ServiceVault privacy overview
This page explains what stays on your iPhone, what the website measures, when cloud features are used, and how to delete your data.
What stays on your iPhone
In On-device mode, records and attachments stay in the app's data on your iPhone instead of being uploaded to ServiceVault's cloud.
iOS may include that app data in a device or iCloud backup. Exporting a ServiceVault backup or turning on Pro backup and sync creates a separate copy.
Backup and sync is available only in an eligible signed-in Pro test build. It starts after an explicit sign-in, purchase, restore, or storage choice.
Once enabled, ServiceVault backs up the existing vault and syncs later changes. Choosing Continue On-device stops future syncing without deleting either copy or cancelling the paid plan.
Website and beta list
Tally hosts the beta-list form. It collects your email address and, if you answer the optional question, the vehicles or equipment you maintain. It also receives the page and campaign fields sent with the form.
ServiceVault uses the response for occasional build updates and TestFlight invitations. Joining the list does not create an app account or start a payment.
The website sends page views, beta-list actions, device class, broad referral and campaign labels, creative version, and form load or submission events to a first-party collector hosted by Cloudflare.
The collector does not receive your Tally answers or anything stored in ServiceVault.
The site remembers anonymous referral and campaign information for up to 30 days so ServiceVault can tell which visits lead to beta signups. Clearing this site's data removes the browser copy.
Cloudflare hosts and protects the site and helps rate-limit abuse. The browser uses a short-lived security cookie and an anonymous session ID. ServiceVault does not store raw IP addresses with marketing events.
To ask for a beta-list response or support email to be deleted, contact support@getservicevault.com.
What changes when you sign in
Local records stay in the app's storage on this iPhone. Signed-in account credentials are stored in the iOS Keychain.
- On-device: No account is required to keep records, reminders, attachments, and local backups on your iPhone.
- Pro: Pro backup and sync uses account sign-in, cloud records, storage, and access-controlled attachments only after you enable it.
Crash reports, product analytics, and replay
When crash reporting is enabled in a beta build, Sentry receives scrubbed crash and error events, not broad behavioral analytics.
When in-app analytics are on, PostHog receives screen names, feature actions, limited app state, plan type, and optional masked interaction replay. Signed-in events may use an account ID so activity is not counted twice.
Email addresses and vault content are not sent to analytics.
Optional native interaction replay masks all text, text inputs, images, and sandboxed system views.
It records layout and touch positions for usability review and heat maps without console logs or network details.
You can turn analytics and replay off independently in Settings > Privacy. ServiceVault does not use this data to track you across other companies' apps or websites.
- Never sent to analytics: Asset IDs or names, VINs and serials, notes, filenames, documents, receipts, photos, Assistant prompts, feedback text, and email addresses.
- Plan types: Free, Pro Preview, and Pro are used to compare adoption and improve each plan.
- Provider: PostHog processes these analytics events and masked replay data for ServiceVault.
Private feedback and community priorities
When you deliberately send in-app feedback, ServiceVault receives the response, the feedback type, and the limited diagnostics shown for review before submission.
Feedback submission is separate from Pro backup and sync and does not upload your vault.
The diagnostics can include the app version and build, iOS and broad device model, build channel, plan/access state, On-device or Pro destination, Guided or Advanced mode, and current screen family.
They can also include the prompt that opened the form. They do not include asset names or IDs, VINs, plates, notes, filenames, documents, receipts, photos, or Assistant conversations.
You can submit without an account. ServiceVault sends a random installation identifier to the feedback service for abuse prevention and one-vote enforcement.
The service stores only a one-way keyed hash of that identifier and does not store a raw IP address with the response.
If you later sign in on the same installation, the service may reconcile only that installation's votes, follows, and poll choices into the account's pseudonymous participation state.
Existing signed-in choices win, and contact permission never moves with an anonymous follow.
This reconciliation never links anonymous feedback text, follow-up contact, public-sharing permission, or Owner Council consent to the account.
Follow-up contact and Owner Council research participation are optional. An email address is collected only when you provide it with the corresponding consent, and you can ask to withdraw or delete it by contacting support.
The app and site can read back only whether the current identity is enrolled in the Owner Council. Research email, topics, consent details, and history are not included in that response.
Feedback is private by default. A separate optional permission lets a moderator quote or summarize it publicly only after review and de-identification.
The original message, contact details, identifiers, and diagnostics are never published automatically.
The public roadmap contains moderator-written themes, status updates, known issues, testing notes, and changelog entries.
Votes and priority polls guide product research but do not guarantee delivery. Open poll totals and voter identities are not public.
When Vault Assistant is enabled
On-device forecasts, cost estimates, and record summaries use the service histories, schedules, readings, costs, and proof you save. That analysis is not sent to Vault Assistant.
Vault Assistant is separate from those on-device features. When available to signed-in Pro testers, it runs as a hosted feature.
When an eligible signed-in user asks a question, ServiceVault sends the prompt and a limited snapshot of relevant saved details. OpenAI processes the request for ServiceVault.
Assistant output is informational. It is not a mechanical diagnosis or professional advice.
The snapshot leaves out VINs, registration and document numbers, note bodies, filenames, and raw attachments.
Before sending the question and recent chat, ServiceVault tries to remove common identifier patterns. Automated redaction can miss details.
Do not enter names, contact details, VINs, plates, policy numbers, account numbers, or serial numbers.
Deletion and support
You can delete records stored on your phone through the app's data controls. To delete cloud data connected to your ServiceVault account, use the account controls or contact support.
Feedback text and optional contact details are sent only after you review and submit the form. The response text and email address are not copied into product analytics.
If the private feedback service is unavailable, ServiceVault can offer a reviewable email draft instead.
Deleting a ServiceVault account deletes feedback and participation rows linked to that account.
Anonymous feedback and research consent are not retrospectively linked to an account and remain available through the support and retention paths described here.
To delete a feedback response, withdraw from the Owner Council, or stop research follow-up, contact support@getservicevault.com with enough information to locate the request.
For early-access support, privacy questions, and deletion help, contact support@getservicevault.com.