DISASTERVAULT DisasterVault.appTM PRIVACY POLICY DisasterVault.app LLC — A Florida Limited Liability Company Effective Date: May 13, 2026 — Last Updated: June 6, 2026 Version 2 — Updated to align with Terms of Service Ver2 June 2026

  1. Introduction and Entity Identification Welcome to DisasterVault, a Disaster Documentation Intelligence (DDI) platform operated by DisasterVault.app LLC (“DisasterVault,” “we,” “our,” or “us”). DisasterVault.app LLC is a limited liability company duly organized and existing under the laws of the State of Florida. This Privacy Policy applies to the DisasterVault mobile application (“App”) and all associated services available at disastervault.app. IMPORTANT: DisasterVault.app LLC is the legal operating entity. No member, manager, officer, or employee of DisasterVault.app LLC shall have personal liability for any obligations of the company arising under this Privacy Policy or otherwise. All rights and obligations described herein are those of the LLC as a legal entity. By downloading, installing, or using the App, you acknowledge you have read and agree to this Privacy Policy. If you do not agree, do not use the App. This Privacy Policy is incorporated by reference into the DisasterVault.app Terms of Service Ver2 June 2026. Capitalized terms not defined herein have the meanings given in the Terms of Service. Contact: [email protected] | disastervault.app
  2. Information We Collect 2.1 Account Information When you create a DisasterVault.app LLC account (via email, Apple Sign In, or Google Sign In), we collect: • Full name — used to personalize your experience throughout the app • Email address — used to identify your account, send important notifications, and allow account recovery • Profile photo — optionally synced from your sign-in provider (Apple/Google) or uploaded by you We use Clerk as our authentication provider. Clerk securely handles the sign-in process and stores your credentials. We do not store your password. You can review Clerk’s privacy practices at clerk.com/privacy.

2.2 Home Address Account creation occurs after payment is confirmed through Apple IAP. We do not create accounts before purchase. This is consistent with our hard paywall model described in the Terms of Service.

© 2026 DisasterVault.app LLC | [email protected] | disastervault.app/privacy Ver2 June 2026

DISASTERVAULT Privacy Policy | Ver2 June 2026 We ask for your primary home address in your profile for the following purposes: • Disaster alert monitoring — your address is geocoded to latitude and longitude coordinates so we can monitor official government weather and disaster alert feeds (NOAA/NWS) for your specific geographic area. • Property association — your address helps us associate your home inventory with the correct property location, so your documentation is organized and ready when you need it. 2.3 Property and Room Information When you add properties and rooms to your vault, we store: • Property name and address • Room names within each property • Cover photos you upload for properties This information exists solely to organize your home inventory so you can thoroughly document your belongings and build a clear record of your property — which you can then share with your insurance company in whatever format they require. 2.4 Home Inventory Items When you scan a room or manually add items, we store: • Item name and category • Estimated replacement value (in USD) • A reference to the source photo used for the scan This data forms your home inventory and is used to calculate a total estimated property value and help you build organized claim evidence. Important limitations homeowners should understand: • Estimates only — AI-generated replacement values are estimates only. DisasterVault makes no guarantee as to the accuracy, completeness, or acceptability of any value generated by the App. You are responsible for reviewing, editing, and confirming all item values before relying on them for any purpose. • You control the values — You can and should edit item values within the App to reflect your own knowledge, receipts, or appraisals. You may also store copies of receipts, invoices, and supporting documents directly in the App to supplement AI-generated estimates. • You are responsible for submission — The documentation DisasterVault produces is intended to support — not replace — the claims process your insurance company directs. You are solely responsible for the accuracy of any information submitted to your insurance provider. Your insurer determines the format, requirements, and final determination for any claim submission. 2.5 Photos and Images DisasterVault.app LLC uses your camera and photo library in the following specific ways: • Room scan photos: When you photograph a room for inventory scanning, the image is uploaded to our secure cloud storage (Convex/Cloudflare), then sent to Google Gemini AI for analysis. After analysis, identified items are saved to your inventory. The original photo is retained in your vault as a visual record. • Property cover photos: You may optionally upload a cover photo for each property. Stored in our cloud and displayed only within your account. • Invoice and document photos: You may photograph insurance policies, invoices, or receipts to store in your vault. These are stored securely and accessible only to you. • Profile photos: Your profile photo is stored and displayed only within the app.

© 2026 DisasterVault.app LLC | [email protected] | disastervault.app/privacy Ver2 June 2026

DISASTERVAULT Privacy Policy | Ver2 June 2026 2.6 Family Members and Emergency Contacts You may optionally add: • Family members — name, age, relationship • Emergency contacts — name, phone number, relationship This information is stored securely and used only within the app to help you maintain a complete household safety profile. We do not contact your family members or emergency contacts, and we do not share this information with any third party. 2.7 Location Data We request access to your device location for one purpose only: to pass your geographic coordinates to the National Oceanic and Atmospheric Administration (NOAA) National Weather Service API — a free, publicly available U.S. government service. When NOAA issues an official alert for your area, that alert is forwarded to you as a push notification through the App. Important: DisasterVault is not a weather service. DisasterVault does not independently monitor weather conditions, does not employ meteorologists or weather experts, and makes no guarantee that any alert will be delivered accurately, completely, or in time. Alert delivery depends entirely on NOAA’s systems, your device connectivity, and push notification availability. For any life-safety emergency, always rely on official sources including your local emergency management authority and NOAA directly at weather.gov.

Your location coordinates are stored in our database solely to enable the NOAA API lookup. This is a one- time or on-demand lookup — we do not continuously track your location in the background. You can disable

alerts at any time in app settings, which stops all location-based API calls. 2.8 Push Notification Token When you enable push notifications, we store your device’s push notification token. This token is used exclusively to send you disaster alerts and app notifications. We do not use it for marketing messages. Push notifications are delivered via Expo Push Notification infrastructure. 2.9 Onboarding Preferences During onboarding, we ask about your home ownership status, home type, disaster concerns, and prior insurance claim experience. These answers personalize your dashboard and tailor coaching content. They are never shared externally. 2.10 Subscription and Payment Information DisasterVault.app LLC offers Claim-Ready Protection at $59.99/year. Payments are processed entirely through Apple’s App Store. We never see, store, or handle your credit card or payment information directly. We receive only a transaction receipt token from Apple confirming your purchase. We use RevenueCat to manage subscription status. RevenueCat receives your App Store receipt to verify your subscription. Review RevenueCat’s privacy practices at revenuecat.com/privacy. 2.11 Crash Reporting and Analytics

© 2026 DisasterVault.app LLC | [email protected] | disastervault.app/privacy Ver2 June 2026

DISASTERVAULT Privacy Policy | Ver2 June 2026 We use Sentry to collect crash reports and error logs. Sentry may collect device type and OS version, app version, stack traces at the time of a crash, and session replay data (limited, at 10% sample rate). Sentry does not receive your home inventory, photos, or personal documents. Review Sentry’s privacy practices at sentry.io/privacy.

  1. How We Store Your Data Your data is stored on Convex (our backend infrastructure provider), which stores data in secure cloud environments with industry-standard encryption at rest and in transit. Photos and documents are stored in Convex’s file storage, backed by Cloudflare R2. We retain your data for as long as your account is active. Upon account deletion, all personal data, inventory items, photos, and documents will be removed from active systems within 30 days. We will confirm completion of active system deletion to you via email within 30 days of a verified request. Residual copies in encrypted backup systems will be purged within 90 days. These timeframes do not apply to data we are required to retain by applicable law or for fraud prevention purposes. This deletion policy is consistent with the Account Termination provisions in the Terms of Service.
  2. How We Share Your Data We do not sell your personal information. We do not share data with advertisers. We will not sell, license, or otherwise provide your personal information, User Content, or property inventory data to insurance companies, data brokers, or financial institutions without your separate, explicit written consent. Our business model is based solely on annual Claim-Ready Protection fees, not data monetization. We share data only with the service providers necessary to operate the app: Service Provider Purpose Privacy Policy Clerk Authentication and account management clerk.com/privacy Convex Backend database and file storage convex.dev/privacy Cloudflare R2 File/photo storage CDN cloudflare.com/privacypolicy Google Gemini AI-powered room scanning (photos sent for

analysis)

policies.google.com/privacy RevenueCat Subscription status management revenuecat.com/privacy Sentry Crash reporting and error logging sentry.io/privacy Expo Push notification delivery expo.dev/privacy Apple App distribution, IAP, and payment

processing

apple.com/privacy

NOAA / NWS Government disaster alert data (read-only,

no data sent)