Legal

Privacy Policy

ExpiryVault stores some of the most sensitive documents you own. This policy explains, in plain language, what we collect, why, who helps us process it, and the control you have over it.

Last updated: 17 September 2026

Summary

  • We collect only what we need to run ExpiryVault: your account, the documents and subscriptions you add, and the settings you choose.
  • Your documents are encrypted in transit and at rest. We do not sell your personal data and we do not use it for advertising.
  • When you use AI features, your document content is processed to extract details. It is never used to train AI models — by us or by our AI providers.
  • Payments are handled by Google Play. We never see your card details.
  • You can delete your account and all stored documents at any time from the app or by following these steps.

1. Who we are

This Privacy Policy applies to the ExpiryVault mobile app for Android (package app.expiryvault.mobile), the website at expiryvault.app and related services (together, the "Service"). "ExpiryVault", "we", "us" and "our" refer to the operator of the Service, which is the controller of your personal data.

If you have any questions about this policy, contact us at privacy@expiryvault.app.

2. Account data (via Clerk)

To create and secure your account we use Clerk, a third-party authentication provider. When you sign up or sign in, Clerk processes on our behalf:

  • your email address and, if you provide it, your name;
  • if you sign in with a third-party account (such as Google), the basic profile information that provider shares, such as your name, email address and profile picture;
  • authentication data such as hashed passwords, one-time verification codes, session tokens and sign-in timestamps;
  • technical data used to protect your account, such as IP address, device and browser/app information, and security events (for example, failed sign-in attempts).

We use this data to create your account, sign you in, keep your account secure and contact you about your account. Clerk's own handling of data is described in its privacy policy at clerk.com/legal/privacy.

3. Documents, files and the information you add

The core of ExpiryVault is the information you choose to store. This may include:

  • Document records — the type of document (for example passport, ID card, driving licence, insurance policy, visa, lease or warranty), its title, issuer, document number, issue and expiry dates, notes, tags and the vault it belongs to;
  • Files — photos, scans and PDFs you attach, including earlier versions if you use version history;
  • Subscriptions — name, category, price, billing cycle and renewal date for services you track;
  • Reminder settings — the offsets and channels you choose for each item;
  • Vaults, trips and family data — vault names, trip names and dates, and which items you add to shared spaces.

Identity documents can contain sensitive information, such as your date of birth, nationality, photograph and signature. We process this only to provide the Service to you: storing it, showing it back to you, calculating expiry status and sending your reminders. We do not use it for any other purpose.

Your data is stored on your device so the app can work offline, and is synced to our secure cloud storage so it is backed up and available when you sign in on a new device. Data on the device is protected by Android's app sandbox and, if you enable it, the ExpiryVault biometric lock.

4. AI processing of documents

ExpiryVault Pro and Family include optional AI features:

  • AI document scanning reads a photo or file you select and suggests details such as the document type, number, issue date and expiry date;
  • AI document assistant answers questions you ask about the documents in your vault.

When you use one of these features, the relevant image, file or text — and your question, if you ask one — is sent securely to our AI service provider to generate the result. This only happens when you actively use an AI feature; your vault is never sent for AI processing in the background.

Your documents are never used to train AI models. We do not use your content to train or improve AI models, and our AI providers are contractually prohibited from doing so. Content sent for AI processing is used only to return the result to you and is not retained by the provider longer than necessary to deliver the service and meet its legal and safety obligations.

AI results can be wrong. Always check suggested dates and details before saving them.

5. Push notifications and email reminders

If you allow notifications, ExpiryVault sends reminders before items expire or renew. To do this we store a push token that identifies your app installation, and the reminder schedule you've set. On Android, push notifications are delivered through Google's Firebase Cloud Messaging service. Reminder text may include the name of the item and its due date; you can keep notification content off your lock screen in your Android settings.

If you enable email reminders (Pro and Family), we send reminder emails to your account email address using an email delivery provider. We also send essential service emails, such as sign-in codes, security alerts and important changes to these terms. We do not send marketing emails unless you have opted in, and every marketing email includes an unsubscribe link.

You can turn off push notifications in the app or in Android settings, and turn off email reminders in the app at any time.

6. Analytics and diagnostics

To keep ExpiryVault reliable and improve it, we collect limited usage and diagnostic information, such as:

  • app events such as screens viewed and features used (for example, "document added" or "reminder set");
  • crash reports and performance data;
  • device model, Android version, app version, language and approximate region derived from IP address;
  • a random app or account identifier used to link these events.

Analytics events do not include the contents of your documents, file images, document numbers or the names of your subscriptions. We do not use analytics data for advertising, and we do not use advertising identifiers to track you across other apps or websites.

The expiryvault.app website does not use advertising cookies or cross-site tracking.

7. Purchases via Google Play and RevenueCat

Pro and Family subscriptions are sold through Google Play. Google processes your payment under its own terms and privacy policy; we never receive your full payment card details.

We use RevenueCat to manage subscriptions — to confirm purchases with Google Play, check which plan you are entitled to, and handle trials, renewals, cancellations and refunds. RevenueCat processes:

  • an app user identifier linked to your ExpiryVault account;
  • purchase details such as the product purchased, price and currency, purchase and expiry dates, trial status, renewal status and Google Play order and purchase token information;
  • basic device and app information, such as platform, app version and country of the store account.

RevenueCat's privacy policy is available at revenuecat.com/privacy, and Google's at policies.google.com/privacy.

8. Sharing and family plans

We share your documents with other people only when you tell us to. If you use secure sharing, the recipient can see the specific document or information you chose to share, for as long as you allow. You can revoke access at any time; however, we cannot control copies a recipient has already made.

A Family plan shares the subscription, not anyone's personal documents. Each member's personal vault remains private to them. Items placed in the shared family vault, and their expiry status on the household dashboard, are visible to all members of that family group. The family organiser can see who is in the group and manage membership, but cannot see members' personal vaults.

9. How we use your data

We use personal data to:

  • provide the Service: store and sync your vault, calculate expiry status, and send the reminders you set up;
  • run optional features you use, such as AI scanning, sharing, family vaults and subscription insights;
  • manage your account, subscriptions and free trials;
  • keep the Service and your account secure, and prevent fraud and abuse;
  • diagnose problems, and understand how features are used so we can improve them;
  • respond to support requests;
  • comply with legal obligations and enforce our Terms of Service.

We do not sell personal data, share it for cross-context behavioural advertising, or use your document contents for any purpose other than providing the Service to you.

  • Contract — to provide the Service you signed up for, including storing documents, sending reminders and managing subscriptions.
  • Consent — for push notifications, optional marketing emails, and for processing sensitive information contained in documents you choose to upload. You can withdraw consent at any time.
  • Legitimate interests — to secure the Service, prevent abuse, and understand and improve app performance, balanced against your rights.
  • Legal obligation — to keep transaction records and respond to lawful requests.

11. Service providers

We use trusted providers who process data on our behalf, under contracts that limit use to providing their service to us:

ProviderPurposeData involved
ClerkAuthentication and account securityAccount and sign-in data
Cloud hosting and storage providersStoring and syncing your vaultDocuments, files and app data (encrypted)
AI service providersAI scanning and document assistantContent you submit to AI features
Google (Firebase Cloud Messaging)Delivering push notificationsPush token, notification content
Email delivery providerEmail reminders and service emailsEmail address, reminder content
Google PlayPayments and subscriptionsPurchase data
RevenueCatSubscription managementPurchase and entitlement data, app user ID
Analytics and crash reporting providersReliability and product improvementUsage events, diagnostics, device info

We may also disclose data if required by law, to protect the rights, safety and security of our users or the Service, or as part of a merger or acquisition — in which case this policy will continue to apply to your data, and we will notify you of any change.

12. Security

We protect your data with encryption in transit (TLS) and at rest, access controls that limit who can reach production systems, and optional biometric app lock on your device. No system is completely secure, so we also encourage you to keep your device updated and protected with a screen lock. If we become aware of a data breach that affects you, we will notify you and the relevant authorities as required by law.

13. Data retention

  • Account data, documents and files are kept for as long as your account is active. Documents you delete are removed from your vault immediately and from our systems as described below.
  • After you delete your account, your account, documents, files, subscriptions and settings are deleted from our active systems within 30 days, and from encrypted backups within a further 60 days, after which they are permanently erased.
  • AI inputs are not stored by us beyond the result you choose to save to your vault.
  • Analytics and diagnostic data are retained for up to 14 months, then deleted or fully anonymised.
  • Purchase records are kept for as long as required by tax, accounting and consumer-protection laws (typically up to 7 years), even after account deletion.
  • Support emails are kept for up to 2 years after the conversation ends.

14. Account and data deletion

You can delete your account and all associated data at any time in the app under Settings → Account → Delete account. If you no longer have the app, email support@expiryvault.app from your account email address. Full instructions are on our account deletion page.

Deleting your account does not cancel an active Google Play subscription. Cancel it in Google Play first to avoid further charges.

15. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate data;
  • delete your data;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting earlier processing;
  • not be discriminated against for exercising your rights.

Most of these you can exercise directly in the app. For anything else, email privacy@expiryvault.app. We will respond within the time required by law (usually 30 days) and may need to verify your identity first. You also have the right to lodge a complaint with your local data protection authority.

16. International transfers

Our service providers may process data in countries other than your own, including the United States. Where data is transferred from the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

17. Children

ExpiryVault is not directed at children and you must be at least 13 years old (or the minimum age of digital consent in your country, if higher) to create an account. We do not knowingly collect personal data from children under that age. On a Family plan, an adult may store a child's documents — such as a passport — in their own or the shared family vault; that adult is responsible for that information. If you believe a child has created an account, contact us and we will delete it.

18. Changes to this policy

We may update this policy as the Service changes. We will post the new version on this page and update the "Last updated" date. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.

19. Contact

Privacy questions or requests: privacy@expiryvault.app
General support: support@expiryvault.app