Tiny Beacon

Privacy

Privacy policy.

Operated by Amir Ariff bin Abdul Hadi · Shah Alam, Selangor, Malaysia · [email protected]

Effective date: 25 June 2026  ·  Last updated: 24 August 2026

Amir Ariff bin Abdul Hadi

Operator and data controller of the Tiny Beacon app

7, Jalan Cassia U17/82, Elmina West, 40160 Shah Alam, Selangor, Malaysia

Telephone: 013-9844412 · Email: [email protected]

Tiny Beacon is a child-safety app for parents and legal guardians, operated by Amir Ariff bin Abdul Hadi(Shah Alam, Selangor, Malaysia). This policy explains what the app on the App Store and Google Play collects, how we use it, and how you can control or delete it. It is designed to comply with the United States’ Children’s Online Privacy Protection Act (COPPA) — Tiny Beacon is a parental-control service operated by adults that collects children’s personal information only with verifiable parental consent — and with Malaysia’s Personal Data Protection Act 2010 (PDPA), our primary market.

Tiny Beacon accounts are created and operated by an adult parent or guardian. We do not knowingly collect personal information directly from a child: any information about a child is entered and managed by the parent, with their consent, as described in section 5.

1. What we collect

The public App Store / Google Play build of Tiny Beacon collects only the following, all encrypted in transit (TLS 1.2+) and at rest (AES-256):

1.1 Parent account & identity

  • Parent name and email address (account creation and sign-in)
  • Account and user identifiers
  • Parent date of birth (used once as an adult age-gate, to confirm the account holder is an adult)
  • Sign-in identity from Apple or Google (OAuth), only when you choose that sign-in method
  • Optional profile photo (parent and child), only if you add one
  • Your device’s encryption public key and an optional device label, so paired devices can exchange data securely
  • Push / notification tokens (to deliver alerts to your own devices)

1.2 Child profile (parent-provided)

Entered and managed by the parent in the parent dashboard — never collected from the child directly:

  • Child’s first and last name
  • Child’s date of birth

1.3 Location sharing (family safety)

With your consent, a child’s device shares its live location with the linked parent / family account, so your family can see where everyone is and get safe-zone arrival and exit alerts — the way a family locator or Find My works. This is family safety, shared openly within your family — not covert monitoring.

  • Location is shared continuously while sharing is on, including in the background and when the app is closed, so safe-zone alerts and emergency context keep working.
  • Sharing is off by defaultand turns on only with explicit parental consent. While it is active, the child’s device shows a persistent on-device notification, so it is always clear that location is being shared.
  • Location is used onlyfor family-safety features — live location, safe-zone (geofence) alerts, and emergency context. It is never used for advertising or cross-app tracking, and we never sell it or share it with third parties; our backend providers (Supabase, PostHog, Sentry, Expo) act only as processors on our behalf.
  • A parent can turn sharing off or delete location data at any time. Withdrawing consent stops collection immediately.

1.4 Screen Time limits & app-use awareness

If you set screen-time limits, the app uses the device’s built-in Screen Time / Family Controls to enforce them. The limit and shield events needed to do this are processed on the device.

On Android, with your consent, the app also collects app-use awareness— the package and app name, category, how long each app was open, screen opens, and daily totals — via the device’s Android Usage Access (PACKAGE_USAGE_STATS) permission, since 2026-07-28. This gives you screen-time insights and lets you set and enforce per-app limits. It is collected only with explicit parental consent, is retained for the family’s rolling retention window (7–180 days), and is deleted when you withdraw consent. iOS does not collect app usage; on iOS, screen-time limits rely on Apple’s built-in Screen Time / Family Controls only.

1.5 Pairing & consent records

  • A hash of the device-pairing code (we store the hash, not the code itself)
  • Parental-consent records (what you consented to, and when) — required to demonstrate compliance
  • Your retention settings

1.6 Diagnostics & analytics

  • Product analytics via PostHog, tagged with account, parent, and child identifiers (no child-entered content; never used for advertising or cross-app tracking)
  • Crash and performance diagnostics via Sentry — with personal identifiers minimised and parent context truncated before transmission

2. What we do not collect

The public build does not collect any of the following:

  • Screenshots or any screen content (supervised editions only — see section 9)
  • App-usage data on iOS (Android collects per-app usage with consent — see section 1.4)
  • SMS, chat, or message content (supervised editions may retain a short redacted WhatsApp notification excerpt — see section 9)
  • Call logs
  • Web browsing or search history
  • Advertising identifiers (IDFA / AAID), and no cross-app tracking
  • Contact lists
  • Biometric data
  • Audio or video recordings

3. How we use it

  • Authentication: to create accounts, sign in, and pair devices
  • Core service:to let a parent set up and manage a child’s profile and the family’s paired devices
  • Safety features: to share live location within your family, send safe-zone arrival and exit alerts, provide emergency context, send emergency and amber alerts, and enforce any screen-time limits you set
  • Alerts:to deliver notifications to the parent’s own devices
  • App improvement: account-scoped analytics and crash diagnostics to keep the app working and improve it

We do not sell or rent personal information, we do not share it with advertisers or data brokers, and we do notuse children’s personal information for behavioural advertising or to build advertising profiles.

4. Encryption & security

  • All data is encrypted in transit using TLS 1.2 or higher
  • Personal data is encrypted at rest with AES-256
  • Device encryption keys are generated on the device and held in the device secure enclave (e.g. iOS Keychain); the private key never leaves the device, and keys are wiped on sign-out
  • Row Level Security (RLS) on every database table — a parent can access only their own family’s data
  • Role-based access separates parent and child accounts

5. Children’s privacy & parental consent (COPPA)

Tiny Beacon is operated for parents and guardians, and our child-data practices are designed around the safeguards described in COPPA:

  • Parental consent before collection.Information about a child is only ever added by the account holder — an adult who confirms they are over 18 through our date-of-birth age-gate and who controls the account. Consent is captured in the app before any child information is collected, and we keep a record of what was consented to and when.
  • Parental review and deletion (COPPA §312.6).A parent can review the information held about their child, delete it, and refuse to permit its further collection or use — at any time, from the app’s settings.
  • Data minimisation (COPPA §312.7).We collect only what is reasonably necessary for the service, and we do not condition a child’s participation on disclosing more than is reasonably necessary.
  • No targeted advertising to children.We do not use children’s personal information for behavioural advertising.
  • Limited retention (COPPA §312.10).You choose how long Tiny Beacon keeps each child’s data — 30 days by default, adjustable per child from 7 days up to a maximum of 180 days. Threat-flagged captures in supervised editions are kept only while needed and deleted automatically when they expire (see section 7).

If you believe a child has provided us personal information without parental consent, contact us at [email protected] and we will delete it.

6. Your rights under Malaysia’s PDPA 2010

Under Malaysia’s Personal Data Protection Act 2010 you have the right to access, correct, and withdraw consent for the processing of personal data. In practice you can:

  • Review the data held in your account via the parent dashboard
  • Correct account and child profile details at any time
  • Withdraw consent and stop further processing
  • Delete your data or your entire account, which permanently removes all associated data
  • Request a data export by emailing [email protected]

7. Data retention & deletion

You can delete your data at any time, with or without the app:

  • In the app:open Settings → Privacy & data controls and choose “Request Account/Data Deletion”. This permanently removes all parent and child data associated with the account from our systems.
  • Without the app (web): email [email protected] from your account email address and ask us to delete your account. We verify the request and delete the data within 30 days.
  • Withdrawal of consent:withdrawing consent stops further collection immediately. Turning off a single safeguard deletes the data collected by that safeguard; turning off every data-collecting safeguard deletes all of that child’s monitoring data. Records of emergency alerts and safe-word triggers are kept when you turn off an individual safeguard, so a past safety event is not erased by a later settings change, and are removed with everything else on a full withdrawal or account deletion.
  • Per-child retention:parents choose how long Tiny Beacon keeps each child’s data — 30 days by default, adjustable per child from 7 days up to a maximum of 180 days. Some supervised-edition data is kept for shorter fixed periods regardless of that setting (see section 9). Scheduled cleanup removes data when its retention period ends.

8. Third-party services

Supabase — backend, database & authentication
Stores account and profile data and auth tokens. RLS policies, data isolation, encrypted at rest.
Apple & Google — sign in with Apple / Google (optional)
If you choose social sign-in, we receive a basic identity token. Only when you select that sign-in method.
PostHog — product analytics
Tagged with account, parent, and child identifiers. No child-entered content; never used for advertising or cross-app tracking.
Sentry — crash & error diagnostics
Crash reports with personal identifiers minimised. Parent context truncated before transmission.
Expo — push notifications & app delivery
Push tokens and device identifiers. Parent-facing notifications only.
Plausible — website analytics (tiny-beacon.com)
Aggregate page views — no cookies, no personal data. Privacy-first; nothing that identifies a visitor.
Cloudflare — website DNS, CDN & security
Processes IP address and request metadata for tiny-beacon.com. Website traffic only; no app data.

9. Supervised & enterprise editions

Everything above describes the public Tiny Beacon app on the App Store and Google Play. Separate supervised and enterprise editions — provided only under a distinct written agreement, not through the public app stores — may additionally collect on-device screen content, detailed app-usage, and web-filtering data for managed-device scenarios. The public app collects only the data described in sections 1–8. Across the service, parents choose how long Tiny Beacon keeps each child’s data — 30 days by default, adjustable per child from 7 days up to a maximum of 180 days. In supervised editions, threat-flagged captures are kept only while needed and deleted automatically when they expire.

In supervised Android editions that include text and call check-ins, the first time the feature runs after a parent or guardian turns it on may include up to the previous seven days of texts and calls already stored on the child’s device, so recent context is not lost at setup. Nothing older than seven days is read, and if the feature is turned off and later turned on again, the seven-day window starts fresh rather than covering the period while it was off.

In supervised Android editions only, we offer an optional WhatsApp notification-excerpt safety feature. It is disabled by default and turns on only after both explicit parent or guardian consent and child-side setup granting notification access. Eligible WhatsApp notifications are evaluated on the child’s phone for narrowly defined high-risk patterns. When something may need care, we send the parent a category and a short redacted excerpt of no more than 64 characters. Whatever retention period is chosen for the child, these excerpts are kept for a maximum of 30 days. We never store, upload, or make full conversations browsable. Because the feature depends on available notifications, it may miss content when notifications are muted or disabled, or when content is deleted, disappearing, or media-only.

9.1 Supervised edition (Android, separate consent)

The supervised editionis a separately distributed Android build (installed directly, not from the app stores) that adds safety capabilities the public app does not include. Each capability is off until a parent grants consent for that specific category, and consent can be withdrawn at any time — withdrawing consent stops collection and deletes the associated data.

  • SMS / MMS text:message content and sender/recipient numbers, reviewed for safety keywords and risk patterns, for the parent’s safety review.
  • Call metadata: call direction, timestamps, duration, frequency, and unknown-number flags. Call audio is never recorded or accessed.
  • Screenshots:periodic device screen captures assessed for high-risk content (self-harm, grooming, adult content). Only frames assessed medium-or-higher are stored, encrypted for the parent’s devices.
  • App use: app/package names, categories, durations, screen opens, and daily totals, for usage summaries and limit enforcement.

These categories are not used for advertising or to build advertising profiles. On iOS, none of these capabilities exist — Apple does not permit third-party apps to access them; iOS supervised safety relies on Apple’s Family Controls / Screen Time only.

Pre-activation semantic analysis.The supervised edition may, in future, perform server-side semantic review of flagged conversation excerpts via Google Gemini to help assess risk. This is a separate consent scope, is currently disabled and fail-closed — no analysis runs unless it is explicitly enabled — and is disclosed here ahead of any enablement.

10. Data storage location

Data is stored on Supabase-managed infrastructure, encrypted at rest (AES-256) and in transit (TLS 1.2+). Backups are encrypted and access-controlled.

11. Changes to this policy

Material changes will be communicated through:

  • In-app notification to all parent accounts
  • An updated “Last updated” date at the top of this page
  • Re-consent for any change that materially affects how children’s data is handled

12. Contact

Questions about this policy, or to exercise your rights:

Amir Ariff bin Abdul Hadi

Operator and data controller of the Tiny Beacon app

7, Jalan Cassia U17/82, Elmina West, 40160 Shah Alam, Selangor, Malaysia

Telephone: 013-9844412

Email: [email protected]

© 2026 Amir Ariff bin Abdul Hadi. Tiny Beacon is committed to protecting children’s privacy. Built in Kuala Lumpur, Malaysia.