Legal

Data Storage, Backup, Retention & Deletion Policy

Mediara Vault (Android package care.mediara.vault) · Published by Mediara · Effective 11 August 2026 · Last updated 11 August 2026

One document covers storage, backup, Google Drive, retention and deletion, because for a local-first app these are a single story: the data is in your custody at every stage. This policy is incorporated into the Terms of Use; the privacy framing lives in the Privacy Policy.

1. Where your data lives

Everything you put into Mediara Vault — profiles, records, vitals, documents, photos, recognised text, pregnancy and surgery data, reminders — is stored on your device, in an encrypted database and an encrypted file vault, under keys held in your device’s secure storage.

There is no Mediara Vault server and no cloud database: the developer never receives, stores, hosts or can read your records.

The App also switches off Android’s own backup and device-to-device transfer channels for its data, so the operating system does not silently copy your records anywhere. The App’s own encrypted backup is the only way your data leaves the device — and only when you set it up.

2. What this means in practice

We cannotBecause…
View or search your recordsThey exist only on your device, encrypted
Edit or correct your recordsSame
Recover your data if your device is lost, broken or resetWe hold no copy
Restore your data if you uninstall the AppUninstalling deletes the App’s local data
Reset or recover your recovery codeIt is never transmitted or stored anywhere by us
Decrypt a code-protected backup for youIt is end-to-end encrypted; only your recovery code can open it
Delete backups from your Google DriveOnly you, or Google at your instruction, can

This is a deliberate design, not a limitation we may later “fix”: privacy is achieved precisely by our not having access. The trade-off is that you are the only person who can protect and preserve your data.

No custodian relationship. Because we never receive, hold or control your data, we are not a custodian, bailee, trustee or record-keeper of it, and no duty to preserve, retrieve or produce your records arises on our side. By using the App you accept that the entire custody of your records — live data, backups, exports and recovery code — rests with you, and, to the maximum extent permitted by law, you agree not to bring claims against us for loss, corruption or unavailability of data that was only ever in your custody.

3. Backups — how they work

Backups are optional and off until you set them up. When you create one:

  1. The App packages your data into an archive on your device.
  2. The archive is encrypted on your device (AES-256-GCM) before anything is uploaded.
  3. The encrypted archive is uploaded over HTTPS to a private app folder in your own Google Drive, using the Google account you signed in with. The App’s Drive access is limited to that app-data folder — it cannot see the rest of your Drive.

Two backup types exist, chosen by you, with the trade-off shown in the App at the moment of choice:

  • Code-protected (recommended for maximum privacy). End-to-end encrypted: the backup can be decrypted only with your recovery code. Neither we nor Google can open it. If you lose the code, the backup is permanently unreadable — there is no reset.
  • Account-portable (convenience). A decryption key is stored, itself protected, inside the same private area of your own Google Drive, so a backup restores on any device where you sign in to your Google account — no code to remember. The trade-off: anyone who controls your Google account — you, someone who compromises it, Google itself, or a party with lawful process against Google — could decrypt an account-portable backup.

One recovery code, not one per backup. You set it once, and the same code opens your Drive backups and any .mediara file you save. Each archive embeds the key wrap that was current when it was written, so changing the code does not re-key backups you have already made: older ones still open with the old code, and only new ones use the new one.

A small amount of unencrypted metadata accompanies each backup file in your Drive so the restore screen can list backups before decryption: the backup date, the format version, and a count of profiles. The profile names themselves are encrypted.

4. Google Drive specifics

  • Your account, your storage. Backups count against your Google Drive quota and live under your Google account’s terms with Google. We are not a party to that relationship and have no access to your account.
  • Scope. The App requests Google Sign-In only to authorise Drive access, and only the app-data-folder scope. It does not read your files, email or contacts.
  • Availability. Google Drive is a third-party service; if it is unavailable, backup and restore are unavailable. Consider keeping an additional local copy — a saved .mediara file, or a PDF summary of critical information.
  • Revocation. You can revoke the App’s Drive access at any time from your Google account settings; existing backups remain in your Drive until you delete them.

5. Your responsibilities

Because the data is exclusively in your custody:

  1. Enable backups if losing the data would matter to you, and verify periodically that a recent backup exists — the App shows the last backup time.
  2. Keep your recovery code safe for code-protected backups: written down or in a password manager, not only memorised.
  3. Protect your device (a screen lock; the App’s biometric lock and a short lock timeout are recommended) and your Google account (a strong password and 2-step verification).
  4. Before uninstalling, resetting or selling a device, confirm a current backup exists, or export what you need. Uninstalling deletes the App’s local data immediately and irreversibly.
  5. Test the restore when changing phones: restore on the new device before wiping the old one.

6. Retention — you control it

We impose no retention schedule because we hold nothing. Your records stay on your device until you delete them; your backups stay in your Drive until you delete them or your Google account’s own policies remove them.

Four technical bounds are disclosed for completeness:

  • Recycle Bin. Deleted records first go to the App’s Recycle Bin so accidental deletions are recoverable, for 30 days. Emptying it, or a hard delete, removes them from the live database.
  • Audit log. The App keeps a local, tamper-evident log of changes for your own history view, bounded to 180 days or 50,000 entries. On a hard delete, the log’s related entries are crypto-shredded — their encryption key material is destroyed. Like everything else, it never leaves the device except inside an encrypted backup.
  • Backup retention. The newest 3, 5 or 10 archives are kept, your choice; older ones are pruned automatically.
  • Crash reports. At most 5 are stored, and only if you turned the setting on. Turning it off deletes them.

7. Deletion — how to delete everything

To delete…Do this
A single recordDelete it in the App, then empty the Recycle Bin
A profileDelete the profile in the App — it removes all of that person’s records
All local dataUninstall the App — Android removes the App’s storage — or use the in-app delete options first for a cleaner sequence
One backupTap the bin icon beside it on the App’s Backup & Restore screen
Every backup at onceGoogle Drive → Settings → Manage apps → Mediara Vault → Delete hidden app data. Backups live in Drive’s private app-data folder, are not visible when browsing Drive, and exist only there — so this removes all of them permanently. Save a .mediara export first if you want to keep a copy
The App’s Drive accessYour Google account → Security → Third-party access → remove Mediara Vault

No deletion request to us is needed — there is nothing on our side to delete. If you contact support@mediara.care with a deletion request anyway, we will confirm the above and help you locate the right controls. Step-by-step instructions, with screenshots of where each control lives, are on the deleting your data page.

8. Data-loss scenarios — read this once

ScenarioOutcome
Phone lost or broken, backup existsInstall the App on a new device, sign in, restore. Code-protected backups also need your recovery code
Phone lost or broken, no backupData is permanently lost. No one can recover it
Uninstalled the App, no backupData is permanently lost
Forgot the recovery code (code-protected backup)That backup is permanently unreadable. Your live on-device data is unaffected — make a new backup with a new code
Google account lost or inaccessibleBackups in that account’s Drive are unreachable until you recover the account with Google. On-device data is unaffected
Google account compromisedOn-device data is safe. Account-portable backups could be decrypted by the attacker; code-protected backups remain protected by your code. Secure the account and consider rotating backups
Saved a .mediara file with no recovery code set, then lost the phoneThe file cannot be opened by anything. It is sealed with a key held in that phone’s secure hardware, which never leaves it. The App warns about this at the moment you write such a file and offers to set a code first
Saved a .mediara file with a recovery code setRestores on any phone, with the code. The code-derived key travels inside the file, so it does not depend on Google Drive or the original device at all
Changed the recovery code, then tried to restore an older backupOlder backups still open with the old code. Each archive embeds the key wrap that was current when it was written

9. Exports

Two kinds, and they behave very differently:

  • PDF summaries — the health summary, the pregnancy and surgery summaries, or an individual document. These are human-readable and unencrypted once shared. They go out through your device’s share sheet.
  • Encrypted .mediara backup files — the full-data export, written wherever you choose. Encryption is the same AES-256 used for Drive backups, and the same recovery-code rules apply: with a recovery code the file opens on any phone; without one it opens only on the phone that wrote it. The App warns you before writing a file of the second kind.

Once you share an export, it leaves the App’s protection — where you send it is up to you, and its handling there is outside this policy. The decrypted copy the App stages for a share is written to its own private temporary directory and deleted straight after, so plaintext health data is never placed in shared storage where other apps could read it.

There is deliberately no plaintext CSV or JSON export. An unencrypted, complete medical export sitting on disk would undo the rest of this policy.

Contact

Questions about this policy: support@mediara.care.


Related: Delete your data · How backup and restore work · Privacy Policy · Terms of Use.