Privacy & security

Your devices, storage you choose, and bounded security claims

The local encrypted Family Vault is authoritative. Private Vault records are encrypted on authorized devices and may be written as opaque encrypted objects to storage you explicitly choose.

Local protection

User-controlled encrypted continuity

Roles and decryption authority

The backend is not a universal Family Vault repository or decryptor. Master Admin is not Family Owner. Admin, support, Partner, and payment-provider roles have no universal decryption key and must not receive private Vault content through their control-plane workflows.

Sharing and revocation

Family membership alone does not grant access to a private item. Access requires explicit policy and cryptographic authorization. Revocation protects future authorized access after the implemented rotation boundary but cannot recall information already viewed, copied, or exported.

Honest limits

A compromised or rooted device, weak device credentials, deliberate readable export, lost recovery material, provider loss, or user error can affect confidentiality or recovery. Security, recovery, availability, and deletion depend on the exact device, provider, release, and authorization state.

Report a security concern to support-yourstogether@creatorgraphai.in. Read the Privacy Policy.