Bacupnote
How it worksUse casesPricingFAQ
Sign inSet up your trip

Privacy Policy

Effective date: 4 August 2026

This policy explains what Bacupnote (“we”, “us”) collects, why, and what your choices are. It applies to the website at bacupnote.com and to the Bacupnote mobile apps for iOS and Android. We are based in Malaysia and handle personal data in line with the Malaysian Personal Data Protection Act 2010 and, where it applies to you, the data-protection law of your own country.

1. The short version

Bacupnote stores the minimum needed to hold your prepared message and attempt to deliver it if you miss your check-ins. We do not track your location, we do not collect identity documents or medical data, we do not show ads, and we never sell your data.

2. What we collect

  • Account data — your name or nickname, email address, an optional phone number, your language preference, and a hashed password (we cannot read your password). If you sign in with Google or Apple, we receive your name and email address from that provider — never your Google or Apple password.
  • Plan data — your prepared message text, your check-in schedule and check-in history, and your trip details if you add them (destination and dates you type in — not tracked location).
  • Trusted recipient data — the name, email, optional phone number, and language of each recipient you add. You confirm you have their permission to share these with us (see section 6).
  • Notification logs — a record of every reminder and delivery attempt (channel, time, status), kept so you can see exactly what was sent and when.
  • Billing status — your membership tier and payment status. Card details go directly to our payment provider (Stripe) and never touch our servers.
  • Device data (apps) — if you enable notifications in the mobile app, a push token that lets us deliver reminders to that device. Uninstalling the app or revoking notification permission invalidates it.
  • Operational logs — short-lived technical logs (such as IP address and request time) created by running the servers, used for security and troubleshooting only. Our logs never contain your message content.

3. What we deliberately do not collect

  • No passport, national ID, or identity documents.
  • No medical or health information.
  • No live GPS tracking or location history — the apps never request location permission.
  • No advertising or cross-site tracking, and no analytics profiles of your behaviour.
  • No contact with police or authorities, so no data flows to them from us.

4. How and why we use your data

We use your data only to run the Service: creating and securing your account, sending you check-in reminders on the channels you enable (email, push notification, WhatsApp), attempting delivery of your prepared message to your chosen recipients when your schedule is missed, showing you your own logs, and processing membership payments. We rely on the contract we have with you (providing the Service you signed up for), our legitimate interest in keeping the Service secure, and your consent for optional channels — which you can withdraw at any time by disabling them. We send only transactional messages; we do not send marketing. We do not use your content for advertising, do not use it to train AI models, and do not sell personal data to anyone.

5. Who receives your data

  • Your trusted recipients — they receive your prepared message if delivery is triggered.
  • Stripe — payment processing. Your card details go only to Stripe; we see the outcome and your subscription status.
  • Resend — sends our transactional email (reminders, verification, password reset, and prepared-message delivery).
  • Meta (WhatsApp Business) — if WhatsApp reminders or alerts are enabled. The WhatsApp alert contains only the sender’s name and a prompt to check email — your message text is never sent through WhatsApp.
  • Google Firebase — delivers push notifications to the mobile apps.
  • DigitalOcean — hosts our servers and database (Singapore region).
  • Cloudflare — provides our network layer and stores encrypted database backups.

These providers process data only to provide their service to us. We do not share personal data with anyone else unless the law requires it.

6. If you are a trusted recipient

Someone who uses Bacupnote may have added your name and contact details so that their prepared message can reach you. We email you first so you can confirm that role — if you do nothing, you stay unconfirmed and we use your details only to deliver that person’s messages. We do not add you to any marketing list. If you want your contact details removed, write to [email protected] and we will remove them.

7. Where your data lives and international transfers

Our servers and database are located in Singapore, and the providers listed above may process data in other regions where they operate. Wherever data is processed, it remains protected by this policy and by our contracts with those providers. If you use Bacupnote from a country whose law restricts international transfers, you consent to these transfers to the extent your consent is required for us to provide the Service.

8. Retention and deletion

  • Your data is kept while your account exists, so your backup note is always ready.
  • When you delete your account (available in settings), your plans, prepared messages, recipient details, and push tokens are removed, and any active subscription is cancelled first so you are not billed again.
  • You can also delete individual plans and recipients at any time, and trusted recipients can remove themselves with the decline link in the email they receive.
  • Encrypted database backups are retained for up to 14 days, after which deleted data ages out of them.
  • Billing records are retained only as long as tax and accounting law requires, then deleted. Operational logs are kept briefly and rotate automatically.

9. Your rights

You can access and correct your data in the app, download a full export of it from settings, and delete your account yourself — no request needed. If you are a trusted recipient added by someone else and want your contact details removed, use the decline link in the email we sent you, or write to [email protected] and we will remove them. Depending on where you live, you may also have legal rights to access, correct, delete, restrict, or object to processing of your data, and to complain to your local data-protection authority. To exercise any right you cannot reach from settings, email [email protected]; we respond to verified requests within the time your local law sets, and we never charge for it.

10. Cookies and local storage

The website uses only what is essential to keep you signed in (a token in your browser’s local storage) and your language preference. There are no advertising cookies and no third-party analytics trackers. If that ever changes, we will update this policy and tell you first.

11. Children

Bacupnote is for adults. We do not knowingly collect data from anyone under 18; if you believe a minor has created an account, contact us and we will remove it.

12. Security

Data is encrypted in transit everywhere. Passwords are stored using a strong one-way hash. Production access is restricted and authenticated, backups are stored encrypted, and payment card data never touches our systems. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as required by law.

13. Changes and contact

If we make material changes to this policy we will notify you by email or in the app before they take effect, and the “Effective date” above will change. Questions or requests: [email protected]. See also our Terms of Service.

見字如面 · 一切平安

HomePricingMembershipSettingsTermsPrivacyDelete account

Bacupnote is a prepared-message tool. It is not an emergency service and does not contact police, hospitals, embassies, or rescue services, and does not confirm safety, health, location, or life status.