Security & Data Privacy
See how your business data is encrypted before it ever leaves your phone
How Your Data Is Encrypted
Your customers, orders, appointments and notes are encrypted on your device before anything is stored, synced or backed up. What differs between setups is who can unlock that encryption — so this page states it plainly.
How Encryption Works
- 1 A random master key is generated on your device when you first set up the app
- 2 Everything sensitive — customers, orders, appointments, notes — is encrypted with that key (AES-256-GCM)
- 3 Records are encrypted before they leave your phone, so anything synced or backed up is already unreadable in transit and at rest
- 4 The master key itself is protected either by a passphrase only you know, or by a key we manage for you — you choose during setup
- 5 Your passphrase is never sent to us and we never store it
Who holds the key
Encryption is only as private as the key that unlocks it. MyPink Party offers two setups, and they differ in exactly one respect: whether we are technically able to recover your key. You choose during setup and can switch later in Settings.
Personal passphrase — zero-knowledge
Your passphrase never leaves your device. It derives a key (Argon2id) that unlocks your master key locally. We only ever receive the encrypted master key, which is useless without your passphrase — so we cannot decrypt your records, and neither could anyone who obtained a copy of our database.
Recovery is yours to keep: store the recovery key the app shows you. Without the passphrase or that recovery key, nobody can restore your encrypted data — including us.
Automatic key management — the default
If you skip the passphrase, your device still encrypts everything locally, but a copy of your master key is stored on our servers, wrapped by AWS KMS and bound to your user ID. That is what lets you reinstall the app or move to a new phone without losing access — and it also means MyPink is technically able to unwrap that key.
The key is only released to a request signed in as your own account, and every unwrap is recorded in AWS CloudTrail. If you would rather that never be possible, set a passphrase — the app switches your existing data over without re-uploading it.
"Zero-knowledge" applies to the passphrase setup: with a passphrase set, a breach of our servers would expose ciphertext we have no way to decrypt. With automatic key management, your data is still encrypted on your device and unreadable in transit and at rest, but the recovery path exists by design — that is the trade-off you are choosing.
Your Business Data Stays Private
- Encrypted on your device, before anything is uploaded
- You choose who holds the key: you alone, or a managed key that makes recovery possible
- With a personal passphrase, not even we can decrypt your business records
Local-Only Mode (Default)
When you first install the app, all your data stays on your device. Nothing is sent to our servers. Your customers, orders, appointments, and everything else lives only on your phone — completely offline and private.
What This Means for You
- Your data never leaves your phone
- No internet connection required to use the app
- Nothing is uploaded, so there is nothing on our side to read
- You are in full control at all times
- Works completely offline
In local-only mode, if you lose your phone or delete the app without a backup, your data is gone forever. Consider enabling cloud sync or using the backup feature to keep your data safe.
Connected Features (Optional)
A few optional features send specific data to clearly disclosed, EU-hosted services — but only when you actively use them, and only the data that feature needs. Unlike your encrypted core data, this content is processed on servers to make the feature work:
What this covers
- WhatsApp messaging — when you connect WhatsApp, message content and customer consent records are handled by Meta and stored on our servers for delivery and compliance.
- AI document scanning — when you scan a questionnaire, invoice, or product catalog, the image is analyzed by AWS Textract and Bedrock (in the EU) to extract the data. It is never used to train AI models.
These features are always optional and clearly labeled. Your everyday customer, order, and appointment data stays end-to-end encrypted, as described above.
What We Can and Cannot See
Full transparency: here is what reaches our servers, what we can read, what we cannot, and what gets processed only because you switched a feature on.
Encrypted business records we cannot read
- Your customer names, phone numbers and details
- Your orders, revenue and financial records
- Your appointments and calendar
- Your notes and the business records you keep in the app
- Your passphrase — it is never transmitted or stored
With a personal passphrase this holds absolutely: we hold ciphertext and no key. With automatic key management the records are encrypted the same way, but we hold a wrapped copy of your key for account recovery, so "cannot read" is a matter of access control rather than mathematics.
Processed for features you switch on
- WhatsApp — message content and customer consent records are handled by Meta and stored on our servers for delivery and compliance
- Document scanning — questionnaires, invoices and product catalogs you scan are analysed by AWS Textract and Bedrock inside the EU; they can contain customer personal data and are never used to train AI models
- Automatic key management — the wrapped copy of your master key, which our infrastructure can unwrap when you restore your account
Account and operational data we can see
- Your email address and account info (for sign-in)
- Your subscription status
- App usage analytics (only if you opted in)
- When your data was last synced (if sync is enabled)
Third-Party Services
Our service integrates with the following third-party services for authentication, data storage, AI-assisted features, analytics, and error tracking. Analytics and error tracking help us continuously improve the app for you:
Amazon Web Services (AWS)
Amazon Web Services (AWS): We host your data on AWS servers in the European Union (Frankfurt). Some features send your content to AWS for processing: scanned questionnaires, invoices, and product catalogs are analyzed by AWS AI services (Amazon Bedrock, Amazon Textract) to extract data. This content may contain personal data about your customers (such as names, contact details, and amounts). It is encrypted in transit and at rest, processed within the EU, not used to train AI models, and not kept longer than needed to return the result. These features run only when you actively trigger them (for example, tapping scan).
WhatsApp Cloud API (Meta)
WhatsApp Cloud API (Meta): If you connect your WhatsApp Business Account, we use Meta's WhatsApp Cloud API to send and receive messages on your behalf. Phone numbers and message content are transmitted to Meta's servers for delivery. We receive incoming messages from your customers via webhook notifications. We cannot read or access your personal WhatsApp — only messages customers send to your connected Business Account are received. Customer consent (opt-in) is required before any marketing message is sent, and all consent records are logged for compliance.
Google Sign-In: When you sign in with Google, we receive your basic profile information (name and email address) as authorized by your Google account settings. Google Calendar Integration: If you connect your Google Calendar, we request access to your calendar events and calendar list (using the calendar.events and calendar.readonly scopes). We access event titles, dates, times, and calendar names to display your busy times and help you avoid scheduling conflicts. All calendar data is stored locally on your device and is not transmitted to our servers or shared with any third parties. You can disconnect your Google Calendar and revoke access at any time through your app settings or your Google Account permissions page. Google Calendar data is retained on your device only for as long as your Google Calendar remains connected. When you disconnect your Google Calendar or delete your account, all associated calendar data is immediately removed from your device. We do not sell Google user data. Google user data is not used for serving advertisements, training AI or machine learning models, credit determinations, lending decisions, or building user profiles for any purpose unrelated to the app's core scheduling functionality. To delete your Google Calendar data, disconnect your Google Calendar in the app settings — all calendar data will be removed immediately.
Apple
Sign in with Apple: When you sign in with Apple, we receive your name and email address (which may be a relay address if you choose to hide your email).
PostHog
PostHog (Analytics): With your consent, we use PostHog to collect anonymous product analytics including page views, feature usage, and masked session recordings. PostHog helps us understand how the app is used so we can improve it. No personal customer data is sent to PostHog.
Sentry
Sentry (Error Tracking): With your consent, we use Sentry to collect error reports, crash data, and performance metrics. All text is masked and authorization headers are stripped before data is sent. This helps us identify and fix bugs faster.
Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of your personal data
- Request deletion of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Withdraw consent
- Opt out of analytics and error tracking at any time via Settings → Preferences
If you are a resident of the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR).