Titipan Privacy Policy

A record of what an adult holds for a child, witnessed over time.

Effective September 6, 2026 · Developer: Saifullah Ahad
Android package: ai.saifullah.titipan

What Titipan does

Titipan helps adults keep inventories and changes to assets held for a young beneficiary. Other adults sign entries in person. Recovery holders keep separate key parts so the beneficiary can open the history after reaching adulthood. Titipan is a recordkeeping tool; it does not establish ownership, decide disputes or provide legal, investment or financial advice.

Data handled by the app

You may enter adult display names, a beneficiary’s name, birth month and coming-of-age date, asset descriptions, physical quantities, transaction explanations and optional currency annotations. The adult setup date is checked on the phone and is not retained. Optional document photographs stay in Titipan’s internal storage and are excluded from its cloud and nearby record exchanges.

The phone creates cryptographic device keys. Its private keys, local records and any recovery part held by that adult are protected by Android Keystore encryption. A guardian’s phone cannot receive a recovery share. The complete beneficiary key is never saved; it exists temporarily while shares are created or combined.

Camera access is optional, for reading nearby QR codes and taking a document photograph. Camera frames used to read QR codes are not uploaded or retained. Optional fingerprint or face unlock uses Android’s biometric prompt; Titipan does not receive biometric templates. An optional app PIN is stored as a salted hash. Titipan does not access contacts, location, microphone, advertising identifiers or payment cards.

How information is used

Records provide the inventory, physical-unit account, witness checks, printed statements, device replacement and adult handover. Device public keys authorize access to encrypted cloud copies. Page hashes, sequence numbers, witness authorizations and server receipt times make conflicting copies detectable. These checks establish agreement between records, not the truth of an event outside the app.

Sharing and service providers

Nearby exchanges are encrypted for the adult selected by you, except public identity and meeting requests. Witnesses and recovery holders you involve can keep their own copies. A printed statement is readable by its recipient. A recovery card contains one secret share: only give it to its intended holder. Three distinct parts can reconstruct the beneficiary key.

Cloudflare Workers, Durable Objects, D1 and R2 operate the anchor and encrypted archive service. The service receives encrypted archives, random record identifiers, public signing keys, membership roles, hashes, signatures, sequence numbers, receipt times and upload sizes. Record names, quantities, asset descriptions and relationships remain inside encrypted data that the service does not have keys to open. Network infrastructure processes IP addresses and standard request information to deliver and protect the service. Titipan includes no advertising, analytics or third-party crash-reporting SDK.

Cloud copies are transmitted over HTTPS after witnessed changes or a requested sync. Local work remains available when there is no connection. Information is not sold. User-directed exchanges and service-provider processing are used only for Titipan’s recordkeeping functions.

Retention and deletion

The account is intended to survive for years, including the beneficiary’s childhood. Local records remain until you remove them in Settings or uninstall the app. Android system backup is disabled for this app. Clearing local data destroys this phone’s access keys; keep the independent recovery arrangements before doing so.

Settings → “Delete copies uploaded by this phone” removes encrypted cloud copies that this device uploaded. This requires a connection and the device’s original keys. Do this before deleting local data if you also want those cloud copies removed. Later syncing creates a new copy. Settings → “Remove this phone’s data” removes local records and local photographs. Other adults’ copies, exported statements and printed cards cannot be erased by another phone.

Signed anchor hashes, public membership history and receipts are retained as independent integrity evidence. They contain no plaintext asset record. The app cannot rewrite or erase this evidence on the guardian’s instruction. For a privacy or deletion request, email www.saifullah.ai@gmail.com; provide only the random account code if relevant, never a recovery part, PIN or private key. We will explain which records can be removed and which independent evidence or third-party copies remain.

Feedback and safety reports

Feedback and reports open your email app. Nothing is sent until you send the email yourself. Your email provider and the developer’s inbox process the content and sender address. Reports are retained only as needed to respond and address the issue. Avoid including a child’s documents, secret recovery parts or other unnecessary personal information.

Children and responsible use

Titipan accounts are for adults aged 18 and over. A minor may be the subject of an adult’s record, but does not need an account, phone, key or identity document. Adults must have authority to record and share the information they enter, use the minimum necessary details, and meet the recovery recipient in person before releasing a share. The app has no public profiles, discovery, feed or stranger messaging.

Child sexual abuse and exploitation, unlawful content, harassment and misuse of another person’s information are prohibited. See the Child Safety Standards. Reports can be made through the in-app safety screen or by email.

Policy changes

This page will show the effective date of any change. Material changes to data handling will be reflected in the app’s disclosures and this policy.