Privacy Policy
How Mina Platform collects, uses and protects your personal data.
Updated: 2026-09-21
ℹ️ This policy covers every service operated by Mina Platform, including the Mina Home smart-home product (home.minaplatform.net).
1. Introduction
This document describes how Mina Platform (“we”, “us”, “the platform”) collects, uses, stores and shares personal information of users of the Mina Home mobile application (the “App”) and the related gateways, sensors and switches.
Mina Platform operates the service and acts as the data controller under Vietnam’s Decree 13/2023/ND-CP on personal data protection. Place of operation: Vietnam. Data protection contact: minaplatform@gmail.com.
By creating an account and using the service, you confirm that you have read, understood and agreed to this policy.
2. Data we collect
2.1. Account information
- Email — required, used as the login identifier and for OTP verification
- Display name — optional, set by you
- Password — stored as a hash; we never see the original password
- Phone number — optional, used for SMS OTP (planned)
- Profile photo — optional, uploaded by you
If you sign in with a Google account (OAuth), we receive from Google: your email, name and public profile photo. We do not read your Gmail, Drive, Calendar or any scope outside basic identity.
2.2. Device data
When you pair a gateway and IoT devices, we store:
- Device identifiers: MAC address, model, manufacturer, firmware version
- Device telemetry: on/off state, brightness, room temperature, humidity, power consumption — depending on the device type
- Automation rules: scenarios and schedules you create
- Names + groupings: device, room and home names you assign
Telemetry is stored on your gateway first. A subset is synced to our cloud so you can monitor your home remotely and so voice integrations work.
2.3. App usage data
- Diagnostic logs: login sessions, API call timestamps, error codes (no sensitive payloads)
- Push notification tokens (Firebase Cloud Messaging) — to deliver alerts (door sensor, power loss…)
2.4. Location — only if you allow it
The App does ask for location permission, but the permission is optional and serves only the two purposes below. If you decline, everything else in the App keeps working.
- Scanning for devices during pairing — Android requires an app to hold location permission before it may scan for Bluetooth (BLE) devices or list nearby Wi-Fi networks. We need both scans to find gateways and devices waiting to be paired. In this case the App does not read your coordinates and does not send any coordinates anywhere — the permission merely unlocks the scan at the OS level.
- Your home’s location — when you create a home, the App offers a “Use current location” button that stores the home’s coordinates (latitude/longitude). This step is skippable. The coordinates are saved as an attribute of the home in our cloud and used to fetch the outdoor weather shown on the home screen — we send those coordinates to Open-Meteo (see section 4). You can review, change or clear them at any time in the home’s settings.
The App does not track your location over time, does not collect location in the background, and does not use location for advertising. It reads coordinates only at the moment you press the button.
2.5. Data we do not collect
- Location history — we keep no trail of your movements; a home’s coordinates are a single point you set yourself, overwritten each time you update it (see 2.4).
- Contacts — the App never accesses your contacts.
- Photo library — the App never scans your library. It reads only the single image you pick when setting a profile, home or room picture.
- Advertising — we do not include advertising SDKs, do not track across apps, and do not use IDFA / AAID.
3. How we use the data
| Data | Purpose |
|---|---|
| Email + password | Authentication, account recovery |
| Device telemetry | Display state in the App, evaluate automations |
| Rules | Run automations under conditions you set |
| Push tokens | Send alerts (sensors, gateway errors) |
| Home coordinates (if you provide them) | Fetch outdoor weather for the home screen |
| Diagnostic logs | Troubleshoot, improve reliability |
We do not use your data for advertising, and we do not sell it to third parties.
We also do not use your data — including any data arising from the Google Home integration — to train artificial-intelligence models or any related tools.
4. Sharing with third parties
We share data only in the cases below, and only the minimum needed for each service:
| Third party | Data shared | Purpose |
|---|---|---|
| Self-hosted IoT backend (Mina Home cloud) | All device data | Storage, sync, command delivery |
| Google (Smart Home Action) | Device names, state, command results | When you link with Google Home for voice control |
| Firebase Cloud Messaging (Google) | Device tokens, notification payload | Push notifications |
| Tuya Cloud (optional) | Tuya account identity, camera commands | When you connect Tuya cameras — only if you opt in |
| Open-Meteo (if you save a home location) | Home coordinates (latitude/longitude) — no account or device identifier attached | Fetch the outdoor weather shown in the App |
| Cloud infrastructure provider | All data (encrypted at rest) | Storage, backup, operations — Oracle Cloud Infrastructure (OCI) |
We do not sell your data. We do not share it for advertising, market analytics or data brokerage.
When required by law (court orders, lawful requests from competent authorities), we may have to provide data — limited to the minimum necessary and in compliance with Vietnamese law.
5. Storage and security
- In transit: TLS 1.2+ for all App ↔ Cloud and Gateway ↔ Cloud connections
- At rest: cloud data is encrypted at rest by our infrastructure provider
- Passwords: stored as bcrypt / argon2 hashes; the original password cannot be recovered
- Region: servers are located in Singapore (Oracle Cloud Infrastructure)
6. Retention
| Data type | Retention |
|---|---|
| Active account | Until you delete it |
| Detailed telemetry | 90 days; long-term aggregates are de-identified |
| Diagnostic logs | 30 days |
| Backups | 30 days after account deletion |
A deletion request has a 10-day waiting period, during which signing back in cancels it. Once the period ends, personal data is deleted and physically removed from backups within 30 days. Details: Account deletion.
7. Your rights
Under Vietnam’s Decree 13/2023/NĐ-CP on personal data protection, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correct — ask us to update inaccurate data
- Delete — delete your account and data (see section 8)
- Restrict processing — request that we pause processing in specific situations
- Complain — file a complaint with the competent authority (Authority of Information Security — Ministry of Information and Communications)
To exercise any of these, email minaplatform@gmail.com. We respond within 30 days.
8. Account deletion
You can delete your account yourself in two ways. See the Delete Account page for step-by-step instructions.
9. Children
The service is not intended for users under 13. We do not knowingly collect data from children. If we discover such data, we delete it. Parents who believe their child has registered should contact minaplatform@gmail.com.
10. Cameras + video
If you use cameras (via the Tuya integration), please also read the Camera Policy for details on video data flow, storage and encryption.
11. Changes to this policy
We may update this policy over time. For material changes we will:
- Update the “Last updated” date at the top
- Email active accounts
- Show an in-app banner
Continued use of the service after the update means you accept the new version.
12. Contact
Privacy questions:
- Email: minaplatform@gmail.com
- Zalo: +84 971 716 682
- Operator: Mina Platform — Vietnam
- Address: No. 2 Le Van Thiem, Thanh Xuan, Hanoi, Vietnam
We answer every personal-data request within 30 days of receipt.
Effective date: 2026-04-27