All my Heart support FAQ

Who is All my Heart for?

All my Heart is for adult parents, guardians, and caregivers.

It is not designed as a child account or an app for children to use independently.

Is All my Heart a medical app?

No.

All my Heart is a personal journal and organization tool.

It does not provide medical advice, diagnosis, treatment, emergency monitoring, or a replacement for a clinician's records.

Always verify health, vaccination, dosage, and appointment information with a qualified healthcare professional.

Contact local emergency services if a child may need urgent help.

What does the Health page show?

The Health page records only the factual measurement fields you choose to enter.

It does not fill missing values, calculate percentiles or trends, compare a child with a reference range, or label a value normal or healthy.

The app does not diagnose, interpret measurements, use AI for health decisions, or provide dosage or urgency guidance.

What is the visit-preparation packet?

The Base visit-preparation feature creates a deterministic factual PDF on the device for the date range you select.

It can include saved profile details, factual records, visit questions, and health-document names and metadata.

It does not embed the attached document files.

The app creates and publishes the packet only after you explicitly request it and does not automatically upload or email it.

Once saved outside All my Heart, the packet is an ordinary unencrypted user-owned PDF.

Save it only in a private location you control.

An in-app local reset does not delete a visit packet that you already published outside the app.

Where is my journal stored?

Your journal is stored locally on your device by default.

You can choose to enable an optional cloud provider for synchronization or restoration.

The structured local journal record is authenticated and encrypted with a key kept in the device secret store.

Device-local restore-point descriptors use a separate encrypted key.

Photos, videos, and document attachments remain files in private app storage so the app can display and open them.

The current release excludes its private iOS vault and copied media from device backup and disables Android app-data backup and transfer.

An older app version or pre-existing operating system backup may still contain earlier data under the platform provider's retention policy.

Do I need an account?

No All my Heart account is required for local use.

Google sign-in is requested only if you choose Google Drive sync.

Signing in with Google authorizes Drive access and does not create a separate All my Heart account.

The submitted Apple build has iCloud sync and CloudKit sharing disabled.

How do Plus purchases work?

Plus purchases are handled by the App Store or Google Play.

The app does not create an All my Heart account for a purchase, and purchase status is not stored inside the journal or its portable archive.

Monthly, yearly, and lifetime choices unlock the same Plus feature set when those products are available in the installed store build.

Subscriptions renew through the store until cancelled there.

A restored purchase must come from the same store and store account that supplied it, so an Apple purchase does not automatically become a Google Play purchase.

What is included in Plus 1.x?

Plus provides automatic sync and restore in your own supported cloud account.

It also provides multiple child journals; protected device-local restore history; filtered care history and local reminders; an on-device Timeline with search, filters, favorites, and On this day; monthly and yearly recaps; ordinary unencrypted A4 and US Letter PDF exports; password-encrypted archive export; self-contained offline HTML albums; silent portrait recap videos; on-device OCR and duplicate-photo review; and bundled themes and premium layouts.

Android also provides a Today's care home-screen widget.

Monthly, yearly, and lifetime choices unlock this same feature set.

All my Heart does not operate a journal-content service, hosted search index, recap or OCR worker, reminder delivery service, or entitlement account.

If Plus expires, automatic sync, adding another child, new restore points, reminder changes, new keepsake exports, new media scans, and new paid appearance choices pause.

Your existing child journals, restore points, care history, enabled device reminders, existing premium pages, and already published files remain usable.

Cloud disconnect and deletion and plain or encrypted archive restore also remain available.

How do multiple child journals work?

One family journal can contain up to 32 child profiles.

Each child keeps separate memories, daily notes, favorites, Health information, care history, and profile media.

The child selected on one device is a local interface preference and is not synchronized or included in an archive.

Adding another child requires active Plus.

Existing children remain available to switch, edit, export, and delete after Plus expires.

The app never permits deletion of the final child.

What are restore points?

Restore points are protected full-journal snapshots kept only on the current device.

They are not uploaded, synchronized, or included in .allmyheart files.

While Plus is active, the app can keep a bounded automatic history and create manual points.

Existing points remain listable, restorable, and deletable after Plus expires.

Restoring first validates the complete point and creates a safety point before replacing the journal.

If the 20-point manual or safety history is full, a successful restore keeps the point you selected and the new safety point, then removes the oldest other saved or safety point.

Long verification or attachment-copy work shows progress and can be cancelled until the final journal commit begins.

Because restore points are device-local, they do not protect against loss of the device or uninstalling the app.

How do local care reminders work?

You can schedule selected-weekday care reminders and one-time appointment or vaccination reminders.

The app asks for notification permission only when you try to enable a reminder.

Reminder wording is generic by default.

Showing a child's name or task title requires a separate privacy opt-in.

The device schedules delivery locally, so All my Heart does not operate a notification service and cannot guarantee exact or emergency delivery.

Do not use reminders for medication intervals, emergencies, or time-critical care.

Existing enabled reminders can continue after Plus expires, but creating, editing, or re-enabling a rule requires active Plus.

Where is the Today's care widget available?

The home-screen widget is currently available on Android only.

It is read-only and shows the latest small snapshot published by the app.

It receives completion totals and at most three optional task labels rather than the complete journal or Health profile.

Names and task labels are hidden unless you opt in.

The iOS and macOS versions do not currently include a WidgetKit widget.

What does Google Drive sync include?

Plus provides automatic Google Drive sync and restore of the complete app state for every child journal after you enable it.

This includes journal memories and media; Health-page profile fields; sparse factual measurements; everyday care routines and completion times; vaccinations; checkups; standalone health documents and their attachments; visit questions; and care-contact cards.

All my Heart does not inspect or medically classify user content before synchronization.

Do not enable Google Drive sync unless you want this sensitive family and health information stored in the connected Google account.

What does iCloud sync include?

iCloud sync is not available in the submitted Apple build.

The build requests no CloudKit entitlement and stores no journal or Family Vault content in iCloud.

How does Family Vault sharing work?

Family Vault is separate from personal full-app sync.

The owner invites an adult's Google account and chooses memory and care permissions separately for each child journal.

How do family invitations work?

The owner shares an invitation link privately with the intended adult.

The recipient opens it in All my Heart, signs in to their provider account, and submits a join request.

The owner checks the verified account, chooses child-specific permissions, and approves access.

Encrypted requests and owner-signed approvals travel through a short-lived Cloudflare relay.

The recipient's app verifies the approval before joining.

Legacy manual invitations still use a separate safety-number comparison.

What does the invitation link contain, and who should I share it with?

The link contains an invitation secret, random invitation identifier, vault locator, expiry, and the owner's pinned public signing key in its URL fragment.

The fragment is not sent to the web server when opening the landing page.

Share it privately only with the intended adult; anyone holding it can request access, although only the owner can approve membership.

The relay cannot decrypt the exchange and never receives journal content or journal keys.

Invitations expire after 24 hours.

One owner purchase sponsors the Family Vault.

Invited family members do not each need Plus for permitted Family Vault actions.

That sponsorship is limited to the Family Vault and does not unlock personal Plus tools on the invited person's device.

If the owner later adds another child journal, they can add it to the vault while the signed sponsorship has capacity.

Existing family members receive no access to that child automatically.

The owner grants its memory or care permissions separately afterward.

An Editor can add permitted memories, attach a sanitized photo, and update a shared memory directly.

Editor changes are signed and encrypted on that device, then merge when the owner's device syncs.

If the owner changed the same memory first, the Editor change waits for an explicit owner decision instead of overwriting it.

A Contributor sends permitted items for owner review, and a Viewer reads only.

Care notes continue to wait for owner review.

Memories, care records, contribution bodies, wrapped keys, and private browser snapshots are encrypted before upload.

Photos included in private browser snapshots are bounded and metadata-stripped before encryption.

The provider can still read sharing and routing metadata such as participant names, emails, stable provider participant identifiers, roles, child identifiers and permissions, browser-grant labels, timestamps, and file sizes.

Google Drive Family Vault supports memories and care in this release.

Every Family Vault provider and private viewer excludes standalone health documents, their attachments, and visit questions.

Private provider-authenticated browser viewing is available only for Google Drive Family Vaults in this release.

The recipient must enter the owner's safety number received through a separate message or call, because a private link cannot authenticate its own owner key.

On devices where the clipboard cannot guarantee private handling and expiry, including Android in this release, All my Heart hides copy actions and uses controlled sharing for the private link and safety number.

Removing a participant rotates affected keys for future content but cannot erase content that person already downloaded, decrypted, exported, or captured.

How do I recover ownership after replacing or losing the owner's device?

While the original owner installation still works, open Family Vault and save the password-encrypted owner recovery file.

Use a password of at least 12 characters, keep it separately from the file, and store both somewhere only the owner can access.

All my Heart cannot recover a forgotten password or recreate a missing recovery file.

On a fresh installation, choose Restore owner access, select the .allmyheart-family-recovery file, enter its password, and sign in to the exact verified Google or Apple provider account that owns the vault.

The app checks the live signed vault, owner identity, public keys, sponsorship, and current encrypted owner key bundle before installing any local vault state.

A wrong password, changed file, different provider account, replaced owner identity, or rolled-back vault is rejected.

The recovery file contains protected owner identity seeds but no journal plaintext or domain keys.

Anyone who obtains both that file and its password may be able to act as the signing owner, so protect and delete old copies deliberately.

What happens when I disconnect sync?

The app stops future synchronization with that provider.

Your local journal remains on your device.

Disconnecting does not delete data that was already uploaded.

Reconnecting Google Drive continues to synchronize the complete app state.

The submitted Apple build has no iCloud provider to reconnect.

How do I make or restore my own complete copy?

Open Privacy & Data and choose Save complete copy.

The .allmyheart file contains every child journal's memories, media, structured Health-page records, standalone health documents and their copied attachments, and visit questions.

It does not contain cloud-provider sign-in state, sync metadata, or a Plus purchase entitlement.

The file is not password-protected, so save it only in a private location you control.

Choose Restore copy to validate the archive and merge it with the journal on the device.

While Plus is active, you can also save a .allmyheart-encrypted copy protected by a password you choose.

All my Heart cannot recover a forgotten encrypted-archive password.

You can restore an encrypted copy after Plus expires.

Password encryption protects the portable file but does not make cloud synchronization end-to-end encrypted.

Are recap PDFs encrypted?

No.

Monthly and yearly recap PDFs are generated on your device in A4 or US Letter format, but the resulting PDF is an ordinary unencrypted file.

Save it only in a private location you control.

Keep an independent copy before deleting or replacing irreplaceable data.

Are offline albums and recap videos encrypted?

No.

An offline album is one self-contained HTML file with sanitized inline copies of supported selected photos.

A recap video is a silent portrait MP4 encoded on the device from generated slides and sanitized photos.

Both are ordinary unencrypted files saved to a destination you choose.

They remain outside All my Heart after export and are not deleted by an in-app local reset.

Can I download a Photo Drop original?

Yes.

Tap a Photo Drop photo to open that captured day's full-screen gallery, then choose Download photo.

The download uses the system save flow and copies the original file that All my Heart stored for that Photo Drop item.

If the local photo is missing, the app says it is not available on this device.

If a photo cannot be previewed, the app still offers the original-file download when the stored file can be read.

Does OCR or duplicate detection upload my photos?

No.

OCR and duplicate detection run on the device for photos in the selected child's journal.

Apple platforms use Apple's Vision framework, and Android uses a bundled English Tesseract model without downloading language data.

Recognized text is a disposable local search overlay and is not written into the journal, cloud sync, portable archives, or restore points.

Duplicate groups are suggestions only.

All my Heart never deletes, merges, or rewrites a photo automatically.

How do I delete one item?

Use the delete action available for that journal element or record.

The item will disappear from the active journal after the change is saved.

If no active journal item still uses a copied photo, video, GIF, or standalone health-document attachment, All my Heart stages that private local copy for removal after the save.

Failed copied-file cleanup remains available for retry in Privacy & Data and after restart.

Older backups, synchronized versions, source photo or document libraries, provider caches, or content-addressed cloud blobs may still contain an earlier copy.

Why can’t I add another photo or attachment?

The current release supports up to 4,096 attachment references across the complete journal, including every child journal.

Photo Drop records, journal photos, GIFs and videos, profile and caregiver photos, and Health attachments share that capacity.

Remove an attachment you no longer need, then try again.

All my Heart does not silently delete or truncate existing attachments when the journal reaches this limit.

Why did text stop accepting characters?

The app counts visible characters rather than UTF-16 code units for user-entered journal text.

The current limits are 80 visible characters for child names, 2,000 for daily notes, 2,000 for freeform canvas text, 160 for link labels, and 2,048 for link URLs.

Import, sync, and restore reject over-limit user text instead of silently truncating it.

Unicode user content remains supported within those limits.

How do I delete all local data?

Before deleting, save a complete portable copy if you may want to restore this journal, and make sure you still have any original photos or documents you want to keep outside All my Heart.

Then open Privacy & Data and choose Delete local journal.

The app immediately stops the erased journal from taking part in ordinary sync, requests provider sign-out, removes active snapshots and Plus restore history, cancels and removes local care reminders, clears the Android widget snapshot and preferences, removes disposable media-intelligence caches, and attempts to remove media and standalone health-document attachments copied into All my Heart's private directories.

It does not delete Photo Drop photo copies, visit-preparation PDFs, recap PDFs, HTML albums, recap videos, or portable copies that you already saved outside the app.

Provider sign-out can finish after the local reset when the provider is slow or unavailable.

If complete cloud deletion was already pending before local reset, All my Heart preserves its exact provider-and-account deletion target instead of silently canceling it.

That separate cloud deletion remains pending and can complete later only through the exact-account recovery flow.

Because the local journal has been erased, that preserved request does not import cloud-only memories back to this device before it deletes the cloud copy.

Any memories held only in that cloud copy will be permanently lost.

If some files cannot be removed safely, the result tells you that local files remain.

If the app closes after deletion starts, it retries staged copied-file cleanup on the next launch.

Privacy & Data keeps an incomplete-cleanup notice and retry action when files still remain.

The notice shows only a count, not the private file paths.

You can also uninstall All my Heart or use your device's app storage controls where available.

The current release excludes its private iOS vault and copied media from device backup and disables Android app-data backup and transfer.

An older app version or pre-existing operating system backup may still retain an earlier copy under the platform provider's retention policy.

How do I delete cloud data?

Open Privacy & Data while the intended Google Drive account is connected and choose Delete cloud copy.

The app records the deletion request before changing remote data, verifies the connected account, performs one final validated import and local merge, removes All my Heart manifests and content-addressed blobs it can enumerate, verifies completion, preserves the merged local journal, and then disconnects.

If the final cloud archive cannot be validated or imported, the normal deletion stops without erasing it.

The app then offers a separate recovery action with a second explicit confirmation.

That recovery action deletes the cloud copy without importing it, so unreadable or cloud-only memories can be permanently lost while the existing local journal remains.

If the deletion cannot be completed or verified, the app reports the failure, blocks ordinary synchronization, and keeps the exact provider and account deletion target available for retry.

Another device that remains connected can upload its local journal again.

Neither deletion action claims to erase provider backups, caches, legal-retention copies, or delayed-deletion copies.

Those copies follow the provider's policies.

Disconnecting alone does not delete remote data.

You can also remove All my Heart's Google access and review hidden app-data controls in Google Drive settings.

Provider interfaces and retention behavior can change, so consult the provider's current help documentation.

All my Heart support cannot directly inspect or delete data held only in your personal Google account.

Can I change cloud providers or accounts?

Disconnect the current provider before connecting another one.

Before changing provider or account, make sure irreplaceable source photos and documents still exist outside All my Heart and verify that the app clearly identifies the destination account.

Do not reconnect to a different person's account on a shared device unless you intend to synchronize the local journal there.

What happens if I lose my device?

Local-only journal data may be lost unless it is present in an optional cloud sync or a complete portable copy you saved elsewhere.

Device-local restore points do not move to a replacement device.

The current release deliberately excludes its private iOS data from device backup and disables Android app-data backup and transfer.

Protect your Apple and Google accounts, and keep the original irreplaceable photos and reports outside All my Heart.

Why can a photo contain location information?

Some photos and videos contain camera, date, device, or location metadata.

When you select media, that embedded metadata may be stored or synchronized with the file unless the app explicitly removes it.

Remove sensitive metadata before importing when necessary.

Can support recover my journal?

Support generally cannot view or recover a journal that exists only on your device or in your private cloud account.

We can help explain available app, device, and provider recovery steps.

How do I contact support?

Email anand14sk@gmail.com or visit https://allmyheart.flownapse.com/support/.

Do not email a child's medical report, full birth date, precise location, account password, OAuth code, or other sensitive journal content.

Support will never ask for your Apple or Google password.