Skip to main content
MystSafe
No Password No Account No Cloud Quantum Safe Family Friendly FAQ Get MystSafe

Legal

MystSafe Privacy Policy

Effective date
August 13, 2026
Version
1.9

Permanent archive for version 1.9

On this page

  1. 1. MystSafe's privacy architecture
  2. 2. Information handled by the Apps and synchronization providers
  3. 2.1 Personal-vault and Family Shared contents, keys, and local App data
  4. 2.2 Device and trusted-device information
  5. 2.3 Optional GitHub authorization and synchronization
  6. 2.4 Optional Google Drive authorization and synchronization
  7. 2.5 Device pairing through a temporary public GitHub repository
  8. 2.6 Device pairing through Google Drive
  9. 2.7 Family Plan enrollment and provider credentials
  10. 2.8 Pairing Service
  11. 2.9 Device authentication and biometrics
  12. 2.10 Camera and QR codes
  13. 2.11 App analytics, advertising, and distribution platforms
  14. 3. Subscription, entitlement, and commercial information
  15. 3.1 MystSafe License Identity and linked devices
  16. 3.2 Why commercial state is used
  17. 3.3 Apple App Store purchases
  18. 3.4 Purchase restoration and future platforms
  19. 4. Share Once information
  20. 4.1 Information processed by the Share Once service
  21. 4.2 How Share Once information is used
  22. 4.3 Sending a link and recipient copies
  23. 5. Information handled through the Website and communications
  24. 5.1 Website and service infrastructure
  25. 5.2 Cloudflare Web Analytics
  26. 5.3 Existing launch-notification requests
  27. 5.4 Support requests, email delivery, and correspondence
  28. 5.5 Cookies and similar technologies
  29. 6. How and why MystSafe uses information
  30. 7. Legal bases for EEA, UK, and Swiss users
  31. 8. When information is disclosed
  32. 9. Retention
  33. 10. Your choices and deletion controls
  34. 11. Your privacy rights
  35. United States state disclosures
  36. 12. International processing
  37. 13. Security and recovery limitations
  38. 14. Children and parental involvement
  39. 15. Third-party services and links
  40. 16. Changes to this Privacy Policy
  41. 17. Contact MystSafe

MystSafe LLC ("MystSafe," "we," "us," or "our") respects your privacy. This Privacy Policy explains how information is handled when you use:

  • the MystSafe website at mystsafe.com and pages that link to this Policy (the "Website");
  • a MystSafe application for iOS, iPadOS, or macOS, and any later Android or Windows application that links to this Policy (the "Apps");
  • the narrow MystSafe-operated services used for Share Once, subscription administration, and supported alternate-direction pairing; and
  • support requests, existing one-time launch-notification requests, and other communications relating to MystSafe.

Together, these are the "Services." The Apps are intended to be suitable for people age 4 and older. A user who has not reached the age of legal majority may use an App only with the authorization and supervision of a parent or legal guardian as described in the Terms of Use. Connected features, purchases, and third-party services may have additional eligibility or minimum-age requirements.

MystSafe LLC is the controller of personal information that MystSafe receives and determines how to use. This includes information processed through the Website support form, existing launch-notification requests, communications, and the Share Once viewer, relay, install bridge, subscription, and Pairing Service endpoints. MystSafe does not operate a central customer-vault or Family Shared synchronization service and, in normal App operation, does not receive decrypted personal-vault or Family Shared contents or the private keys needed to decrypt them. MystSafe operates narrow services that process the pseudonymous, commercial, encrypted, and technical information described below.

Apple, Cloudflare, Google, GitHub, Microsoft, your email or messaging provider, your employer, and other third parties may separately process information under their own privacy notices.

1. MystSafe's privacy architecture

MystSafe separates local personal-vault processing, Family Shared processing, external-provider synchronization, one-time sharing, subscription administration, pairing rendezvous, and Website operations. When a corresponding feature is used, the relevant path operates as follows:

  • Personal vault: Personal-vault records and cryptographic keys are created and processed on your device. Personal-vault contents are encrypted before being written to disk or synchronized, and every Family Plan participant keeps a separate personal vault.
  • Family Shared: Secrets deliberately placed in Family Shared are processed in a separate encrypted local store and provider collection. Every active Family Plan participant can receive every Family Shared secret, while personal-vault contents remain separate.
  • Provider synchronization: If you enable synchronization, the App communicates with either Google Drive or GitHub, according to the provider selected for that personal vault or Family Plan. Encrypted personal-vault and Family Shared payloads and signed or encrypted synchronization, membership, control, and security data are stored in storage associated with the selected provider account. MystSafe does not operate an intermediary customer-vault synchronization server.
  • Share Once: share.mystsafe.com provides the first-party browser viewer, relay.mystsafe.com provides short-lived encrypted coordination and first-valid-claim state, and open.mystsafe.com provides a fragment-free install and launcher bridge. The viewer performs claim validation and decryption locally. The relay processes encrypted protocol envelopes and limited metadata, but is not a vault, backup, synchronization provider, or account service.
  • Subscription administration: subscription.mystsafe.com maintains pseudonymous entitlement, billing-provider state, linked entitlement-device and Family Plan authorization, and Share Once quota state. It is not a vault or synchronization service.
  • Pairing rendezvous: pairing.mystsafe.com provides short-lived, end-to-end-encrypted rendezvous for supported alternate-direction device and Family Plan pairing. The selected Google Drive or GitHub provider remains authoritative for membership, credentials, and normal synchronization.
  • Website: Cloudflare delivers and secures the Website and provides the Website, support-request, and email-delivery infrastructure described in Section 5.

In normal operation, MystSafe does not receive your decrypted personal-vault or Family Shared contents, vault or collection keys, usable Google or GitHub credentials, biometric templates, device passcode, camera images, or pairing QR images through a MystSafe server. A Family provider credential can transit Pairing Service only inside an end-to-end-encrypted bootstrap intended for the authenticated receiving device; MystSafe is not designed to hold the decryption key. The subscription service does not receive Share Once or pairing ciphertext. The fact that information is encrypted or pseudonymous does not necessarily make it anonymous, and network, account, transaction, membership, storage, access-pattern, and timing metadata may still be personal information.

2. Information handled by the Apps and synchronization providers

Features and system-security mechanisms may differ by operating system and App version.

2.1 Personal-vault and Family Shared contents, keys, and local App data

You may enter record titles, folder names, usernames, passwords, notes, and any other information you choose to store. The Apps also generate and maintain cryptographic keys, vault, Family Plan, Member, Family Shared collection, secret, and device identifiers, public keys, signatures, trusted-device and membership records, creator attribution, aliases, key epochs, removal barriers, and synchronization state, as well as plan, entitlement, and Share Once state.

Personal-vault contents are stored in an encrypted file in the App's application-data area. Family Shared uses a separate encrypted local store. Sensitive device, personal-vault, Family Shared, pairing, and provider keys and credentials are stored using operating-system-protected storage where supported by the applicable platform. Personal-vault information normally remains on your device unless you enable synchronization, device pairing, or Share Once. Family Shared Data is synchronized to every active Family Plan participant through the selected provider. MystSafe does not receive decrypted personal-vault or Family Shared contents through its subscription, Share Once, or Pairing Service endpoints.

Every active Family Plan participant can view, reveal, copy, save a private copy of, and use Share Once with every Family Shared secret. A Member can change or delete only a secret that Member created; the Owner can change or delete every Family Shared secret. A newly activated Member receives all existing Family Shared Data and later accepted updates. Information already revealed, copied, or retained by a current or former participant cannot be revoked retroactively.

Your operating-system provider, device backups, security or device-management software, your employer if it manages the device, or another person with access to the device may process or retain App data outside MystSafe's control.

2.2 Device and trusted-device information

The Apps process information needed to identify and manage trusted devices and Family Plan participation. Depending on the platform and App version, this can include a user-assigned device name; an Owner-assigned Member alias; random device, vault, Family Plan, Member, or collection identifiers; role; public keys; pseudonymous hashes; authorization, membership, removal, or revocation status; and synchronization metadata. Trusted-device information may be stored in the encrypted personal vault and synchronized in encrypted or signed form through the provider selected for that vault. Family Plan administration and membership information is stored in recipient-encrypted or signed provider objects and in the applicable participant's local state.

The Owner keeps an Owner-only administration record of enrolled Members and Owner-local aliases. A Member does not receive a Family roster, other Member identities, other Member device information, or another participant's personal-vault contents. A Member's Owner-assigned alias and the fixed label Family plan owner are disclosed to active participants only as needed for Family Shared creator attribution. A former Member's last accepted attribution may remain with retained Family Shared Data.

For a GitHub-backed vault, the Apps may also store GitHub configuration on the device, such as your GitHub login and numeric account ID, GitHub App installation and repository identifiers, repository owner and name, branch, a random vault identifier, and synchronization path. For a Google Drive-backed vault, the Apps may store the Google account binding and derived one-way account hash, OAuth credential and related authorization information, opaque Drive object identifiers, provider origin, random vault identifier, and synchronization state described below.

Device and Family Plan authorization information used for subscription entitlement and Share Once allowances is separate from the trusted-device, membership, and synchronization information stored with a personal vault or selected provider. Section 3 explains that processing.

2.3 Optional GitHub authorization and synchronization

GitHub synchronization is optional and is available in MystSafe Free and Pro. If you enable it for a personal vault or Owner-managed Family Plan, the App communicates directly with GitHub to:

  • authorize the MystSafe GitHub App through GitHub's device-authorization flow;
  • retrieve your GitHub login and numeric account ID, GitHub App installation information, repository metadata, and relevant permissions;
  • create or use the private repository named mystsafe-vault-sync-data; and
  • read and write signed or encrypted personal-vault, Family Plan control, membership, Family Shared, and security objects beneath opaque paths.

GitHub imposes its own minimum-age and account-eligibility requirements. A user who does not independently satisfy those requirements may not enable or use GitHub synchronization, GitHub-based pairing, or another feature that relies on a GitHub account.

The GitHub credential is stored locally using protected device storage. MystSafe's subscription and Share Once services do not receive the credential or GitHub synchronization objects. Paired personal-vault devices and enrolled Family Plan devices intentionally may use copies of the same applicable GitHub credential. Removing one trusted device or Family Member does not by itself revoke that device's copy. Revoking or rotating the shared credential may affect every paired personal-vault or Family Plan device.

GitHub necessarily receives or can observe information such as the connected GitHub account and repository identity, IP address, request date and time, opaque object paths, object sizes and counts, access patterns, repository operations, and the fact that Family Plan or Family Shared objects exist. Although personal-vault and Family Shared payloads are encrypted, this surrounding metadata may identify or be linked to participants. GitHub handles that information under the GitHub Privacy Statement.

2.4 Optional Google Drive authorization and synchronization

Google Drive is optional; users may choose GitHub instead. If selected, Google processes the account and technical data needed for authentication and encrypted vault synchronization. MystSafe does not use Google data for advertising or tracking. Google Drive is available in MystSafe Free and Pro. Each connected personal vault or Family Plan uses either Google Drive or GitHub as its synchronization provider. The providers operate independently and do not depend on or automatically fall back to one another.

When you connect Google Drive, the App uses Google Sign-In and requests access to MystSafe's application-specific Google Drive data through the https://www.googleapis.com/auth/drive.appdata scope. Google Sign-In also makes a stable Google user identifier and basic account profile information available during authorization. MystSafe uses the stable identifier to bind the vault to the correct Google account. MystSafe does not use or copy your Google account name, email address, or profile image into your MystSafe vault or synchronization configuration.

The App stores the stable account binding, a derived one-way account hash, OAuth access and refresh tokens, token expiration and scope information, OAuth client and device identifiers, opaque Drive file identifiers, and synchronization state locally in device-protected storage. For ordinary personal-vault pairing, Google credentials are not sent to MystSafe, placed in a pairing QR code or synchronization object, stored in another device's personal vault, or transferred between devices. Family Plan enrollment uses the separate credential-transfer process described in Section 2.7.

The drive.appdata permission allows MystSafe to create, list, read, write, and delete MystSafe-specific objects in Google Drive's hidden application-data folder. When an Owner connects Google Drive for Family Plan enrollment, MystSafe also requests https://www.googleapis.com/auth/drive.file, which allows the App to create and manage files that MystSafe creates or the user expressly opens with MystSafe. MystSafe uses it for the exact temporary enrollment file described in Section 2.7. These permissions do not allow MystSafe to list, read, modify, or delete arbitrary ordinary Google Drive files.

The application-data folder may contain:

  • encrypted personal-vault and Family Shared payloads;
  • signed control, device-membership, Family Plan membership, and security records that are not necessarily encrypted;
  • encrypted and signed temporary pairing objects;
  • pseudonymous account, vault, Family Plan, Member, collection, and device identifiers;
  • public cryptographic material; and
  • operational metadata such as opaque file identifiers, object types, versions, sizes, modification times, and change-tracking state.

Google can receive or observe the Google account connection, network address, device or user-agent information, request timing, file identifiers, object sizes and counts, API operations, access patterns, the existence of a Family Shared collection, and the contents and metadata stored in the application-data folder or temporary Family enrollment file. MystSafe's subscription and Share Once services do not receive Google credentials or Google Drive synchronization objects.

MystSafe uses information received through Google APIs only to authorize, provide, secure, troubleshoot, and delete the Google Drive synchronization and pairing features you request. MystSafe's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google processes information under the Google Privacy Policy.

2.5 Device pairing through a temporary public GitHub repository

When you use the GitHub pairing method to pair another device, the App creates a cryptographically random public GitHub repository and places a limited, encrypted credential package in it. The package contains an encrypted copy of the shared GitHub credential and configuration the new device needs to join the vault. The App allows the new device to retrieve the package and then attempts to delete the temporary repository.

You should understand that:

  • the encrypted package and public-repository metadata are publicly accessible while the repository exists;
  • another person or automated system may copy the encrypted package before deletion;
  • deleting a repository is not cryptographic erasure, and GitHub or third parties may retain logs, caches, backups, or copies;
  • anyone who obtains a live pairing QR code before it expires may be able to retrieve and decrypt the package; and
  • removing a trusted device does not individually revoke the shared GitHub credential already held by that device.

Pairing sessions expire within 10 minutes. The App presents a separate notice before initiating this pairing method. Do not display or share a live pairing QR code except with the device you intend to trust.

2.6 Device pairing through Google Drive

Ordinary Google Drive personal-vault pairing uses temporary encrypted and signed objects in MystSafe's hidden Google Drive application-data folder rather than a public repository. Each device separately authorizes the same Google account; Google credentials are never transferred through ordinary personal-vault pairing.

Pairing QR codes and temporary objects contain account- and session-bound identifiers, opaque Drive file identifiers, public cryptographic material, and encrypted and signed pairing messages. They do not contain a Google access token, refresh token, authorization code, ordinary Google Drive file, vault master key, or device private key.

Pairing sessions expire within 10 minutes. The Apps attempt to delete temporary objects after pairing, cancellation, expiration, or recovery cleanup, but network interruption or provider unavailability can delay cleanup. Google may retain logs, backups, or security records under its own practices. Treat every live pairing QR code as sensitive and verify the comparison words shown by both devices before approving pairing.

2.7 Family Plan enrollment and provider credentials

Family Plan enrollment uses one of two QR directions. In the default direction, the Owner displays a time-limited provider-specific QR and the Member scans it. GitHub uses an exact temporary public repository, and Google Drive uses an exact temporary ordinary Drive file with a non-discoverable public-reader capability. Each contains an authenticated encrypted Family bootstrap. The Member retrieves the object without signing in to the Owner's provider account, authenticates the package, stages and validates the exact Family-scoped provider credential in protected storage, attempts to delete and verify unavailability of the exact temporary object, and promotes the credential only after membership becomes Active.

The transferred GitHub or Google credential is a shared bearer credential and cannot necessarily be revoked independently for one Member device. Removing a Member advances authenticated membership and encryption-key state so compliant Apps reject later Family writes and do not provide future Family Shared keys or content. Removal does not recall a package or credential already copied, revoke the underlying provider grant, or prevent a holder of an extracted credential from observing provider-level metadata or attempting denial of service.

The Owner assigns a local alias during enrollment. Both devices process public cryptographic material, temporary device keys, a random Family and Member identity, role, provider and session bindings, expiration, and five comparison words. The Member receives no family roster or Owner personal-vault contents. The Apps process the QR image locally and do not send the image to MystSafe.

2.8 Pairing Service

In the alternate direction, pairing.mystsafe.com provides short-lived rendezvous before Google Drive or GitHub becomes authoritative for membership, credentials, Family control, and normal synchronization. The service processes a public high-entropy session identifier; encrypted, authenticated, write-once protocol envelopes; request timestamps; IP address and routing information; App or protocol version; request size and status; rate-limit state; and security or abuse signals.

The Pairing Service is not designed to receive personal-vault or Family Shared plaintext, provider account identifiers, a participant roster, or a usable provider credential outside the end-to-end-encrypted bootstrap intended for the authenticated receiving device. It has no vault, provider API, account, list, search, or recovery capability. MystSafe is not designed to possess the temporary private keys needed to decrypt the pairing envelopes.

2.9 Device authentication and biometrics

On supported platforms, the Apps ask the operating system to verify you using a biometric method, device passcode, PIN, password, or another system authentication method. The operating system performs that authentication. The App receives the result needed to allow or deny access locally. MystSafe does not receive or store your fingerprint, facial geometry, biometric template, device passcode, PIN, or system password.

2.10 Camera and QR codes

On supported devices, the Apps request camera access only when you choose a feature that needs it, such as scanning a device-pairing, Family Plan enrollment, or Share Once QR code. QR images are processed for the requested function and are not sent to MystSafe. You can manage camera permission in your operating-system settings.

2.11 App analytics, advertising, and distribution platforms

The production Apps do not contain third-party advertising, behavioral-tracking, attribution, or analytics SDKs, and MystSafe does not use App activity for targeted advertising. Development builds may produce local debug logs for software development.

Apple, Google, Microsoft, or another distributor may independently process app-download, account, device, purchase, usage, and diagnostic information under its own privacy notice and your platform settings. A platform may provide MystSafe with aggregate statistics or crash and diagnostic reports that users have chosen to share. MystSafe uses information made available to it only to operate, secure, support, and improve the Apps and administer purchases as described below.

3. Subscription, entitlement, and commercial information

MystSafe Free does not require a purchase. Acquiring Pro or using features that require allowance or entitlement checks causes the App and subscription.mystsafe.com to process limited commercial and pseudonymous state.

3.1 MystSafe License Identity and linked devices

The Apps create or use a pseudonymous MystSafe License Identity to associate entitlement and Share Once allowance with the subscriber, that person's linked MystSafe devices, and the in-App Family Plan that person owns. A License Identity is not a MystSafe user account and does not require a name, email address, or memorized password. It is also not anonymous: transaction, device, network, support, and provider information may be capable of being associated with it.

When an applicable event occurs, the subscription service may process:

  • a random License Identity identifier and related public cryptographic material, signed proofs, or authorization state;
  • pseudonymous linked entitlement-device identifiers, device authorization or revocation status, platform, App version, and linkage timestamps;
  • current plan, entitlement status, paid-through date, renewal state, migration or downgrade state, and purchase-restoration status;
  • pseudonymous Family Plan tier, Owner and Member device-authorization or allowance proofs, active counts, and limit decisions needed to apply the plan, without receiving Member aliases, a Family roster, personal-vault contents, or Family Shared contents;
  • current Share Once allowance, the applicable weekly period, successful-creation count, reset state, and limited creation-event records needed to enforce the allowance across linked devices;
  • Apple transaction and subscription information, such as transaction and original-transaction identifiers, product and subscription-group identifiers, purchase and expiration dates, renewal status, refund or revocation information, environment, ownership type, storefront, price, and currency, to the extent included in signed transaction information, App Store Server API responses, or App Store Server Notifications;
  • signed Apple payloads or verification results and the association between an Apple transaction and a License Identity; and
  • request timestamps, IP address and routing information, protocol and App version, request identifiers, validation outcomes, rate-limit state, fraud or abuse signals, and security logs.

MystSafe will not receive your full payment-card number, bank-account number, Apple Account password, personal-vault or Family Shared plaintext, vault or collection keys, Google or GitHub credentials, provider synchronization objects, Share Once ciphertext, or pairing ciphertext through the subscription service.

3.2 Why commercial state is used

MystSafe uses this information to:

  • activate, verify, maintain, restore, and revoke Pro entitlements;
  • apply paid-through access, renewal, refund, revocation, cancellation, and natural-expiration state;
  • link authorized Owner and Member devices to the applicable entitlement and apply active-device, Family Member, and Family Shared limits;
  • count successfully created Share Once links across linked devices and reset the allowance Monday at 00:00 UTC;
  • apply the approved post-expiration migration and device-selection behavior without deleting local secrets;
  • respond to purchase and entitlement support requests;
  • reconcile App Store records, maintain business and accounting records, and comply with tax or legal obligations; and
  • detect replay, fraud, refund abuse, chargebacks, unauthorized access, and security incidents.

Free permits one active Family Member excluding the Owner, two active Owner devices, one active device for that Member, and one active Family Shared secret for the Owner plus one for the included Member. Each active Family Plan participant therefore has one Free creation allowance; retained former-Member content continues to occupy the Member allowance. Pro permits up to six active Members excluding the Owner and imposes no commercial numeric limit on Owner devices, devices per Member, or Family Shared secrets, subject to technical, security, acceptable-use, provider, and platform limits. The Apps and selected provider also process authenticated plan and collection state needed to apply these rules without disclosing Family Shared plaintext to MystSafe.

The subscription service receives only the Share Once allowance information needed for these purposes. It does not receive the encrypted item being shared, its plaintext, its decryption material, or recipient contact details.

3.3 Apple App Store purchases

Apple handles checkout, payment credentials, localized pricing, taxes charged through the App Store, billing, renewal, cancellation, and refund administration for Apple-platform purchases. Apple may provide MystSafe with signed transaction and renewal information and server notifications concerning purchases, renewals, billing status, expiration, refunds, and revocations. Apple may also provide storefront, price, currency, tax, settlement, and aggregate sales information through App Store administration and reporting tools.

The App may send Apple-signed transaction information or selected transaction identifiers to the subscription service for verification and purchase restoration. Apple and MystSafe process their respective copies of transaction information for their own responsibilities. Apple handles information under Apple's Privacy Policy and App Store & Privacy notice.

Canceling renewal through Apple does not immediately remove paid-through access. MystSafe uses the entitlement status and paid-through date supplied or verified through Apple to determine when Pro features end. Refund, revocation, fraud, or chargeback events may result in earlier entitlement changes where permitted by the Terms of Use and applicable law.

MystSafe's in-App Family Plan is separate from Apple's Family Sharing feature. Enrolling a MystSafe Family Member does not add that person to an Apple family group or transfer an Apple purchase. If Apple Family Sharing is enabled for an applicable subscription, Apple independently processes the family group, sharing preference, ownership type, receipts, transactions, and entitlement under Apple's policies.

3.4 Purchase restoration and future platforms

Purchase restoration uses Apple transaction or subscription information and the License Identity to restore an eligible entitlement on an authorized MystSafe device. Because the License Identity is pseudonymous and device-linked, restoration on a completely new device may require access to an existing linked device or another supported recovery method.

Android and Windows availability and billing options will be announced separately. If MystSafe later supports Google Play Billing, a Windows billing provider, or cross-store entitlement linkage, the relevant store or payment provider will independently process purchase and account information, and MystSafe may receive the transaction, entitlement, regional pricing, tax, refund, and restoration information needed to provide the purchased service. MystSafe will update this Policy and any required in-product notices before materially different processing begins.

4. Share Once information

Share Once lets a sender create an encrypted, time-limited link that one valid native-App or first-party browser recipient can claim before it expires. The feature uses the sender App, the browser viewer at share.mystsafe.com, the encrypted coordination relay at relay.mystsafe.com, the optional fragment-free install bridge at open.mystsafe.com, and a limited allowance check with subscription.mystsafe.com.

4.1 Information processed by the Share Once service

When Share Once is used, and depending on the protocol stage, the Share Once service may process:

  • a random share or session identifier;
  • encrypted protocol envelopes and encrypted item data;
  • public cryptographic material, signatures, message-authentication data, and protocol-version information needed to authenticate the sender and recipient and coordinate encryption for the successful claimant;
  • selected expiration, server creation and expiration timestamps, encrypted-envelope size, state, and status;
  • pseudonymous License Identity, entitlement, or allowance proofs needed to authorize creation and count a successfully created link;
  • creation, claim-attempt, first-valid-claim, delivery, acknowledgement, cancellation, revocation, expiration, and error state; and
  • IP address and routing information, request timestamps, request and App identifiers, user-agent or device information, rate-limit state, validation results, and security or abuse signals.

The complete link includes bootstrap material in its URL fragment. A URL fragment is processed locally by the browser or App and is not sent to the viewer or relay as an HTTP path or query. Loading the first-party viewer fetches and verifies the signed offer and displays its countdown without claiming the share. An ordinary page visit, link preview, opening of the non-consuming save options, or visit to the fragment-free installation bridge does not by itself claim the share.

The recipient does not need a MystSafe App to view the secret. Explicitly selecting View securely in browser begins the browser claim. Selecting Copy to clipboard is also an explicit browser claim and, after successful local verification and decryption, writes a plaintext-equivalent MystSafe secret envelope to the recipient's clipboard. MystSafe is optional if the recipient wants to import and save the secret in a vault.

The first-party viewer performs cryptographic validation and decryption in the recipient's browser using the same production protocol as a compatible native recipient. It is designed not to persist the URL-fragment bootstrap material, recipient private keys, or decrypted secret in cookies, local storage, session storage, IndexedDB, a cache, or a service worker. Those values exist in volatile browser memory while needed for the active flow. Browser and operating-system behavior, extensions, accessibility software, screenshots, clipboard use, memory paging, backups, or a person with device access may nevertheless process or retain information outside MystSafe's control.

The Share Once relay does not receive the shared item's plaintext or a relay-held decryption key. The viewer's static hosting layer and the fragment-free install bridge are not designed to receive the URL fragment, plaintext, or recipient private key. These services do not receive personal-vault or Family Shared keys, Google or GitHub credentials, provider synchronization objects, or the sender's or recipient's email address or telephone number merely because the link is created or claimed. Encrypted information may nevertheless be personal information, and the associated protocol and network metadata may be linked to a sender, recipient, device, or License Identity.

4.2 How Share Once information is used

MystSafe uses Share Once information to:

  • create and maintain the short-lived encrypted coordination session;
  • enforce the sender-selected, server-controlled expiration;
  • validate protocol messages and atomically record the first valid native or browser recipient claim;
  • allow the unlocked sender App to encrypt the item specifically for the successful claimant;
  • deliver encrypted protocol messages and record available acknowledgement state;
  • count a successful server-side creation against the applicable weekly allowance;
  • process cancellation or revocation where the protocol permits; and
  • prevent replay, denial-of-service abuse, unauthorized claims, fraud, and security incidents and troubleshoot failures.

The subscription service may receive or update the pseudonymous successful-creation and quota state, but does not receive Share Once ciphertext. The Share Once relay is separate from Google Drive and GitHub synchronization and does not receive or store a customer vault.

4.3 Sending a link and recipient copies

If you send a Share Once link through text message, email, or another service, the operating-system share sheet and the messaging, email, or other service you choose process the link and recipient information under their own terms and privacy notices. MystSafe does not send the message for you or control copies retained by those services or recipients.

Share Once limits the protocol to the first successful valid claim; it cannot prevent a recipient from copying, saving, photographing, or screen-capturing information after local decryption. This includes information shown by the browser viewer or placed on the recipient's clipboard. A lost final acknowledgement can also leave the sender without confirmation even after a recipient reveals the item.

5. Information handled through the Website and communications

5.1 Website and service infrastructure

MystSafe uses Cloudflare for Website hosting and delivery, the existing launch-notification database, Pages Functions, Workers, Email Service delivery, security, abuse prevention, Turnstile, and Web Analytics and to operate the Share Once browser viewer, encrypted relay, fragment-free install bridge, subscription, and Pairing Service endpoints. Cloudflare processes content that transits or is stored on its network as a service provider or processor for MystSafe and may separately process network, delivery, abuse-prevention, and security data under its own privacy notice.

When you access a MystSafe Website or service endpoint, Cloudflare and MystSafe may process technical and network information needed to deliver, operate, and protect the request, including IP address, request date and time, requested hostname, URL path, referring page, browser or App and device information, operating system, network or approximate location information, routing data, request size and response status, security signals, and challenge or validation results. A URL path or query may contain information you or another person placed in a link; do not place personal-vault or Family Shared secrets, Share Once fragment material, or private pairing material in a path or query.

Cloudflare Turnstile runs browser checks to distinguish legitimate support-form submissions from automated abuse. It may process browser-environment, interaction, network, device, IP-address, user-agent, and challenge-result information. The Website's Pages Function receives the validation result with the related support submission. MystSafe does not include the Turnstile token in the support email, store it in a support-message database, or retain it as part of the support record. Existing launch-notification data remains separate. Cloudflare describes its practices in its Privacy Policy and Turnstile Privacy Addendum.

5.2 Cloudflare Web Analytics

MystSafe uses Cloudflare Web Analytics worldwide to understand aggregate Website traffic and performance. Analytics can report page views, visits, page paths without query strings, referring sites, approximate country, device type, browser, operating system, page-load performance, and Core Web Vitals. MystSafe uses these reports to maintain and improve the Website and understand which pages are useful.

Cloudflare states that Web Analytics does not use cookies, local storage, or fingerprinting to track visitors and does not track a person across unrelated websites. MystSafe receives aggregate reports rather than advertising profiles and does not combine those reports with launch-notification email addresses or License Identities. At this Policy's effective date, Cloudflare states that it retains unsampled beacon data for seven days, aggregates it to a smaller sample for longer-term storage, and makes Web Analytics data available for the previous six months. Cloudflare may change its service practices; its current documentation and privacy notice govern its processing.

5.3 Existing launch-notification requests

New launch-notification registrations are closed. MystSafe retains existing requests only to deliver or reconcile the one product-availability notice that each registrant previously requested and to honor the retention, deletion, security, and evidentiary commitments that applied when the request was collected.

An existing record may include the registered email address, request status, the Website source and notice version, and creation or update timestamps. MystSafe does not convert these records into a newsletter, offer, campaign, recurring product-update, profiling, or general marketing list.

You may cancel an outstanding request or ask MystSafe to delete it before the notice is sent by emailing info@mystsafe.com from the address you registered. Removing the public registration form does not authorize MystSafe to delete outstanding delivery or reconciliation evidence before its applicable retention lifecycle is complete.

A child under 13 must not provide personal information directly to MystSafe. A parent or legal guardian may communicate about an existing request on the child's behalf using the adult's own contact information.

5.4 Support requests, email delivery, and correspondence

If you submit the form at mystsafe.com/support/, MystSafe receives the information you choose to provide through the form:

  • your self-declared plan status as Free, Pro, or not sure;
  • issue category and platform;
  • optional name;
  • required reply email address;
  • optional App version;
  • required subject and message;
  • the submission's source origin and path, without its query string or fragment; and
  • a random server-generated ticket reference and UTC submission time.

The plan selection is self-declared and is used to classify the request for queue handling; it is not a verified entitlement assertion. The public form does not accept file, screenshot, vault-export, device-log, receipt, or other attachments and does not ask for an Apple ID email or transaction identifier.

Cloudflare Pages and a Pages Function receive and validate the form, apply same-origin and size controls, and verify Cloudflare Turnstile. After validation, the Function sends a bounded internal payload through a private Cloudflare service binding to a dedicated Worker. That Worker uses a destination-restricted Cloudflare Email Service binding to send one plain-text message from website@forms.mystsafe.com to help@mystsafe.com, with the validated reply email used only as Reply-To. Google Workspace receives that message and processes later correspondence so MystSafe can respond, provide Standard or Premium priority support as applicable, maintain security, and keep appropriate business records.

MystSafe does not store support submissions in D1, KV, R2, Durable Objects, browser storage, or another support-message database. The form does not send an automatic confirmation email to the requester. After Cloudflare accepts the internal delivery, the browser displays the ticket reference; a reference confirms submission acceptance but does not promise a response time or resolution.

Cloudflare, email-delivery systems, Google Workspace, and MystSafe may process ordinary network, routing, delivery, abuse-prevention, and security metadata, such as IP address, request and delivery timestamps, host and path, user-agent or device information, message-routing information, delivery status, rate-limit state, and validation or security results. Those providers may retain operational or security records under their own policies even though MystSafe does not operate a support-message database.

Do not submit personal-vault or Family Shared contents, vault exports, passwords, recovery information, private keys, Google or GitHub credentials, License Identity authorization material, live device or Family pairing QR codes, or complete Share Once or pairing links. MystSafe does not need decrypted personal-vault or Family Shared contents to provide ordinary support.

A child under 13 must not submit a support request or otherwise provide personal information directly to MystSafe. A parent or legal guardian may communicate with MystSafe on the child's behalf using the adult's own contact information.

5.5 Cookies and similar technologies

MystSafe does not use advertising cookies or cross-site behavioral-tracking technology. Cloudflare Web Analytics does not use cookies or browser storage. Cloudflare may use strictly necessary cookies or comparable signals for content delivery, security, fraud prevention, and Turnstile, depending on the request and Cloudflare configuration.

Because MystSafe does not sell personal information or use it for targeted or cross-context behavioral advertising, browser Do Not Track or Global Privacy Control signals do not currently change MystSafe's practices. If those practices change, MystSafe will honor legally required opt-out signals.

6. How and why MystSafe uses information

In addition to the purposes described above, MystSafe uses personal information it receives to:

  • provide, maintain, secure, and troubleshoot the Services;
  • administer plan features, Family Plan authorization and allowances, linked Owner and Member devices, purchase restoration, Share Once allowances, and support tiers;
  • fulfill outstanding one-time launch-notification requests and process support submissions and correspondence;
  • respond to support, privacy, legal, and security requests;
  • measure and improve Website performance and content using aggregate analytics;
  • prevent fraud, spam, abuse, chargebacks, replay, and security incidents;
  • enforce the Terms of Use and protect users, MystSafe, and others;
  • reconcile transactions and comply with accounting, tax, legal-process, and regulatory obligations; and
  • establish, exercise, or defend legal claims.

MystSafe does not:

  • sell personal information;
  • share personal information for targeted or cross-context behavioral advertising;
  • use personal-vault or Family Shared contents or personal information to train generative artificial-intelligence models; or
  • use personal-vault or Family Shared contents for advertising, data brokerage, or user profiling.

7. Legal bases for EEA, UK, and Swiss users

Where the law requires a legal basis, MystSafe relies on the following:

  • Contract and steps requested before a contract: to provide the Apps, Family Plan and Family Shared functions, pairing, subscription entitlement, purchase restoration, Share Once, support, and an outstanding one-time launch notification previously requested and to perform the Terms of Use.
  • Legitimate interests: to secure and operate the Services; enforce membership, device, and allowance rules; reconcile transactions; provide support; understand aggregate Website use and performance; prevent fraud and abuse; improve the Services; communicate about a request; and protect or enforce legal rights. MystSafe considers the nature and limited scope of the information and your rights when relying on these interests.
  • Consent: for processing for which MystSafe specifically requests consent. You may withdraw consent at any time.
  • Legal obligation: to comply with applicable tax, accounting, consumer-protection, privacy, legal-process, and regulatory or recordkeeping duties.

Where local law requires consent for a particular analytics, security, or communications technology, MystSafe will request that consent before using the technology for that purpose.

MystSafe does not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Automated systems do evaluate entitlement, Family membership and device authority, plan limits, first-valid-claim state, rate limits, and Turnstile or other security signals to allow or deny a particular request. You may contact MystSafe if you believe a legitimate request or entitlement was incorrectly denied.

8. When information is disclosed

MystSafe may disclose personal information it receives to:

  • Service providers: Cloudflare for Website and service hosting, edge compute, content delivery, the existing launch-notification database, security, Turnstile, Web Analytics, support-form processing, the private support-mailer Worker, and Email Service delivery, and Google Workspace for receipt of support messages, business email, and correspondence;
  • Services you direct the Apps to use: Google Drive or GitHub for optional authorization, account-associated storage, personal-vault and Family Shared synchronization, membership control, and pairing;
  • App distributors and commerce providers: Apple for distribution, In-App Purchase, transaction verification, renewal and refund administration, purchase restoration, reporting, and platform services, and Google, Microsoft, or another provider if MystSafe later supports its platform or billing service;
  • Communication providers selected by you: when you send a Share Once link or communicate with MystSafe through an email, text-message, or other provider;
  • Professional advisers: such as lawyers, accountants, auditors, insurers, and security specialists, subject to appropriate duties of confidentiality;
  • Government authorities or other parties when legally necessary: to comply with law, legal process, or a valid governmental request, or when reasonably necessary to investigate abuse or protect rights, safety, and security; and
  • Transaction participants: in connection with a proposed or completed merger, financing, reorganization, bankruptcy, sale of assets, or transfer of all or part of MystSafe, subject to applicable law and appropriate confidentiality protections.

MystSafe requires service providers that process personal information on its behalf to use that information only for authorized purposes and to provide privacy and security protections consistent with this Policy, MystSafe's instructions, and applicable law.

GitHub, Cloudflare, Apple, Google, Microsoft, email and messaging providers, and other third parties may act as independent controllers or businesses for some processing and apply their own terms and privacy notices. MystSafe does not control their independent practices.

9. Retention

MystSafe retains personal information it controls only as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, accounting, tax, legal, and recordkeeping needs.

  • Local App data and provider credentials remain on your device until you delete the applicable data, delete the local personal vault, complete an authenticated Family Plan removal or departure, disconnect the selected provider where permitted, uninstall the App, or the operating system removes them. A completed Family removal erases the departed device's Family Shared cache, pending journal, and collection keys after the terminal state is authenticated, but it cannot erase plaintext or private copies already retained. Device backups and managed-device systems may retain copies outside MystSafe's control.
  • Private GitHub synchronization and Family Plan data remains in the selected private GitHub repository until an applicable authorized deletion occurs or the repository is deleted through GitHub. Deleting a local personal vault, disconnecting GitHub, uninstalling the App, removing a Family Member, or ending Pro does not by itself delete all remote GitHub or Family Shared data.
  • Temporary public pairing and Family enrollment repositories are intended to be short-lived, and the App attempts to delete them after pairing or cleanup. Copies, logs, caches, backups, an encrypted package, or an extracted bearer credential may remain with GitHub or third parties.
  • Google Drive synchronization and Family Plan data remains in MystSafe's hidden application-data folder until the App deletes it through an applicable cleanup, disconnection, Family Plan lifecycle, or remote-erasure operation, or you delete MystSafe's app data through Google. Encrypted synchronization snapshots expire after 30 days and are normally deleted sooner after verified acknowledgement. Manually deleting Google app data can stop synchronization but does not delete a healthy local personal vault on a device.
  • Temporary Google Drive Family enrollment files are intended to be short-lived, and the Apps attempt to delete them and verify their public capabilities are unavailable during successful enrollment or after cancellation, expiration, or recovery. Network interruption or provider unavailability can delay cleanup, and copies, logs, caches, backups, an encrypted package, or an extracted bearer credential may remain.
  • Temporary Google Drive pairing objects expire within 10 minutes, and the Apps attempt to delete them sooner after pairing, cancellation, expiration, or recovery cleanup. Network interruption, provider unavailability, logs, caches, backups, or security retention can delay or limit deletion.
  • Signed synchronization, membership, and security evidence may remain after ordinary cleanup, Member removal, departure, or provider disconnection when the protocol needs it to verify device or Family membership, creator attribution, removal barriers, key epochs, pruning, checkpoints, terminal removal, or other security state. This evidence does not contain decrypted personal-vault or Family Shared payloads, but it can contain pseudonymous identifiers, roles, public cryptographic material, signatures, object state, and timestamps.
  • Pairing Service records remain live only for the short pairing-session period and are then expired or purged from the active protocol. Limited request, rate-limit, error, replay-prevention, purge, and security records may be retained longer to secure the service, investigate incidents, and resolve disputes. MystSafe is not designed to possess the keys needed to decrypt retained protocol envelopes.
  • Share Once browser-viewer data is designed to remain only in volatile browser memory for the active flow and not to be persisted by the viewer in cookies, local storage, session storage, IndexedDB, a cache, or a service worker. Leaving or reloading the viewer, closing the tab or browser, or completing the flow clears viewer-managed state, but MystSafe cannot control browser or operating-system paging, extensions, accessibility software, screenshots, clipboard contents, backups, or copies a recipient makes.
  • Live Share Once records are retained in the active service only until they are consumed, canceled, revoked, or expire, and no longer than the selected expiration, which is at most 24 hours. They then become unavailable through the protocol and are queued for deletion. Limited creation, quota, claim, error, rate-limit, and security records may be retained longer to reconcile allowances, prevent replay and abuse, investigate incidents, and resolve disputes. Those records do not contain the shared plaintext or relay-held decryption keys.
  • Subscription and License Identity records are retained while needed to administer an active or restorable entitlement, authorized Owner and Member devices, Family Plan and Share Once allowances, paid-through access, and the approved post-expiration migration period. Transaction, refund, revocation, chargeback, accounting, tax, fraud-prevention, dispute, and consent records may be retained longer for the applicable limitation period or as required by law. MystSafe deletes or de-identifies pseudonymous commercial state when it is no longer reasonably needed for these purposes.
  • Apple purchase information is also retained independently by Apple under Apple's policies and legal obligations. Ending a MystSafe entitlement or requesting deletion from MystSafe does not delete Apple's transaction records.
  • Existing launch-notification records are deleted or de-identified no later than 24 months after the most recent request or interaction, unless a shorter period applies or a longer period is reasonably necessary for a security incident, legal obligation, dispute, legal claim, or compliance need. An outstanding request remains limited to the previously requested one-time availability notice and is not converted into a marketing list.
  • Ordinary support, Premium priority support, and communications records in Google Workspace and MystSafe-controlled correspondence are deleted or de-identified no later than 24 months after your last interaction with MystSafe, unless a shorter period applies or a longer period is reasonably necessary for a security incident, transaction dispute, legal obligation, or legal claim. The Website does not create a separate support-message database.
  • Support delivery and abuse-prevention records held by Cloudflare, Google Workspace, and other email infrastructure may remain under those providers' operational, security, delivery, backup, suppression, and legal-retention policies. MystSafe limits the support data it places in logs and provider features under its control, including by disabling optional support-message previews where available.
  • Website analytics and infrastructure information is retained according to Sections 5.1 and 5.2, MystSafe's provider configuration, the applicable security or measurement purpose, and provider retention schedules.
  • App-store statistics and diagnostics are retained according to the applicable platform's settings and retention rules and, when received by MystSafe, only as long as reasonably necessary for purchase administration, reporting, issue diagnosis, and App improvement.

When retention ends, MystSafe deletes or de-identifies information where reasonably feasible. Deleted information may persist temporarily in access-restricted backups or security systems until normal rotation, and legal-hold copies may persist until the hold ends. MystSafe cannot delete information held independently by a recipient or third-party provider.

10. Your choices and deletion controls

The Apps provide controls with different effects:

  • Delete Local Vault removes the local personal vault, keys, settings, and local synchronization-provider configuration from that device. Remote personal-vault data and the separate Family Shared provider collection remain.
  • Erase All Vault Data attempts to delete the selected personal vault's connected synchronization objects from the selected provider. It does not delete the separate Family Shared provider collection, a GitHub repository, ordinary Google Drive files, unrelated vault namespaces, provider logs or backups, or signed terminal-removal and security evidence that the protocol retains.
  • Disconnect GitHub removes the local GitHub credential and configuration from that device where the Family Plan lifecycle permits. Remote GitHub and Family Shared data remains.
  • Disconnect Google Drive retires that device from the shared Google Drive-backed vault, attempts to clean up transient objects as the protocol permits, preserves signed terminal-removal security evidence, and keeps the vault contents on that device under a new independent local vault identity. It removes the local Google Drive provider origin and credential and signs the App out of Google on that device. It does not revoke Google credentials separately issued to other devices or automatically revoke the Google-level grant in your Google Account.
  • Remove or revoke a trusted device updates personal-vault device authorization but does not necessarily delete that device's local data, its copy of a shared provider credential, or separate subscription records needed to enforce entitlement-device status.
  • Remove a Family Member or leave a Family Plan ends future Family authorization after the signed terminal state is authenticated and erases the departed device's Family Shared cache and keys. It does not delete that person's separate personal vault; remotely wipe an uncontrolled device; erase information already revealed, copied, saved, exported, photographed, or otherwise retained; individually revoke a copied provider credential; or delete Family Shared secrets retained for the remaining participants.
  • Cancel Pro through Apple turns off future renewal but does not immediately delete License Identity or transaction records and does not delete personal-vault or Family Shared secrets. Paid-through access continues according to the verified entitlement state, after which the applicable Free and migration behavior applies. Existing Family Shared Data remains available, while new creation and new Member or device admission may be blocked at the Free limits.
  • Revoke or cancel Share Once affects the live protocol record only where the feature permits. It cannot delete a link from a message service or information a recipient has already decrypted, displayed, copied to a clipboard, saved, photographed, or otherwise retained through the App, browser viewer, device, or another service.

You can manage or delete repositories and revoke the MystSafe GitHub App through GitHub, and manage MystSafe's app data or third-party connection through Google Account and Google Drive controls. Revoking a shared GitHub authorization or Google Family grant may affect every associated personal-vault or Family Plan device. Revoking or deleting a Google connection or its app data may stop Google Drive synchronization; a Google or GitHub account alone cannot decrypt or recover a personal vault or Family Shared collection without the necessary device-held cryptographic keys.

You can manage App Store subscriptions, billing, and certain purchase history through Apple. You may ask MystSafe to delete or de-identify eligible License Identity and commercial state by contacting info@mystsafe.com. Because the state is pseudonymous, MystSafe may require the License Identity or a signed in-App proof to locate the record and verify your authority. Deletion may make cross-device entitlement, allowance, support, or purchase restoration unavailable and does not require Apple or another independent provider to delete its records. MystSafe may retain limited transaction, security, or legal records as described in Section 9.

You can cancel an outstanding launch-notification request as described in Section 5.3, request deletion of eligible support or communications records by contacting info@mystsafe.com, and manage camera and authentication permissions through your device settings. MystSafe may need reasonable verification before acting on a privacy or deletion request. Uninstalling an App does not necessarily delete provider or Family Shared data, License Identity or transaction records, operating-system backups, app-store records, messages previously sent to MystSafe, Share Once links held by others, or copies retained by recipients or current or former Family Plan participants.

11. Your privacy rights

Depending on where you live and subject to applicable exceptions, you may have the right to:

  • know whether and how MystSafe processes your personal information;
  • request access to or a copy of personal information;
  • correct inaccurate personal information;
  • request deletion of personal information;
  • request restriction of, or object to, certain processing;
  • receive certain information in a portable format;
  • withdraw consent, where processing is based on consent;
  • opt out of sale, targeted advertising, or certain profiling;
  • appeal MystSafe's denial of a request; and
  • complain to a privacy or data-protection regulator where you live or work, or where you believe a violation occurred.

To exercise a right or appeal a decision, email info@mystsafe.com. Describe your request and the email address, communication, License Identity, transaction, or interaction to which it relates. MystSafe may take reasonable steps to verify your identity and authority while requesting only information necessary for verification. An authorized agent may submit a request where allowed by law, subject to verification of the agent's authority and, when permitted, confirmation from you.

A parent or legal guardian may exercise applicable privacy rights on behalf of a child, subject to reasonable verification of the adult's identity and authority. For information stored only on the child's device or in a third-party account, the parent or guardian must use the applicable App, device, or third-party controls because MystSafe does not possess or control that information.

MystSafe will not discriminate against you for exercising an applicable privacy right. MystSafe cannot access, provide, correct, or delete information it does not possess or control, such as a personal vault held only on your device, Family Shared Data held by a current or former participant or provider, Share Once information retained by a recipient, or data controlled solely through Apple, Google, GitHub, or another provider. For that information, use the relevant App, device, or provider controls.

If you are in the EEA, United Kingdom, or Switzerland, you may lodge a complaint with your local data-protection authority. MystSafe encourages you to contact us first so we can try to resolve the concern.

United States state disclosures

During the preceding 12 months, MystSafe may have collected the following categories of personal information described in this Policy: identifiers and contact information; Internet or other electronic-network activity; approximate location derived from an IP address; communications and other content you choose to send; and professional or employment information if you include it in a communication. Sources include you, your browser or device, and service or platform providers. MystSafe uses and discloses these categories for the business purposes described in Sections 6 and 8.

When Pro, License Identity, Share Once, Pairing Service, and their related controls are used, MystSafe may collect the pseudonymous device, Family Plan authorization, License Identity, commercial and subscription, encrypted protocol, and network categories described in this Policy.

MystSafe has not sold personal information or shared it for targeted or cross-context behavioral advertising during the preceding 12 months. MystSafe does not use or disclose sensitive personal information to infer characteristics about individuals. Because MystSafe does not engage in these activities, it does not offer a sale or targeted-advertising opt-out link. Contact MystSafe if you believe an applicable state-law right has not been addressed.

12. International processing

MystSafe is based in the United States. MystSafe and the providers described in this Policy may process information in the United States and other countries whose privacy laws may differ from those where you live.

Where an international-transfer mechanism is required for personal information MystSafe controls, MystSafe uses an applicable adequacy decision, a provider's participation in a legally recognized data-privacy framework, standard contractual clauses or an approved equivalent, or another lawful safeguard. You may contact info@mystsafe.com for information about applicable safeguards.

13. Security and recovery limitations

MystSafe uses administrative, technical, and organizational safeguards designed to protect personal information. The Apps use measures such as authenticated encryption, digital signatures, device-protected key storage, local user authentication, authenticated Family membership, removal barriers, and collection-key epochs. MystSafe-operated services use measures such as encrypted transport, signed or end-to-end-encrypted protocol messages or transaction verification, access controls, rate limits, logging, short expirations, and separation among subscription state, pairing ciphertext, and Share Once ciphertext. Cloudflare processes customer content for MystSafe under contractual data-protection and security commitments applicable to the configured services.

No device, network, cloud provider, encryption method, or software system can be guaranteed completely secure or continuously available. Pseudonymous identifiers and encrypted content can still be personal information. Metadata can reveal that a device communicated with a service, when it did so, the size or frequency of activity, and whether an operation succeeded.

MystSafe does not operate a master-key or master-password recovery service and generally cannot recover a personal vault or Family Shared collection that becomes inaccessible. A License Identity, purchase record, Google account, or GitHub account is not by itself a vault-recovery credential. Protect your devices, selected provider account and shared Family credential, live device and Family pairing and Share Once links or QR codes, and recovery mechanisms, and maintain trusted devices and backups appropriate for your needs.

If you use MystSafe for individual professional or work purposes, your employer or organization may separately control the device, Apple, Google, or GitHub account, network, purchase, or information you store. Its privacy and retention rules may apply independently of this Policy.

14. Children and parental involvement

The Apps are intended to be suitable for users age 4 and older. They are not intended for children under 4.

A child who has not reached the age of legal majority where the child lives may use an App only after a parent or legal guardian has reviewed and accepted the Terms of Use for the child and authorized and supervises the child's use. A parent or guardian must handle any Pro purchase and authorize a child's participation in a Family Plan or use of a connected feature that transmits persistent identifiers or encrypted information to MystSafe or a third party.

MystSafe's core local App features are designed so that a child can create and use a personal vault without creating a MystSafe account or providing personal-vault contents to MystSafe. In normal local operation, personal-vault contents and cryptographic keys remain on the device, and MystSafe does not receive them. If the child participates in Family Shared, uses Share Once or Pairing Service, or uses another connected feature, MystSafe, Cloudflare, and the selected provider process the limited pseudonymous, encrypted, and technical information described in this Policy to provide and secure that feature. MystSafe does not use that information for advertising, behavioral profiling, or tracking a child across unrelated services.

A child under 13 must not submit the Website support form or otherwise provide contact information directly to MystSafe. A parent or legal guardian may communicate about an existing launch-notification request, exercise a privacy right, or contact MystSafe on the child's behalf using the adult's own contact information.

Google, GitHub, Apple, and other connected services impose their own account, purchase, and minimum-age requirements. A child who does not satisfy a provider's requirements may not independently enable or use that provider's synchronization, pairing, purchase, or another connected feature. An App Store age rating and permission from a parent or guardian do not override a third party's eligibility rules.

MystSafe does not sell children's personal information, share it for targeted or cross-context behavioral advertising, or use it to train generative artificial-intelligence models. MystSafe does not require a child to disclose more personal information than is reasonably necessary to use an applicable feature.

If MystSafe learns that it received personal information directly from a child under 13 in circumstances requiring parental consent that was not obtained, MystSafe will take reasonable steps to delete the information. A parent or legal guardian may contact info@mystsafe.com to ask whether MystSafe holds personal information received from a child, request access to or deletion of that information, or refuse further collection. MystSafe generally cannot access, review, or delete personal-vault or Family Shared data held only on a device, by another participant, or through a third-party provider account.

15. Third-party services and links

The Services may link to or interoperate with GitHub, Apple, Google, Microsoft, Cloudflare, messaging services, social networks, and other third-party services. MystSafe does not control their security, availability, or independent privacy practices. Review the terms and privacy notices that apply to those services before using them.

16. Changes to this Privacy Policy

MystSafe may update this Policy to reflect changes in the Services, practices, providers, or law. MystSafe will post the updated version at mystsafe.com/privacy/ and change its effective date. Prior versions will remain available through the Website's policy archive.

If a change materially affects how MystSafe uses personal information already collected, MystSafe will provide additional notice through the Website, an App, or email when reasonably possible and required by law. MystSafe will request consent before using previously collected information for a materially different purpose when applicable law requires it.

17. Contact MystSafe

For privacy questions, requests, appeals, or complaints, contact:

MystSafe LLC

1309 Coffeen Ave Ste 1200, Sheridan, WY 82801, United States

Email: info@mystsafe.com

Telephone: +1 972 332 1230

MystSafe

A fundamentally different secret vault.

No Password No Account No Cloud Quantum Safe Family Friendly Get MystSafe Plans FAQ Support Privacy Policy Terms

© 2026 MystSafe LLC.

Designed and built in Texas, USA.

Private by design. Secure by default.