ℹ️ This policy covers every service operated by Mina Platform, including the Mina Home smart-home product (home.minaplatform.net).

1. Introduction

This document describes how Mina Platform (“we”, “us”, “the platform”) collects, uses, stores and shares personal information of users of the Mina Home mobile application (the “App”) and the related gateways, sensors and switches.

Mina Platform operates the service and acts as the data controller under Vietnam’s Decree 13/2023/ND-CP on personal data protection. Place of operation: Vietnam. Data protection contact: minaplatform@gmail.com.

By creating an account and using the service, you confirm that you have read, understood and agreed to this policy.

2. Data we collect

2.1. Account information

  • Email — required, used as the login identifier and for OTP verification
  • Display name — optional, set by you
  • Password — stored as a hash; we never see the original password
  • Phone number — optional, used for SMS OTP (planned)
  • Profile photo — optional, uploaded by you

If you sign in with a Google account (OAuth), we receive from Google: your email, name and public profile photo. We do not read your Gmail, Drive, Calendar or any scope outside basic identity.

2.2. Device data

When you pair a gateway and IoT devices, we store:

  • Device identifiers: MAC address, model, manufacturer, firmware version
  • Device telemetry: on/off state, brightness, room temperature, humidity, power consumption — depending on the device type
  • Automation rules: scenarios and schedules you create
  • Names + groupings: device, room and home names you assign

Telemetry is stored on your gateway first. A subset is synced to our cloud so you can monitor your home remotely and so voice integrations work.

2.3. App usage data

  • Diagnostic logs: login sessions, API call timestamps, error codes (no sensitive payloads)
  • Push notification tokens (Firebase Cloud Messaging) — to deliver alerts (door sensor, power loss…)

2.4. Location — only if you allow it

The App does ask for location permission, but the permission is optional and serves only the two purposes below. If you decline, everything else in the App keeps working.

  • Scanning for devices during pairing — Android requires an app to hold location permission before it may scan for Bluetooth (BLE) devices or list nearby Wi-Fi networks. We need both scans to find gateways and devices waiting to be paired. In this case the App does not read your coordinates and does not send any coordinates anywhere — the permission merely unlocks the scan at the OS level.
  • Your home’s location — when you create a home, the App offers a “Use current location” button that stores the home’s coordinates (latitude/longitude). This step is skippable. The coordinates are saved as an attribute of the home in our cloud and used to fetch the outdoor weather shown on the home screen — we send those coordinates to Open-Meteo (see section 4). You can review, change or clear them at any time in the home’s settings.

The App does not track your location over time, does not collect location in the background, and does not use location for advertising. It reads coordinates only at the moment you press the button.

2.5. Data we do not collect

  • Location history — we keep no trail of your movements; a home’s coordinates are a single point you set yourself, overwritten each time you update it (see 2.4).
  • Contacts — the App never accesses your contacts.
  • Photo library — the App never scans your library. It reads only the single image you pick when setting a profile, home or room picture.
  • Advertising — we do not include advertising SDKs, do not track across apps, and do not use IDFA / AAID.

3. How we use the data

DataPurpose
Email + passwordAuthentication, account recovery
Device telemetryDisplay state in the App, evaluate automations
RulesRun automations under conditions you set
Push tokensSend alerts (sensors, gateway errors)
Home coordinates (if you provide them)Fetch outdoor weather for the home screen
Diagnostic logsTroubleshoot, improve reliability

We do not use your data for advertising, and we do not sell it to third parties.

We also do not use your data — including any data arising from the Google Home integration — to train artificial-intelligence models or any related tools.

4. Sharing with third parties

We share data only in the cases below, and only the minimum needed for each service:

Third partyData sharedPurpose
Self-hosted IoT backend (Mina Home cloud)All device dataStorage, sync, command delivery
Google (Smart Home Action)Device names, state, command resultsWhen you link with Google Home for voice control
Firebase Cloud Messaging (Google)Device tokens, notification payloadPush notifications
Tuya Cloud (optional)Tuya account identity, camera commandsWhen you connect Tuya cameras — only if you opt in
Open-Meteo (if you save a home location)Home coordinates (latitude/longitude) — no account or device identifier attachedFetch the outdoor weather shown in the App
Cloud infrastructure providerAll data (encrypted at rest)Storage, backup, operations — Oracle Cloud Infrastructure (OCI)

We do not sell your data. We do not share it for advertising, market analytics or data brokerage.

When required by law (court orders, lawful requests from competent authorities), we may have to provide data — limited to the minimum necessary and in compliance with Vietnamese law.

5. Storage and security

  • In transit: TLS 1.2+ for all App ↔ Cloud and Gateway ↔ Cloud connections
  • At rest: cloud data is encrypted at rest by our infrastructure provider
  • Passwords: stored as bcrypt / argon2 hashes; the original password cannot be recovered
  • Region: servers are located in Singapore (Oracle Cloud Infrastructure)

6. Retention

Data typeRetention
Active accountUntil you delete it
Detailed telemetry90 days; long-term aggregates are de-identified
Diagnostic logs30 days
Backups30 days after account deletion

A deletion request has a 10-day waiting period, during which signing back in cancels it. Once the period ends, personal data is deleted and physically removed from backups within 30 days. Details: Account deletion.

7. Your rights

Under Vietnam’s Decree 13/2023/NĐ-CP on personal data protection, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correct — ask us to update inaccurate data
  • Delete — delete your account and data (see section 8)
  • Restrict processing — request that we pause processing in specific situations
  • Complain — file a complaint with the competent authority (Authority of Information Security — Ministry of Information and Communications)

To exercise any of these, email minaplatform@gmail.com. We respond within 30 days.

8. Account deletion

You can delete your account yourself in two ways. See the Delete Account page for step-by-step instructions.

9. Children

The service is not intended for users under 13. We do not knowingly collect data from children. If we discover such data, we delete it. Parents who believe their child has registered should contact minaplatform@gmail.com.

10. Cameras + video

If you use cameras (via the Tuya integration), please also read the Camera Policy for details on video data flow, storage and encryption.

11. Changes to this policy

We may update this policy over time. For material changes we will:

  • Update the “Last updated” date at the top
  • Email active accounts
  • Show an in-app banner

Continued use of the service after the update means you accept the new version.

12. Contact

Privacy questions:

We answer every personal-data request within 30 days of receipt.


Effective date: 2026-04-27