UrusFamily privacy notice
UrusFamily stores family data only to run the app. We show no ads and never sell data. Kid profiles are created by a parent or guardian who gives consent. You can access, correct or delete your data at any time under Malaysia's Personal Data Protection Act 2010.
What are your rights under PDPA 2010?
- Access: ask for a copy of your personal data, or export family data from Settings.
- Correction: fix data in the app, or ask us to correct it.
- Withdraw consent: delete your account or, as owner, delete the family.
- Send requests to privacy@urusfamily.com. We reply within 21 days.
Which third parties do we use?
| Supabase | Database hosting, sign-in and storage, in the Singapore region. |
|---|---|
| Google Sign-In | Only if you choose to sign in with Google. Shares name and email. |
| Sign in with Apple | Only if you choose to sign in with Apple. Shares name and email. |
| Google Play and App Store | Process purchases. We never receive card numbers. |
| RevenueCat | Verifies Premium subscriptions from the stores. Receives a random family ID and the purchase record, no card numbers. |
| Expo | Delivers push notifications. Receives your phone delivery token and one short line of text. |
| Apple and Google | Carry that notification to your phone. Receive the same token and the same text. |
No ad SDKs, third-party analytics or trackers. Usage and error records stay in our own database.
What stays on your phone?
- Documents vault files stay on the phone that holds them; only a locked copy goes to our servers.
- Gallery photos are re-encoded on the phone, which drops EXIF, and locked before they are sent.
- Private notes are encrypted on the phone with a key we do not hold.
- A saved email and password stay in the phone Keychain or Keystore.
Full notice
The text below is the same notice shown in the app.
Who we are
UrusFamily is a family app for housework, points and shared goals. For the data you keep in the app, UrusFamily is the data user under the Personal Data Protection Act 2010 (Act 709).
This notice explains what data we process, why, who can see it, how long it is kept and your rights.
What we store
Account: email and password (stored hashed, we cannot read it). If you sign in with Google or Apple, that provider shares only your name and email with us, never a password. Apple private relay emails work too.
Family: the family name, each member's display name and avatar, role, daily target, profile PIN (hashed), and a birthday if you enter one.
Activity: chores, points, badges, goals, the virtual wallet, grocery lists, notes, the calendar and other features your family switches on.
Family faith (optional): if a parent chooses it, the family faith is stored to tailor festive seasons and practices in the app. Only members of your family can see it, and it is not used for anything else.
Kid's savings (optional): parents can record a child's savings kept outside the allowance, such as duit raya amounts, gold weight and purity, and the type of account such as ASB. No account numbers, IC numbers, receipts or photos are stored.
We do not collect GPS location, biometrics, phone contacts, or a child's email or phone number.
Cards (optional): if your family switches Cards on, the card name, number or barcode, code type and notes are encrypted on the phone before they are sent, so we cannot read them. The server keeps only the card type, who owns it, who may see it, one colour and an expiry date if there is one. Apple Wallet pass files and card images are never uploaded.
Family gallery (optional): if your family switches the gallery on, every photo is re-encoded on the phone first, and that step drops the hidden EXIF details a camera writes into a picture, such as GPS location, camera model and orientation. It is then locked with your family key before it is sent, exactly as documents vault files are, and the caption is locked too. Two locked objects are stored for each photo, the picture and a small thumbnail, and we cannot open either. All we can read is which family it belongs to, who added it, when it was added, when the phone says it was taken, the two storage keys, the two file sizes and a key fingerprint. No filename, no location, no EXIF and nothing read out of the picture itself is ever stored. Parents, adults and teens can open the gallery; extended family and a helper cannot.
Notifications (optional): if you switch notifications on, your phone gives us a delivery token from Apple or Google so a message can reach that phone. The token belongs to your login, so a kid profile, which has no login, never has one. A notification says only what happened and who did it, from a fixed list of words. Chore titles, task titles, reward names, points, ringgit amounts and anything a member typed are never put in one.
Optional fingerprint or face unlock is handled by your phone's operating system. The app only receives a yes or no; it never receives or stores biometric data, and nothing is sent to us.
Purpose
Data is used only to run the app for your family: showing chores, counting points, syncing between family members' phones, sending the reminders and notifications you choose and supporting your account.
We never use family data for advertising and never sell it to anyone.
Children's data and parental consent
Kid profiles have no account or email. A kid profile is created only by a parent or legal guardian, who consents on the child's behalf. The date and time of that consent is stored on the kid profile.
Kid screens show no ads and send no child data to third-party analytics tools.
Disclosure
Family data is seen only by your family members, according to their role. For example, extended family do not see wallets or notes.
We disclose data to service providers who run the app for us, such as database hosting, under contracts that require confidentiality. Where servers are outside Malaysia, we only use providers with comparable data protection.
If you switch notifications on, Expo, our push service provider, receives the delivery token and that one line of text, and passes it to Apple or Google, who deliver it to your phone. They act for us under contract, and they receive no sealed content, no free text, no points and no ringgit amounts. Quiet hours are applied before anything is sent, so a notification that falls inside your quiet window is never handed to them and is not sent later either.
We do not disclose data to anyone else unless the law requires it.
Premium subscriptions are paid through Google Play or the App Store, which handle your payment details; we never receive card numbers. RevenueCat, our service provider, receives a random family ID and the store purchase record (product, dates, renewal status and transaction) so Premium opens for the whole family. Subscription event records are deleted after 90 days; payment records are kept as described below.
Storage and retention
Data is kept while your family or account is active. When the owner deletes the family, data is removed from the main database immediately and from backups within 30 days.
After deletion we keep only anonymous counts (number of members and the age of the family) as proof the deletion happened.
We keep no photograph that we can look at. A chore proof photo is deleted as soon as it is checked, and at most 72 hours after upload. A share proof screenshot is deleted after it is reviewed, and at most 14 days after upload. Documents vault files are encrypted on your family's phones before they go anywhere. One copy stays on the phone that added it, and one encrypted copy is kept on our servers so every parent's phone can open the document. We cannot read that copy: it is locked with your family key, which we never receive. All we can read is the title, type, whose document it is, expiry date, reminder, note and the name of the phone holding the file. The encrypted copy is kept as long as the document is; deleting the document deletes it within 15 minutes, and deleting your family deletes all of them. If every family phone and the recovery code are lost, nobody can open the copy on our servers. Tickets and boarding passes in Cards are deleted 30 days after they expire; store cards and coupons stay until you remove them.
Family gallery photos are the one kind of photo we do keep, and the difference matters: a proof photo is evidence, so it goes as soon as it has done its job, while a gallery photo is your family album, so it stays until someone in your family deletes it. We still cannot see it, because the copies on our servers are locked with your family key. Deleting a photo removes both locked copies, the picture and its thumbnail, within 15 minutes, and deleting your family removes every photo in the gallery.
A notification delivery token is deleted when you sign out, when you switch notifications off, when you withdraw permission in your phone settings, and when Apple or Google tell us that device is gone. Records of notifications sent, and of ones quiet hours held back, are deleted after 14 days.
Daily ibadah logs are kept for 13 full months, then combined into monthly totals for each member and the daily logs are deleted. A hafazan teacher's name is kept only on the phone that recorded it.
Other records are kept only as long as they are needed, then deleted automatically: "Sampai rumah" check-ins after 7 days; invites 30 days after they expire or are used; app usage and error records after 90 days; problem reports 180 days after they are handled; referral link opens after a year; a rejected or withdrawn share post link after 90 days. Usage and error records carry only a random app id that changes every year, never your name or email.
For affiliates, bank details are asked for only when a payout is due. The account number is deleted after 90 days without payout activity, and the name and MyKad number are deleted 15 months after the tax form (CP58) deadline for the last payout. Payment records with no family details are kept for 7 years because tax law requires it.
Security
Data travels over encrypted connections. Each family is isolated on the server, so other families cannot read your data.
Private notes (notice details, family meeting outcomes, house rule consequences, hafazan notes and task notes) are encrypted on your family's phones with a key that is never sent to us, so we cannot read them. Only parents hold the recovery code. If every phone and that code are lost, those notes cannot be recovered. Card content and documents vault files are encrypted with the same key. Because that key is one per household, choosing who may see a card is access control on the server, not a separate key per member.
Access and correction
You can view and correct most data directly in the app. Parents can export a copy of the family data from Settings.
You can also ask for access or correction by email. We will reply within 21 days.
Your choices
You can withdraw consent at any time by deleting your account or, for the owner, deleting the family. Without consent we cannot run the app for you.
Contact us
For questions, access or correction requests, or complaints about personal data: hello@urusfamily.com
Changes to this notice
If this notice changes in substance, the app will ask for your consent again. If the BM and EN versions differ, the BM version applies.