Skip to main content
Tiny Beacon

Privacy

What TinyBeacon collects, and what you control.

This page contains the legal detail. The short version: every data-collecting scope starts off, the parent or legal guardian chooses what to enable, your child can see what is shared, and the parent or legal guardian can withdraw or delete data through the available controls.

Version 1.1.0  ·  Effective date: 25 June 2026  ·  Last updated: 29 August 2026

Amir Ariff bin Abdul Hadi

Operator and data controller of the Tiny Beacon app

7, Jalan Cassia U17/82, Elmina West, 40160 Shah Alam, Selangor, Malaysia

Telephone: 013-9844412 · Email: [email protected]

Tiny Beacon is a family-safety app for parents and legal guardians. This policy tells you what the public app receives, what it does not receive, and what changes when you choose a safeguard. Each data-collecting scope starts off; emergency help remains available. Your child can see the shared categories, and the parent or legal guardian can turn off any safeguard anytime.

Tiny Beacon accounts are created and operated by an adult parent or guardian. We do not knowingly collect personal information directly from a child: any information about a child is entered and managed by the parent, with their consent, as described in section 5.

1. What we collect

Here is the map before the detail: the public app receives only the family, location, app-use, alert, consent, and device information described below, and some categories depend on the phone and build. Each entry explains why the category exists, who can see it, and how you can change the choice.

1.1 Parent account & identity

  • Parent name and email address (account creation and sign-in)
  • Account and user identifiers
  • Parent date of birth (used once as an adult age-gate, to confirm the account holder is an adult)
  • Sign-in identity from Apple or Google (OAuth), only when you choose that sign-in method
  • Optional profile photo (parent and child), only if you add one
  • Your device’s encryption public key and an optional device label, so paired devices can exchange data securely
  • Push / notification tokens (to deliver alerts to your own devices)

1.2 Child profile (parent-provided)

Entered and managed by the parent in the parent dashboard — never collected from the child directly:

  • Child’s first and last name
  • Child’s date of birth

1.3 Location and safe zones

Location sharing is a family choice, not a hidden setting. While it is on, the child’s device shares location with the linked parent or family account and shows a persistent notice; turning it off stops new location collection. Location sharing starts off. While it is active, the child’s device shows that the choice is on. A parent or legal guardian can withdraw the safeguard, and the privacy controls explain what happens to retained data. This safeguard is available on every build.

  • Location is shared continuously while sharing is on, including in the background and when the app is closed, so safe-zone alerts and emergency context keep working.
  • Sharing is off by defaultand turns on only with explicit parental consent. While it is active, the child’s device shows a persistent on-device notification, so it is always clear that location is being shared.
  • Location is used onlyfor family-safety features — live location, safe-zone (geofence) alerts, and emergency context. It is never used for advertising or cross-app profiling, and we never sell it or share it with third parties; our backend providers (Supabase, PostHog, Sentry, Expo) act only as processors on our behalf.
  • A parent or legal guardian can turn sharing off or delete location data at any time. Withdrawing consent stops collection immediately.

1.4 App time and screen-time limits

Screen-time controls use the phone’s own tools. On Android, app-use details are an optional, consent-gated category; on iPhone, cross-app app-use details are not collected. The bullets below name the fields and the retention window.

App-use details are collected only after the parent or legal guardian enables that scope. The retention window is 7-180 days (default 30), and withdrawal behaviour is shown with the choice. If you set screen-time limits, the app uses the device’s built-in Screen Time / Family Controls to enforce them. The limit and shield events needed to do this are processed on the device. On Android, only after a parent or legal guardian gives explicit consent and Android Usage Access (PACKAGE_USAGE_STATS) is enabled, the app collects app-use awareness— the package and app name, category, how long each app was open, screen opens, and daily totals — via the device’s Android Usage Access, since 2026-07-28. This gives you screen-time insights and lets you set and enforce per-app limits. It is collected only with explicit parental consent, is retained for the family’s 7-180 days (default 30) retention window, and is deleted when the parent or legal guardian withdraws consent. iPhone does not collect cross-app app usage; on iOS, screen-time limits rely on Apple’s built-in Screen Time / Family Controls only.

1.5 Pairing & consent records

  • A hash of the device-pairing code (we store the hash, not the code itself)
  • Parental-consent records (what you consented to, and when) — a record of the family’s choice
  • Your retention settings

1.6 Diagnostics and analytics

  • Product analytics is limited to improving the app, and it is separate from family safety records. It contains unlinked product-interaction events and app/build context, no child-entered content, and no advertising use. You can change the analytics choice in Privacy & data controls. Product analytics via PostHog is anonymous and unlinked: events are not linked to an account, parent, or child identity. Automatic lifecycle events are off, session replay is not used, and these events are not used for advertising or cross-app profiling.
  • Crash and performance diagnostics via Sentry — with personal identifiers minimised and parent context truncated before transmission

1.7 Device wellbeing status

After a parent or legal guardian gives consent and enables this safeguard, the app shares a coarse battery band, whether the device is charging, a connection bucket (Wi-Fi, mobile data, offline, or other), and a server-recorded last-seen time. It does not share a raw battery percentage, IMEI, SSID, carrier, or a device-history stream. The latest status is kept as a current device-status row, not a historical series.

A persistent offline connection alert retains last_seen_at, the server-recorded last-seen time. When the device checks in again, that alert can be marked resolved while retaining last_seen_at and resolution status. Offline and resolved alert records are kept within the selected rolling retention window of 7-180 days (default 30). The rolling window trims data; it does not expire consent. Consent ends only when a parent or legal guardian explicitly withdraws it.

2. What we do not collect

The quickest reassurance is what the public build does not receive: no screenshots or screen content, no cross-app app-use details on iPhone, no SMS or chat content, no call logs, and no web or search history. Android app-use details are described in section 1.4; separate supervised-edition details appear in section 9.

  • Screenshots or any screen content in the public store app (supervised editions may add this — see section 9)
  • Cross-app app-use data on iPhone (Android collects per-app usage only after a parent or legal guardian gives consent and enables Android Usage Access — see section 1.4)
  • SMS, chat, or message content (supervised editions may retain a short redacted WhatsApp notification excerpt — see section 9)
  • Call logs
  • Web browsing or search history
  • Advertising identifiers (IDFA / AAID), and no cross-app profiling
  • Contact lists
  • Biometric data
  • Audio or video recordings

3. How we use it

  • We use each category only to deliver the family choice connected to it: account access, paired devices, location and safe-zone alerts, emergency help, screen-time tools, notices, and app improvement. We do not sell family data or use children’s information for advertising. Account access creates accounts, signs users in, and pairs devices.
  • Core service:to let a parent set up and manage a child’s profile and the family’s paired devices
  • Safety features: to share live location within your family, send safe-zone arrival and exit alerts, provide emergency context, send emergency and amber alerts, and enforce any screen-time limits you set
  • Alerts:to deliver notifications to the parent’s own devices
  • App improvement: unlinked product analytics and crash diagnostics to keep the app working and improve it

We do not sell or rent personal information, we do not share it with advertisers or data brokers, and we do notuse children’s personal information for behavioural advertising or to build advertising profiles.

4. Encryption and security

  • Security is part of the everyday experience: data moves over TLS 1.2+ and is encrypted at rest with AES-256. The details below explain access boundaries, keys, and family separation. All data is encrypted in transit using TLS 1.2 or higher.
  • Personal data is encrypted at rest with AES-256
  • Device encryption keys are generated on the device and held in the device secure enclave (e.g. iOS Keychain); the private key never leaves the device, and keys are wiped on sign-out
  • Row Level Security (RLS) on every database table — a parent can access only their own family’s data
  • Role-based access separates parent and child accounts

5. Children’s privacy & parental consent

A parent or legal guardian creates the child profile and chooses each safeguard. Each data-collecting safeguard starts off, the child can see the shared categories, and the parent or legal guardian can review or withdraw a choice anytime. A child can raise a concern or ask a grown-up for help; the parent or legal guardian controls consent and any location-sharing pause.

  • Parental consent before collection.Information about a child is only ever added by the account holder — an adult who confirms they are over 18 through our date-of-birth age-gate and who controls the account. Consent is captured in the app before any child information is collected, and we keep a record of what was consented to and when.
  • Parental review and deletion.A parent or legal guardian can review the information held about their child, delete it, and refuse to permit its further collection or use — at any time, from the app’s settings.
  • Data minimisation.We collect only what is reasonably necessary for the service, and we do not condition a child’s participation on disclosing more than is reasonably necessary.
  • No targeted advertising to children.We do not use children’s personal information for behavioural advertising.
  • Limited retention. The parent or legal guardian chooses the 7-180 days (default 30) retention window for each child. Threat-flagged captures in supervised editions are kept only while needed and deleted automatically when they expire (see section 7).

If you believe a child has provided us personal information without parental consent, contact us at [email protected] and we will delete it.

6. Your rights under Malaysia’s PDPA 2010

You can review, correct, export, or delete your account and family information. You can also withdraw a safeguard from the app; the next section explains what stops and what is removed.

  • Review the data held in your account via the parent dashboard
  • Correct account and child profile details at any time
  • Withdraw consent and stop further processing
  • Delete your data or your entire account, which permanently removes all associated data
  • Request a data export by emailing [email protected]

7. Data retention & deletion

The parent or legal guardian chooses the rolling retention window for each child: 7-180 days (default 30). Turning off a safeguard stops new collection and removes its related data as described below; emergency records have the specific exception stated here. The rolling window trims older data; it does not expire consent. Consent ends only when a parent or legal guardian explicitly withdraws it.

  • In the app:open Settings → Privacy & data controls and choose “Request Account/Data Deletion”. This permanently removes all parent and child data associated with the account from our systems.
  • Without the app (web): email [email protected] from your account email address and ask us to delete your account. We verify the request and delete the data within 30 days.
  • Withdrawal of consent:withdrawing consent stops further collection immediately. Turning off a single safeguard deletes the data collected by that safeguard; turning off every data-collecting safeguard deletes all of that child’s data from those safeguards. Records of emergency alerts and safe-word triggers are kept when you turn off an individual safeguard, so a past safety event is not erased by a later settings change, and are removed with everything else on a full withdrawal or account deletion.
  • Per-child retention: parents choose the 7-180 days (default 30) retention window for each child. Some supervised-edition data is kept for shorter fixed periods regardless of that setting (see section 9). Scheduled cleanup removes data when its retention period ends.
  • Device wellbeing alerts: offline and resolved connection alerts retainlast_seen_at, the server-recorded last-seen time, and status within the selected 7-180 days (default 30) rolling window. The latest device status is a current row, not a historical series.

8. Third-party services

Supabase — backend, database & authentication
These providers help deliver sign-in, storage, notifications, product analytics, diagnostics, and the website. Each entry identifies the service's role and the kind of information it receives. Stores account and profile data and auth tokens. RLS policies, data isolation, encrypted at rest.
Apple & Google — sign in with Apple / Google (optional)
If you choose social sign-in, we receive a basic identity token. Only when you select that sign-in method.
PostHog — product analytics
Anonymous, unlinked product analytics. Events are not linked to an account, parent, or child identity. Automatic lifecycle events are off and session replay is not used; PostHog receives limited product-interaction and app/build context without a family account link. TinyBeacon does not send child-entered content to this service and does not use these events for advertising or cross-app profiling. You can change the analytics choice in Privacy & data controls.
Sentry — crash & error diagnostics
Crash reports with personal identifiers minimised. Parent context truncated before transmission.
Expo — push notifications & app delivery
Push tokens and device identifiers. Parent-facing notifications only.
Plausible — website analytics (tiny-beacon.com)
Aggregate page views — no cookies, no personal data. Privacy-first; nothing that identifies a visitor.
Cloudflare — website DNS, CDN & security
Processes IP address and request metadata for tiny-beacon.com. Website traffic only; no app data.

9. Supervised and enterprise editions

The public store app is the baseline for sections 1–8. Separate supervised editions may add narrowly scoped safety capabilities only after the family chooses those scopes; the following paragraphs name the device, consent, visibility, and retention limits for each one. Everything above describes the public Tiny Beacon app on the App Store and Google Play. Separate supervised and enterprise editions— including the supervised direct-install Android edition made available from the Tiny Beacon website to parents and legal guardians, while enterprise editions remain available under a distinct written agreement — may additionally collect on-device screen content, detailed app-usage, and web-filtering data for managed-device scenarios. The public app collects only the data described in sections 1–8. Across the service, parents choose the 7-180 days (default 30) retention window for each child. In supervised editions, threat-flagged captures are kept only while needed and deleted automatically when they expire.

In supervised Android editions that include text and call check-ins, the first time the feature runs after a parent or guardian turns it on may include up to the previous seven days of texts and calls already stored on the child’s device, so recent context is not lost at setup. Nothing older than seven days is read, and if the feature is turned off and later turned on again, the seven-day window starts fresh rather than covering the period while it was off.

In supervised Android editions only, we offer an optional WhatsApp notification-excerpt safety feature. It is disabled by default and turns on only after both explicit parent or guardian consent and child-side setup granting notification access. Eligible WhatsApp notifications are evaluated on the child’s phone for narrowly defined high-risk patterns. When something may need care, we send the parent a category and a short redacted excerpt of no more than 64 characters. Whatever retention period is chosen for the child, these excerpts are kept for a maximum of 30 days and within the 7-180 days (default 30) retention window. We never store, upload, or make full conversations browsable. Because the feature depends on available notifications, it may miss content when notifications are muted or disabled, or when content is deleted, disappearing, or media-only.

9.1 Supervised direct-install edition (Android, separate consent)

In the supervised direct-install Android edition, each added category starts off and needs its own parent or guardian choice. Supervised-plus Android messages and call check-ins also require child-side setup; turning a choice off stops new collection and removes associated data as described here. The edition is installed directly from the Tiny Beacon website, not from the public app stores.

  • SMS / MMS text:message content and sender/recipient numbers, reviewed for safety keywords and risk patterns, for the parent’s safety review.
  • Call metadata: call direction, timestamps, duration, frequency, and unknown-number flags. Call audio is never recorded or accessed.
  • Screenshots:periodic device screen captures assessed for high-risk content (self-harm, grooming, adult content). Only frames assessed medium-or-higher are stored, encrypted for the parent’s devices.
  • App use: app/package names, categories, durations, screen opens, and daily totals, for usage summaries and limit enforcement.

These categories are not used for advertising or to build advertising profiles. On iOS, none of these capabilities exist — Apple does not permit third-party apps to access them; iOS supervised safety relies on Apple’s Family Controls / Screen Time only.

Pre-activation semantic analysis.The supervised edition may, in future, perform server-side semantic review of flagged conversation excerpts via Google Gemini to help assess risk. This is a separate consent scope, is currently disabled and fail-closed — no analysis runs unless it is explicitly enabled — and is disclosed here ahead of any enablement.

10. Data storage location

Storage has a clear boundary: family data is kept on Supabase-managed infrastructure, encrypted in transit and at rest, with access-controlled backups. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

11. Changes to this policy

If we materially change how a child's data is handled, we will notify parent accounts, update the dates above, and ask for a fresh choice when the change affects an existing safeguard.

  • In-app notification to all parent accounts
  • An updated “Last updated” date at the top of this page
  • Re-consent for any change that materially affects how children’s data is handled

12. Contact

Questions about a family choice, a child's information, or deletion? We're here to help. Use the contact details below.

Amir Ariff bin Abdul Hadi

Operator and data controller of the Tiny Beacon app

7, Jalan Cassia U17/82, Elmina West, 40160 Shah Alam, Selangor, Malaysia

Telephone: 013-9844412

Email: [email protected]

© 2026 Amir Ariff bin Abdul Hadi. Tiny Beacon is committed to protecting children’s privacy. Built in Kuala Lumpur, Malaysia.