MahasDev MahasDev
← Privacy Policy
Legal

Privacy Policy — HR Mini

Effective date: August 15, 2026 · Last updated: August 21, 2026

1. General Information

This Privacy Policy explains how the HR Mini application (“the App”, “we”) handles, stores, and protects your information. HR Mini is a simple attendance and payroll app for small businesses that runs locally on your device. All core features — employee records, attendance, shift schedules, cash advances, leave, and payroll calculation — work without an account and without an internet connection.

To date the App has no login system and does not sync your business data to our servers. No employee record, attendance entry, photo, or payslip ever leaves your device unless you share it yourself (see Section 5).

By downloading or using this App, you agree to the practices described in this policy.

2. Data We Collect

Data CategoryExamplesStored InStatus
Employee DataName, phone number (optional), job title, salary settings, leave allowance, profile photo (optional)Local (your device)Local
Attendance & Schedule DataClock-in/out times, lateness/overtime, shift schedules, holidays, shift swapsLocal (your device)Local
Attendance SelfiesFront-camera photo taken when clocking in/out (Employee Mode)Local (your device)Local
Attendance LocationGPS coordinates at clock-in, distance to the outlet, mock-location flagLocal (your device)Local
PINsEmployee PIN (Employee Mode) & the owner’s app-lock PINLocal, fingerprint onlyLocal
Financial DataCash advances and their transaction history, payslips, commissions/deductionsLocal (your device)Local
Business DataBusiness name, business type, time zone, outlet location & radiusLocal (your device)Local
Diagnostic & Crash DataStack traces, OS version, device model, active plan codeFirebase CrashlyticsAutomatic
Analytics DataScreen names opened and feature-usage events, app version, active plan codeFirebase AnalyticsAutomatic
Purchase DataSubscription status and purchase history (no card numbers)RevenueCat & Google PlayWhen subscribing

Important: The App does not require an account, does not ask for national ID numbers or full home addresses of employees (data minimisation), and displays no advertising.

PINs are never stored as-is. Both employee PINs and the app-lock PIN are stored only as a salted fingerprint (HMAC-SHA256). As a result, a forgotten PIN cannot be recovered by anyone, including us — the only way back is to reinstall the App and restore from your backup file.

3. How We Use Data

  • Business data (local) — Used entirely by you to manage employee attendance and payroll. We cannot access data stored locally on your device.
  • Selfies & location — Used only to evidence attendance in Employee Mode (to prevent buddy punching). They are not analysed, not transmitted anywhere, and not used for facial recognition.
  • Crash & diagnostics — To improve the App’s stability and quality.
  • Analytics — To understand feature usage in aggregate for product development. Events sent contain only an event name (e.g. absensi_dicatat, laporan_dibuka) and the plan code — no employee names, salary amounts, photos, or coordinates.
  • Purchase data — To determine which subscription plan is active on your device.

4. Data Storage

All of your business data is stored only on your device in a local SQLite database. This data is not sent to our servers.

Attendance selfies and employee profile photos are stored as files inside the App’s private directory (a sandbox other apps cannot read), not in the device photo gallery.

The Backup & Export features (.db database file, JSON, Excel) produce files on your device. Backup files are kept in the App’s private directory and only leave the device if you share them yourself. We do not receive those files. Because the data is local, you are responsible for keeping your backup files — if the device is lost without a backup, we cannot recover the data.

Diagnostic and analytics data is handled by Firebase and subject to the Firebase/Google Privacy Policy.

5. Data Sharing with Third Parties

We do not sell your data. The following third-party services are integrated into the App, along with the data they may receive:

ServicePurposeData Shared
Firebase Crashlytics & AnalyticsCrash reporting, usage analyticsCrash logs, screen names, usage events, app version, plan code
RevenueCatSubscription status managementAnonymous device identifier, product ID, subscription status
Google Play BillingProcessing subscription paymentsPayment details are handled by Google — we never receive your card number

No other third party receives your data. The App contains no advertising SDKs.

Sharing that you initiate

Some features hand files or text to another app of your choosing (WhatsApp, email, Google Drive, iCloud, a file manager). In those cases you determine the recipient, not us:

  • Send payslip to WhatsApp — sends a PDF payslip containing the employee’s name and salary breakdown.
  • Backup & Export — sends a file containing all of your business data. Treat that file as carefully as you would a payroll ledger.
  • Export Reports (PDF/Excel) — contains the data of the selected report.
  • Reports & Feedback — sends your message along with the app version, device type, OS version, active plan, and business name. Employee, attendance, and payroll data are not included.

6. Camera, Location, and Notifications

The permissions below are requested only when the feature that needs them is actually used, and the App keeps working if you decline.

PermissionUsed forIf declined
CameraAttendance selfies in Employee Mode, and employee profile photosEmployee Mode cannot be used; manual attendance entry by the owner still works
LocationRecording position when clocking in via Employee ModeAttendance is still recorded, simply without coordinates, with the reason noted
NotificationsOccasional reminders related to app usageNo notifications; no other feature is affected

Rules that apply to self-service attendance (Employee Mode):

  • Only the front camera is used, and photos cannot be chosen from the gallery — so the photo is genuinely taken at that moment.
  • Employees see a consent screen on the device before their first clock-in, explaining what is collected, why, and for how long it is kept.
  • Location is captured only at the moment the attendance button is pressed — never continuously, and never in the background.
  • If the device is detected using a mock location, attendance is still recorded but flagged so the business owner can judge it.
  • Selfies are deleted automatically according to your plan’s retention period (see Section 9). Non-photo attendance data (times, status) is retained.

7. Employee Data & Indonesian Data Protection Law

As the business owner recording employee data, you act as the data controller for your employees under Indonesia’s Personal Data Protection Law No. 27/2022. Because the data never reaches our servers, we do not process your employees’ data — the App is simply a tool you run on your own device.

HR Mini supports that compliance by providing:

  • Data minimisation — The App only asks for data needed for attendance and payroll; there are no fields for national ID numbers or full addresses.
  • Consent — A per-employee consent screen before selfies and location are captured for the first time.
  • Limited retention — Selfies are deleted automatically per Section 9, with no action needed from you.
  • Right to erasure — Departing employees may request deletion of their data; you can deactivate an employee, or delete them permanently, from within the App.
  • Transparency — Payslips and cash-advance history can be shared with employees as proof of calculation.

Facial photographs are a specific category of personal data. Please make sure your employees genuinely understand and consent to their use before you enable Employee Mode.

8. Data Security

  • Local data is protected by your device operating system’s app sandbox.
  • PINs are stored as salted fingerprints, never as plain text.
  • The App offers an optional PIN lock: when enabled, the PIN is required every time the App is opened and when leaving Employee Mode — so employees sharing a device cannot reach payroll data.
  • Connections to diagnostic and subscription services use encryption in transit (HTTPS).

We recommend enabling your device’s screen lock and storing backup files somewhere safe. That said, no method of electronic storage is 100% secure.

9. Data Retention

  • Local business data — Kept on your device for as long as the App is installed, or until you delete it yourself (per record, or entirely by clearing app data/uninstalling).
  • Attendance selfies — Deleted automatically when the App is opened, according to your plan’s retention period (see the table below).
  • Local backup history — The App keeps up to the 10 most recent backup files on the device; older ones are discarded automatically. You can delete them at any time from the Backup & Data page.
  • Crash & analytics data — Follows Firebase’s retention policy (typically 90 days for detailed crash data).
  • Subscription data — Retained by RevenueCat/Google Play while the subscription is active and thereafter per their policies.

Attendance selfie retention by plan:

PlanPhoto retention
FreeNo photos stored at all
Basic30 days
Pro6 months
Business12 months

10. Your Rights & Data Deletion

You retain full control over the data on your device:

  • Delete individual employee records or entries directly within the App.
  • Delete attendance photos sooner than their retention period by deleting the attendance record.
  • Delete all data by clearing app data (device Settings) or uninstalling the App. This cannot be undone and we cannot recover it.
  • For questions or data-related requests (including diagnostic data), contact us via Section 13, or through the Reports & Feedback menu inside the App.

11. Children’s Privacy

This App is intended for business owners and is not directed at children under 13. We do not knowingly collect data from children.

12. Changes to This Policy

This policy may be updated from time to time, including when new features (such as cloud sync or attendance from each employee’s own phone) are released. Material changes will be announced through app updates and the “Last updated” date above.

13. Contact Us

For questions about this privacy policy or data-related requests: