The short version: Sovereign Vault stores your records on your phone. There is no account, no server of ours, and no database we can look at. We do not collect your health information, because the app contains no mechanism by which we could receive it.
The app is not silent on the network, and we would rather show you exactly what it does than claim an absolute we cannot honestly claim. Every connection it makes is listed below, along with what moves and why.
Who we are
Barca Labs, LLC, a limited liability company registered in the State of Kansas, United States. Barca Labs, LLC is the developer and publisher of the mobile application Sovereign Vault ("the app").
For any question about this policy or about your data, contact [email protected].
What the app stores, and where
Sovereign Vault holds three kinds of information: what you enter yourself, what it reads from services you connect it to, and a small amount the app records about its own workings. Nothing else. The complete list:
- A first name, if you give one, so the app can address you. Nothing else identifies you — there is no account, no email address, no phone number.
- What you take, with doses, units, route, timing and schedule. This may include prescription medication.
- How your protocol has changed over time — what you were taking before, and when it changed.
- Whether you took each dose, skipped it, or took it late, together with any note you write against it.
- Training — what you planned, and what you completed.
- Lab results you enter from blood work.
- Body weight and blood pressure, over time.
- Readings the app did not get from you — heart rate variability, resting heart rate, sleep duration and sleep score, steps, and — where a connected service supplies them — measures like strain and VO2 max. These come from Apple Health, Health Connect, or a wearable you connect. Worth knowing that Apple Health and Health Connect are stores rather than devices: what the app reads from them may have been written by a scale, a watch, or another app entirely, not only by something you think of as a wearable.
- Menstrual cycle entries, which may be your own or a partner's — see below.
- Abstinence counters — see below.
- Which check-in cards you have been shown, when you dismissed or answered them, and what you answered — including anything you typed into a free-text box. See below.
- A small technical error log. When something inside the app goes wrong, it records the type of the error and a short description we wrote ourselves. It deliberately does not record the error's own message, because those routinely contain the exact value that caused the failure — which would put your data in a log. It never leaves your device and it is encrypted with everything else.
All of it is written to an encrypted database on your device. None of it is transmitted to us. We operate no server that receives it, and there is no account under which it could be stored.
A small number of things sit outside that database, in your device's own secure storage — the Keychain on iOS, keystore-backed encrypted storage on Android. Those are the cryptographic keys themselves, plus a handful of flags and timestamps: whether you have turned on biometric unlock, whether the vault has been set up, when a prompt was last shown to you. No health information is among them, and nothing the app stores is stored unencrypted.
Cycle tracking
The app can track a menstrual cycle and place it on the same timeline as your sleep, training and adherence — so that a week which felt different has something around it to explain why. The cycle may be your own or a partner's, and the two are handled differently.
Your own cycle is recorded and stored like any other entry, and it is included in anything you export.
A partner's cycle means you are recording health information about someone other than yourself. The app deliberately holds as little as it can:
- What is stored: one date — the start of their last period — and two numbers, their average cycle length and average period duration, along with any cycle event you log yourself. There is no stored day-by-day record. Anything resembling a calendar is worked out when it is needed and not kept.
- What is exported: nothing. Not the dates, not the entries, not the fact that you are tracking a partner's cycle at all. An export from this app is identical whether you track a partner's cycle or track none — so nobody you hand it to can tell the difference. We considered noting the exclusion and decided against it: saying "a partner's cycle was omitted here" would itself tell a stranger that another person's reproductive data exists on your phone.
- What they have agreed to: nothing, because they have no relationship with us and we hold nothing of theirs. Whether to record another person's health information is your decision — and one better made with them than about them. The app says the same thing when you set it up.
Abstinence counters
The app can count the days since you stopped something — alcohol, nicotine, cannabis, sugar, caffeine, or a label you write yourself — optionally toward a milestone, with a note about what it means to you.
We treat that as sensitive information rather than as a streak counter, because that is what it is. It is encrypted on your device alongside everything else and we never receive it.
How the encryption works
The key that opens the database is derived from the PIN you set, and is not stored anywhere in a form that can be used without it. Biometric unlock, if you enable it, is a faster route to the same key rather than a second way in. Supporting key material is held in your device's secure hardware store — the Keychain on iOS, the Keystore on Android. The key never leaves your phone.
We have no copy of any of it. If you lose your phone we cannot recover your records, and if you forget your PIN we cannot reset it. That is a direct consequence of the design rather than an oversight, and you should plan your own backups accordingly.
There is a second and separate reason to keep your own copy. The database engine the app is built on carries a known defect that can, in some circumstances, lose a recently saved entry without warning. There is no fixed version available to us yet. It is described in full on the security page.
The full specifics — cipher, key derivation, iteration count — are on the security page. Being straight with you about what this does and does not protect against:
- Device backups differ by platform. On Android, the supporting key material is excluded from cloud backups and device-to-device transfers. On iOS it is not — it is included in encrypted iCloud and computer backups and can be restored to a new device. Worth knowing before you rely on the app rather than after.
- An unlocked device in someone else's hands. If a person has your phone and your PIN or biometric, the app will show them your records exactly as it shows you.
- A jailbroken or rooted device. The operating system's secure storage can potentially be defeated where OS protections have been removed.
What we collect
Nothing on its own. The app has no user accounts and no sign-in. It does not report usage, does not phone home, and contains no advertising or analytics software.
There is one way anything reaches us, and it only happens if you deliberately make it happen: the app can write a short check-in message for you to send us from your own phone. It is described in full below. Unless you send that message, we do not know who you are, that you installed the app, or whether you still use it.
Connections the app makes
Below is every connection Sovereign Vault makes, what it carries, and what it is for.
App updates
Sovereign Vault delivers updates over the air using EAS Update, a service operated by Expo. Each time the app starts, it contacts Expo's servers to ask whether a newer version is available. If one is, the app then downloads the updated application code and any changed assets from Expo's content delivery network.
According to Expo's documented update protocol, the request identifies the platform, the runtime version, and the release channel, so the service knows whether a newer version applies. As with any internet request, Expo's servers can also observe the IP address it came from. No health information, and nothing you have entered, is sent in this request or in any part of the update process.
This happens automatically on every launch and requires no action from you. Expo's handling is governed by Expo's privacy policy.
Polar sync
If you choose to connect a Polar account, the app signs in to Polar's servers on your behalf and requests your readings from them. This is a connection to a third party's servers over the internet — it is not a local read from your device.
It happens only if you set it up, and only when a sync runs. You can disconnect at any time. Data retrieved from Polar is then stored on your device like any other entry.
The connection runs directly between your device and Polar. There is no server of ours in the middle, and your Polar data does not pass through us at any point. Your relationship with Polar is governed by Polar's privacy notice.
Buying the app
Sovereign Vault is sold as a one-time purchase through the Apple App Store and the Google Play Store. Payment is handled entirely by Apple and Google. We never see your payment details.
Apple and Google collect their own information when you buy or download an app, and provide us with aggregate, anonymised sales statistics that cannot identify you individually. Their handling is governed by Apple's privacy policy and Google's privacy policy.
On your device only
Apple Health and Health Connect
Where the app reads from Apple HealthKit (iOS) or Health Connect (Android), that is a local read on your own device, mediated by your operating system and limited to the data types you approve. Nothing is transmitted over the network and no third party receives it. You can withdraw these permissions at any time in your device's system settings.
What the app reads this way becomes part of your record, alongside what you typed. That means it is shown to you in the app and it is included when you copy your record out — see below.
Taking your data out
Export
The app can produce a summary of your record — as JSON or as Markdown — so you can take it elsewhere: to your own notes, to a clinician, or to an AI tool you want to ask questions of. That summary covers your whole record — both what you entered and what the app read from services you connected: what you take, with doses, units, routes and schedules; how your protocol has changed over time; your adherence history; lab results; body weight and blood pressure; training plans and sessions; your abstinence counters; and the readings pulled from Apple Health, Health Connect or a wearable — heart rate variability, resting heart rate, sleep, steps, strain, VO2 max.
Two limitations worth knowing while we fix them. Readings that came from Apple Health or Health Connect are not currently marked as such in what you copy out, so a reader cannot tell them apart from figures you typed yourself. They also carry no date of their own — so if a sync has fallen behind, a reading can be older than it looks. We are adding source and date labelling, and this section changes when we do.
Cycle entries are included only when the cycle is your own. If you are tracking a partner's cycle, all of it is excluded — see above.
That summary is copied to your device's clipboard, and that is the only thing that happens. No file is written to your device. Nothing is shared through your device's share sheet. The app does not transmit it anywhere. It is placed on your clipboard and left there for you to paste.
What you paste it into is a separate and deliberate act you perform.
Worth being clear about the consequence: once you paste or share an export into another application — an AI assistant, an email, a cloud drive — that copy is governed by that service's policies, not by this one, and it is outside our reach entirely. Nothing we do can protect a copy you have handed to someone else. That is the trade for being able to take your data anywhere you want it.
The check-in message
A few days in, the app may show a short check-in card. It asks whether you expect to still be logging in two weeks, whether you would recommend the app, and — if you would not — what is missing, in a box you type into yourself.
If you choose to answer, the app opens your own messaging app with the message already written, addressed to a Barca Labs phone number. It contains your answers and whatever you typed, exactly as you wrote it.
The app cannot send it. You send it, from your own number, after reading it. If you do send it, we receive your phone number along with the message — that is simply how text messages work, and it is the one thing in this entire app that could identify you to us. If you would rather we did not have it, dismiss the card, or delete the message instead of sending.
Because you write that free-text part yourself, please do not put anything in it you would not put in an ordinary text message. It travels as a normal SMS and it is not protected the way your vault is.
Diagnostics and analytics
As of 30 August 2026, Sovereign Vault contains no analytics software, no advertising software, no crash reporting service, and no third-party tracking of any kind. Beyond the connections described above, the app makes no network requests. If that ever changes, this section changes with it and the effective date above moves.
Your device's operating system and the app store you installed from may collect their own diagnostic information, independently of the app. That collection is controlled by Apple's and Google's settings and policies, and by the choices you have made in your device settings.
Deleting your data
The app includes an erase function that removes your records from the device. Uninstalling the app also removes its database.
Because we never hold a copy, there is nothing for you to ask us to delete, and no request process to go through. When it is gone from your phone, it is gone.
Your rights
Privacy law generally gives you rights to access, correct, export or delete the personal information a company holds about you. We hold none — no account, no profile, no copy of your records — so there is nothing for us to disclose or erase.
The third parties described above hold whatever they hold under their own policies. To exercise rights against Expo or Polar, contact them directly using the links in those sections.
If you believe we hold information about you and wish to exercise a right in relation to it, write to [email protected] and we will respond.
Children
Sovereign Vault is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children, which in this case follows from not collecting personal information from anyone.
Not medical software
Sovereign Vault records information you choose to record. It is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. Nothing in the app is medical advice, and no output of the app should be read as a clinical finding.
Decisions about your health belong between you and a qualified clinician.
This website
This website is a set of static pages. It sets no cookies, runs no analytics, embeds no third-party scripts, and loads no external fonts or trackers. Our hosting provider processes standard server request data, including IP address, in order to deliver the page to you.
Changes to this policy
If this policy changes, the effective date at the top of this page changes with it. If a change ever affected how your data is handled in a way that mattered, it would be announced in the app rather than quietly posted here.
If a future version of the app adds a connection not listed above, or begins collecting information we do not collect today, we will describe it here before it takes effect.
Contact
Barca Labs, LLC
Kansas, United States
[email protected]