This Privacy Policy explains how the MSY mobile application ("App", "MSY", "we", "us") collects, uses, stores, shares, and protects user data. By using the App, you agree to the practices described in this Privacy Policy.
1. About us
MSY is a mobile application that helps users manage personal habits, goals, daily activities, reminders, statistics, and subscription/payment services.
MSY may collect or process the following types of data.
2.1. Account and profile data
To create an account, sign in, and manage your profile, we may process:
email address;
password or authentication tokens;
username;
display name;
selected language;
selected country;
when using Google Sign-In, the Google identity token, email, and basic profile information provided by Google.
Passwords are sent to the server only for secure authentication. We do not store your plain-text password inside the App.
2.2. Activities, plans, and goals
To provide the App's core features, we may store:
activity names;
activity notes or descriptions;
module, category, and subcategory selections;
start and end dates;
daily time ranges;
repetition counts;
difficulty levels;
checklist items;
statuses such as completed, missed, paused, archived, or pending;
goal titles, descriptions, deadlines, and icons;
achievements and progress indicators.
This data is used to show your schedule, progress, analytics, and reminders.
2.3. Analytics and progress data
MSY processes personal progress data to show in-app statistics, including:
completed, missed, pending, or paused activity counts;
streaks and progress metrics;
module/category-based results;
time-based trends;
coins, balance, and reward history.
This analytics data is used for your personal in-app insights and is not used to create an advertising profile.
2.4. Payment and subscription data
To manage premium plans, invoices, and payment history, we may process:
selected subscription plan;
invoice identifier;
payment provider;
payment status;
amount and currency;
invoice creation, expiration, and payment dates;
return URL used to redirect from Payme or Click checkout pages.
MSY does not store full bank card numbers, CVV codes, or complete payment card credentials inside the App. Payments are processed through external payment providers such as Payme or Click.
2.5. Notifications and reminders
The App may create local notifications and Android alarms for activities selected by the user. This may include:
activity title;
date and time;
reminder offset in minutes;
task/activity identifiers;
notification permission status;
Android alarm keys stored on the device.
In the current implementation, MSY does not rely on push tokens for marketing messages. Reminders are mainly scheduled locally on the user's device.
2.6. Device and technical data
For app functionality, security, and troubleshooting, we may process:
operating system information;
app version;
network connection status;
API error information;
login session and token status;
language, theme, and notification settings.
2.7. Data stored locally on your device
The App may store some data locally on your device, including:
access token and refresh token;
authenticated user data;
selected language and country;
notification, alarm, and dark mode settings;
PIN status and PIN hash;
whether biometric unlock is enabled;
offline cache;
pending activity changes created while offline.
Biometric data, such as fingerprint or Face ID images, is not sent to MSY servers. Biometric verification is handled by the device operating system.
3. How we use data
We use your data to:
create and authenticate accounts;
verify email addresses;
set up and update profiles;
save language and country preferences;
create and manage activities, plans, checklists, and goals;
schedule reminders and local notifications;
show progress, statistics, coins, and analytics;
manage premium plans, invoices, and payment statuses;
receive feedback;
protect accounts, refresh sessions, and prevent unauthorized access;
detect errors and improve service quality;
comply with legal requirements and resolve disputes.
4. Sharing data
We do not sell user data.
Where necessary, data may be processed by or shared with:
our backend/API server, to store account, profile, activity, goal, analytics, coin, feedback, and billing data;
Google Sign-In, to provide Google authentication;
Payme and Click, to start checkout sessions and process payment status;
Expo/React Native platform services and libraries, to provide local notifications, local authentication, storage, network status, and app functionality;
public authorities, if required by applicable law.
Third-party services may have their own privacy policies. Data processed during payment or Google Sign-In may also be governed by those providers' terms.
5. Data retention
We keep data for as long as needed to provide the service.
Account data is kept while your account is active.
Activity, goal, analytics, and payment history data is stored in connection with your account.
Local cache and pending offline changes may be deleted when you log out or clear app data.
Some payment records may be retained longer if required by law, accounting rules, fraud prevention, or dispute resolution.
6. Account and data deletion
You can request deletion of your account and associated personal data.
Please include the email address associated with your MSY account. For security, we may ask you to verify that you are the account owner.
When your account is deleted, the following data may be deleted or anonymized:
profile data;
activities, plans, checklists, and progress records;
goals and achievements;
feedback records;
personal in-app settings.
Some data may be retained for a limited period where required for legal, financial, security, fraud prevention, or dispute-resolution purposes.
7. Permissions
The App may use the following permissions:
Notifications: to show activity and plan reminders.
Alarm/SET_ALARM: to schedule system alarms on Android devices.
Face ID, Touch ID, or fingerprint: to unlock the App using biometrics instead of a PIN.
Internet/network access: to communicate with the server for login, sync, payments, and analytics.
You can disable notification or biometric permissions in your device settings.
8. Security
We use technical and organizational measures to protect user data, including:
HTTPS communication with the server;
authentication using access and refresh tokens;
session refresh when tokens expire;
local PIN hash storage;
biometric verification through the device operating system;
clearing offline cache and pending offline changes when the user logs out.
No method of transmission over the internet or electronic storage is guaranteed to be 100% secure.
9. Children's privacy
MSY is not specifically intended for children. If the App is offered to children under 13 or to minors under applicable local law, this Privacy Policy and Google Play settings should be reviewed and updated accordingly.
If a parent or guardian believes that a child's personal data has been submitted to us, they may contact us at apps.msydigital.com@gmail.com.
10. International transfers
Servers, payment providers, or third-party services may be located in different countries. By using the App, you understand that your data may be processed outside your country of residence.
11. User rights
Depending on applicable law, you may have the right to:
access your personal data;
correct inaccurate data;
request deletion of your data;
restrict certain processing;
object to certain processing;
request a copy of your data.
To exercise these rights, contact us at apps.msydigital.com@gmail.com.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated date will be shown at the top of this page. For material changes, we may notify users in the App or through another appropriate method.
13. Contact
For privacy questions, complaints, or account deletion requests: