All my Heart Privacy Policy
Effective date: 2026-10-11
All my Heart is provided by Anand Sharma ("we", "us", or "our").
This policy explains how All my Heart handles information when an adult parent, guardian, or caregiver uses the app.
All my Heart is not directed to children and does not offer child accounts.
1. What All my Heart is
All my Heart is a personal journal and organization tool for recording memories, routines, notes, media, contacts, and care information about one or more children.
It is not a medical device or healthcare service.
It does not provide a diagnosis, treatment, emergency monitoring, or medical advice.
2. Information you may add
You decide what to add to All my Heart.
Depending on the features you use, this may include:
- A child's name, photograph, date of birth, age or day count, height, weight, blood group, routines, notes, and journal entries for each child profile you create.
- Health-related information such as allergies, medication notes, nutrition notes, vaccination status, sparse factual measurements, appointments, checkup notes, standalone health documents and their attachments, and visit questions.
- Photos, videos, drawings, stickers, GIFs, files, links, and captions.
- Location information that you deliberately add, including location metadata that may already be embedded in selected media.
- Names, profile photos, relationships, comments, and replies for family members or other caregivers.
- Contact details that you enter for doctors, teachers, nannies, or other important contacts.
Please obtain permission before adding another person's personal information or content.
Avoid storing information that you do not need.
3. Local storage by default
All my Heart stores journal content locally on your device by default.
We do not operate an app account or a server that receives a copy of your journal merely because you use the app.
The structured local journal record is stored in an authenticated encrypted envelope using a key held in the device secret store.
Device-local Plus restore-point descriptors use a separate authenticated encrypted envelope.
Journal photos, videos, standalone health-document files, restore-point attachment blobs, and published files remain separate files so the operating system and user-selected destinations can open them.
The current iOS release marks All my Heart's private vault and copied media or standalone health-document attachments as excluded from device backup and applies available Data Protection.
The current Android release disables Android backup and device-to-device transfer for app data.
An older app version, pre-existing operating system backup, or provider-held cloud copy may still retain data under its own settings and retention policy.
Removing the app generally removes its active local data but does not automatically remove those older or external copies.
Plus restore points are full-journal snapshots kept in protected storage on the current device.
They are not synchronized or included in portable copies.
The selected child, reminder rules, notification identifiers, widget preferences, and derived OCR or duplicate-photo results are also device-local and are not placed in journal sync, portable copies, or restore points.
Android's Today's care widget receives only a bounded local snapshot with the selected child identifier, day, completion totals, and up to three optional labels.
Names and task labels are hidden from that widget unless the user explicitly opts in.
The Android widget does not receive the complete journal or Health profile.
The operating system schedules local reminders after the user creates and enables a rule and grants notification permission where required.
Reminder wording is generic by default.
Showing a child's name or task title in a notification requires a separate opt-in.
All my Heart does not operate a notification-delivery server.
4. Optional cloud sync
Automatic cloud sync and restore are optional Plus features and are not required to use the local journal.
When you enable a cloud provider while Plus is active, the app uploads selected journal data so that you can restore or synchronize it using that provider.
Cloud providers process data under their own terms and privacy policies.
Synchronized content is stored in the user's selected cloud account.
All my Heart does not operate a journal-content server.
It operates a short-lived invitation relay on Cloudflare for encrypted Family Vault join requests and owner-signed approvals.
If Plus expires, ordinary automatic synchronization pauses without deleting the local journal, provider choice, or provider copy.
Cloud disconnect, exact-account cloud deletion, and the local journal remain available.
Family Vault sharing
Cloudflare processes invitation relay data on behalf of All my Heart.
The relay receives random invitation identifiers, capability hashes, encrypted payloads, expiry times, and network metadata.
It never receives journal content, journal keys, private identity keys, or invitation encryption keys.
Invitations expire after 24 hours and a scheduled alarm clears their stored state.
Application request logging is disabled; Cloudflare still processes network metadata to operate the service.
Family Vault is an optional Plus collaboration feature that is separate from personal full-app cloud sync.
An adult owner chooses provider accounts to invite and assigns separate memory and care permissions for each child journal.
If the owner later adds another child to the vault, existing participants and browser grants receive no key or content access for that child until the owner grants it separately.
Journal memories, care records, contribution bodies, member key material, and private browser snapshots are encrypted on a participant's device before upload.
Google or Apple can read the provider account, folder, participant, stable provider participant identifier, role, child identifier and permission, browser-grant label, key epoch, timestamp, and file-size metadata needed to store and share the vault.
Invited participants receive provider-native access and only the device-held cryptographic keys allowed by the signed Family Vault policy.
The final invitation handoff is signed by the owner and binds the invited device, provider invitation locations, and owner public key, and the owner confirms the verified account requesting access.
The owner shares the invitation link directly and privately with the intended adult.
Legacy manual invitations still require comparing the owner safety number through a separate channel.
The signing owner can save a password-encrypted recovery file to a location they choose.
That file contains encrypted owner identity seeds, pinned owner public keys, the provider account identity, vault locator, and minimum signed manifest revision.
It does not contain journal plaintext or Family Vault domain keys.
Restore checks the exact verified provider account and live signed vault before installing the owner identity or current encrypted vault keys locally.
All my Heart does not receive the recovery file or password and cannot recover either one.
The owner's verified Plus purchase creates a signed, vault-scoped sponsorship lease.
Invited devices can use that sponsorship for permitted Family Vault actions without a separate Plus purchase, but it does not unlock personal Plus features.
Editor memory additions and revision-matched edits can merge when the owner device syncs.
Concurrent Editor edits, Contributor submissions, and care notes remain encrypted until the owner reviews the applicable decision.
Contributed photos are decoded, metadata-stripped, bounded, re-encoded, and stored in the owner's private journal media directory before the journal references them.
The Google Drive private browser viewer requires provider-authenticated membership, the client-side secret in the private link, and the owner's safety number received through a separate channel.
That static viewer does not send readable journal content or the grant secret to an All my Heart server.
Images placed in private browser snapshots are decoded, bounded, metadata-stripped, re-encoded, and omitted if they cannot be safely sanitized.
The submitted Apple build does not include iCloud Family Vault sharing or iCloud private browser viewing.
Every Family Vault provider and private viewer excludes standalone health documents, their attachments, and visit questions.
Removing a participant rotates affected keys for future content but cannot recall content the participant already decrypted, downloaded, exported, or captured.
Google Drive
Google sign-in lets you authorize optional Google Drive sync and Google Drive Family Vault access.
The app may receive basic Google account information needed to show and maintain the connection, such as your name, email address, profile image, and Google account identifier.
Full-app sync uses the app-specific Google Drive application data area where supported.
After you enable Google Drive sync, the app uploads and imports the complete app state for every child journal.
This includes journal memories and media; Health-page fields such as blood group, birth date, care status, allergies, medication, nutrition, average sleep, and next checkup; sparse factual measurements; everyday care routines and completion times; vaccinations; checkups; standalone health documents and their attachments; visit questions; and care-contact cards including names, roles, organizations, phone numbers, addresses, and notes.
The app does not inspect or medically classify user content before synchronization.
Do not enable Google Drive sync unless you want this sensitive family and health information stored in the connected Google account.
Disconnecting Google Drive stops future sync but does not by itself delete data already uploaded.
Reconnecting continues to synchronize the complete app state.
iCloud
The submitted Apple build has iCloud sync and CloudKit sharing disabled.
It does not request a CloudKit entitlement or store journal or Family Vault content in iCloud.
5. Portable copies, keepsakes, and purchases
Privacy & Data can save a complete .allmyheart copy containing every child journal's memories, media, structured Health-page data, standalone health documents and their copied attachments, and visit questions.
The portable file is not password-protected.
You choose where to save or share it, and the selected storage provider or receiving app processes that copy under its own privacy terms.
Portable copies exclude cloud-provider sign-in state, sync metadata, and Plus purchase entitlement.
Plus can also save a complete .allmyheart-encrypted copy protected by a password chosen by the user.
All my Heart cannot recover a forgotten encrypted-archive password.
Encrypted restore remains available after Plus expires so that the user can regain access to a copy created while entitled.
Archive encryption protects that portable file and is not a claim that cloud synchronization or collaboration is end-to-end encrypted.
Plus can generate monthly and yearly recaps from the journal on the device and export an A4 or US Letter PDF.
The PDF is an ordinary unencrypted file, so the user chooses where to save it and is responsible for protecting it.
The Base visit-preparation feature can generate a factual PDF on the device for a date range selected by the user.
The packet is created only after an explicit user action, lists standalone health-document metadata without embedding attached files, and does not diagnose, interpret measurements, calculate trends or reference ranges, use AI, or provide dosage or urgency guidance.
All my Heart does not automatically upload or email the packet.
Once the user publishes it, the visit packet is an ordinary unencrypted file outside the app's private storage.
Photo Drop can save an original-photo copy through the system picker to a destination chosen by the user.
That saved copy is an ordinary unencrypted file outside the app's private storage.
Plus can also create a self-contained offline HTML album and a silent portrait recap video from selected journal memories.
HTML albums exclude Health data and attachments and contain sanitized inline copies of supported selected photos.
Recap video frames use sanitized photos so original image metadata is not copied into the generated video.
HTML albums and MP4 recap videos are ordinary unencrypted files.
The user chooses where to publish each file, and the destination provider or receiving app handles it under its own privacy terms.
Published Photo Drop photo copies, PDFs, HTML albums, recap videos, and portable copies are outside the app's private storage and are not deleted by an in-app local reset.
When Plus is offered, the App Store or Google Play processes the purchase and reports product, transaction, and entitlement status to the installed app.
All my Heart does not send that purchase status to an operator-hosted account or place it inside journal data, cloud synchronization, or portable archives.
Monthly, yearly, and lifetime products unlock the same Plus feature set.
Purchases restore only through the same store and store account and do not transfer between Apple and Google Play.
6. How information is used
Information is used to provide the features you request, including displaying child journals, saving edits, organizing daily memories, showing factual measurement and care history, scheduling local reminders, publishing a bounded Android widget snapshot, opening attachments, contacting a saved contact, performing optional cloud sync and Family Vault collaboration, creating a local memory index, generating factual visit-preparation packets, generating recaps and albums, downloading Photo Drop originals, exporting files, and creating portable copies.
Timeline, search, filters, favorites, On this day, recap selection, PDF generation, HTML album generation, recap video preparation and encoding, archive encryption, OCR, duplicate detection, and theme or layout rendering run on the device.
Search queries, derived search indexes, recognized text, duplicate groups, generated recap output, reminder rules, and widget snapshots are not sent to All my Heart or an operator-hosted service.
OCR scans selected child-journal photos only and uses Apple Vision on Apple platforms or a bundled English Tesseract model on Android.
Recognized text is bounded, cached by photo content hash, and used as a disposable search overlay rather than written into the journal or synchronized.
Duplicate detection compares local photo hashes and never deletes, merges, or rewrites a photo automatically.
We do not sell your journal or health information.
We do not use journal or health information for advertising.
We do not use journal content to build advertising profiles.
The release described by this policy does not include our own analytics or advertising service.
Google's Sign-In SDK declares processing of account information, coarse location, device identifiers, usage data, and other data for sign-in functionality and SDK analytics.
Its privacy manifest declares that this data is linked to identity and is not used for tracking.
Google's processing is governed by its privacy policy and your Google account settings.
If that changes, we will update this policy and the relevant store disclosures before collecting new data.
7. When information is shared
Information may be processed by:
- Apple, when you use the App Store or other Apple platform services.
- Google, when you use Google sign-in, Google Drive sync, Google Play, or other Google platform services.
- The device operating system, when it stores and displays local notification requests or the bounded Android widget snapshot.
- Apps or storage providers you deliberately choose through system export, sharing, calling, maps, links, or file-opening actions.
- Adult family participants you explicitly invite to a Family Vault, limited by the provider role and signed child permissions you choose.
- A person to whom you deliberately give a private browser link, while that person is signed in to a provider account that can access the matching vault.
- People who have access to your device, your cloud account, or content you deliberately open or share through another app.
We may disclose limited information if legally required, but because we do not receive your local journal on our own server, we generally cannot access or produce it.
8. Retention and deletion
You can delete visible journal items and local records in the app where a delete control is available.
After the updated journal is saved, All my Heart stages any copied photo, video, GIF, or standalone health-document attachment that no active journal item still references and attempts to remove that private local copy.
Failed copied-file cleanup stays in a durable retry list and is retried through Privacy & Data and after restart.
Deleting a visible item may still not immediately erase every copy from older device backups, previously synchronized archives, provider backups, external source libraries, or content-addressed cloud blobs.
Disconnecting a cloud provider does not delete remote data.
The Privacy & Data screen lets you delete the active local journal separately from the complete All my Heart cloud copy for the connected provider.
Deleting a readable cloud copy first records a durable deletion request, verifies the exact provider account, performs one final validated import and local merge, then preserves that merged local journal and disconnects sync after the provider confirms deletion.
If the final cloud archive cannot be validated or imported, the normal deletion stops before erasing it.
The app can then offer a separate recovery action that requires an additional explicit confirmation.
That recovery action deletes the cloud copy without importing it, so unreadable or cloud-only memories can be permanently lost while the existing local journal remains.
If the deletion cannot be completed or verified, the app reports the failure, blocks ordinary synchronization, and retains the exact provider and account deletion target so you can retry.
Another device that remains connected can upload its local journal again.
Local journal deletion immediately fences the erased journal from ordinary synchronization, requests provider sign-out, removes active and on-device recovery snapshots, and stages owned copied-file cleanup.
Local journal deletion also removes device-local Plus restore points, reminder rules, scheduled care notifications, the Android widget snapshot and preferences, and disposable media-intelligence caches.
It does not delete ordinary files that you already published outside the app, including Photo Drop photo copies, PDFs, HTML albums, recap videos, or portable copies.
Provider sign-out can finish after the local reset when the provider is slow or unavailable.
If complete cloud deletion was already pending, local reset preserves the exact provider-and-account deletion target instead of silently canceling that separate request.
That cloud deletion remains pending and can complete later only through the exact-account recovery flow.
Because the local journal has been erased, that preserved request does not import cloud-only memories back to this device before it deletes the cloud copy.
Any memories held only in that cloud copy will be permanently lost.
If local journal deletion is interrupted after copied-file cleanup has been staged, All my Heart retries that cleanup on the next launch.
If copied files still cannot be removed, Privacy & Data keeps a non-sensitive remaining-file count and a retry action without displaying the private file paths.
Neither deletion action claims to erase provider backups, caches, legal-retention copies, or delayed-deletion copies.
Those copies remain subject to the provider's policies.
You can also uninstall the app to remove its active local data and use your Apple or Google account storage controls to manage provider-held app data.
Provider backups and deletion processes may follow the provider's own retention schedule.
For step-by-step guidance, visit https://allmyheart.flownapse.com/support/ or contact anand14sk@gmail.com.
Because we do not hold the journal in our own account system, support cannot directly erase data held only on your device or in your personal Apple or Google account.
9. Security
All my Heart relies on operating system app isolation and the security of your device and chosen cloud provider.
Cloud transfers use the provider's supported encrypted network connections.
No storage method is perfectly secure.
Use a device passcode, protect your Apple and Google accounts, review backup settings, and avoid giving others access to an unlocked device.
Portable .allmyheart files are not password-protected, so save them only in a private location you control.
Portable .allmyheart-encrypted files are password-encrypted, but a forgotten password cannot be recovered by All my Heart.
An encrypted portable file does not make provider synchronization end-to-end encrypted.
10. Adult audience and children's privacy
All my Heart is intended for adults who are documenting information about one or more children in their care.
It is not intended for use by children and does not knowingly collect information directly from children through an operator-controlled account or service.
If you believe a child has used the app in a way that requires assistance, contact anand14sk@gmail.com.
11. International processing
If you enable Apple or Google services, those providers may process or store data in countries other than your own under their applicable terms, privacy policies, and transfer safeguards.
12. Your choices and rights
You can choose what to record, whether to enable sync, which provider to use, and whether to grant optional device permissions.
You can revoke notification, photo, file, camera, microphone, location, or account access through device or provider settings, although affected features may stop working.
Privacy rights vary by location.
You may contact us at anand14sk@gmail.com about a privacy request, but we may be unable to identify or access data that exists only on your device or in your personal cloud account.
13. Changes to this policy
We may update this policy when the app or legal requirements change.
We will post the revised policy at https://allmyheart.flownapse.com/privacy/ and update the effective date.
If a change materially affects an optional data use, we will request any new consent that applicable law requires.
14. Contact
Anand Sharma
Email: anand14sk@gmail.com
Support: https://allmyheart.flownapse.com/support/