Legal

Privacy Policy

Effective date: August 27, 2026 · Version 2.4

In plain words

  • We are myAngelVault Kft., a Hungarian company operating under EU law — the GDPR applies to everything we do.
  • We collect what the service needs to run: your account details, the content you place in your vault, heartbeat signals, and the contact details of the people you name.
  • Your vault is yours — we do not review or monitor its contents in the ordinary course of operating the service.
  • Storage is encrypted (256-bit AES at rest, TLS in transit), passwords are stored only as hashes, and card details live with Stripe, not with us.
  • Your data has one job: running your vault and delivering it to the people you chose. We do not profile you for advertising.
  • You can access, correct, export, or delete your data at any time — and your whole vault is downloadable whenever you want.
  • If we ever had to wind down the service: at least six months’ notice, your vault downloadable the whole time, and a pro-rata refund — the same written commitment as in our Terms (Section 16.4).

This summary is here to help you find your way — the full text below is what governs. The human story of how we protect what you entrust to us lives on our Trust & Longevity page.


1. Introduction and Data Controller

myAngelVault is operated by myAngelVault Kft., a limited liability company registered in Hungary (referred to as "we", "our", or "us" throughout this Policy).

For all personal data processed in connection with the myAngelVault platform (the "Service") — including personal data of users, Guardians, and recipients — myAngelVault Kft. acts as the data controller. Our full contact details are in Section 19.

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect personal information and user-generated content when you use the Service, and it also informs Guardians and recipients — who are not users of the Service — about how their data is handled.

This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), and — to the extent applicable — U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).


2. Information We Collect

2.1 Information You Provide Directly

We may collect the following information when you create an account or use the Service:

  • Name
  • Email address
  • Phone number (when provided for verification or notification purposes)
  • Account credentials (password hash; we never store plaintext passwords)
  • Payment information (processed by Stripe; we do not store full card details)
  • Billing details you provide at checkout (billing name, address, country, and — for business customers — tax number), used for tax calculation and legally required invoicing
  • User-generated content, including messages, photos, videos, voice and video recordings, files, and instructions ("User Content"). If you record directly in the app or on the website, the microphone and camera are used only while you are recording, and only at your request — recordings become part of your User Content like any other upload
  • Guardian-related information (names, email addresses, phone numbers, relationship labels)
  • Recipient information you provide for scheduled deliveries
  • Your acceptance of our Terms of Service and related consents (we record the date, time, and document version you accepted)

You are responsible for ensuring that any information you provide is accurate and lawful, and that you have the right to share information about third parties (such as Guardians and recipients).

2.2 Automatically Collected Information

When you access the Service, we may automatically collect:

  • Access timestamps and activity signals related to the Heartbeat monitoring system (heartbeat timestamps, device health status)
  • App version (for the mobile application)
  • Push notification tokens (Firebase Cloud Messaging) for the mobile application

When you access delivered content (as a recipient) or perform administrative actions, we additionally collect:

  • IP address
  • Browser type (user agent string)

These are stored for security audit purposes only and are not collected during normal use of the Service.

When you register a mobile device, we collect:

  • Device name (e.g., "iPhone 14", "Pixel 7")
  • Device type (phone or tablet)
  • Operating system and version
  • App version
  • Device permission states (notification, battery optimization) for diagnostics purposes

We do not use this information to profile users for advertising purposes. IP addresses in application logs are partially masked (last octet redacted) before storage.

2.3 Information from Third-Party Sign-In Providers

If you choose to register or sign in using a third-party identity provider (e.g., Apple Sign In), we receive limited profile information from that provider, typically including your name and email address. We do not receive or store your third-party account password.

2.4 Referral Program Data

If you participate in our referral program ("Give a month. Get a month."), we process: your personal referral code, the fact that another user registered using your referral, and the status of any earned rewards. When you register using someone's referral link or code, we record the connection between your account and the referrer's account for the purpose of granting rewards. We do not disclose your activity details to your referrer beyond the fact that you joined and, if applicable, subscribed.


3. How We Use Your Information

We process your information solely for the following purposes:

  • To provide, operate, and maintain the Service
  • To create and secure your account and prevent unauthorized access
  • To enable content storage, scheduling, and delivery mechanisms
  • To operate the Heartbeat monitoring system, including reminder and escalation notifications
  • To facilitate Guardian verification workflows
  • To process payments, manage subscriptions, calculate applicable taxes, and issue legally required invoices and receipts
  • To operate the referral program
  • To communicate essential service-related messages (account, security, billing, delivery events)
  • To detect, prevent, and respond to fraud, abuse, or security incidents
  • To process and respond to illegal content reports (see our Terms of Service, Section 11)
  • To keep records evidencing your acceptance of our Terms and consents
  • To comply with legal obligations (including tax and accounting laws)

We do not sell personal data and do not use data for targeted advertising.


4. Legal Bases for Processing (GDPR)

Where the GDPR applies, we process personal data on the following legal bases:

  • Performance of a contract (Article 6(1)(b)) — to provide the Service you have subscribed to, including content storage, delivery, Heartbeat monitoring, and Guardian workflows
  • Legitimate interests (Article 6(1)(f)) — to secure the Service, prevent fraud and abuse, monitor system reliability, improve functionality, and process the personal data of Guardians and recipients that users provide (see Sections 6 and 7), in each case balanced against the rights and interests of the individuals concerned
  • Legal obligation (Article 6(1)(c)) — where processing is required by applicable law, including tax and accounting obligations (invoicing, payment records), responding to lawful requests from competent authorities, and complying with content removal obligations
  • Consent (Article 6(1)(a)) — where you have given consent to specific processing through a separate, affirmative declaration (such as a dedicated checkbox), independent of your general use of the Service. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal
  • Explicit consent for special categories of data (Article 9(2)(a)) — where your User Content voluntarily includes special category data (see Section 5.2)

A structured overview of our processing activities — data categories, purposes, legal bases, and retention periods — is provided in Appendix A.


5. User Content & Sensitive Information

User Content stored in myAngelVault may include sensitive, emotional, or deeply personal information.

You acknowledge and agree that:

  • You choose what content to upload or store
  • You are solely responsible for the nature, accuracy, and legality of such content
  • We do not review, interpret, or validate User Content
  • Encrypted storage protects User Content from unauthorized access, but you remain responsible for what you choose to share

We strongly recommend that you do not upload information you are not legally permitted to store or share.

5.1 Sensitive Content — Credentials, Financial Data, and Access Information

The Service allows you to leave behind information that helps your loved ones manage your affairs. This may include login credentials, banking information, cryptocurrency keys, insurance details, and other sensitive access data. You are never required to store such information — doing so is entirely your own choice.

We process such content on the legal basis of performance of a contract (GDPR Article 6(1)(b)) — storing and delivering the content you choose to place in your vault is the Service you have subscribed to. In addition, at registration you provide a separate, explicit consent declaration covering any sensitive or special-category information you may voluntarily choose to include in your User Content (see Section 5.2).

Important considerations:
  • No online service — ours included — can make storing live credentials risk-free; treat such material as inherently sensitive wherever it is kept
  • myAngelVault provides encrypted storage (256-bit AES at rest, TLS 1.2+ in transit) and secure, token-based delivery mechanisms
  • However, myAngelVault is not a financial institution, a PCI DSS-certified vault, or a regulated custodian of financial data
  • We do not access or review the contents of your stored data in the ordinary course of operating the Service
  • You are solely responsible for deciding what sensitive information to store, for keeping it up to date, and for understanding the associated risks
  • We are not liable for financial loss arising from the storage or delivery of such content (see Terms of Service, Sections 6.1, 9, and 14)

5.2 Special Categories of Personal Data (GDPR Article 9)

User Content may incidentally contain special categories of personal data as defined under GDPR Article 9, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data, or data concerning a person's sex life or sexual orientation.

We do not specifically request, require, or encourage any special category data. Where such data is included in User Content by your voluntary choice, the legal basis for processing is your explicit consent (GDPR Article 9(2)(a)).

This explicit consent is collected through a separate, dedicated consent declaration presented at account registration — distinct from your acceptance of the Terms of Service — in which you expressly consent to our storage and processing of any special categories of personal data and other sensitive information that you voluntarily choose to include in your User Content. This consent applies only if and to the extent you actually include such data in your content; it does not oblige you to include any.

You may withdraw this consent at any time by deleting the relevant content, deleting your account, or contacting us at legal@myangelvault.com. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. Please note that if you withdraw consent while special-category data remains in your vault, we may need to ask you to remove that content, as we can no longer lawfully store it.

5.3 Third-Party Personal Data in User Content

Your User Content may contain personal data of third parties (e.g., names, stories, or photos of family members, friends, or other individuals). Because you use the Service in a personal, private capacity, myAngelVault Kft. is the data controller for the processing of such third-party personal data that takes place on our platform (storage and delivery).

By uploading such content, you represent and warrant that:

  • You have the right to share this information, and no obvious overriding interest of the individuals concerned prevents it
  • You have informed the relevant individuals, where reasonably possible and appropriate, that content concerning them may be stored and delivered through the Service
  • You will promptly remove such content if an individual concerned objects to it

Individuals whose personal data is included in User Content may contact us at legal@myangelvault.com to exercise their rights (see Section 14). Because content is encrypted and private by design, we may need to coordinate with the account holder to locate and act on specific content.


6. Guardians — Data Processing and Information Notice

The Service allows users to designate a trusted third party (a "Guardian") who serves as a verification contact during the safety chain process. Guardians do not register on the platform — their data is provided by the user. myAngelVault Kft. is the data controller for Guardian personal data.

If you are a Guardian, this Section 6 (together with Sections 10–14 and 19) constitutes the information notice provided to you under GDPR Article 14. It is linked from the first email we send you.

6.1 Data We Process About Guardians

Provided by the user (source of the data):
  • Guardian's full name
  • Guardian's email address
  • Guardian's phone number (optional)
Generated by the system:
  • Consent token (single-use link, 7-day expiry)
  • Consent status and timestamp
  • Response during safety chain (ALIVE / DECEASED / UNKNOWN / NO_RESPONSE)
  • Response timestamp and deadline
  • SMS reminder tracking (if phone number is provided)

6.2 Purpose and Legal Basis

We process Guardian data solely to operate the Guardian verification workflow: inviting the Guardian, obtaining their acceptance of the role, contacting them during the safety chain, and recording their response.

The legal basis is legitimate interests (GDPR Article 6(1)(f)): the user has a legitimate interest in designating a trusted person to help verify their status, and the Guardian verification step protects both the user (against premature delivery) and the recipients. The processing is minimal (name and contact details), proportionate to this purpose, and the Guardian can decline or resign from the role at any time, which stops any further processing. We have carried out and documented a balancing assessment of these interests.

6.3 Communications Sent to Guardians

Invitation email — when the user designates a Guardian:
  • Contains: user's name, Guardian's name, role explanation, consent link, and a link to this Privacy Policy
  • Does NOT contain: vault contents, recipient names, messages, or any private data
Alert email — during the safety chain (if the user becomes inactive):
  • Contains: user's name, Guardian's name, response link with 3 options
  • Does NOT contain: vault contents, recipient names, or any private data
SMS reminders (if a phone number is provided, during the safety chain only):
  • Day 2: reminder to check email
  • Day 4: urgent reminder
  • SMS messages do NOT contain vault data, recipient names, or private details

6.4 What Guardians Can See

Guardians can see:

  • The user's name
  • A request to confirm the user's status
  • Three response options ("They're OK" / "I'm not sure" / "They are no longer with us")

Guardians cannot see:

  • Vault contents (messages, photos, videos, files)
  • Recipient names or contact details
  • The user's personal information (email, phone, address)
  • Subscription or payment information

6.5 Guardian Rights and Retention

As a Guardian, you have the rights described in Section 14, including the right to object to the processing (which you can exercise simply by declining or resigning from the Guardian role, or by contacting us), the right of access, the right to erasure, and the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or your local supervisory authority.

Retention:

  • Active Guardian: Data retained for the duration of the user's account
  • Declined invitation (token expired): Token deleted; name and email remain in the user's profile until the user removes them or deletes the account
  • Guardian resigns from role: The user is notified and must designate a new Guardian; data is removed when the user updates the Guardian information
  • User deletes account: All Guardian data permanently deleted within 30 days

7. Recipients — Data Processing and Information Notice

The Service allows users to designate recipients who will receive User Content upon delivery. Recipients do not register on the platform, do not have accounts, and are not informed of their designation until delivery occurs — this is inherent to the nature of the Service (delivery of personal messages after the user's death or prolonged inactivity). Their data is provided entirely by the user. myAngelVault Kft. is the data controller for recipient personal data.

If you have received a delivery from myAngelVault, this Section 7 (together with Sections 10–14 and 19) constitutes the information notice provided to you under GDPR Article 14. It is linked from the delivery email — the first communication we send you, in accordance with GDPR Article 14(3)(b).

7.1 Data We Process About Recipients

Provided by the user (source of the data):
  • Recipient's full name (required)
  • Recipient's nickname (optional)
  • Recipient's email address (required for delivery)
  • Recipient's phone number (optional)
  • Recipient's profile picture (optional, uploaded by the user)
  • Category assignment (e.g., "family", "friends")
  • Delivery preferences (e.g., gentle delivery scheduling)

7.2 Purpose and Legal Basis

We process recipient data solely to store the user's delivery configuration and, if delivery is triggered, to deliver the user's content to the designated recipient.

The legal basis is legitimate interests (GDPR Article 6(1)(f)): the user has a compelling personal interest in leaving personal messages for their loved ones, and recipients typically have a corresponding interest in receiving them. The processing is minimal (contact details), the data is never made public or used for any other purpose (never for marketing), and recipients can object and request deletion at any time after being contacted. Because recipients cannot be informed before delivery without defeating the purpose of the Service, we provide the required information at the moment of first contact, as permitted by GDPR Article 14(3)(b). We have carried out and documented a balancing assessment of these interests.

7.3 What Recipients Receive Upon Delivery

Recipients are contacted only when delivery is triggered. They receive:

  • An email composed by the user (custom subject and body)
  • A secure, time-limited link to access the content package designated for them
  • A link to this Privacy Policy

Recipients can see:

  • The email package name (defined by the user)
  • The user's name (sender identification)
  • The user's message (email body composed by the user)
  • The list of files in their specific package (name, type, size)

Recipients cannot see:

  • Other recipients' names, email addresses, or packages
  • The user's personal details (email, phone, subscription status)
  • Guardian information
  • Any vault content not specifically included in their designated package

Receiving a delivery does not create any obligation for the recipient. Recipients are free not to open or access the content.

7.4 Data Collected During Delivery Access

When a recipient accesses a delivery link, the following is automatically logged for security audit purposes:

  • IP address
  • Browser type (user agent string)
  • Access type (view / download / download all)
  • Which files were downloaded
  • Access timestamp

This log does not store the recipient's name or email address — only the delivery token ID, IP address, and browser information. The legal basis is our legitimate interest in securing deliveries and investigating unauthorized access.

7.5 Recipient Rights and Retention

As a recipient, you have the rights described in Section 14, including the right to object to the processing of your contact data, the right of access, the right to erasure, and the right to lodge a complaint with the NAIH or your local supervisory authority. To exercise these rights, contact legal@myangelvault.com.

Retention:

  • Before delivery: Data retained for the duration of the user's account
  • After delivery: Delivery access remains available until the delivery link expires or the account is deleted
  • Delivery access logs: IP address and browser information retained for up to 12 months, then deleted
  • User deletes account: All recipient data permanently deleted within 30 days
  • Recipient requests deletion after delivery: We remove the recipient's contact data from active systems without undue delay; security access logs (which do not contain the recipient's name or email) are retained for the remainder of their 12-month period

8. Privacy Governance

We regularly review our processing activities and maintain internal records of processing in accordance with GDPR Article 30. Where a processing activity is likely to result in a high risk to the rights and freedoms of individuals, we carry out a data protection impact assessment in accordance with GDPR Article 35 before proceeding.

We have assessed the requirements of GDPR Article 37 and have determined that we are not currently required to designate a Data Protection Officer, given the scale and nature of our processing. Privacy matters are handled directly by our management. You can reach us on any privacy matter at legal@myangelvault.com.


9. Email & Notifications

We may send communications related to:

  • Account creation and verification
  • Security alerts
  • Heartbeat verification prompts, reminders, and escalation notices (email, push notification, or SMS)
  • Delivery events
  • Subscription, billing, and renewal notifications
  • Periodic reminders related to Service activity
  • Referral program events you participate in
  • Important service updates and policy changes

We do not send marketing emails unrelated to the Service unless you have separately opted in.


10. Data Storage & Security

We implement reasonable administrative, technical, and organizational safeguards to protect your data, including:

  • Encryption of data in transit (TLS 1.2+)
  • Encryption of data at rest (256-bit AES, server-side encryption provided by our cloud infrastructure provider)
  • Application-level field encryption of message content and envelope letters (AES-256-GCM): these are stored in unreadable, encrypted form and are decrypted only when you access your own vault or when a delivery is executed; the encryption key is managed outside the database
  • Secure authentication mechanisms, including optional Two-Factor Authentication (2FA via TOTP)
  • Role-based access controls within our infrastructure
  • Regular security review of systems and practices
  • Secure token-based access for content delivery (time-limited links)
  • Partial masking of IP addresses in application logs
Important clarification on encryption: The Service uses server-side encryption (SSE) provided by our cloud infrastructure provider (Microsoft Azure). This means your data is encrypted while stored on our servers and decrypted when accessed through authorized means (e.g., during content delivery). The Service does not use end-to-end encryption (E2EE) — authorized personnel with appropriate access controls may technically access stored data for operational purposes such as complying with valid legal orders. We do not routinely access, review, or monitor User Content.

However, no system is 100% secure. You acknowledge that data transmission and storage may involve inherent risks. We are not responsible for unauthorized access resulting from circumstances beyond our reasonable control, including compromise of your own devices, accounts, or credentials.


11. Service Providers and Processors

We engage carefully selected third-party service providers (data processors) to operate the Service. These currently include:

  • Microsoft Azure (cloud infrastructure, compute, and blob storage) — primary region: Canada Central
  • Stripe, Inc. (payment processing and tax calculation) — United States
  • Twilio Inc. (SMS services, phone verification) — United States
  • SendGrid (Twilio Inc.) (transactional email delivery) — United States
  • Google LLC (backup transactional email delivery via Gmail SMTP, used only if our primary email provider fails; push notification delivery via Firebase Cloud Messaging) — United States
  • PostHog (PostHog EU Cloud) (privacy-preserving product analytics — pseudonymous usage events only) — European Union
  • Apple Inc. (Sign In with Apple authentication) — United States
  • KBOSS.hu Kft. (szamlazz.hu) (issuance of legally required electronic invoices; processes billing name, address, country, and tax data) — Hungary

All processors are bound by data processing agreements that comply with applicable data protection laws, including GDPR Standard Contractual Clauses where personal data is transferred outside the European Economic Area.

We do not sell your personal information to any third party. We do not share your User Content with third parties except as required to operate the Service (for example, to deliver scheduled messages to designated recipients) or as required by law.


12. International Data Transfers

myAngelVault is operated from Hungary (EU). Your data may be transferred to and processed in:

  • The European Union and European Economic Area (including invoicing in Hungary)
  • The United States (where certain processors are located, including Stripe, Twilio, SendGrid, Google, and Apple)
  • Canada (where our primary cloud infrastructure is hosted)

For transfers outside the EU/EEA, we rely on appropriate safeguards including:

  • European Commission adequacy decisions where applicable (Canada, United States under the EU-U.S. Data Privacy Framework)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other lawful transfer mechanisms under GDPR Articles 44–49

13. Data Retention

We retain personal data and User Content:

  • For as long as your account remains active
  • As necessary to provide the Service
  • As required by law, accounting obligations, or the establishment, exercise, or defense of legal claims

Specific retention periods:

  • Active accounts: Data retained for the duration of the account
  • After account deletion: User Content and personal data permanently removed within 30 days
  • After subscription expiry: Account and data deleted approximately 90 days after expiry (with prior notice)
  • Payment and invoicing records: Retained in anonymized or minimized form for 8 years after the transaction, as required by Hungarian accounting law (Act C of 2000, Section 169)
  • Terms acceptance records: Retained for the duration of the account and thereafter as needed to evidence the contract (up to the applicable limitation period)
  • Legal holds: Data may be retained beyond standard periods where required by a court order, legal obligation, or pending legal proceedings
  • Logs and security data: Retained for up to 12 months for security and abuse prevention purposes
Service continuity. The timelines above describe the normal operation of an active Service. Separately, our Terms of Service (Section 16.4) contain a written service continuity commitment: if we ever decided to discontinue the Service, we will give you at least six (6) months' advance notice by email, keep your entire vault available for download throughout that notice period, and provide a pro-rata refund of prepaid subscription fees. User Content is permanently deleted only after the shutdown date. (See Section 16.4 of the Terms for details, including the limited exceptions for events beyond our reasonable control.)

You may delete your content or close your account at any time, subject to technical and legal limitations.


14. Your Rights

Under applicable data protection laws — including the GDPR and, where applicable, U.S. state privacy laws — you have rights over your personal data. These rights belong to users, Guardians, and recipients alike.

Under the GDPR:
  • Right of access (Article 15) — you may ask us to confirm whether we process your personal data and to provide a copy of it, together with information about the purposes, categories, recipients, and retention of the processing
  • Right to rectification (Article 16) — you may ask us to correct inaccurate data or complete incomplete data without undue delay
  • Right to erasure (Article 17) — you may ask us to delete your personal data, for example where it is no longer necessary for the purposes it was collected for, where you withdraw consent, or where you object and no overriding grounds exist. We will also take reasonable steps to inform any processors of the erasure request
  • Right to restriction of processing (Article 18) — you may ask us to limit the processing of your data while a dispute about its accuracy or lawfulness is resolved; restricted data will only be stored and not otherwise processed without your consent
  • Right to data portability (Article 20) — you may receive the personal data you provided to us in a structured, commonly used, machine-readable format and transmit it to another controller
  • Right to object (Article 21) — you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests; we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms
  • Right to withdraw consent (Article 7(3)) — where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of prior processing
  • Automated decision-making (Article 22) — we do not make solely automated decisions that produce legal effects concerning you. The Heartbeat safety chain is an automated process, but it acts only on your own account configuration, includes multiple human-response checkpoints (escalation prompts, Guardian verification, emergency stop), and can be halted by you at any time before delivery

To exercise these rights, contact us at legal@myangelvault.com. We will respond within one month (extendable by two further months for complex requests, with notification). Exercising your rights is free of charge. If we refuse a request, we will explain why and inform you of your right to complain.

You also have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH — www.naih.hu) or with the supervisory authority of your place of residence or work in the EU.

Under U.S. state privacy laws (where applicable):

Depending on your state of residence, you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and the right not to be discriminated against for exercising these rights. We honor such requests from all U.S. users regardless of whether a given state law technically applies to us. We do not sell or share personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. To submit a request, contact legal@myangelvault.com. You may use an authorized agent where the law provides for it; we may need to verify your identity before acting on a request.


15. Cookies and Tracking Technologies

We use only essential cookies and similar technologies necessary for the operation of the Service, including:

  • Session cookies for authentication
  • Security cookies to prevent unauthorized access (e.g., CSRF protection)
  • Functional cookies to remember your preferences (including referral attribution when you follow an invite link)

We also measure how the Service's features are used with privacy-preserving product analytics (PostHog, hosted in the European Union). This measurement is cookie-free and pseudonymous: PostHog itself stores nothing persistent on your device, and usage events are linked only to a random internal identifier — never to your name or email address. Your vault content (messages, files, recipients) is never included in analytics data. (A short-lived, session-scoped attribution entry we use to credit registrations to their traffic source is described in our Cookie Policy.)

We do not use advertising cookies, third-party tracking pixels, or cross-site analytics tools that profile users.

You can manage cookies through your browser settings. Please note that disabling essential cookies will prevent the Service from functioning correctly.

Because we use only strictly necessary cookies (exempt under Article 5(3) of the ePrivacy Directive 2002/58/EC), a separate cookie consent banner is not required. For details, see our Cookie Policy at /cookies.


16. Children's Privacy

The Service is intended for individuals 18 years of age or older.

We do not knowingly collect personal data from minors. If we become aware that personal data of a minor has been collected, we will take reasonable steps to delete it promptly.

If you believe a minor has provided us with personal data, please contact us at legal@myangelvault.com.


17. Content Moderation and Illegal Content

In connection with our obligations under the Terms of Service (Section 11: Illegal and Infringing Content), we may process personal data for the following purposes:

  • Receiving, reviewing, and acting upon reports of illegal or infringing content (including notices under the EU Digital Services Act and the U.S. Digital Millennium Copyright Act)
  • Communicating with reporters and affected users regarding content moderation decisions
  • Cooperating with competent authorities in relation to illegal content
  • Maintaining records of content moderation actions as required by applicable law

The legal basis for this processing is legal obligation (GDPR Article 6(1)(c)) and, where applicable, legitimate interests (GDPR Article 6(1)(f)) in maintaining a safe and lawful platform.


18. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version becomes effective upon publication, with the "Effective date" updated accordingly. For material changes, we will provide reasonable advance notice (typically 30 days) via email or in-app notification. Where a change requires renewed consent under applicable law, we will ask for it separately.


19. Data Controller & Contact Information

The data controller responsible for personal data processed in connection with the Service is:

myAngelVault Kft.

Limited liability company registered in Hungary

Registered office: 2011 Budakalász, Dombhát utca 7., Hungary

Company registration number: 13-09-246835

Tax ID: 33038746-2-13

EU VAT number: HU33038746

Contact:

General and privacy inquiries: legal@myangelvault.com

Legal notices and illegal content reports: legal@myangelvault.com

Supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary

Website: www.naih.hu


Appendix A — Overview of Processing Activities

For transparency, this appendix summarizes each processing activity with its data categories, purpose, legal basis, and retention period.

1. Account management
  • Data: name, email, password hash, phone (optional), profile picture (optional), 2FA data (encrypted)
  • Purpose: account creation, authentication, security
  • Legal basis: performance of a contract (GDPR Art. 6(1)(b))
  • Retention: duration of the account; deleted within 30 days of account deletion
2. Contract and consent records
  • Data: acceptance timestamps, accepted document versions, consent declarations
  • Purpose: evidencing your agreement to the Terms and your consents
  • Legal basis: legal obligation and legitimate interests (Art. 6(1)(c), (f))
  • Retention: duration of the account, plus the applicable limitation period
3. User Content storage and delivery
  • Data: messages, files, photos, videos, links you upload; delivery configuration
  • Purpose: storing your vault and delivering it as you configured
  • Legal basis: performance of a contract (Art. 6(1)(b)); explicit consent for any special-category data you choose to include (Art. 9(2)(a))
  • Retention: duration of the account; deleted within 30 days of account deletion
4. Heartbeat monitoring and safety chain
  • Data: activity timestamps, heartbeat logs, device data, notification tokens, escalation and safety-chain events
  • Purpose: detecting inactivity and running the multi-phase safety verification process
  • Legal basis: performance of a contract (Art. 6(1)(b))
  • Retention: duration of the account; technical logs up to 12 months
5. Guardian workflow
  • Data: Guardian name, email, phone (optional), consent status, safety-chain responses
  • Purpose: Guardian invitation, consent, and verification during the safety chain
  • Legal basis: legitimate interests (Art. 6(1)(f)) — see Section 6.2
  • Retention: see Section 6.5
6. Recipient management and delivery
  • Data: recipient name, email, phone (optional), profile picture (optional), delivery preferences
  • Purpose: storing delivery configuration; delivering content when triggered
  • Legal basis: legitimate interests (Art. 6(1)(f)) — see Section 7.2
  • Retention: see Section 7.5
7. Payments, tax, and invoicing
  • Data: billing name and address, country, tax number (business customers), payment history, Stripe identifiers
  • Purpose: charging subscriptions, calculating taxes, issuing invoices/receipts, accounting
  • Legal basis: performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
  • Retention: payment and invoicing records 8 years (Hungarian accounting law); other billing data for the duration of the account
8. Referral program
  • Data: referral code, referrer–invitee connection, reward status
  • Purpose: operating the "Give a month. Get a month." program
  • Legal basis: performance of a contract (Art. 6(1)(b))
  • Retention: duration of the account
9. Security, fraud prevention, and audit logs
  • Data: IP address (partially masked in application logs; full IP in delivery access and admin audit logs), user agent, security events
  • Purpose: securing the Service, preventing abuse, investigating incidents
  • Legal basis: legitimate interests (Art. 6(1)(f))
  • Retention: up to 12 months
10. Service communications
  • Data: email address, phone number, notification tokens, communication logs
  • Purpose: transactional and safety-related communications (see Section 9)
  • Legal basis: performance of a contract (Art. 6(1)(b))
  • Retention: communication logs up to 12 months; contact data for the duration of the account
11. Content moderation and legal compliance
  • Data: reported content, reporter contact details, moderation records
  • Purpose: handling illegal-content and copyright notices, cooperating with authorities
  • Legal basis: legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
  • Retention: as required by the applicable legal obligation

This Privacy Policy is provided in English. In the event of a conflict between this version and any translated version, the English version shall prevail. Version 2.4, effective August 27, 2026.
myAngelVault

The legal pages set out the rules.

These pages tell you how we think — how your words are kept safe, and how they reach the people you love.

Related: Terms of Service · Content & Delivery Disclaimer · Cookie Policy