Legal

Third-Party Services & Open-Source Notices

Mediara Vault (Android package care.mediara.vault) · Published by Mediara · Effective 11 August 2026 · Last updated 11 August 2026

1. Third-party services the app uses

Each service below activates only when you use the relevant feature. None receives your medical records from us — we have none to give (see the Privacy Policy).

ServiceProviderWhen it runsWhat it handlesWhere processing happens
Google Sign-InGoogleOnly if you set up backups (optional)Standard Google account authentication; no health dataGoogle’s servers
Google Drive (app-data folder)GoogleOnly when you back up or restoreYour already-encrypted backup archive, plus minimal file metadata — date, format version, profile countYour own Google account
Google Play BillingGoogleOnly if you buy or restore Mediara PlusThe purchase, handled entirely by Google under Google’s terms. We never receive your payment details, and no health data is involvedGoogle Play
Android Health ConnectGoogle / device OSOnly if you connect itRead-only import of the vitals you authorise — steps, heart rate, blood pressure, glucose, weight and the rest — into the app’s encrypted storeOn your device
ML Kit Text RecognitionGoogleOnly when text is read from a documentConverts your document photo to textOn your device — the recognition model runs locally and images are not uploaded
Platform speech recognizer (voice input)Device OS vendorOnly when you tap the microphoneYour dictated audio, converted to textOn your device. The app requires on-device recognition; where a device cannot provide it, dictation is disabled rather than falling back to a network service. The app stores no audio and operates no audio service
Android photo picker, camera, file pickerDevice OSOnly when you attach an image or PDFReturns the single item you chose; the app holds no gallery or storage permissionOn your device
System dialer (tap-to-call)Device OSOnly when you tap an emergency contact or the emergency-services buttonOpens the dial screen with the number; the app does not place calls itselfOn your device

Wearable app detection. To help you set up Health Connect, the app checks locally whether specific companion apps are installed — Samsung Health, Fitbit, Garmin Connect and similar — using a narrowly declared Android package-visibility list. This check happens on-device; no list of your installed apps is collected or transmitted.

Each provider’s own terms and privacy policy govern its service. Google’s are at policies.google.com; your device vendor’s policies govern its speech recognizer and other OS services.

1a. Google API Services — Limited Use

Mediara Vault’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing backup and restore feature, is never transferred to third parties, is never used for advertising, and is never read by humans.

The app requests only the Drive app-data folder scope. It cannot read your other Drive files, your email or your contacts.

1b. What the app does not use

No analytics or crash-reporting SDKs. No social-media SDKs. No third-party cloud databases. No push-notification service — every notification is generated locally on your device. No third party receives data from the app for advertising purposes; see Privacy Policy §6a for the limits that would apply if the app ever carried advertising.

The optional Crash reports setting is not an exception to this. It is off unless you turn it on, it saves a technical record on your device, and it sends nothing. If you choose to send one, you do it yourself with the share sheet, after reading it.

2. Open-source software notices

The app is built with open-source software. The binding, always-complete list ships inside the app: Settings → About → Open-source licences presents the standard Flutter licences screen, which is generated from the actual build and includes every package’s licence text.

The table below is a human-readable summary of the principal components, not the legal notice itself.

ComponentLicence
Flutter SDK and DartBSD-3-Clause
drift, sqlite3 (Dart bindings)MIT
SQLite3MultipleCiphers — the database encryption layerMIT (SQLite itself: public domain)
riverpod / flutter_riverpodMIT
go_router, path, path_provider, url_launcher, image_picker, file_picker, share_plus, http, uuid, archive, image, timezone, flutter_timezoneBSD/MIT-family — as generated in-app
cryptography (Dart)Apache-2.0
flutter_secure_storageBSD-3-Clause
flutter_local_notificationsBSD-3-Clause
local_authBSD-3-Clause
google_sign_in, google_mlkit_text_recognition, health, in_app_purchaseBSD/Apache — as generated in-app
fl_chartMIT
pdf, pdfxApache-2.0 / MIT
speech_to_textBSD-3-Clause
Inter typeface (bundled in the app, and used on this website)SIL Open Font License 1.1
Material Icons fontApache-2.0

The cells marked “as generated in-app” are deliberately not hand-maintained: the in-app licences screen is authoritative and is regenerated from the build. This table exists so a reader can see at a glance that the app carries no copyleft (GPL) obligations.

This website

The pages you are reading are plain HTML and CSS with a small amount of JavaScript, all served from this domain. The only third-party component is the Inter typeface, self-hosted here under the SIL Open Font License 1.1 — the same typeface the app bundles. Nothing is loaded from a font CDN or any other third-party host, so visiting this site does not disclose your visit to anyone else.

3. Trademarks

Google Play, Google Drive, Android, Health Connect and ML Kit are trademarks of Google LLC. Samsung Health, Fitbit, Garmin, and the other wearable-app and device names shown in the app’s setup wizard are trademarks of their respective owners, used only to identify those apps and devices.

Mediara Vault is not endorsed by, or affiliated with, any of them.

Contact

Questions about these notices: support@mediara.care.


Related: Privacy Policy · Terms of Use · the plain-English list of third-party services.