myna — Privacy Policy
Last updated: 28 August 2026 · Effective: 28 August 2026
myna is a family-coordination appliance built by Herbert Chan (Singapore). This policy explains what we collect, why, how it's used, and your rights. We follow Singapore's Personal Data Protection Act (PDPA) and apply the same standard everywhere myna ships.
Who we are
- Operator: Herbert Chan (sole developer, Singapore).
- Contact: [email protected]
- App package:
com.herbertchan.familyhub(Android),com.herbertchan.familyhub(iOS).
What we collect
| Category | Examples | Why |
|---|---|---|
| Account & profile | Name, role (parent/kid/helper/relative), avatar, gender, language, household name, optional email, optional birthday, optional Apple/Google Sign-In ID | To let family members address each other correctly and personalise Aunty's voice narration. |
| Messages & tasks | Text, voice notes, photos, video notes, calendar events, task titles, completion state | The core messaging and household-coordination features. |
| Voice transcripts | Speech-to-text transcripts of voice messages and voice announcements | So Aunty can narrate the contents aloud and translate across languages. |
| Location | Precise device coordinates from members who have location sharing switched on — including in the background, and a short recent trail of past points. On iOS we use Apple's location-push mechanism so a position can be refreshed while the app is closed. We also derive an approximate city from your IP address to show local weather. | The family map ("where is Laura now?"), arrival and departure alerts for places you define, and weather. Off by default; each member can turn it off at any time in their device settings. |
| Documents & household knowledge | Anything you or Aunty file into your household's records: scanned or photographed documents and the details read out of them. Depending on what you choose to store, this can include health information (allergies, diagnoses, doctors, immunisations), financial information (bank and insurance details), government identifier numbers (NRIC, passport, licence), and — where it appears on a Singapore NRIC — race. Also home address, emergency contacts and phone numbers. | So the household has one reliable place for the paperwork it actually needs, and so Aunty can answer questions about it. Identifier numbers and other secrets are encrypted at rest (AES-256-GCM). You choose what to file; none of it is required to use myna. |
| Camera & microphone | Live camera and microphone audio during calls; image captures for avatars and message photos | Voice/video calls and message attachments. We never record calls server-side. |
| Calendar (iOS) | Read access to selected iCloud calendars; optional write access to a chosen calendar | Two-way sync between myna and your iPhone calendar. Disabled by default. |
| Push tokens | Firebase Cloud Messaging tokens; APNs VoIP tokens (iOS) | To deliver call rings, message banners, and Aunty audio to your devices. |
| Crash & error reports | App version, device model, the error itself and a short trail of the actions leading up to it — which can include the web addresses myna called, and those contain your household and account identifiers. Collected automatically whenever the app hits an error, not only when you ask. | So crashes get found and fixed. Sent to Sentry. It is not used for advertising or profiling, and we do not use it to track you. |
| Feature-usage records | Which member triggered which AI feature and when, and a record of who called whom | To keep the service running within its cost limits and to size features. Never sold, never used for ads. |
| Subscription state | Whether the household has an active subscription, billing status from Apple/Google | To gate paid features. We do not store credit-card data — Apple and Google handle payments. |
What we do NOT collect
- We don't sell or share data with advertisers.
- We don't track you across third-party apps or websites.
- We don't record voice or video calls server-side.
- We don't read your contacts or other apps' data.
- We don't fingerprint your device for marketing.
Third-party services we rely on
myna uses these processors strictly to deliver its features. Each is bound by their own privacy terms; we share data with them only as needed to operate the app.
- Firebase (Google) — authentication and Cloud Messaging push delivery.
- Agora.io: real-time voice and video for in-app calls. The media passes through Agora's network and is never recorded, by them or by us.
- ElevenLabs: speech-to-text for voice notes and voice announcements.
- Google Cloud Speech-to-Text: a fallback transcriber when the above is unavailable.
- Google Vertex AI / Gemini: reading documents and photos, Aunty's voice narration, and translation.
- Fireworks AI (serving DeepSeek models) and MiniMax: Aunty's reasoning and writing.
- Google Maps Geocoding: turning a typed address into coordinates for the family map.
- Open-Meteo and ipwho.is: local weather, and the approximate city it is shown for.
- Sentry: automatic crash and error reporting.
- Expo: delivering app updates.
- Apple Sign in with Apple & Google Sign-In: optional parent identity bootstrapping.
- RevenueCat with Apple and Google: subscription receipt validation. They receive a household identifier and the receipt, never your name or email.
- Cloudflare: TLS termination and DDoS protection.
We do not use any advertising, attribution or ad-network service. myna contains no advertising identifier and no ad SDK of any kind.
Google Calendar & Google API Services — Limited Use
When a parent chooses to connect their Google Calendar, myna requests the https://www.googleapis.com/auth/calendar scope to provide two-way sync between the household calendar and the parent's Google Calendar. This connection is optional, off by default, and can be disconnected at any time in myna's settings — which immediately revokes our access and stops all sync.
myna's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data accessed through Google Calendar is:
- used only to provide and improve the calendar-sync feature the parent turned on, prominently within the app;
- never sold, and never transferred to others except to provide that feature, to comply with applicable law, or in connection with a merger or acquisition (with notice to affected users);
- never used for advertising of any kind; and
- never read by humans, unless we have your explicit consent for specific items, it is necessary for security or to comply with the law, or the data has been aggregated and anonymized for internal operations.
How long we keep data
- Messages, announcements, calendar events: household-configurable retention (default 90 days). Auto-purged after retention window.
- Voice notes & their transcripts: same retention window as messages.
- Account & household profiles: kept while the household exists. Deleted when the owning parent removes the household.
- Location trail: a rolling recent window only — older points are purged automatically after 14 days, and we keep just the last 200 points per device.
- Filed documents & household records: kept until you delete them, or until the household is deleted.
- Crash & error reports: retained by Sentry under their standard retention (about 90 days).
- Diagnostic logs: 30 days.
- Subscription state: kept for tax + audit reasons (typically 7 years per Singapore law).
Children's data
myna serves households that include children. We collect only the minimum needed for the app to function: display name, optional avatar, a parent-administered task list, and — where a parent has switched it on for that child's device — precise location, including in the background, which is the point of the family map. On Android, a parent may also see which apps are installed on a child's phone and how long they are used, in order to set time limits; on iOS this is handled by Apple's own Screen Time system and those details never reach us. Children's accounts are administered by parents through the in-app Family settings. We do not show ads, do not enable behavioural profiling, and children cannot interact with anyone outside their own household.
Your rights
You can:
- See or export your household's data — email [email protected] from your registered account.
- Delete the household and all associated data — same channel.
- Withdraw permissions (location, microphone, camera, calendar) any time via your device's Settings → Apps → myna → Permissions.
- Lodge a PDPA complaint with Singapore's Personal Data Protection Commission.
Security
- All network traffic uses TLS 1.2 or above (HTTPS).
- Push notification audio is signed with a short-TTL HMAC URL — only your device can fetch it.
- The myna server runs on a dedicated virtual server hosted in Singapore, behind Cloudflare.
- Identifier numbers and other secrets in your household records are encrypted at rest with AES-256-GCM.
- Database is local-disk SQLite, backed up daily.
Changes to this policy
We'll update this page when we add or change data practices, and bump the "Last updated" date at the top. Material changes will be surfaced in-app the next time you open myna.
Contact
Questions, requests, complaints — email [email protected]. We aim to respond within 7 business days.