Complete public copy

Privacy Policy

Veyo Quiet Grounds is designed as an offline fieldbook. This policy describes the audited version 1.0 behavior—not a future service or an unrelated website.

Effective and last reviewed: July 29, 2026

Plain-language summary. The app has no account, advertising, analytics, tracking, cloud sync, or Internet permission. Optional checks, selections, intention, and reflection stay in private storage on the device and can be erased in the app, through Android storage controls, or by uninstalling.

01. Responsible entity and scope

VEYO CEMETERY is the responsible publisher for Veyo Quiet Grounds, package org.veyocemetery.quietgrounds. The registered organization address is 177 E Center St, Veyo, Utah 84782-4040. This policy applies only to the Android application and its local features. The address is an organization registry address and is not presented as visitor directions or a confirmed cemetery entrance.

02. Information stored locally

If a user chooses to interact with the app, it can store eight visit-preparation check states, six research-method check states, one selected story prompt, a short visit intention of up to 80 characters, and one reflection of up to 600 characters. The app also stores simple interface state needed to restore these choices. This information remains in Android app-private SharedPreferences on the device.

The app does not require real names. Users are repeatedly asked not to enter sensitive details such as a living person’s identity, exact travel plans, medical information, account credentials, private family conflict, burial-plot data, or material they do not have permission to record.

03. Purposes and user choices

Local information is used only to show personal progress, restore the chosen prompt, and return the user’s intention and reflection on the same device. Every entry is optional. The app works as a read-only guide when no local information is saved. No automated decision, eligibility determination, risk score, ranking, profile, recommendation about a person, or public record is produced.

04. Information the app does not collect

The audited release does not request or collect a name, email address, telephone number, birth date, government identifier, account credential, contact list, photo, audio, video, precise or approximate location, route, device identifier, advertising identifier, health information, payment information, school record, funeral record, burial record, plot ownership record, or usage analytics. It does not scan a marker, recognize a face, upload a journal, or query a cemetery database.

05. Permissions, SDKs, advertising, and analytics

The app requests no dangerous runtime permission and no Internet permission. It uses Android platform components and official AndroidX/Jetpack libraries for compatibility, lifecycle handling, interface rendering, controls, icons, and private local state. It contains no advertising, analytics, attribution, tracking, social, payment, authentication, crash-reporting, cloud-database, mapping, camera, microphone, location, or health-data SDK. It does not access the Android advertising ID.

06. Sharing, sale, and disclosure

Because the publisher does not receive the optional local content, it does not sell, rent, share, disclose, or use that content for advertising. The organization has no server copy to search, correct, export, or delete. If a device owner voluntarily shows the screen to another person, uses operating-system backup tools outside the app’s supported configuration, or records a screenshot, that action is controlled by the device owner rather than the app.

07. Network and external services

The application has no Internet permission, web view, live map, external website button, email action, phone action, upload control, or cloud synchronization. It does not open this support website from inside the audited release. The public app-support website is technically separate and has its own server logs and hosting behavior; visiting it in a browser is not required to use the application.

08. Children and family use

The app is written for adults, family historians, and families visiting together; it is not designed as a child-directed social service. It has no messaging, public profile, child-adult matching, location sharing, advertising, or in-app purchase. A parent, guardian, or trusted adult should guide a young person’s visit and decide what family information is appropriate to write. Users should never enter a child’s precise schedule, route, school information, health details, or identifying record.

09. Cemetery, heritage, and safety limits

Veyo Quiet Grounds is informational. It is not an official burial register, ownership record, lot-availability system, visitor map, access authorization, decoration policy, funeral provider, emergency service, preservation assessment, or permission to touch or clean a marker. A completed checklist is not approval. Current directions from the responsible operator, property owner, family, public authority, conservator, and emergency service take priority.

The app advises observation before intervention. Users should not move objects, enter closed areas, publish private details, clean a marker, make a rubbing, use chemicals, or perform repairs without appropriate authorization and qualified guidance.

10. Retention

Optional content remains on the device until the user changes it, uses the in-app clear command, clears the app’s storage in Android settings, or uninstalls the application. There is no publisher-controlled retention period because the publisher does not receive a copy.

11. Deletion, access, correction, and no-account status

No account is created, so account deletion is not applicable. Users can view and edit the intention and reflection directly in the app. The clear command removes all saved checks, the selected prompt, intention, and reflection after confirmation. Android app-storage controls or uninstalling provide additional device-level deletion. The publisher cannot recover deleted content or fulfill a server export because no server copy exists.

12. Security, backup, and device access

Local content is protected by Android’s application sandbox and is not intentionally transmitted. The manifest disables Android backup, and the backup/data-extraction rules exclude app files, databases, and SharedPreferences from cloud backup and device transfer. No local-only design can prevent a person who controls an unlocked, compromised, rooted, or shared device from viewing its screen or storage. Use a device lock and avoid sensitive entries.

13. Changes and user choices

A future version that adds a network feature, permission, account, external action, SDK, advertising, or different data practice must update the implementation, this policy, the in-app copy, the Play Data safety declaration, and the store listing before release. The effective date will change when a material revision is published. Users can decline all optional storage and still read every guide.

14. Contact and corrections

Privacy or factual-correction correspondence may be sent to: VEYO CEMETERY, 177 E Center St, Veyo, UT 84782-4040, United States. Users may also use the developer contact shown on the official Google Play listing when available. Do not send private family records, identity documents, health information, payment details, account credentials, or original archival materials. This contact route is for the application and its published privacy/source statements; it is not a burial, plot, funeral, visitor-access, or emergency service.