to disable an App already installed on your device or delete data held on your device, by a current or former Family Plan participant, in your Google or GitHub account, or by another third party. Suspension or termination does not itself authorize MystSafe to delete local Vault Data or Family Shared Data.

Upon termination, the license rights granted under these Terms end. Provisions that by their nature should survive—including ownership, separate software licenses, third-party terms, deletion consequences, payment obligations, disclaimers, liability limitations, indemnity, and dispute provisions—will survive.

27. Disclaimer of warranties

TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED "AS IS," "AS AVAILABLE," AND WITH ALL FAULTS. MYSTSAFE AND ITS LICENSORS DISCLAIM ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, SECURITY, ACCURACY, AVAILABILITY, AND QUIET ENJOYMENT.

MYSTSAFE DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, IMMUNE FROM ATTACK, OR COMPATIBLE WITH EVERY DEVICE; THAT A SHARE ONCE LINK WILL BE CLAIMED, DELIVERED, ACKNOWLEDGED, OR VIEWED ONLY ONCE; THAT ENCRYPTED OR DELETED INFORMATION CANNOT BE RECOVERED OR COPIED BY OTHERS; THAT A TEMPORARY PUBLIC REPOSITORY, GOOGLE DRIVE PAIRING OBJECT, OR FAMILY ENROLLMENT OBJECT WILL BE DELETED BEFORE ANOTHER PARTY ACCESSES IT; THAT REMOVAL CAN RECALL INFORMATION OR A PROVIDER CREDENTIAL ALREADY OBTAINED BY A FAMILY PLAN PARTICIPANT; OR THAT MYSTSAFE, A DEVICE, GOOGLE, GITHUB, APPLE, OR ANOTHER SERVICE CAN RECOVER YOUR PERSONAL VAULT OR FAMILY SHARED DATA OR PREVENT EVERY LOSS.

Some jurisdictions do not allow certain warranty exclusions. In those jurisdictions, these exclusions apply only to the extent permitted by law, and you retain all non-waivable consumer rights.

28. Limitation of liability

TO THE FULLEST EXTENT PERMITTED BY LAW, MYSTSAFE AND ITS AFFILIATES, OFFICERS, EMPLOYEES, CONTRACTORS, LICENSORS, AND SERVICE PROVIDERS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES; LOSS OF DATA, CREDENTIALS, ACCESS, REVENUE, PROFITS, BUSINESS, OPPORTUNITY, GOODWILL, OR SECURITY; OR THE COST OF SUBSTITUTE SERVICES ARISING FROM OR RELATED TO THE SERVICES, EVEN IF ADVISED THAT SUCH LOSS IS POSSIBLE.

TO THE FULLEST EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF MYSTSAFE AND THE OTHER PARTIES IDENTIFIED ABOVE FOR ALL CLAIMS ARISING FROM OR RELATED TO THE SERVICES WILL NOT EXCEED THE GREATER OF:

  1. THE AMOUNT YOU PAID MYSTSAFE FOR THE SERVICES DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM; OR
  2. US$100.

These exclusions and limitations apply regardless of the theory of liability and even if a remedy fails of its essential purpose.

They do not apply to liability that cannot lawfully be excluded or limited. Depending on applicable law, this may include liability for fraud, fraudulent misrepresentation, willful misconduct, gross negligence, death or personal injury caused by negligence, or violation of non-waivable consumer rights.

29. Indemnification

To the extent permitted by law, you agree to defend, indemnify, and hold harmless MystSafe and its affiliates, officers, employees, and contractors from third-party claims, damages, judgments, fines, costs, and reasonable legal fees arising from:

  • Vault Data or Family Shared Data you did not have the right or authority to store, use, or share;
  • your unlawful or unauthorized use of the Services;
  • your infringement of another person's rights; or
  • your material violation of these Terms.

MystSafe will provide reasonable notice of a covered claim. You may control its defense, subject to MystSafe's right to participate and to approve any settlement that imposes an obligation, admission, or restriction on MystSafe.

This section does not apply to the extent a claim was caused by MystSafe or to the extent applicable consumer law prohibits the indemnification.

30. Export controls and sanctions

The Services use strong encryption and may be subject to United States and other export-control, import, and sanctions laws.

You may not export, re-export, transfer, provide, or use the Services in violation of applicable law, including by making them available to a prohibited person, entity, destination, or end use.

You represent that you are not prohibited from receiving or using the Services under applicable sanctions or export-control laws.

31. Changes to these Terms

MystSafe may update these Terms prospectively. Each version will identify its effective date.

MystSafe will provide reasonable notice of material changes through the App, Website, or another contact channel appropriate to affected users, when reasonably available. If a change materially affects your rights or obligations, MystSafe will request renewed acceptance where required by law or reasonably appropriate.

A change to these Terms does not retroactively authorize materially broader use of personal information, shorten an already-paid subscription term, or eliminate rights that accrued before the change took effect.

If you do not agree to revised Terms, you must stop using the affected Services and cancel any future subscription renewal. Non-waivable cancellation and paid-through rights continue to apply.

32. Governing law and disputes

These Terms are governed by the laws of the State of Wyoming, without regard to its conflict-of-law rules, except that applicable United States federal law and any non-waivable consumer protections also apply.

This choice of law does not deprive you of mandatory protections provided by the law of the country or region where you habitually reside.

Before filing a claim, you and MystSafe agree to send the other party a written description of the dispute and the requested resolution and allow 30 days for a good-faith attempt at informal resolution. Notices to MystSafe must be sent to info@mystsafe.com or the mailing address in Section 34.

Except where applicable law permits or requires you to bring a claim elsewhere, exclusive jurisdiction lies with the state courts located in Sheridan County, Wyoming, and the United States District Court for the District of Wyoming. You and MystSafe consent to the personal jurisdiction of those courts.

These Terms do not require arbitration and do not contain a waiver of the right to participate in a class action.

Nothing in this section prevents either party from seeking urgent injunctive or protective relief from a court with appropriate jurisdiction.

33. General provisions

These Terms, applicable app-store or distribution-platform terms, and any additional terms expressly presented for a feature or purchase constitute the agreement governing your use of the Services. The Privacy Policy describes MystSafe's handling of personal information.

If a provision is found unenforceable, it will be enforced to the maximum lawful extent, and the remaining provisions will remain effective.

MystSafe's failure to enforce a provision is not a waiver. A waiver is effective only if it is in writing and signed by MystSafe.

You may not assign these Terms without MystSafe's written consent. MystSafe may assign these Terms in connection with a merger, acquisition, financing, corporate reorganization, or sale of all or part of its business, subject to applicable law.

The in-App labels "Family Plan Owner" and "Family Member" define product roles and permissions only. They do not establish legal parentage, guardianship, domestic partnership, agency, fiduciary duty, employment, partnership, joint venture, franchise, team-service, or enterprise-service relationships among MystSafe or any participant.

Except for rights granted under applicable platform terms, these Terms do not create third-party beneficiary rights.

Headings are for convenience and do not affect interpretation. Electronic records and notices satisfy written-notice requirements to the extent permitted by law.

34. Contact information

Support requests may be submitted through mystsafe.com/support/ or sent to help@mystsafe.com.

General business inquiries, partnerships, media, legal notices, privacy requests, and non-product corporate correspondence may be directed to:

MystSafe LLC

1309 Coffeen Ave Ste 1200, Sheridan, WY 82801, United States

Email: info@mystsafe.com

Telephone: +1 972-332-1230

MystSafe

A fundamentally different secret vault.

No Password No Account No Cloud Quantum Safe Family Friendly Get MystSafe Plans FAQ Support Privacy Policy Terms

© 2026 MystSafe LLC.

Designed and built in Texas, USA.

Private by design. Secure by default.