Data deletion and retention

This document is the source copy for All my Heart's public deletion guidance and internal release review.

It must stay consistent with the released app and Privacy Policy.

At a glance

All my Heart has no operator-hosted journal account.

Journal data is local by default, and optional cloud data is held in the user's own Apple or Google account.

The structured local journal record is authenticated and encrypted with a device-held key, and device-local restore-point descriptors use a separate encrypted key.

Media, health-document attachments, restore-point attachment blobs, and published user-owned files remain separate files so the app and user-selected destinations can open them.

Deleting a visible item does not guarantee immediate physical erasure from every operating system backup, synchronized archive, provider backup, or content-addressed cloud blob.

Disconnecting sync stops future synchronization but does not delete remote data.

The Privacy & Data screen provides separate actions to delete the active local journal or the complete All my Heart cloud copy for the connected provider.

Before deleting a readable cloud copy, All my Heart performs one final validated import and merges remote memories into the local journal.

Deleting the cloud copy then preserves that merged local journal and disconnects sync after the provider confirms deletion.

If the cloud archive cannot be validated or imported, All my Heart stops before deletion.

The app offers a separate, explicitly confirmed recovery action that discards unreadable or cloud-only memories and deletes the cloud copy without importing it.

Attachment capacity

The current release supports up to 4,096 attachment references across the complete journal, including every child journal.

Photo Drop records, journal photos, GIFs and videos, profile and caregiver photos, and Health attachments share that capacity.

The app rejects an addition or portable merge that would exceed the limit and leaves the existing journal unchanged.

It never silently truncates attachments.

If an older or concurrently merged journal already exceeds the limit, the app keeps that content readable and removable but blocks new attachment references until the journal is back within the supported capacity.

A journal containing more than 4,096 unique attachment files may require a newer archive format before it can be exported or synchronized losslessly.

Delete a journal item

Use the item's delete control in All my Heart.

The item will no longer appear in the active journal after the change is saved.

After the save, All my Heart stages any copied photo, video, GIF, or standalone health-document attachment that no active journal item still references and attempts to remove that private local copy.

Failed copied-file cleanup remains in a durable ledger and is retried through Privacy & Data and after restart.

Older backups, synchronized versions, external source libraries, or provider copies may still contain the item.

Media or archive blobs that no longer have an active reference may remain until the user deletes the complete cloud copy or the provider removes them under its processes.

Remove active local data

Delete individual content in the app where controls are available.

To remove all active local app data, open Privacy & Data and choose Delete local journal.

The app immediately fences the erased journal from ordinary synchronization, requests provider sign-out, removes active snapshots and Plus restore history, cancels and removes local care reminders, clears the Android widget snapshot and preferences, removes disposable OCR and duplicate-result caches, and attempts to remove media and standalone health-document attachments copied into All my Heart's private app directories.

Provider sign-out can finish after the local reset when the provider is slow or unavailable.

If complete cloud deletion was already pending before local reset, All my Heart preserves its exact provider-and-account deletion target rather than silently canceling that request.

That cloud deletion remains pending and can complete later only through the exact-account recovery flow.

Because the local journal has been erased, that preserved request does not import cloud-only memories back to this device before it deletes the cloud copy.

Any memories held only in that cloud copy will be permanently lost.

If any file cannot be removed safely, the app reports that some local files remain.

The app records the owned-file cleanup list before resetting the journal.

If the process stops after the reset, the next launch retries the staged cleanup.

If files still cannot be removed, Privacy & Data retains a remaining-file count and retry action without exposing private paths.

Uninstalling All my Heart or using the operating system's app storage controls is an additional device-level option.

The current release excludes its private iOS vault and copied media from device backup and disables Android app-data backup and transfer.

Loss of the device-held local encryption keys requires restoring from a readable cloud copy or portable copy.

An older app version or pre-existing operating system backup may preserve an earlier copy according to the platform provider's retention policy.

Before uninstalling, make sure any original photos or documents you want to keep still exist outside All my Heart.

Privacy & Data can save a complete .allmyheart copy containing every child journal's memories, media, structured Health-page records, standalone health documents and their copied attachments, and visit questions.

The portable file is not password-protected, so the user must save it only in a private location they control.

The portable copy excludes provider sign-in state, sync metadata, and Plus purchase entitlement.

Restore validates the archive and merges its journal content into the journal on the device.

While Plus is active, Privacy & Data can also save a complete .allmyheart-encrypted copy protected by a password chosen by the user.

All my Heart cannot recover a forgotten encrypted-archive password.

Encrypted restore remains available after Plus expires and validates and authenticates the complete container before importing anything.

Expiry does not hide journal content or premium themes and layouts already stored on a page.

Photo Drop can save an original-photo copy to a destination chosen by the user.

Plus can publish ordinary unencrypted PDFs, self-contained HTML albums, and MP4 recap videos to a destination chosen by the user.

The Base visit-preparation packet is also an ordinary unencrypted PDF published only after explicit user action.

It lists health-document metadata without embedding the attached files and is not automatically uploaded or emailed by All my Heart.

Those published photo copies, other published files, and portable copies are outside All my Heart's private storage.

Local reset and uninstall do not promise to delete them.

The user must delete those files through the destination app, storage provider, or filesystem.

Device-local Plus data

Multiple children's journal content is part of the complete journal and follows the same local, cloud, archive, and deletion rules described in this document.

The currently selected child is a device preference and is not synchronized, archived, or stored in restore points.

Plus restore points are full-journal snapshots kept only in protected storage on the current device.

Their descriptor records are authenticated and encrypted with a key separate from the active local journal record.

They are not synchronized and are not included in .allmyheart or .allmyheart-encrypted files.

Local journal reset removes restore points and their unreferenced protected assets.

Cloud disconnect and cloud deletion do not remove local restore history.

Reminder rules and native notification identifiers are device-local and excluded from the journal, sync, archives, and restore points.

Local reset cancels scheduled care notifications and deletes those rules.

The Android care widget stores only a bounded device-local snapshot.

Local reset clears that snapshot and its privacy preference.

Recognized text and duplicate-photo groups are disposable local caches keyed by photo content.

They are not synchronized or archived, and local reset removes them.

Full-app cloud data

Plus automatically synchronizes the complete app state for every child journal through Google Drive after the user enables it.

This includes Health-page profile fields such as blood group, birth date, care status, allergies, medication, nutrition, average sleep, and next checkup; sparse factual measurements; everyday care routines and completion times; vaccinations; checkups; standalone health documents and their attachments; visit questions; care-contact cards; journal memories; and media.

The submitted Apple build has iCloud sync and CloudKit sharing disabled.

The app does not inspect or medically classify user content before synchronization.

Stop Google Drive sync

Disconnect Google Drive in All my Heart to stop future synchronization.

Disconnecting does not delete existing data from Google Drive.

Reconnecting Google Drive continues to synchronize the complete app state.

To remove All my Heart's Google Drive app-data copy from inside the app, open Privacy & Data and choose Delete Google Drive copy while the intended Google account is connected.

The app records a durable deletion request before changing remote data, verifies the connected account, performs one final validated import and local merge, removes all All my Heart manifests and content-addressed blobs it can enumerate, verifies completion, preserves the merged local journal, and then disconnects.

If that final archive is unreadable or cannot be validated, the app does not delete it automatically.

A separate recovery action requires a second explicit confirmation that unreadable or cloud-only memories will not be imported before deleting the cloud copy.

If deletion is interrupted or cannot be verified, the app reports the failure, blocks ordinary synchronization, and retains the exact provider and account target for retry.

If authentication is no longer valid, the app requires the user to reconnect that exact account before retrying the deletion.

Another device that remains connected can upload its local journal again.

The user can also remove All my Heart's Google access from their Google Account settings.

Where available, the user can manage or delete hidden app data through Google Drive settings.

Google documents that the Drive appDataFolder is hidden from the normal Drive interface and that users can delete an app's data folder through Drive settings.

See Google Drive app-specific data documentation.

Stop iCloud sync

iCloud sync is not available in the submitted Apple build, so it creates no All my Heart CloudKit copy to disconnect or delete.

Invitation relay retention

Encrypted Family Vault invitation exchanges expire after 24 hours, when a scheduled alarm clears stored exchange state.

Cancellation retains a tombstone until expiry to prevent the invitation from being recreated.

After expiry and cleanup, there is no stored invitation exchange for the user to delete.

The relay does not store journal content or journal encryption keys.

Leave or revoke a Family Vault

Leaving a Family Vault removes that vault's protected identity, domain keys, encrypted offline cache, and provider connection from the device.

Leaving does not delete the owner-controlled Google Drive folders.

An owner can remove a participant to revoke provider access and rotate affected keys for future Family Vault content.

Revocation cannot erase content that a participant already decrypted, downloaded, exported, captured, or retained in provider backups.

The provider account owner controls deletion of the user-owned Family Vault folders or records through the provider's own storage controls.

All my Heart support cannot access or delete a Family Vault stored only in user-owned provider accounts.

Health information

Google Drive synchronizes structured Health-page profile fields, sparse factual measurements, everyday care routines and completion times, vaccinations, checkups, standalone health documents and their attachments, visit questions, and care-contact cards after the user enables full-app sync.

Family Vault excludes standalone health documents, their attachments, and visit questions.

Google Drive full-app consent must clearly disclose that synchronized data can include sensitive family and health information.

The app does not inspect or medically classify free-form journal content.

Support requests

Contact anand14sk@gmail.com or visit https://allmyheart.flownapse.com/support/ for help locating device or provider controls.

Support may explain the steps but cannot retrieve, inspect, or delete journal data that exists only on the user's device or in the user's personal cloud account.

Cloud deletion limits

The in-app cloud-delete action is scoped to All my Heart data visible to the connected provider account.

The normal action imports and merges valid remote memories before it removes the active All my Heart cloud copy.

The separately confirmed recovery action intentionally skips that import when the remote archive is unreadable, so unreadable or cloud-only memories can be lost.

Neither action claims to erase provider backups, caches, legal-retention copies, or delayed-deletion copies, which remain subject to the provider's terms.

The app cannot prevent another connected device from uploading its remaining local journal again.