Privacy Policy
Effective Date: April 15, 2026 · Last Updated: July 21, 2026
1. Introduction
LendMesh LLC (“LendMesh,” “we,” “us,” or “our”) operates the MyDocuVa platform at mydocuva.com and related services (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
MyDocuVa is built on AES-256 encryption with AWS KMS-managed keys. Your files are encrypted in transit over TLS and at rest in our storage, and the keys are protected in AWS KMS under strict access controls and full audit logging.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (used for authentication and account recovery)
- Full name (optional, for your profile display)
- Country of residence (optional, for customs form defaults)
- Authentication method (email/password, Google, Apple, or Facebook OAuth)
2.2 Subscription and Billing
If you subscribe to a paid plan, payment processing is handled by Stripe, Inc.We do not store your credit card number, CVV, or full billing details on our servers. We retain only a Stripe customer identifier and subscription status to manage your plan. Subscriptions purchased inside our mobile apps are handled differently — see section 2.11.
2.3 Encrypted Document Data
All documents, photos, and files you upload are transmitted to our servers over an encrypted TLS connectionand stored as encrypted ciphertext. Your files are encrypted with AES-256, with keys managed in AWS KMS under strict access controls and full audit logging. Because those keys are managed in AWS KMS under our control, MyDocuVa is technically capable of decrypting stored files — see section 4 for what that means and when we do it. Unencrypted metadata we store includes:
- File size (for storage quota calculation)
- Upload timestamp
- Content type (e.g., image/jpeg, application/pdf) for display purposes
- Item titles, categories, and descriptions as entered by you
We treat all user data, including metadata, with the highest level of security. We do not use item metadata for profiling, automated decision-making, or any purpose other than providing the Service.
2.4 OCR Processing
Our mobile app offers optional OCR (Optical Character Recognition) and image labelling to extract text and suggest categories from document and receipt images. This processing occurs entirely on your device, using the on-device Google ML Kit text recognition library on both iOS and Android. (On iOS, Apple VisionKit provides the document-capture camera itself, but not the text recognition.) The image and the recognised text are not sent to us, or to any third party, for OCR purposes. Any extracted text that you choose to save is then stored like your other data — encrypted with AES-256, using keys managed in AWS KMS.
2.5 Usage Data
We collect limited usage data to operate and improve the Service:
- Login timestamps and session activity (for security and audit logging)
- Device information (browser type, operating system) from session records
- IP address at login (stored in audit logs with a 3-year retention period)
- Feature usage patterns (aggregated, non-personally identifiable)
2.6 Cookies and Local Storage
We use the following browser storage mechanisms:
- Authentication tokens — stored in localStorage, required by AWS Amplify for session management. Cleared on logout.
- Passphrase session cookie — an HMAC-signed HttpOnly cookie that verifies your passphrase session without storing the passphrase itself. Expires when you close the browser or after the configured session duration.
- Theme preference — stored in localStorage for dark/light mode. Persists indefinitely.
The storage mechanisms above are strictly necessary for the operation of the Service. We do not use advertising cookies or third-party tracking pixels, and we do not sell or share your data for advertising.
On our public marketing pages only (such as the home, pricing, and guide pages), our website uses Google Analytics to measure page views and understand how visitors find us. Automatic page-view tracking is disabled everywhere else: no analytics event is sent from the signed-in app, the authentication pages, or share, invitation, and legacy portal links, so the URLs of your vault, items, and shared links are never transmitted to Google Analytics. The mobile app contains no analytics or advertising SDK of any kind.
2.7 Photos, Camera, and Location (Mobile App)
The mobile app can use your camera to scan documents and capture item photos, and can access your photo library when you choose to add existing photos. Media you select is uploaded to your vault over an encrypted connection and stored encrypted; media you do not select never leaves your device.
The app also offers an optional Photo Discovery feature that scans your photo library on your device to help you find pictures of items you may want to add. The resulting index is stored in a local database on your device and is not uploaded. As part of this, the app reads photo metadata, including the precise GPS coordinates that your camera embedded in the photo (on Android this requires the ACCESS_MEDIA_LOCATIONpermission). The app does not track your live device location — it has no access to your device's location services, and only ever reads location that is already stored inside a photo you took.
When you turn Photo Discovery on, you choose what happens to that location data. The app offers two settings:
- Keep — precise coordinates are saved as ownership-proof evidence on the item you attach the photo to, which strengthens your item's confidence score for insurance or customs purposes. This is the setting the app starts on, so if you turn Photo Discovery on without changing it, precise coordinates are kept.
- Remove — the coordinates are discarded as photos are indexed and no location is stored on the item
Photo Discovery is off until you turn it on, so no photo location is read or stored unless you opt in. You choose the setting at the point you turn the feature on. You can turn Photo Discovery off again at any time, which clears the on-device index; turning it back on lets you choose the setting again.
To turn coordinates into a readable place name, coordinates are sent to our own servers, which look them up against an offline place-name dataset held inside our infrastructure. Your coordinates are not sent to Google, Apple, or any other mapping or geocoding provider.
2.8 Contacts (Mobile App)
When adding a Legacy Vault nominee, you may optionally import their details from your device's address book instead of typing them. If you grant permission, the app reads your contacts on your device only, solely to display a picker. Your address book is never uploaded to us and is never sent to any third party. Only the details of the single contact you select are placed into the nominee form, and only if you then save that nominee do those details (name, email, phone) reach our servers as nominee data — where they are used to send that person their invitation. You can decline the contacts permission and type nominee details manually instead; the feature is the only place the app uses contacts.
2.9 Push Notifications (Mobile App)
If you enable push notifications, we register a push token for your device so that we can deliver alerts such as document expiry reminders, sharing activity, and Legacy Vault events. We store the push token, the platform (iOS or Android), and the device name you have given your device. Any such delivery would go through the push infrastructure of the platform you are on — Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM). Push tokens are deleted when you sign out and when you delete your account. We currently retain a registered token until one of those events occurs. You can turn push notifications off at any time in your device settings or in the app. Notifications are also available inside the app itself, which does not require a push token.
2.10 Crash and Error Reporting (Mobile App)
The mobile app uses Sentryto report crashes and errors so we can fix them. A report contains diagnostic information such as the error message, the stack trace, the app version and build, the device model and operating system version, and the in-app action that was in progress (for example, “document scan step 2”). We have configured Sentry not to attach personally identifying information and notto attach your user ID or email address, and we do not enable Sentry's performance-tracing or session-replay features. The contents of your documents and files are never included in crash reports. Where an upload or import fails, the report may include the file name and the local device path of the file involved, so that we can reproduce the failure. This feature is not present in the web app.
2.11 In-App Purchases (Mobile App)
Subscriptions bought inside the mobile app are processed by the Apple App Store or Google Play, and are managed for us by RevenueCat, Inc. We never see or receive your card details. To link a purchase to the right account, we pass RevenueCat your MyDocuVa account identifier; RevenueCat receives the purchase and subscription status associated with it and tells our servers which plan you are entitled to. We do not send RevenueCat your email address, name, or any vault content. Purchases made on the website are processed by Stripe instead (see section 2.2).
3. How We Use Your Information
We use your information solely to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your sessions
- Process subscription payments through Stripe (web) or the Apple App Store and Google Play via RevenueCat (mobile), and confirm which plan you are entitled to
- Deliver push notifications to your device, if you have enabled them
- Diagnose and fix crashes and errors in the mobile app
- Send transactional emails (password resets, sharing notifications, expiry alerts, legacy vault triggers)
- Enforce subscription plan limits (item count, storage quota)
- Maintain audit logs for your account security
- Respond to your support requests
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Encryption
MyDocuVa uses AES-256 encryption with keys managed in AWS KMS:
- Your passphrase adds a strong access layer, derived on your device via PBKDF2 (600,000 iterations)
- Encryption keys are managed by AWS Key Management Service (KMS) under strict access controls and audit logging
- Your documents are encrypted with AES-256-GCM at rest, and travel between your device and our servers over TLS 1.2+
Your passphrase is never transmitted to or stored on our servers. It is a strong access layer protecting your account, and we recommend keeping a copy in a safe place.
If you forget your passphrase, you can reset it after verifying your identity by email, and your items and files remain intact. We want to be clear about what that implies: because encryption keys are managed in AWS KMS under our control, MyDocuVa is technically capable of decrypting stored content. We deliberately avoid marketing claims suggesting otherwise, because they would not be accurate. We access content only where necessary to operate the Service — for example, to generate a report you asked for, to serve a file back to you, or to deliver an item to a share recipient or Legacy Vault nominee you designated — or where we are legally required to. Every such access is audit-logged, and we never use your content for advertising, profiling, or training machine-learning models.
5. Data Storage and Security
Your data is stored on Amazon Web Services (AWS) infrastructure in the United States (us-east-1 region):
- Encrypted files — Amazon S3 with server-side encryption (SSE-KMS)
- Database records — Amazon DynamoDB with encryption at rest using AWS-managed KMS keys and Point-in-Time Recovery (PITR)
- Authentication — Amazon Cognito with secure credential management
- Content delivery — Amazon CloudFront with signed URLs for media access
- Data in transit — all communications are encrypted via TLS 1.2+
We implement security best practices including Content Security Policy (CSP) headers, input sanitization, rate limiting on sensitive endpoints, and multi-factor authentication (MFA) support.
6. Data Sharing and Disclosure
We may share your information only in the following circumstances:
- With your consent — when you use our Sharing feature to create time-limited, password-protected links to specific items
- Family Plan members — items marked as “Family” visibility are accessible to members of your Family Plan
- Legacy Vault disclosure — when a Legacy Vault trigger is activated (per your configured inactivity period), designated nominees receive access to allocated items through a secure portal
- Service providers — the sub-processors listed below, with whom we maintain Data Processing Agreements
- Legal requirements — we store your data encrypted and require a valid legal process (such as a subpoena or court order) before disclosing anything. We minimize what we access, and every access is audit-logged
Third-Party Service Providers (Sub-Processors)
| Provider | Purpose | Data they receive |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, database, authentication, encryption keys, email delivery (S3, DynamoDB, Cognito, KMS, Lambda, SES, CloudFront) | All account data and encrypted content |
| Vercel | Web application hosting | Requests to our website, including IP address |
| Stripe | Payment processing for web subscriptions | Email address, account identifier, payment details you enter on Stripe's own checkout page |
| RevenueCat | Managing in-app subscriptions bought on iOS and Android | Account identifier, purchase and subscription status |
| Apple and Google | App distribution, in-app purchases, push notification delivery (APNs / FCM), and sign-in if you choose Apple or Google sign-in | Purchase records, push tokens and notification content, and the email address associated with the sign-in method you choose |
| Meta Platforms (Facebook) | Facebook sign-in, if you choose it | The email address and basic profile associated with the Facebook account you sign in with |
| Expo | Mobile app build tooling and push token issuance | Build artifacts and push token registrations |
| Sentry | Crash and error reporting for the mobile app | Diagnostic data only — no user ID, email, or vault content |
| Google Analytics | Page-view measurement on our public marketing pages only | Marketing page URL, referrer, approximate location and device type |
We do not use any other analytics, advertising, profiling, or AI/machine-learning vendor, and we do not send your documents or item content to any third party.
7. Data Retention
- Account data — retained for the lifetime of your account
- Deleted items — moved to a recovery bin for 30 days, then permanently deleted
- Audit logs — retained for 3 years from the date of the event, then automatically purged. Audit logs may be exempt from individual deletion requests where retention is necessary for security monitoring or the establishment, exercise, or defense of legal claims
- Session records — retained for security monitoring; older sessions are periodically cleaned
- Push notification tokens — retained until you sign out or delete your account, at which point they are deleted
- Crash reports — retained by Sentry under their standard retention period (currently 90 days) and contain diagnostic data only
- Account deletion — when you delete your account from the app, all associated data (items, documents, encrypted files, family associations, and metadata) is removed immediately, and there is no way to restore it from within MyDocuVa. Our storage keeps prior versions of files, so an encrypted copy can remain in that version history for a period afterwards; it is not reachable through the Service. Deletion requests sent to support by email are completed within 30 days. One exception: if another user named you as a nominee or co-owner in their own Legacy Vault, that entry belongs to their record and only they can remove it
8. Your Rights and Choices
You have the following rights regarding your data:
- Access — you can view all your stored data within the app at any time
- Export — you can download or share any individual item, document, photo, or report from its page in the app. A one-click archive of your whole account is not available yet; email support@mydocuva.com and we will provide a copy of your data
- Correction — you can update your profile, items, and documents at any time
- Deletion — you can delete individual items (30-day recovery) or request full account deletion
- Portability — data you download or that we provide on request comes in standard formats (PDF and the original file formats you uploaded)
- MFA control — you can enable or disable multi-factor authentication at any time via Settings > Security
- Notification preferences — you can control which email notifications you receive via Settings > Preferences, and you can turn push notifications off at any time in your device settings
- Permission control — camera, photo library, and contacts access in the mobile app are optional and can be granted or revoked at any time in your device settings. Declining them only disables the related convenience feature
- Photo location choice — you decide whether photo GPS coordinates are kept or removed as photos are indexed (see section 2.7)
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with additional rights regarding your personal information.
Categories of Personal Information Collected
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Email address, name, IP address | Account authentication, security |
| Commercial Information | Subscription plan, purchase history (via Stripe, or the App Store / Google Play through RevenueCat) | Billing, plan enforcement |
| Geolocation Data | Precise coordinates embedded by your camera in photos you add, if you choose to keep them (optional; not collected from device location services) | Ownership proof and item confidence scoring |
| Sensory Information | Photos, scanned documents, and videos you choose to upload | Secure storage on your behalf |
| Internet Activity | Login timestamps, browser type, session data | Security monitoring, audit trails |
| Encrypted Content | Documents, photos, files (encrypted with AES-256, keys managed in AWS KMS) | Secure storage on your behalf |
Your California Rights
- Right to Know — request what personal information we collect, use, and disclose
- Right to Delete — request deletion of your personal information
- Right to Correct — request correction of inaccurate personal information
- Right to Non-Discrimination — we will not discriminate against you for exercising your rights
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not use your personal information for cross-context behavioral advertising.
To submit a verifiable consumer request, contact us at support@mydocuva.com. We will verify your identity before processing your request and respond within 45 days.
10. Additional Rights for EEA, UK, and Swiss Users
If you are located in the European Economic Area, United Kingdom, or Switzerland, the following additional provisions apply:
Legal Basis for Processing
- Contract performance — processing your account data, subscription, and encrypted files to provide the Service
- Legitimate interest — security monitoring, audit logging, and fraud prevention
- Legal obligation — compliance with applicable tax, anti-money-laundering, or law enforcement requirements
Additional Rights
In addition to the rights in Section 8, you also have the right to:
- Restrict the processing of your personal data
- Object to processing based on legitimate interest
- Lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, CNIL in France, or your national data protection authority)
International Data Transfers
Your data is stored and processed in the United States. International transfers of personal data from the EEA/UK to the United States are conducted pursuant to Standard Contractual Clauses (SCCs) adopted by the European Commission, as implemented in our agreements with the sub-processors listed in section 6 (including AWS, Vercel, Stripe, RevenueCat, Sentry, Expo, Apple, Google, and Meta).
As a supplementary measure, the content of your documents transferred to US servers is encrypted with AES-256, with keys managed in AWS KMS under strict access controls and audit logging. Any access to your data requires a valid legal process, and we minimize what we access and log every access.
11. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected users by email and/or in-app notification within 72 hours of becoming aware of the breach, or as required by applicable law.
Your files are encrypted at rest and the keys are protected in AWS KMS with strict access controls and audit logging. A breach could affect account metadata such as email addresses, item titles, and usage data. We will clearly communicate the nature and scope of any breach in our notification.
12. Children's Privacy
MyDocuVa is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 13 as defined by COPPA. If you believe a child has provided us with personal information, please contact us and we will promptly delete such information.
13. US State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with consumer privacy laws may have additional rights similar to those described in the California section above, including the right to access, delete, and correct personal information, and the right to opt out of the sale of personal information. We do not sell personal information under any state's definition.
To exercise any rights under your state's privacy law, contact us at support@mydocuva.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last Updated” date. For significant changes, we may also send an email notification to the address associated with your account.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
LendMesh LLC
Email: support@mydocuva.com