Third-Party Services & Open-Source Notices
1. Third-party services the app uses
Each service below activates only when you use the relevant feature. None receives your medical records from us — we have none to give (see the Privacy Policy).
| Service | Provider | When it runs | What it handles | Where processing happens |
|---|---|---|---|---|
| Google Sign-In | Only if you set up backups (optional) | Standard Google account authentication; no health data | Google’s servers | |
| Google Drive (app-data folder) | Only when you back up or restore | Your already-encrypted backup archive, plus minimal file metadata — date, format version, profile count | Your own Google account | |
| Google Play Billing | Only if you buy or restore Mediara Plus | The purchase, handled entirely by Google under Google’s terms. We never receive your payment details, and no health data is involved | Google Play | |
| Android Health Connect | Google / device OS | Only if you connect it | Read-only import of the vitals you authorise — steps, heart rate, blood pressure, glucose, weight and the rest — into the app’s encrypted store | On your device |
| ML Kit Text Recognition | Only when text is read from a document | Converts your document photo to text | On your device — the recognition model runs locally and images are not uploaded | |
| Platform speech recognizer (voice input) | Device OS vendor | Only when you tap the microphone | Your dictated audio, converted to text | On your device. The app requires on-device recognition; where a device cannot provide it, dictation is disabled rather than falling back to a network service. The app stores no audio and operates no audio service |
| Android photo picker, camera, file picker | Device OS | Only when you attach an image or PDF | Returns the single item you chose; the app holds no gallery or storage permission | On your device |
| System dialer (tap-to-call) | Device OS | Only when you tap an emergency contact or the emergency-services button | Opens the dial screen with the number; the app does not place calls itself | On your device |
Wearable app detection. To help you set up Health Connect, the app checks locally whether specific companion apps are installed — Samsung Health, Fitbit, Garmin Connect and similar — using a narrowly declared Android package-visibility list. This check happens on-device; no list of your installed apps is collected or transmitted.
Each provider’s own terms and privacy policy govern its service. Google’s are at policies.google.com; your device vendor’s policies govern its speech recognizer and other OS services.
1a. Google API Services — Limited Use
Mediara Vault’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing backup and restore feature, is never transferred to third parties, is never used for advertising, and is never read by humans.
The app requests only the Drive app-data folder scope. It cannot read your other Drive files, your email or your contacts.
1b. What the app does not use
No analytics or crash-reporting SDKs. No social-media SDKs. No third-party cloud databases. No push-notification service — every notification is generated locally on your device. No third party receives data from the app for advertising purposes; see Privacy Policy §6a for the limits that would apply if the app ever carried advertising.
The optional Crash reports setting is not an exception to this. It is off unless you turn it on, it saves a technical record on your device, and it sends nothing. If you choose to send one, you do it yourself with the share sheet, after reading it.
2. Open-source software notices
The app is built with open-source software. The binding, always-complete list ships inside the app: Settings → About → Open-source licences presents the standard Flutter licences screen, which is generated from the actual build and includes every package’s licence text.
The table below is a human-readable summary of the principal components, not the legal notice itself.
| Component | Licence |
|---|---|
| Flutter SDK and Dart | BSD-3-Clause |
| drift, sqlite3 (Dart bindings) | MIT |
| SQLite3MultipleCiphers — the database encryption layer | MIT (SQLite itself: public domain) |
| riverpod / flutter_riverpod | MIT |
| go_router, path, path_provider, url_launcher, image_picker, file_picker, share_plus, http, uuid, archive, image, timezone, flutter_timezone | BSD/MIT-family — as generated in-app |
| cryptography (Dart) | Apache-2.0 |
| flutter_secure_storage | BSD-3-Clause |
| flutter_local_notifications | BSD-3-Clause |
| local_auth | BSD-3-Clause |
| google_sign_in, google_mlkit_text_recognition, health, in_app_purchase | BSD/Apache — as generated in-app |
| fl_chart | MIT |
| pdf, pdfx | Apache-2.0 / MIT |
| speech_to_text | BSD-3-Clause |
| Inter typeface (bundled in the app, and used on this website) | SIL Open Font License 1.1 |
| Material Icons font | Apache-2.0 |
The cells marked “as generated in-app” are deliberately not hand-maintained: the in-app licences screen is authoritative and is regenerated from the build. This table exists so a reader can see at a glance that the app carries no copyleft (GPL) obligations.
This website
The pages you are reading are plain HTML and CSS with a small amount of JavaScript, all served from this domain. The only third-party component is the Inter typeface, self-hosted here under the SIL Open Font License 1.1 — the same typeface the app bundles. Nothing is loaded from a font CDN or any other third-party host, so visiting this site does not disclose your visit to anyone else.
3. Trademarks
Google Play, Google Drive, Android, Health Connect and ML Kit are trademarks of Google LLC. Samsung Health, Fitbit, Garmin, and the other wearable-app and device names shown in the app’s setup wizard are trademarks of their respective owners, used only to identify those apps and devices.
Mediara Vault is not endorsed by, or affiliated with, any of them.
Contact
Questions about these notices: support@mediara.care.
Related: Privacy Policy · Terms of Use · the plain-English list of third-party services.