Privacy policy
Consumer health data privacy and your rights
Sideyard has a minimum account age of 16. Account access also depends on country availability and any required eligibility review. This policy explains what we process, what other members can see, and your choices.
Intimate-image removal
If an intimate photo or video of you was shared on Sideyard without consent, request intimate-image removal. You or an authorized representative can request this without a Sideyard account. Valid requests covered by the US TAKE IT DOWN Act have a separate 48-hour removal process; the ordinary seven-day review aim does not replace it. Send identifying details, not intimate files or identity documents.
Who operates the app
Sideyard is provided by FUSIONTECH LABS PTE. LTD., Singapore.
Company contact address:
160 ROBINSON ROAD
#14-04
SINGAPORE BUSINESS FEDERATION CENTER
SINGAPORE 068914
For privacy, access, correction or deletion requests, email contact@fusiontech.sg. This policy applies to the app and its supporting website.
A short guide
Choose spaces with people you trust. People who join a space can read its existing shared history. Sharing your location or birthday is optional. Your age band and country declaration stay in your private account information. You can report a concern, block someone or contact support; your report and identity as the reporter are not shown to the reported person. They may see a limited record of a completed decision affecting them. A family-space owner is not automatically your guardian.
Information you provide
We process your name, email address, account identifiers, password hash or connected sign-in identity, and your settings. We also process what you choose to share: messages, photos, voice notes, files, tasks, event dates, expenses, notes, family relationships, care entries and other shared records. Financial entries are records you enter; the app does not connect to bank accounts or transfer money. Your optional profile birthday is separate from the account eligibility check. Where recorded, we also keep the account ID of the person who last wrote each text field of a shared planning record. This helps distinguish the text's writer from the record's owner when reviewing a concern.
Account age and country eligibility
We ask for an age band, country of residence and, where needed, a statement that you meet a higher regional age threshold. For an account, we record your declaration, its policy version, time and eligibility outcome. These are your own statements, not independently verified age or identity. This check does not ask for your date of birth, identity documents, selfies or guardian evidence. Account access is available only where the current country policy and launch safeguards permit it. If guardian or country review is required, ordinary account access is unavailable until that review can be properly completed. Contacting support, verifying an email address or naming a family-space owner does not itself provide guardian approval. We do not promise availability in every country.
Optional device information
Camera, photo, microphone and foreground location access is requested when you use the corresponding feature. You can refuse or revoke permission in device settings. Location sharing is optional: it shares one snapshot with the other member of a two-person space for a maximum of two hours. It does not continuously track or refresh your position. Visibility is renewed only while the app or browser tab is in the foreground. Leaving the location screen alone continues sharing, with a visible sharing indicator and Stop control. When the app or tab goes into the background, it attempts to stop sharing immediately. If that request cannot reach the service, or the app closes unexpectedly, the snapshot becomes unavailable within 90 seconds of its last successful renewal. Reopening the app does not restart sharing; you must choose to share again. Stop sharing removes the current snapshot when the request succeeds. The snapshot also becomes unavailable if the session that shared it is signed out, expires or is revoked, or if the account is no longer permitted access. We process notification tokens and session identifiers to deliver alerts to the right signed-in device.
How information is used
We use this information to run your account and spaces, store and show shared records, send requested reminders, protect access, prevent abuse, respond to reports and requests, and diagnose service failures. We do not sell your personal information or use your private content for targeted advertising. Generative AI features are disabled for this release.
Analytics and your choices
We use aggregate counts from existing service records to understand sign-ups, group types, invitations and messaging activity. We also record limited successful actions, such as sending an ordinary message, creating an invitation or approving a group join. These action records contain the action type, time and internal account, group and record identifiers for counting and deduplication. They do not copy message text, photos, group names, invitation codes, family relationships or expense details. Only the authorized Sideyard operator can access the aggregate dashboard; it does not display individual accounts or private content.
Optional sign-up measurement is off by default. If you enable it, we record limited steps and outcomes, the sign-in method, app platform and whether the attempt began from an invitation. We use a random identifier for an attempt lasting up to 24 hours; this optional record does not contain your account identifier, email address, country, age, invitation code or page URL. In Analytics & privacy, you can turn it off at any time to stop future optional events and clear the local attempt identifier. Events already received are not recalled by this switch.
Action and optional sign-up records expire after 90 days and are excluded from reports then. Automatic removal normally follows within 24 hours; recovery copies follow the backup policy below. Account-linked action records are included in your private data export and removed by account-deletion cleanup. Optional attempt records are not linked to your account, so account deletion cannot identify them for removal. Existing service records keep their normal retention periods. Our endpoint also uses short-lived, keyed abuse-prevention counters; these expire after two hours.
These measurements stay in our existing Google Cloud hosting and database. We do not add an advertising service or a separate analytics provider. Turning off optional measurement does not stop aggregate counts from existing records or the limited successful-action records described above.
Invitation links and previews
When you create an invitation, anyone with its link or code can see the space name and invitation deadline before signing in. This also applies to two-person spaces. Messaging and social services may fetch these details to show a link preview. The preview does not grant membership or show the space’s member list, conversations or files. When an invitation expires or is revoked, Sideyard stops serving its named preview and no longer allows it to be used to join. We ask browsers and preview services not to cache or index these responses, but other services may keep previews already fetched. Expiry or revocation cannot erase those copies. Avoid sensitive details in a space name and share invitation links only with intended recipients.
Who can see shared content
Current members can see the content shared in their space, including its existing history when they join. Check who belongs to a space before sharing or inviting someone. Every space has separate membership; a family-tree entry does not grant access. Members see your display name, permitted profile photo and any status you choose to set; that status appears across all your spaces. If you add an optional profile birthday, its month and day can appear as a birthday occasion in your spaces, without your birth year. Your email and private eligibility declaration are not shown in shared member profiles. Authorized service personnel may access information where needed to support the service, investigate a report, enforce the rules or meet a legal obligation. Messages and files are not end-to-end encrypted. HTTPS protects the connection, and access checks protect the service.
Service providers
Google Cloud and Firebase provide hosting, database, file storage, authentication, security checks and Android/web notifications. Expo and Apple support iOS notification delivery where enabled. These providers process the information needed for those functions, including device tokens and account or service identifiers. Data is hosted in Singapore where configured; authentication, notification and provider operations can involve processing in other countries. Lovable hosts the Sideyard website at sideyard.ai. When you open the website, Lovable and its hosting providers receive ordinary request information, such as your IP address, browser details, requested page and time of access, to deliver and protect the website. Sideyard's account and shared-content services continue to use Google Cloud and Firebase.
Places and maps
When you add a place, the service sends the place name or search text you enter to Photon, operated by Komoot, and may try OpenStreetMap Nominatim if no result is found. The resulting place name, address and coordinates are saved in your space. Do not include private information in a place search. Maps load tiles directly from OpenStreetMap; that provider receives the requested map area, your IP address and ordinary request information. These map services operate even though generative AI features are disabled.
Remote images and web resources
Decorative artwork is included with the app. When a Google profile photo is displayed, it loads from Google, which receives your IP address and ordinary request information. Unsupported profile-photo links display initials instead. The web notification component loads Firebase software from Google. An Expo Go preview can also load icon fonts from jsDelivr; this fallback is not used by the standalone app builds. Opening a link you choose takes you to that website, whose privacy practices apply.
Photo safety checks
When photo safety screening is enabled, Google Cloud Vision checks the uploaded photo for explicit or violent imagery before it is shared. These automated checks can make mistakes. Rejected photos are not added to your space; contact support if you think a photo was incorrectly blocked. The check does not identify people or read text from the image.
Saved and disappearing photos
Saved photos remain until you delete them or the relevant account or space cleanup removes them. In a two-person space, a disappearing photo becomes unavailable after the recipient opens it or after 24 hours. In a group, it becomes unavailable after 24 hours. Expiry checks apply when the app serves the photo; physical deletion is retried by scheduled cleanup. Disappearing uploads use storage without soft-delete recovery or object versioning. Recipients can still take screenshots or keep copies outside the app.
Retention and backups
We retain active account and shared records while they are needed to provide the service, until you or an authorized member deletes them, or until an applicable expiry. Your private eligibility declaration and its recorded outcome are part of your account and follow the same account-removal and recovery-retention rules. Database recovery history, daily backups and recovery copies of saved files are retained for up to seven days after removal from active storage. Notification jobs expire within two days, or sooner for expiring content. Completed deletion receipts remain for 30 days; failed deletion jobs remain pending until cleanup can finish. Security and service logs are retained under the configured cloud logging policy. Safety reports are retained for up to 90 days. Photo-check support references contain no image or user identifier and expire after 30 days. Blocks remain until you unblock the person or delete your account. Provider records have separate timelines. Firebase Authentication may retain logged IP addresses for several weeks and authentication information for up to 180 days after the provider receives a deletion request. Firebase Hosting may retain request IP data for several months. Notification-provider records follow separate retention schedules. Website hosting providers retain operational records under their own retention policies; deleting your Sideyard account does not necessarily remove those records immediately. Recorded text-writer IDs stay with the planning record while the attributed text remains; they can change when that text is edited and are cleared when it is removed after review. Account-deletion cleanup removes your recorded writer IDs from other members' planning records, although their text may remain. Copies in safety cases follow the separate safety-case retention period.
Deleting your account
In Settings, choose Delete account and verify your sign-in. Transfer ownership first if you are the only owner of a space with other members. Deletion disables your access and processes removal of your account, memberships, connected sign-in identities, records you created and associated uploads. Earlier edits within someone else's record may remain where the app has no edit history. Copies others made outside the app cannot be recalled. A short delay allows ongoing requests to finish, and interrupted cleanup is retried. Visit the account deletion page for a request option without the app. Cleanup also removes your recorded text-writer IDs from other members' planning records, without deleting those records' remaining text.
Your choices and requests
You can edit your profile, remove shared records where permitted, mute spaces, control notifications, stop location sharing and leave spaces. Contact us to request access to or correction or deletion of your personal data, or to raise a privacy concern. We may ask for proportionate proof of account ownership. Depending on your location, you may also have rights to object, restrict processing, withdraw consent or contact your local data protection authority. While eligibility review is pending, you can still use the available account-help, privacy and deletion options. A family member or space owner does not automatically have authority to access your account, messages or personal export.
Reports and help
You can report messages, Moments, shared pages, files, members, and supported task, event, care, expense and saved-link text. The relevant reference, selected text or title, a saved link's URL where applicable, recorded author where known, attachment-presence indicator, your account ID and your note are shared with the operator for review. Reported text can include names, health or fitness notes, event details and purchase or other financial descriptions. Separate expense amount, share and settlement fields are not copied into the report. Attachments are not copied into the report. The operator can check the current text of the reported item before deciding. Other members cannot read your report, notes or identity as the reporter. A person affected by a completed decision can see a limited receipt identifying the affected item and action. For a decision about text with an unknown or mixed writer, the record owner can receive a content-only receipt; this does not identify that owner as the writer. The reporter, affected person or record owner with a receipt can request another review, creating a separate appeal case. Each report or appeal is retained for up to 90 days; an appeal may retain a minimal receipt of its parent decision, without copying the original evidence. Blocking limits contact and messages; it does not remove shared-group membership or erase every shared record. Contact contact@fusiontech.sg for help, including a privacy or safety concern. Do not send suspected unlawful imagery by email. Sideyard is not an emergency service.
Information about other people
Do not create an account for someone under 16. Share information about relatives and other people only when you are entitled to do so. Take extra care with children’s information, health details and identity documents. Being a space owner or adding someone to a family tree does not establish parental responsibility or permission to share their information. Tell us if you believe information has been shared without appropriate permission.
Changes
We will update this page when our practices change. Material changes that affect your choices will also be explained in the app before they take effect. Last updated: 16 September 2026.