Privacy Policy — PulangAman
Last updated: 25 August 2026
Android package: com.tursinalabs.pulangaman
1. Scope
This page is the privacy policy for the PulangAman Android app published by Tursina Labs. It describes only this app. Other Tursina Labs products are covered by the studio Privacy Policy. Using PulangAman is also subject to the PulangAman Terms of Service.
2. What PulangAman is
PulangAman is a family safety app. A parent or guardian account can watch over a child account: live location, safe zones (geofences), screen time, panic, trips, home-by times, and related family tools. Children join with an invite code created by a parent. The app needs a network connection and our API (hosted at pulangaman-api.onrender.com) to work.
3. Data we collect
We collect only what the product needs to run. We do not sell this data and we do not use it for advertising.
3.1 Account and identity
- Parent and guardian sign-in uses Firebase Phone OTP. We store the verified phone number, a Firebase user id, and a display name.
- Email is optional. We store it only if you provide it.
- Child accounts are created by a parent with an invite code. We store the child's name and account records. Child photos are not used; parents pick a boy or girl avatar in the app.
- Guardian invitations, approval status, and which children a guardian may view.
3.2 Location and safety
- Live location from the child device, sent to our API over HTTPS and (when the app is open) over a WebSocket so the parent or guardian map can update.
- Location history for that child. History older than 7 days is deleted automatically.
- Safe zones you create (name, type such as home or school, map center, and radius).
- Trips, home-by times, and related alerts (including Maghrib home-by when that feature is used).
- Panic alerts, including the location at the time the alert is sent, status, and who was notified.
- Emergency contact names and phone numbers that a parent enters.
- Optional community safety reports (category, optional note, and a location). Reports expire after about 72 hours. The in-app map may show a reduced-precision grid for privacy.
3.3 Devices, notifications, and screen time
- Device records: platform and a Firebase Cloud Messaging (FCM) token so we can send alerts.
- Screen-time telemetry from the child device when protection is enabled: app package names, usage duration, and blocked or override events. Usage records older than about 42 days are deleted automatically.
- Short family messages ("kabar") that a parent or guardian sends to a child, delivered through the API, FCM, and WebSocket.
3.4 On the device
Language preference (English or Indonesian) and session tokens stay on the phone. Clearing app data or uninstalling removes on-device copies. Server copies remain until you delete the account as described below.
4. How we use this data
We use it to:
- Create and authenticate accounts (Firebase Phone OTP for parents and guardians; custom token sign-in for children)
- Show live location, history, and zones to the parent and approved guardians
- Send FCM (and, if panic SMS is configured, SMS) alerts for zones, panic, home-by, and similar events
- Provide screen-time insights to the parent
- Operate trips, rewards, reminders, and related features
- Keep the service secure and debug failures
Location is used for family safety in the app. It is not used for advertising.
5. Children's privacy
PulangAman is built for families. A child account is created and managed by a parent. Children cannot delete their own account from the app or from the public deletion page. A parent can delete a child's data in the app, or delete the parent account, which also deletes children that parent exclusively owns (location history, zones, devices, and related records). Guardians lose access when that child is removed.
Firebase Analytics is enabled only for parent and guardian accounts, not for child accounts. Crash reporting (Firebase Crashlytics) may run for all roles so we can fix crashes.
6. Guardians
A guardian (wali) can view children they have been approved to see. Deleting a guardian account removes that guardian only. Children stay with their parent; child data is not deleted as a side effect.
7. Third parties
We use these processors so the app can run. Their own terms and privacy policies apply to what they receive.
7.1 Firebase (Google)
Firebase Authentication (phone OTP and custom tokens), Cloud Messaging, Crashlytics, optional App Check, and Analytics for parent/guardian accounts. Phone verification is handled by Firebase; we then create or update your PulangAman profile from the verified session.
7.2 Google Maps and Places
Map tiles in the app use Google Maps. When you search for a place to set a zone, our API may query Google Places / Geocoding with your search text. Google may process that request under Google's maps policies.
7.3 Aladhan (api.aladhan.com)
For Maghrib home-by, the API may request Maghrib time with rounded latitude and longitude (not a precise street coordinate). That request is not used for advertising.
7.4 Hosting
The PulangAman API and database run on Render. This marketing site (including the account-deletion page) is hosted on Vercel. Standard server logs (such as IP address and time) may be generated by those hosts.
7.5 SMS (panic, when enabled)
If SMS sending is configured on the server, a panic cascade may send a short text to numbers the parent has set (for example emergency contacts). The SMS provider then processes that phone number and message.
8. What this app does not do
PulangAman does not:
- show ads or use an advertising SDK
- sell your personal information
- use child or location data for advertising
- upload child photos (avatars are boy/girl drawings)
9. Retention
- Account profile, zones, devices, and related records: until you delete the account or the parent deletes the child.
- Location history: about 7 days, then purged.
- Screen-time usage telemetry: about 42 days, then purged.
- Community reports: about 72 hours, then they expire.
- Audit events about account deletion may be kept in a limited form for security and abuse prevention.
10. Your choices and deletion
- Parents and guardians can delete their account in the app (Account settings). That calls
DELETE /api/v1/accountand removes the Firebase user. For a parent, exclusively owned children and their location history, zones, and devices are deleted too. - The same deletion is available on the web after phone OTP: https://www.tursinalabs.com/pulangaman/account-deletion. Child accounts cannot be deleted there; a parent must do it.
- Parents can delete one child's account and related data from inside the app without deleting the parent account.
- You can revoke location, notification, or usage-access permissions in Android settings. The safety features that need those permissions will stop working.
- If OTP is not possible, email support@tursinalabs.com with the registered phone number. We process manual requests within 7 business days.
11. Changes
We may update this page. The "Last updated" date will change when we do. The current policy is always at https://www.tursinalabs.com/pulangaman/privacy.
12. Contact
If you have questions about this policy, contact Tursina Labs:
- Email: support@tursinalabs.com
- Contact page: /contact
This policy is effective as of 25 August 2026 and applies only to PulangAman.