1. Who we are
MaPause is offered by Fraction Compliance Inc., a Washington C Corporation (“Fraction Compliance,” “we,” “us,” or “our”). Our mailing address is [[COMPANY_MAILING_ADDRESS]]. Our privacy contact is [[PRIVACY_EMAIL]]. These identity and contact fields must be confirmed before launch.
2. Scope and a note about the product
This policy applies to the MaPause mobile app for iOS and Android, the MaPause website, and related support interactions (together, the “Services”). It does not apply to third-party services linked from or used with MaPause; those services have their own notices.
MaPause is a relationship-support and self-reflection tool. It is not medical, mental-health, crisis, legal, or professional relationship advice. Do not use it as a substitute for qualified care or emergency services.
Current versus planned behavior
Current source-backed behavior: a local 5-, 10-, or 20-minute pause, guided breathing language, a reconnect prompt, optional local photos and montage, and a bundled local “Eucalyptus Rain” soundscape. Photos are not uploaded automatically; normal device backup behavior may still include app data.
Conditional or planned behavior: accounts, pairing, cloud coordination, shared media, notifications, provider integrations, premium features, and any analytics or measurement must be described only after the shipped build, privacy disclosures, provider settings, and retention choices are confirmed.
3. Information we may collect
The exact collection depends on the features enabled in the released build. The owner must reconcile this inventory with the final Apple App Store privacy answers, Google Play Data safety form, SDK list, and backend configuration.
| Information | Why it may be used | Status and handling |
|---|---|---|
| Account identifiers, such as email or provider subject ID | Create, authenticate, secure, and support an account. | Only when account or cloud features are enabled. Confirm the identity providers, fields, and retention. |
| Couple profile, invite, or pairing data | Connect consenting users and coordinate an enabled experience. | Conditional. Confirm whether names, email addresses, invite codes, or relationship metadata are stored. |
| Pause state and readiness signals | Run a pause, show timer state, and support an enabled reconnect flow. | Core timer state is local in the current source. Any synced state requires separate confirmation. |
| Photos selected in the app | Display a private local collection or montage. | Current source stores them in app-local storage and does not automatically upload them. Device backup and user-initiated provider storage are outside this promise. |
| Music-provider information | Support optional Apple Music or Spotify playback controls if the user connects a provider. | Optional and user initiated. Provider permissions and data use remain governed by that provider. |
| YouTube account or video information | Support an enabled ambient-video or music feature. | Conditional and gated in the current app. Confirm exact OAuth scopes, tokens, logs, and retention before launch. |
| Support messages and contact details | Respond to questions, privacy requests, or deletion requests. | Support and privacy channels are placeholders in this draft. Confirm the system of record and retention. |
Based on the reviewed source, MaPause is not designed to collect conversation transcripts, ambient microphone audio, precise location, emotion classifications, or a relationship-health score. That statement must be revisited if product scope changes.
4. How we use information
Subject to the final product configuration and applicable law, we may use information to:
- provide, maintain, and secure the Services;
- run pauses and other features a user requests;
- authenticate users and coordinate enabled cloud features;
- respond to support, privacy, and deletion requests;
- prevent abuse, troubleshoot failures, and protect users and our systems;
- comply with law and enforce our agreements; and
- perform limited product operations only as disclosed in the final notice.
Do not publish a broader analytics, advertising, profiling, or automated-decision statement unless those practices are actually implemented and disclosed.
5. How we share information
We may share information with service providers that help us operate the Services, such as hosting, authentication, database, storage, email/support, error monitoring, or payment providers. The current policy workspace identifies Supabase and optional Google, Apple Music, Spotify, and YouTube connections as items requiring final configuration review.
We may also disclose information when required by law, to protect rights and safety, in connection with a corporate transaction, or with a user’s direction. We do not sell personal information or use private relationship content for targeted advertising under this draft. Confirm that statement against every SDK, provider, and business model before publication.
6. Cookies and similar technologies
The landing page is designed as static HTML, CSS, and JavaScript with no required analytics or advertising scripts. If cookies, pixels, analytics, embedded media, or other tracking technologies are added, update this section and any consent experience before launch.
7. Retention and deletion
We retain information only for as long as reasonably needed for the purposes described in the final notice, legal obligations, dispute resolution, security, and legitimate operational needs. Exact retention periods are [[RETENTION_SCHEDULE_TO_CONFIRM]].
The current mobile source includes an in-app Settings → Cloud coordination → Delete account path that clears local app data and calls a Supabase Edge Function when a valid cloud session exists. The source also contains a deletion migration and function, but hosted deployment and end-to-end execution have not been verified for this site. The public deletion page is therefore a documented request boundary, not proof that a web request deletes an account.
Deletion may not remove copies held in device backups, third-party provider accounts, legal records, or independent systems outside our control. See Account deletion for the current implementation boundary.
8. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the Services. No service is completely secure. Final publication should name the operating environment, access controls, incident process, encryption posture, logging limits, and responsible owner only after they are confirmed.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing is consent-based. To make a request, use the deletion page or contact [[PRIVACY_EMAIL]]. We may need to verify the request and may have lawful exceptions. The request workflow and response timelines are [[PRIVACY_REQUEST_PROCESS_TO_CONFIRM]].
10. Children
The Services are not directed to children under [[MINIMUM_AGE_TO_CONFIRM]], and we do not knowingly collect personal information from children in violation of applicable law. If you believe a child provided information, contact [[PRIVACY_EMAIL]]. Confirm the age gate, parental-consent approach, and jurisdictional requirements before publication.
11. International users
Information may be processed in the United States and other countries where our providers operate. The countries, transfer mechanisms, and supplemental disclosures are [[INTERNATIONAL_TRANSFER_DETAILS_TO_CONFIRM]].
12. Third-party services and links
MaPause may link to or work with Apple, Google, YouTube, Spotify, Supabase, app stores, or other providers. Their terms, privacy notices, permissions, and deletion controls apply to their services. Review every integration in the shipped build and avoid suggesting that Fraction Compliance controls a provider’s data.
13. Changes to this policy
We may update this policy as the Services change. We will post the updated version at this URL and change the effective date. Material-change notice, if required, will be provided through [[NOTICE_METHOD_TO_CONFIRM]].
14. Contact
Privacy questions and requests: [[PRIVACY_EMAIL]]
General support: [[SUPPORT_EMAIL]]
Mail: [[COMPANY_MAILING_ADDRESS]]
Publication gate
Before publishing, the owner and counsel should confirm the legal entity, contact details, dates, age policy, retention, rights process, international transfers, provider list, SDKs, store disclosures, cloud deployment, account deletion, and every placeholder in this document.