Executive Summary
If you only have 30 seconds, here are the essential takeaways:
100% Local-First
Your sales, product catalogs, and customers reside solely on your phone (SQLite/Room).
Zero Tracking
No third-party analytics SDKs, no advertising trackers, no user profiling.
Zero Data Brokerage
We never sell, rent, monetize, or transfer your commercial data to third parties.
Hardware-Grade Security
PINs hashed via SHA-256; biometric auth processed inside Android Keystore / TEE.
Minimal Permissions
Camera strictly for barcode scanning; Bluetooth for ESC/POS receipt printers; local Wi-Fi LAN.
Instant Total Purge
Uninstalling the application irreversibly purges all local databases from hardware.
TUANIC ("we", "us", "our", or "the Company") operates the mobile application TUANIC Express POS ("the Application"), a point-of-sale and inventory solution designed for Android. Distributed under the brand ecosystem of tuanic.app, it operates independently with a Local-First architecture.
Local-First Philosophy & Sovereign Data Control
TUANIC Express POS is engineered following strict Privacy by Design principles:
- Sovereign local storage. All of your commercial databases (product catalog, sales records, cash drawer balance, customer credit ledgers, and Kardex inventory movements) are stored locally and exclusively within your Android device's internal storage (SQLite/Room).
- No data commercialization or brokerage. We do NOT sell, lease, monetize, or transmit your commercial data, customer lists, or transaction logs to any data brokers, third-party advertisers, or marketing intermediaries.
- True offline operation. The application requires no permanent internet connection or cloud connectivity to generate receipts, process sales, manage cash, or track inventory. It is entirely yours even if the global internet goes down.
- No mandatory account registration. You do not need to register, create an account, or provide personal credentials on tuanic.app to use TUANIC Express POS.
Data Safety Summary (Google Play Console 1:1 Mirror)
This section strictly mirrors the declarations submitted in the Google Play Console Data Safety Form for TUANIC Express POS. It represents our verifiable and auditable public standard.
| Data Category | Collected? | Shared? |
|---|---|---|
| Location (approximate or precise) | No | No |
| Personal info (name, email address, phone number) | No | No |
| Financial info (credit card numbers, bank accounts) | No | No |
| Health & fitness data | No | No |
| Messages (SMS, emails, chat messages) | No | No |
| Photos and videos | No | No |
| Audio recordings or microphone data | No | No |
| Files and documents | No | No |
| Contacts (address book) | No | No |
| Calendar entries | No | No |
| App activity (in-app analytics, crash logs) | No | No |
| Web browsing or search history | No | No |
| Device identifiers (Advertising ID / AAID) | No | No |
Declared Security Practices: Data is encrypted in transit where applicable (P2P synchronization within your private local Wi-Fi network). You can delete all your data instantly directly from your device. The Application does NOT collect data for third-party advertising or cross-app tracking.
Device Permissions & Technical Purposes
Every requested permission serves an explicit, necessary technical purpose. We never request unnecessary permissions or use hardware features beyond operating your point-of-sale system.
| Permission | Technical Purpose |
|---|---|
Camera android.permission.CAMERA | Optical real-time scanning of 1D barcodes (EAN-13, UPC, Code-128) and 2D QR codes via Google ML Kit On-Device Vision. No photos or video streams are ever captured, stored, or transmitted to external servers. |
Bluetooth BLUETOOTH_CONNECT · BLUETOOTH_SCAN | Discover, pair with, and transmit ESC/POS print commands directly to wireless thermal receipt and ticket printers. |
Biometrics USE_BIOMETRIC · USE_FINGERPRINT | Fast and secure terminal unlocking via fingerprint or facial recognition. Authentication is processed inside the Android Keystore / Trusted Execution Environment (TEE); the Application never accesses raw biometric data. |
Local Wi-Fi Network ACCESS_NETWORK_STATE · INTERNET | Peer-to-peer (P2P) inventory and order synchronization between Master and Slave POS terminals within your same private local Wi-Fi router. No external cloud server is required. |
Haptic Vibration android.permission.VIBRATE | Tactile haptic confirmation feedback upon scanning barcodes, adding items to the register, or completing transactions. |
What We Explicitly DO NOT Collect
For absolute transparency with our users, Google reviewers, and independent security auditors, here is what we never access or collect:
Third-Party Services & Google Play Subscriptions
The Application integrates only the following essential third-party services. No analytics, tracking, or ad-network SDKs are present.
Securely handles the purchase and validation of commercial PRO licenses and subscriptions. All payment information is processed directly by Google Play. TUANIC never accesses credit card numbers or banking data. Subscriptions renew automatically and can be managed or cancelled at any time through Google Play Store > Payments & subscriptions.
View Google's Privacy Policy →On-device barcode and QR decoding executed locally by your phone's processor. Zero image frames or video feeds are sent to external servers.
View Google ML Kit Terms →Data Retention, Export & Permanent Deletion
You Are the Exclusive Owner of Your Data
Because all data resides within your hardware, you can export your sales registers, product catalog, and ledger reports to CSV or Excel at any moment from the in-app tools menu.
Immediate & Irreversible Deletion
If you uninstall the Application or select "Clear Data / Storage" in Android System Settings, the entire local database is immediately and permanently wiped from your hardware. We maintain no remote copies because no server sync takes place.
Data Deletion Inquiries
Should you elect to link optional cloud services in future versions, you may request full account and data deletion by writing to privacidad@tuanic.app. Requests are acknowledged and resolved within 30 calendar days.
Information Security & Cryptography
We implement industry-standard administrative and cryptographic security measures:
- Cashier and administrator PIN passwords hashed locally with cryptographic SHA-256 algorithms and individual random salts.
- Local Wi-Fi P2P terminal communication secured with pre-shared keys and ephemeral private session tokens.
- Biometric authentication strictly delegated to the Android Keystore hardware-backed Trusted Execution Environment (TEE).
- Zero background telemetry, tracking beacons, or analytics daemons.
International Privacy Rights (GDPR · CCPA · LGPD)
Although TUANIC Express POS does not harvest personal records on central servers, we formally recognize and guarantee user rights under international data protection laws:
European Union
GDPR (EU Regulation 2016/679)
- Right of access
- Right to rectification
- Right to erasure (to be forgotten)
- Right to data portability
- Right to restriction and objection
California, USA
CCPA / CPRA
- Right to know categories collected
- Right to delete personal information
- Opt-out of data sales (guaranteed: we never sell)
- Right to non-discrimination
Brazil
LGPD (Lei 13.709/2018)
- Confirmation of processing
- Access to personal records
- Correction and anonymization
- Commercial data portability
To exercise any of these statutory rights or submit formal privacy inquiries, contact our Data Protection Officer at privacidad@tuanic.app. We respond within a maximum of 30 calendar days.
Children's Privacy Protection
TUANIC Express POS is a commercial point-of-sale and business management software that is not intended for use by children under 13 years of age. We do not knowingly collect personal information from minors. If a parent or legal guardian becomes aware that a child has provided data, contact us and we will promptly ensure its permanent removal.
Product Autonomy & Sovereign Scope
TUANIC Express POS is an autonomous mobile software engineered by the TUANIC core team. Its installation and on-device operation do not require mandatory registration on the web platform tuanic.app, unless the user voluntarily opts to enable future cloud backup add-ons.
Modifications to This Privacy Policy
We may update this Privacy Policy periodically to reflect technical enhancements, new features, or statutory regulatory mandates. Material modifications will be published on this canonical URL (https://tuanic.app/privacy/express) and communicated via Google Play Store release notes.
Official Contact & Support Channels
If you have questions, regulatory feedback, or inquiries regarding this Privacy Policy or data sovereignty in TUANIC Express POS, reach out through our official channels:
Data Controller & Intellectual Property Owner
TUANIC Development Team · Samuel Alejandro Barrera Lau