What OurHug does with your family's things
Last updated 15 September 2026. This is the whole of it, written plainly. If anything here is unclear, ask and we will fix the wording.
The short version
- Your family's things are visible to your family and to nobody else.
- We do not sell anything, share anything, or show advertising.
- There is no tracking, no analytics company, and no profiling. The app contains no third-party code at all.
- You can delete your family and everything in it, from inside the app, at any time.
Who we are
OurHug is run by Witawat M., an individual in Bangkok, Thailand. There is no company behind it and no investors. You can reach a person at support@ourhug.app.
What is stored
Your account
Your name, your role in the family, and — if you set one up — an email address and a password. Passwords are stored only as a slow one-way hash; nobody, including us, can read yours.
What your family puts in
Everything the app is for: calendar events, to-dos and chores, shopping lists, meals and recipes, what is in the pantry, spending and allowances, points and rewards, challenges, notes, contacts, trips, occasions, school work and term dates, home maintenance records, time capsules, photographs and files, documents kept behind a passcode, an emergency card, and height and weight measurements where a family chooses to record them.
Some of that is sensitive by any definition — a passport scan, a child's school record, a measurement, a photograph of your family. It is treated as such below.
Technical records
Sign-in sessions, the devices you have allowed notifications on, a log of significant actions inside your household (who invited whom, who closed what) so a family can see its own history, and a short-lived record of failed sign-in attempts so an account can be protected from guessing.
What is not stored
No location or GPS. No contacts from your phone — the contacts in the app are the ones somebody typed in. No microphone or camera access except when you take a photo or record a message, and that recording goes only where you put it. No advertising identifiers.
Children
OurHug is a tool for a household, and households contain children. This is deliberate and it changes how the app is built.
- A child never signs themselves up. A parent creates the family and each person in it. A child's access exists because a parent made it and lasts as long as the parent allows.
- A parent can see and delete everything about their child at any time, including anything the child added.
- Nothing about a child leaves the family. No advertising, no profiling, no analytics, no recommendations, no third party of any kind.
- Children are not contacted. Notifications go to devices the family has set up; there is no messaging with anyone outside the household, and no way for a stranger to reach a child through OurHug.
If you are a parent and want a child's information removed, you can do it yourself in the app, or write to us and we will do it.
Who else can see any of it
Within a family, some things are deliberately narrower: documents and the emergency card sit behind a second passcode, and anything marked adults-only is not shown to a child's account. Outside your family, the list of everyone who touches your data is short and complete:
- Render hosts the server and the disk. The data lives in Singapore.
- Resend sends the handful of emails the app sends — an invitation, a password reset, a confirmation. They receive the recipient's address and the message, nothing else.
- Apple, Google or Mozilla deliver push notifications to your phone, because that is the only way notifications work. The contents are encrypted before they are handed over, so the delivery service cannot read them.
That is the entire list. There is no analytics provider, no advertising network, no crash reporter, no customer-support widget and no tag manager, because the app has no third-party code in it.
We would hand over data if a court with jurisdiction over us ordered it. We will tell you if that happens, unless we are forbidden from doing so.
How it is protected
- Every file and photograph is encrypted on the disk with a key belonging to your household alone.
- Households are separated in the database itself: a query that does not name a household is refused rather than trusted.
- Documents and the emergency card need a second passcode, entered again each session.
- Everything travels over HTTPS.
No system is perfect and it would be dishonest to say otherwise. If something goes wrong that affects your data, we will tell you what happened and when, in plain language.
How long it is kept, and how to end it
Your family's data is kept while your family exists. There is no expiry and nothing is deleted behind your back.
Closing your family is done in the app, by an owner. It takes effect immediately and signs everyone out. For seven days it can be undone, in case it was a mistake or a bad afternoon. After that it is purged permanently — every table, every file, every photograph.
One honest detail: the server keeps nightly backups for up to fourteen nights, so for a short period after a purge your data still exists inside those backup files. They are encrypted, nobody reads them, and they roll off on their own within two weeks. After that it is gone everywhere.
Your rights
Under Thailand's PDPA, and under the GDPR if you are in Europe, you can ask to see what is held about you, correct it, delete it, or have a copy of it. Most of that you can do yourself inside the app, immediately, without asking anyone. For anything you cannot, write to support@ourhug.app and we will answer within 30 days.
If you think we have handled your data badly, you are entitled to complain to your data protection authority — in Thailand, the PDPC.
Changes to this page
If this changes in a way that matters, everyone with an account will be told inside the app before it takes effect — not by quietly editing this page and changing the date at the top.