Privacy Policy
This policy covers the LiveVault iOS app, this website, and optional account, sync, analytics, diagnostic, notification, and listening-history data paths. We don’t sell your data, and you can request deletion.
Last updated · August 14, 2026
The short version
- When publicly released, release 1.2 offers optional accounts and signed-in sync for supported library fields. Previously downloaded audio stays on its original device; new Archive downloads are disabled in this release.
- App analytics, diagnostics, server-side device identifiers, and push tokens are used only as described below and only when the relevant release, configuration, sign-in state, or permission enables them.
- Website analytics stay off until you allow them. App analytics and diagnostics described below apply only to releases that include those features.
- We do not sell, rent, or trade your personal information.
- You can export or delete your data any time at jesse@livevaultapp.com or use our support form.
- LiveVault streams from the Internet Archive, which has its own privacy policy covering stream requests.
Information we collect
Account information
LiveVault 1.2 offers optional accounts. If you create one, we store your email address, a one-time email sign-in or third-party authentication identifier, and a display name. LiveVault does not store a password for your account. If you sign in with Apple or Google, we receive only the fields you authorize.
Your library
Favorites, playlists, personal show notes, recently played items, and playback resume can be kept on the device. When you sign in, supported fields—including favorites, playlists, and notes—may sync through LiveVault’s service. Downloaded audio files stay on the device where you saved them and do not sync across devices.
Device & usage information
When enabled in the installed app configuration, LiveVault may collect basic diagnostics such as device model, OS version, app version, crash reports, and pseudonymous first-party product events (for example, that a user played a show). We do not associate those events with advertising profiles. Separately, when configured, this website may send server-side form or API exceptions to Sentry; form bodies, names, and email addresses are not intentionally attached to those exception events.
Website analytics choices
Website analytics are off by default. If you choose “Allow analytics,” we record pseudonymous page views, demo engagement, App Store clicks, and form outcome categories. We do not include names, email addresses, message text, full query strings, or raw IP addresses in those events. Campaign parameters are limited to short, sanitized UTM values. You can change the choice at any time with the “Privacy choices” control; turning analytics off clears LiveVault’s local marketing identifiers. Global Privacy Control is honored as a deny choice when no preference has already been saved.
Device identifiers
When you use account-backed features in release 1.2, LiveVault uses a random identifier stored in platform-protected local storage and on our servers to coordinate a device with the service. It is not an advertising ID and is not shared with ad networks. Depending on platform storage behavior, reinstalling that release may not reset it; an uninstall is not an account-deletion request. Use the in-app deletion flow where available or contact support to request deletion of account-linked data.
Push notifications
Release 1.2 offers optional notifications. If you opt in, we store the push token provided through Apple, Google, and Expo so we can deliver the notification categories shown in that release. You can revoke permission at any time from your OS settings, and you can ask us to delete a registered token by emailing jesse@livevaultapp.com. We do not include personal content in a push.
Website contact, support, and newsletter forms
Contact and support submissions include the name, email address, category, message, reply permission, and any optional product diagnostics you choose to provide. Newsletter subscriptions include your email address, explicit consent, signup source, timestamp, and limited campaign-attribution fields when present. That consent is for the weekly editorial LiveVault Letter; it does not opt you into a separate launch or product-update stream. Contact and support submissions do not subscribe you to either program.
The website uses a short-lived hashed network identifier to limit automated abuse; the forms do not store your raw IP address in the application ledger. Hosting and email providers may retain operational logs under their own policies.
For each newsletter subscriber, we also keep limited operational records needed to deliver mail and honor suppression choices. These may include totals for deliveries, unsubscribes, complaints, temporary or permanent bounces, and provider suppressions; relevant timestamps and a bounded list of hashed event identifiers used to recognize retries or duplicates; and the status, attempt count, and timing of synchronization with the email provider. We use this information to apply preferences, prevent inappropriate delivery, reconcile provider state, and document delivery or suppression outcomes. The email provider also processes the subscriber address and newsletter-topic status to perform those functions.
Listening history
Playback-resume history remains on the device. When you are signed in, My Trip stores account-linked listening events such as start, progress, completion, and skip to calculate your private statistics, milestones, and listening journey. This functional history is separate from optional PostHog product analytics. Turning product analytics off does not disable My Trip. You can turn off My Trip history to stop saving new events and discard queued events on this device. Existing account history remains until you delete your account in Settings, which permanently deletes your stored history and derived recommendation preferences.
In release 1.2, if you open the app from a LiveVault campaign link, the app records that first campaign on the device and attaches it to the listening events described above. The fields are campaign_id, creative_id, channel, marketing_source, attribution_method, and install_scope. They are a fixed set of campaign labels, not advertising or device identifiers, and they carry no cross-app or cross-site tracking. Because they travel with account-linked listening events, they become an account-linked server-side record that we use to see which campaigns bring listeners who actually listen. If product analytics are off — including before the app has read your saved choice — the app sends no campaign fields, while My Trip history continues to work. These records are deleted with your account.
IP addresses and server logs
When you use this website or an app release that contacts LiveVault-operated APIs, our APIs and infrastructure providers may process IP addresses and user-agent strings for security, debugging, and rate limiting. Retention follows the configured service and provider policies. LiveVault does not include raw IP addresses in ordinary product-analytics events.
How we use your information
- Operate and improve the LiveVault app and website.
- In releases that offer signed-in sync, synchronize supported library fields across devices.
- Send the weekly LiveVault Letter only when you explicitly join that editorial program.
- Send necessary account or service messages; any future promotional product-update stream requires its own notice and consent where applicable.
- Detect and prevent abuse, fraud, or illegal activity.
- Comply with legal obligations.
What we don’t do
- Sell your personal data to third parties.
- Share your listening history with advertisers or social networks.
- Build cross-app tracking profiles.
- Show ads inside the music experience.
Third-party services
LiveVault uses a small set of providers for the current website and service. Some mobile integrations below apply only when the installed release and configuration include them:
- Internet Archive — streams the audio recordings.
- Supabase — the website newsletter consent ledger and, in releases that offer them, database and authentication services.
- Apple / Google — App Store distribution and optional sign-in. Live Guide does not require payment.
- PostHog / Sentry — consented website analytics and server-side website error reporting; mobile analytics and diagnostics only in app releases that include them.
- Resend — contact and support email delivery and optional newsletter contact synchronization.
- Vercel / Upstash — website hosting and short-lived form rate limiting.
- Expo (EAS) — mobile build pipeline and, only in releases that offer notifications, a push relay that receives a token after you opt in.
Data location and retention
LiveVault account data is hosted through service providers that operate U.S. data centers. Account-linked records are kept while needed to provide and secure the service. Completing the in-app account-deletion flow in a release that provides it removes the account and its dependent records from LiveVault’s primary database. Limited backups, provider logs, legal records, and non-identifying suppression proof may remain for their configured retention periods where required for security, recovery, or compliance.
Your rights under GDPR / UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, port, restrict, or delete the personal information we hold about you, and to object to certain processing. Our legal basis for processing is either (a) performance of the contract to deliver the LiveVault service, (b) our legitimate interest in improving and securing the product, or (c) your consent for the weekly editorial LiveVault Letter, push notifications, and optional analytics. To exercise any right or lodge a complaint with your local supervisory authority, contact jesse@livevaultapp.com or use the privacy category in Support.
Your rights under CCPA / CPRA
California residents have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its “sale” or “sharing” as those terms are defined under the CCPA/CPRA. We do not sell or share personal information for cross-context behavioral advertising. To submit a request, email jesse@livevaultapp.com or use Support; we will respond within 45 days.
Your rights
You can, at any time:
- Access a copy of your data.
- Correct or update information.
- Delete your account and request deletion of account-linked data.
- Opt out of product emails.
- Change website analytics at any time with the “Privacy choices” control. In the app, use the Profile analytics control to stop optional PostHog product events. Use the separate My Trip control to stop new functional listening history, or delete your account in Settings to permanently remove stored events and derived recommendations. Use the privacy category in Support if your installed version does not expose those controls.
Email jesse@livevaultapp.com or use Support for any of the above. We’ll respond within 30 days.
Children
LiveVault is not directed to children under 13 (or the equivalent minimum age in your jurisdiction, whichever is higher). We do not knowingly collect personal information from anyone below that age. If you believe a child has created an account, email jesse@livevaultapp.comand we will delete it promptly.
Changes to this policy
We’ll update this page when things change. Material changes will be announced in-app and via email. The “Last updated” date above always reflects the current version.
Contact
Questions? Email jesse@livevaultapp.com or use Support.