Privacy Policy
Effective August 22, 2026 · Missionary Vault, a product of Mwanga LLC, an Idaho limited liability company · help@missionaryvault.com
This policy explains what information Missionary Vault collects through missionaryvault.com and the Missionary Vault app (the "Service"), how we use it, and the choices you have. We wrote it to be read, not skimmed past.
1. The short version
Missionary Vault is a private vault for your family’s missionary memories. Your emails, photos, and journal entries belong to you. We use them only to run your vault — we don’t sell your personal information, we don’t show ads, and we don’t use your family’s content for marketing. Your memories are never deleted for time or money reasons: when your term ends, your vault becomes read-only, and you can export everything at any time.
2. What we collect
Account information. Your name and email address. If you sign in with Google, we receive your basic Google profile (name, email, account identifier) — never your Google password. If you use email/password sign-in, your password is handled by Firebase Authentication and we never see it in plain text.
Deadline reminders. If you use the free countdown tool at /countdown and ask to be reminded, we store the email address you give us and the homecoming date you entered — nothing else, and no account is created. We use it only to send you up to three reminders about that date, and then we stop. Every reminder has an unsubscribe link, and you can also email help@missionaryvault.com and we will remove you. We never sell or share this list.
Vault content. The emails forwarded to your missionary’s capture address (the email text and photo attachments), photos you upload, your family’s journal entries ("Thoughts"), and your missionary’s profile (name, mission, dates). This content often includes information about people other than you — your missionary, and family members who appear in photos, including your children. You choose what goes in, and it stays in your family’s private vault.
Photos you import from Google Photos. If you choose to bring photos in from Google Photos, we ask Google for one narrow permission — photospicker.mediaitems.readonly — which lets us receive only the specific photos you pick in Google’s own picker. We never get access to your Google Photos library, and we cannot browse it, search it, or see anything you do not select. The photos you pick are downloaded at full resolution and stored in your vault exactly like any other photo. We also hold the access token Google issues so the import can finish; in the iPhone app we keep a refresh token so you don’t have to reconnect every time, and you can revoke it at any time in your Google Account settings. Section 7 explains our Limited Use commitments for this data.
Purchase information. Payments are processed by Stripe on the web, or by Apple in the iOS app. We never see or store your card number. We receive confirmation of your payment and basic transaction details (what you bought, when, and the amount), plus any referral or promo code you used. If you start the free 30-day trial described in our Terms, Stripe stores your card for the future charge and gives us a token that stands in for it, along with the billing email you gave Stripe.
Error and diagnostic data. If something breaks on our website, we collect error reports (through Sentry) with technical details like browser type, app version, and what the page was doing when it failed — so we can fix it. The iOS app does not include crash reporting today; if we add it, we will update this policy first. We also keep basic server logs (such as IP address) needed to operate and secure the Service.
Cookies and local storage. Inside your vault we use only the essentials: keeping you signed in and remembering app state. We do not run Meta’s advertising pixel, or any other advertising tracker, on the pages that show your vault — not your letters, your photos, your journal, your sharing settings, or your account. The pixel is loaded only on our public pages: the front door, the landing page, the demo, pricing, and gift. Because the app opens at the same web address as our front door, that one address can load the pixel for a signed-in family too; even then, the only thing it can record is that a browser opened missionaryvault.com. We have switched off the pixel’s automatic collection, so it reports only the specific events we choose to send — a page view, a checkout start, a purchase — carrying an event name and, for a purchase, an amount and currency. Never a name, an email, or anything from a vault.
How you found us. When a browser first arrives at our site, we record in that browser which ad or link brought it: the campaign parameters in the web address, the referring site, and the click identifiers advertising networks attach to their own ads (fbclid, gclid, igshid). We also count one visit per browser per day. If that browser later becomes an account, we attach that first record to the account, so we can tell which campaigns bring real families. We want to be precise about this one: it is linked to your account rather than anonymous. It stays on our own servers, no one using the app can read it, and it is never sent to an advertising network.
3. How we use information
To run your vault: capturing and storing emails, showing your content to you and the people you share it with, processing your purchase, sending service emails (receipts, capture confirmations, invitations, trial and deadline reminders, support replies), keeping the Service secure, fixing errors, and complying with law. That’s the whole list. We never use your vault content — your emails, photos, or journal entries — for advertising, and we never sell it.
Separately, we advertise Missionary Vault to people who have never heard of it. We measure those ads two ways: with the Meta pixel on the public pages listed in Section 2, and with the first-touch record described there, which we keep on our own servers and join to an account when a visitor becomes a customer. Neither of them reads a vault, and nothing from a vault is ever sent to an advertising network.
4. The capture address
Each missionary gets a unique email address (like name-xxxx@letters.missionaryvault.com). Anything sent to that address is processed by Postmark, our inbound email provider, and stored in your family’s vault. Emails are stored verbatim — exactly as received, never edited by us. Treat the capture address like a family phone number: share it with the people who should be sending emails to your vault, and no one else.
5. Sharing your vault: join codes
Your vault is private until you share it. You share it with a join code: each missionary in your vault has its own 8-character code, which you can show, text, or read aloud to the people you want to include.
A join code is a key, not a password. Please read these three points before you send one:
It is not addressed to anyone. A code works for whoever has it. We cannot tell who that is, and we cannot stop it from being passed on.
It keeps working. Codes can be used any number of times, by any number of people, and they do not expire on their own. A code stays live until you turn it off or replace it in Settings → Sharing.
So share it the way you would share a house key — with the people you actually want inside your family’s memories, and never anywhere public.
When someone uses a code, they create their own sign-in — a name, an email address and a password, or their Google or Apple account — and confirm that they are 18 or older before that account is created. You choose what the code grants:
View only — they can read letters, photos, and shared Thoughts.
View and add Thoughts — they can also write in the family journal, signed with their name.
View and add memories — they can also add photos and letters.
Admin is separate. You promote a specific person to Admin in Settings — never by code — and no more than three people can hold it. Admins can add and delete content.
What a person you let in can see. A code belongs to one missionary, and it opens that missionary only — their letters, their photos, the Thoughts filed under them. Our servers enforce that boundary rather than the app merely drawing it: someone who joined for one missionary cannot reach another missionary in the same vault, cannot see the list of people you have invited, and cannot see anyone’s shipping address or your capture history.
There is one thing they can see that isn’t about their missionary. Everyone using a vault needs to know the vault is paid up, or their own app would never unlock, so the small record that says so is readable by everyone you share with. Today that record also carries the billing email address and our payment processor’s internal references for the card alongside the expiry date. It never contains your card number. That is a known gap and we are splitting the record so that only the part everyone needs is shared.
Removing someone stops what comes next, not what already arrived. You can remove a person, or turn off or replace a code, at any time in Settings → Sharing. That immediately stops them from receiving anything further and stops the code from letting anyone else in. But Missionary Vault is built to work offline, which means the app keeps a copy of what it has already synced on each person’s own device. We cannot reach into someone else’s phone or computer and erase what they already have, and anything they saved, exported, or printed is out of our reach entirely. Please choose who you give a code to with that in mind.
Content about your missionary and your family. When you forward an email, you’re sharing something your missionary wrote — you confirm that you received it and have the right to keep it in your family’s vault (see our Terms of Service). If your missionary, or anyone else, wants something in a vault corrected or removed, the vault owner can do it in the app, or contact us at help@missionaryvault.com and we’ll help.
6. Children and age
Missionary Vault accounts are for adults 18 and older, including accounts created by someone joining with a code. The Service is not directed to children, and everyone who creates an account — whether they are starting a vault or joining one — must confirm they are 18 or older before we create it.
We ask this at the moment it matters. A join code circulates, and the person who redeems one may be someone the vault owner has never met. We do not knowingly collect personal information from anyone under 13. If a child under 13 has created an account, contact us at help@missionaryvault.com and we will delete it and the information collected from it.
Photos and stories about your children are a different thing: they are added by adults in your family and controlled by the vault owner. Section 5 explains who can see them, and why you should be deliberate about who you hand a code to.
7. Google user data
Missionary Vault’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We receive Google user data in two places: signing in with Google (your basic profile — name, email, account identifier), and the optional Google Photos import described in Section 2, which uses the photospicker.mediaitems.readonly scope and returns only the individual photos you select in Google’s own picker.
Specifically:
We use Google user data only to provide and improve the features you asked for: signing you in, and placing the photos you chose into your vault.
We do not transfer Google user data to others, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
We do not use Google user data for advertising, and we never serve advertisements based on it.
We do not allow humans to read Google user data, unless: we have your specific consent (for example, when you ask support for help with a particular import); it is necessary for security purposes, such as investigating a bug or abuse; we are required to by law; or the data has been aggregated and anonymized.
Photos you import are stored in your vault at your direction. You can delete them or export them at any time, and you can disconnect Google Photos in the app or revoke our access in your Google Account settings.
8. Who we share information with
We do not sell your personal information, and we have never sold it. We share information only with:
Service providers under contract who help us run the Service: Google Firebase (hosting, database, file storage, and authentication, in the United States); Vercel (website hosting); Postmark (inbound email processing for your capture address, and delivery of the email we send you); n8n (n8n.cloud — the workflow service that assembles and sends the email we owe you: it receives the address the message goes to and the details that message needs, such as the name of the person inviting you, your missionary’s name and capture address in a welcome email, the recipient details and code for a gift, the date and amount for a trial reminder, the homecoming date for a countdown reminder — it never receives your letters, your photos, or your journal); Stripe (payments on the web, including storing the card for a free trial); Apple and RevenueCat (purchase processing for the iOS app — they receive an app account identifier and transaction details, never your vault content); Sentry (error monitoring on our website); and Meta (which receives the advertising events described in Section 2 from our public pages — an event name and, for a purchase, an amount and currency, never your name, your email address, or anything from a vault).
A print partner, when you order a book. If you order a printed keepsake book (offered separately, later), our print-on-demand partner will receive your name, shipping address, and the book contents — only to print and deliver your order.
Legal requirements — if the law requires it, or to protect rights and safety.
A business transfer. Missionary Vault may one day move to its own company or a new owner. If that happens, this policy’s promises travel with your content, and we’ll notify you.
Each provider receives only what it needs to do its job. Every one of them is bound by contract to use what it receives only to perform that work for us, and to protect your information to at least the same standard we apply ourselves. None of them is permitted to sell your information or to use it for their own advertising.
9. Retention: never deleted
Your vault content is kept for your full service term. When your term ends, your vault becomes read-only — it is never erased. You can export everything, at any time, in either mode. "Never deleted" protects you from losing memories to an expired term or a missed email; it doesn’t override your own choices — if you explicitly ask us to delete your account and vault, we will (see Section 10).
10. Your choices and rights
Export: download all of your emails, photos, and Thoughts from the app, any time.
Access and correction: view and edit your account and vault content in the app.
Deletion: delete your account yourself, any time, in the app (Settings → Delete my account). Vault owners take their whole vault with them; people who joined with a code remove only their own sign-in. Prefer to ask us? Email help@missionaryvault.com from your account email and we’ll do it for you. Either way it’s permanent, so there’s a confirmation first.
We honor these requests for everyone, wherever you live. Missionary Vault is well below the size at which state privacy laws like the California Consumer Privacy Act or the Utah Consumer Privacy Act apply, but the practices those laws expect — we never sell personal data, we never share vault content for targeted advertising, and a real person answers privacy requests — are how we operate anyway. The advertising cookies on our public marketing pages may count as “sharing for targeted advertising” under some of those laws. You can turn them off at any time using your browser’s cookie or tracking-protection settings, or by using a Global Privacy Control signal, which we honor: when your browser sends that signal, the advertising pixel and the first-touch record described in Section 2 do not run at all.
11. Security
Your data lives on Google Firebase infrastructure in the United States, encrypted in transit and at rest, with server-enforced access rules so each family can reach only its own vault. No system is completely secure, but we take reasonable measures to protect your information, and we’ll notify you as required by law if a breach ever affects your data.
12. United States
We operate from the United States, store data in the United States, and the Service is intended for U.S. users. If you use Missionary Vault from another country, your information is processed in the U.S., and the choices in Section 10 still apply to you.
13. Changes
We may update this policy and will post a new effective date here. For material changes we’ll give you reasonable notice by email. No update will ever take away your right to export your content.
14. Contact
Missionary Vault, a product of Mwanga LLC · help@missionaryvault.com