Privacy Policy

Effective August 16, 2026

Draft pending legal review. This page describes, in plain language, the data MyInfo actually collects and how it is actually used, based on the current codebase. It is written to be accurate, not to be legal advice — before this is treated as final, binding policy text, it should be reviewed by qualified legal counsel for COPPA (children under 13, US) and GDPR-for-minors (EU/UK) compliance in the jurisdictions MyInfo operates in. Questions or corrections: support@myinfo.iver03.com.

On this page

MyInfo ("we," "us," "our") provides physical NFC tags that link to a public, no-login web page showing emergency contact and safety information for a child, pet, or belonging. This policy explains what information we collect when you create an account and register a tag, why we collect it, who can see it, and the choices you have.

Information we collect

Account information. When you sign up, we collect your email address, a password (stored as a one-way bcrypt hash — we never store or can recover your actual password), and your full name.

Profile information you add. For each tag you register, you choose to add a name, an optional photo, and — for a person (e.g. a child) — an optional date of birth. For an item (e.g. a backpack or pet), you may add a short description.

Medical information (person profiles only, optional). You may optionally add allergies, medical conditions, current medications, and blood type. This field is entirely optional and is only ever shown on the public page if you turn on "Show medical information" for that profile.

Contact information. For each profile you add one or more contacts (guardians for a person, or owner contacts for an item): a name, relationship (e.g. "Mother," "Owner"), phone number, preferred contact method, and — optionally — a link to a public Facebook profile. This contact information is the core purpose of the product and is always shown on an active tag's public page; it cannot be hidden the way photo or medical information can, since the whole point of the tag is to let a finder reach you.

Consent record. When you create an account, we record the timestamp at which you agreed to this policy (so we can show, if ever needed, that consent was given and when).

Information collected automatically when a tag is scanned. Any time anyone scans or opens a MyInfo tag link — including a finder who has never created an account — we log the scan: a timestamp, the IP address, and the browser/device "user agent" string of whoever scanned it. This is never shown on the public page or to the finder; it is only visible to you (for tags you own) and to us, and exists to detect abuse (e.g. someone scripting requests against tag URLs) and to let you see roughly how often your tag has been scanned.

Information we never collect

MyInfo has no home address field anywhere in the product, by deliberate design. A lost tag is meant to get a child, pet, or item back to a guardian safely — publishing a home address on a tag any stranger can scan would create a physical safety risk, so the option to add one does not exist in the system at all.

How the public tag page works

This is the most important thing to understand about MyInfo: the tag page is intentionally public and requires no login. Anyone who physically has the tag — taps it with a phone, or scans a printed QR/NFC equivalent — can view the information you've chosen to show, with no account and no password. That is the product working as intended: a stranger who finds a lost child, pet, or backpack needs to be able to reach a guardian immediately, without creating an account first.

Because of that, only add information to a profile that you are comfortable a stranger seeing, if the tag is ever lost or scanned by someone other than its intended finder.

What a finder sees depends on the tag's status:

How we use information

We do not use your information for advertising, we do not run third-party analytics or tracking scripts on MyInfo, and we do not sell or rent your information to anyone.

Who can see your information

We do not share your information with any other third party.

Data security

Passwords are hashed with bcrypt and are never stored in plain text. All portal and account actions require an authenticated session and are protected against cross-site request forgery. Login and tag-claim attempts are rate-limited to slow down brute-force attacks. As with any online service, no method of storage or transmission is 100% secure, but we take reasonable, industry-standard measures to protect your information.

Data retention

We retain your account and profile information for as long as your account is active. Scan logs (timestamp, IP address, user agent) are retained to support abuse detection and are tied to the tag, not to a named individual, since the person scanning a tag is typically not a MyInfo user at all. If you delete a profile, any tag linked to it is deactivated first, so a tag can never end up in an "active" state with no profile behind it. If you'd like your account and all associated data permanently deleted, contact us (see below) and we will process the request.

Your choices and rights

Children's privacy

MyInfo is a tool for parents and guardians to manage safety information about their children — children do not create their own MyInfo accounts, do not log in, and are never asked to provide any information directly themselves. All information about a child is entered by the parent or guardian who controls the account, who confirms agreement to this policy when the account is created.

Because a child's profile can include sensitive information (photo, medical details), we apply the same protections described throughout this policy, and we do not use any child's information for marketing or advertising of any kind.

If you are a parent or guardian and believe your child's information has been added to MyInfo without your consent, contact us and we will investigate and remove it.

International users (GDPR)

If you are located in the European Union, United Kingdom, or another jurisdiction with similar data protection law, you may have additional rights over your personal data, including the right to access, correct, export, or erase your data, and the right to object to or restrict certain processing. Our lawful basis for processing account and profile information is your consent (given at signup) and our legitimate interest in operating the safety service you signed up for. To exercise any of these rights, contact us using the details below.

Cookies

MyInfo uses a single first-party session cookie to keep you logged in to your account. We do not use advertising, analytics, or third-party tracking cookies anywhere on the site, including on the public tag page.

Changes to this policy

If we make material changes to this policy, we will update the effective date at the top of this page. Continued use of MyInfo after a change means you accept the updated policy.

Contact us

Questions, corrections, or requests about your data can be sent to support@myinfo.iver03.com.