Information we collect
- Account information: your name, email address, username and password (stored only as a one-way hash). Optionally a phone number (if you sign in with a code by text message), a profile photo, and your company name and intended use if you tell us.
- Sign-in with Google, Apple or Facebook: if you choose this, we receive your name, email address and an account identifier from that provider. We don't receive your password for those services.
- Billing information: payments are processed by Stripe. We receive and keep your plan, billing status, invoices, and your card's brand and last four digits. We never receive or store full card numbers.
- Files you store: the documents, photos and videos you upload, together with their names, sizes, types and folders.
- Photo and video details: when you upload a photo or video, we read information stored inside it, such as the date and time it was taken and, if your camera recorded it, the location. We use this to show when and where it was taken. See "How we use it" for how locations are turned into place names.
- Device and sign-in information: your IP address, the type of device and browser you use, and when you sign in. From your IP address we work out an approximate location (city/country level) to protect your account, for example to warn you about a sign-in from somewhere new. This is done on our own servers with an IP location database; your IP address is not sent to anyone else for this.
- Security settings: whether two-factor authentication, trusted devices and Face ID/fingerprint unlock are turned on. Face ID and fingerprint checks happen entirely on your device; we never receive your biometric data.
- Messages you send us: support requests and their contents.
Photo backup in our mobile apps
Photo backup is off until you turn it on. If you turn it on, the app reads the photos and videos in your phone's photo library (all of them, or only new ones, as you choose) and uploads them to your vault. The app keeps a list on your phone of which items it has already uploaded so nothing is uploaded twice. You can turn photo backup off at any time in the app or pause it on our website; photos already backed up stay in your vault until you delete them. The app only reads your photo library to add items to your vault, and only with the permission you grant in your phone's settings.
How we use it
We use your information to:
- provide the service: store, show, organize, share and let you download your files;
- create thumbnails and previews of your files, show photo dates and places, and let you open and edit documents in your browser;
- keep your account secure: sign-in codes, two-factor authentication, alerts about new sign-ins, and preventing abuse;
- process payments and manage your plan;
- answer your support requests;
- send you service emails, such as sign-in codes, security alerts, receipts and important changes.
We do not sell your personal information, and we do not use your files or personal information for advertising.
Encryption & access
Your files and data are encrypted in transit (HTTPS/TLS) whenever they move between your device and our servers, and encrypted at rest in our storage and database.
MDS Vault is not end-to-end encrypted: our systems can process your files in order to provide features such as thumbnails, previews, photo dates and places, in-browser document editing, sharing and downloading folders as zip files. Access by our staff is limited to what's needed to provide support you ask for, keep the service secure, or meet a legal obligation, and is restricted to authorized personnel.
Locking a folder with a password prevents it from being opened without that password, including by other people you share with; it is an access control, not a separate layer of encryption.
How we protect your account
Signing in on a new device requires a one-time code sent by email (or text message, if you sign in with your phone number), or your authenticator app if you turn that on. You can see and sign out of your active sessions at any time, and you'll get an email when your account is signed in from a new network or location.
Retention & deletion
- While your account is active, we keep your account information and files until you delete them.
- Deleted files and folders go to your Trash, where you can restore them for 45 days. After that they are permanently deleted. You can also empty your Trash at any time to delete them immediately.
- If your account stays over its storage limit for more than 30 days (for example after a paid plan ends), your oldest files are permanently deleted until you're back within the limit. We email you reminders first; see our Terms.
- When you delete your account, you are signed out everywhere and can no longer sign in, straight away. Within 30 days, your files, folders, share links, profile and personal details are permanently deleted from our systems. Files you uploaded to an organization's shared storage belong to that organization and are not deleted.
- Backups: deleted data may remain in our encrypted backups for up to 30 days, until those backups are overwritten on a rolling basis. Backups are only used to recover from failures.
- What we keep: billing and payment records (kept by Stripe and by us) as long as tax and accounting law requires, and a minimal record needed to prevent fraud and abuse, which no longer identifies you.
- Unconfirmed sign-ups: if an account's email address is never confirmed, the account is removed after 7 days, and the remaining record (email address or phone number and sign-up date) is deleted 30 days after that. We never use it for marketing.
How to delete your account
You can delete your account yourself at any time:
- iPhone or Android app: open the Me tab, scroll to the bottom, tap Delete account, and confirm.
- Website: sign in at app.mds-vault.com, open your Profile, and choose Delete account.
- Can't sign in? Email info@mds-vault.com from the email address on your account and we'll delete it for you after confirming it's yours.
If you have a paid plan, cancel it first from Profile → Billing on the website, so you aren't charged again. What is deleted, and what we're required to keep, is described under Retention & deletion.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to or restrict how we use it. You can do most of this yourself: edit your profile, download your files (including a zip of your whole vault from Privacy settings), and delete your account. For anything else, email info@mds-vault.com. We'll respond within 30 days.
Children's privacy
MDS Vault is not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we'll delete it.
Changes to this policy
We'll update this page if our practices change, and update the date above. We'll tell you about material changes by email or in the app before they take effect.
Contact us
Questions about this policy or your data? Email info@mds-vault.com.
Anshin Sumai LLC,3-6-9 Minamisuna, Koto-ku, Tokyo, Japan
"This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com." or: "IP geolocation by DB-IP (https://db-ip.com), licensed under CC BY 4.0."]]