Your Data & Privacy
May 2026
Your privacy matters to us. Here's exactly how your data is handled — no surprises, no hidden details.
Local-Only Mode (Default)
When you first install the app, all your data stays on your device. Nothing is sent to our servers. Your customers, orders, appointments, and everything else lives only on your phone — completely offline and private.
What This Means for You
- Your data never leaves your phone
- No internet connection required to use the app
- Nothing is uploaded, so there is nothing on our side to read
- You are in full control at all times
- Works completely offline
In local-only mode, if you lose your phone or delete the app without a backup, your data is gone forever. Consider enabling cloud sync or using the backup feature to keep your data safe.
How Your Data Is Encrypted
Your customers, orders, appointments and notes are encrypted on your device before anything is stored, synced or backed up. What differs between setups is who can unlock that encryption — so this page states it plainly.
How Encryption Works
- 1 A random master key is generated on your device when you first set up the app
- 2 Everything sensitive — customers, orders, appointments, notes — is encrypted with that key (AES-256-GCM)
- 3 Records are encrypted before they leave your phone, so anything synced or backed up is already unreadable in transit and at rest
- 4 The master key itself is protected either by a passphrase only you know, or by a key we manage for you — you choose during setup
- 5 Your passphrase is never sent to us and we never store it
Who holds the key
Encryption is only as private as the key that unlocks it. MyPink Party offers two setups, and they differ in exactly one respect: whether we are technically able to recover your key. You choose during setup and can switch later in Settings.
Personal passphrase — zero-knowledge
Your passphrase never leaves your device. It derives a key (Argon2id) that unlocks your master key locally. We only ever receive the encrypted master key, which is useless without your passphrase — so we cannot decrypt your records, and neither could anyone who obtained a copy of our database.
Recovery is yours to keep: store the recovery key the app shows you. Without the passphrase or that recovery key, nobody can restore your encrypted data — including us.
Automatic key management — the default
If you skip the passphrase, your device still encrypts everything locally, but a copy of your master key is stored on our servers, wrapped by AWS KMS and bound to your user ID. That is what lets you reinstall the app or move to a new phone without losing access — and it also means MyPink is technically able to unwrap that key.
The key is only released to a request signed in as your own account, and every unwrap is recorded in AWS CloudTrail. If you would rather that never be possible, set a passphrase — the app switches your existing data over without re-uploading it.
"Zero-knowledge" applies to the passphrase setup: with a passphrase set, a breach of our servers would expose ciphertext we have no way to decrypt. With automatic key management, your data is still encrypted on your device and unreadable in transit and at rest, but the recovery path exists by design — that is the trade-off you are choosing.
Cloud Sync (Optional)
If you choose to enable cloud sync, your data is backed up securely to the cloud. This lets you recover your data if you lose your phone, or use it on multiple devices.
Benefits of Cloud Sync
- Automatic backup — your data is safe if you lose your phone
- Use your data on multiple devices
- Seamless recovery when switching phones
- Sync happens in the background — no extra work for you
Even with cloud sync enabled, your data is encrypted on your device before it is uploaded — we store ciphertext, never plain customer, order or financial data. Whether we could decrypt it depends on your key setup: with a personal passphrase we hold no key at all, with automatic key management we hold a KMS-wrapped copy so your account can be recovered.
Connected Features (Optional)
A few optional features send specific data to clearly disclosed, EU-hosted services — but only when you actively use them, and only the data that feature needs. Unlike your encrypted core data, this content is processed on servers to make the feature work:
What this covers
- WhatsApp messaging — when you connect WhatsApp, message content and customer consent records are handled by Meta and stored on our servers for delivery and compliance.
- AI document scanning — when you scan a questionnaire, invoice, or product catalog, the image is analyzed by AWS Textract and Bedrock (in the EU) to extract the data. It is never used to train AI models.
These features are always optional and clearly labeled. Your everyday customer, order, and appointment data stays end-to-end encrypted, as described above.
What We Can and Cannot See
Full transparency: here is what reaches our servers, what we can read, what we cannot, and what gets processed only because you switched a feature on.
Encrypted business records we cannot read
- Your customer names, phone numbers and details
- Your orders, revenue and financial records
- Your appointments and calendar
- Your notes and the business records you keep in the app
- Your passphrase — it is never transmitted or stored
With a personal passphrase this holds absolutely: we hold ciphertext and no key. With automatic key management the records are encrypted the same way, but we hold a wrapped copy of your key for account recovery, so "cannot read" is a matter of access control rather than mathematics.
Processed for features you switch on
- WhatsApp — message content and customer consent records are handled by Meta and stored on our servers for delivery and compliance
- Document scanning — questionnaires, invoices and product catalogs you scan are analysed by AWS Textract and Bedrock inside the EU; they can contain customer personal data and are never used to train AI models
- Automatic key management — the wrapped copy of your master key, which our infrastructure can unwrap when you restore your account
Account and operational data we can see
- Your email address and account info (for sign-in)
- Your subscription status
- App usage analytics (only if you opted in)
- When your data was last synced (if sync is enabled)
You Are in Control
You decide how your data is handled. You can change your settings at any time.
Your Options
- Stay local-only — your data never leaves your phone
- Enable cloud sync — encrypted backup with multi-device access
- Export your data — download everything as a file at any time
- Delete your account — removes all data from our servers permanently