Privacy Policy
Last updated: 9 July 2026
This is the same Privacy Policy shown inside the MyTring app (Settings → Terms & Privacy). To delete your account and data, see How do I delete my account? on our support page.
1. Who We Are
MyTring acts as the "data controller" (GDPR/UK GDPR), "business" (CCPA/CPRA), and "Data Fiduciary" (India DPDP Act 2023) for the personal data described in this Privacy Policy.
Questions, requests, or complaints about your data can be sent to support@mytring.com — this is also our designated contact point for grievances under India's DPDP Act 2023.
2. Personal Data We Collect
Account & profile data: name, photo, title, company, phone number, email, and the other fields you choose to add to your Corporate, Personal, Student, or Business profiles.
Contacts & exchange data: the cards you scan or are sent, including the other person's profile snapshot, when and roughly where you met, and notes you add.
Location data: if you enable Reconnect, we collect background location to detect when you and a starred contact are near a place you previously met. This is precise/sensitive location data under several laws — see "Location Data" below for how it's used and how to turn it off.
Photos: profile photos and any business-card images you scan for AI enrichment.
Content you send to AI features: text and images you submit to Smart Search, Smart Intro, bio generation, or card enrichment (see "AI Processing Disclosure" below).
Chat messages: if you message a contact in-app, your message content is end-to-end encrypted on your device before it ever reaches our servers — we store only ciphertext we cannot read, plus the metadata needed to deliver it (who sent it, which conversation, and when).
Device & push data: a push notification token tied to your device, used only to deliver MyTring notifications.
Biometric data: if you enable Face ID / Touch ID app-lock, your device performs that check entirely locally using your phone's own biometric hardware. MyTring never receives, transmits, or stores any biometric data — we only ever receive a yes/no "unlocked" result from your device.
3. How We Use Your Data
To operate the Service: create and render your profiles and QR codes, save contacts you scan, generate wallet passes, send the notifications you've opted into, and run the AI features you invoke.
To improve and secure the Service, including diagnosing technical issues and preventing abuse.
To communicate with you about your account, including responding to support requests.
4. Legal Bases for Processing (GDPR/UK GDPR)
Contract: processing needed to provide the Service you've signed up for (profiles, saved contacts, wallet passes).
Consent: optional features you actively turn on — Reconnect background location, biometric app-lock, AI features you invoke, push notifications. You can withdraw consent at any time in Settings, which stops that processing going forward.
Legitimate interests: limited use for security, fraud prevention, and service reliability, balanced against your rights.
Legal obligation: where we must retain or disclose data to comply with the law (see "Data Retention & Deletion" below).
5. AI Processing Disclosure
Smart Search, Smart Intro drafting, AI bio generation, and business-card enrichment send the relevant contact details, notes, or card images to our AI provider, Anthropic, solely to generate the result you requested. This content is sent only when you trigger one of these features — it is not sent in the background.
Anthropic processes this data under its own data-processing terms as our sub-processor and does not use it to train its models on our plan.
6. Location Data
Reconnect is off by default. If you turn it on, MyTring uses background location (via your device's OS) to detect when you're near a place where you previously met a contact you've starred, so we can show a "you're nearby" notification.
This location data is used only for that purpose, is processed on our servers solely to compare against your own previously saved meeting points, and is never sold or shared with advertisers or other third parties. You can disable Reconnect at any time in Settings, which stops new location collection immediately.
8. International Data Transfers & Storage
MyTring currently stores all user data — regardless of where you're located — in a single EU-based Supabase region. If you access MyTring from outside the EU/EEA (for example, from the US or India), your data is transferred to and stored in the EU.
Where required, we rely on Standard Contractual Clauses or an equivalent safeguard for any transfer of EU/UK personal data to a sub-processor located outside the EU/UK (for example, Anthropic, Apple, and Google, which may process data in the US).
9. Data Retention & Deletion
While your account is active, we keep your data for as long as you keep using MyTring.
When you delete your account (Settings -> Delete account), we permanently delete your live profile, contacts, messages, location history, push tokens, and every other table tied to your account, and delete your auth credentials so you can never sign back into that account.
Before deletion, a full snapshot of your account — including your profile, contacts, messages metadata, and any photos you uploaded (profile photo and contact photos) — is moved into a locked-down, encrypted archive that no app user (including you, if you sign up again) can ever read. That archive exists only for limited purposes such as responding to a legal/regulatory request, fraud investigation, or dispute, and is never used for marketing or any other purpose.
We retain archive data for as long as necessary to serve those purposes, consistent with applicable law (for example GDPR Art. 17(3), CCPA/CPRA, and India's DPDP Act legal-compliance, fraud-prevention, and dispute-resolution exceptions), after which it is deleted.
Chat messages work the same way, with one difference: your own sent messages are archived and removed from the live conversation the moment you delete your account, regardless of whether the other participant still has an active account — but deleting your account never deletes their copy of the conversation or their own messages. Once every participant in a conversation has deleted their account, the conversation record itself (which links those archived messages to who was in it) also moves into the same locked-down archive. This preserves a traceable record of who messaged whom and when for lawful requests, without us ever being able to read what was actually said.
10. Your Rights — GDPR / UK GDPR (EEA, UK)
If you're in the EEA or UK, you have the right to: access the personal data we hold about you; correct inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time.
Most of these (profile editing, account deletion, turning off optional features) are self-serve in the app. For anything else, email support@mytring.com. You also have the right to lodge a complaint with your local data protection authority.
11. Your Rights — California / USA (CCPA/CPRA)
If you're a California resident, you have the right to know what personal information we collect, to request deletion of it, to correct inaccurate information, and to opt out of the sale or sharing of personal information.
We do not sell or share your personal information as defined by the CCPA/CPRA, so there is no "opt out" toggle needed for that. We will not discriminate against you for exercising any of these rights.
To exercise a right, email support@mytring.com from your account's registered email or phone for verification.
12. Your Rights — India (DPDP Act 2023)
If you're in India, as a Data Principal you have the right to access a summary of your personal data and the processing activities we carry out, to correct or complete inaccurate or incomplete data, to erase data that is no longer needed, and to withdraw consent at any time as easily as you gave it (Settings toggles, or account deletion).
For grievances, contact our Grievance Officer at support@mytring.com. We aim to respond within the timelines required under the DPDP Act and its rules.
13. Children's Privacy
MyTring is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
14. Security
We use industry-standard measures to protect your data, including encryption in transit, access controls limiting who can read production data, and row-level security policies that restrict each user to their own data. No system is 100% secure, and we cannot guarantee absolute security.
15. Data Breach Notification
If a breach affecting your personal data occurs, we will notify affected users and the relevant regulators without undue delay, as required under GDPR, India's DPDP Act, and other applicable law.
16. Changes to This Policy
We may update this Privacy Policy as the Service evolves. Material changes will be announced in the app before they take effect.
17. Contact Us
For any question about these Terms, this Privacy Policy, or your data: support@mytring.com.