Legal

Privacy Policy

This Privacy Policy explains how Tech And Graphics (“we”, “us”, or “our”) handles information when you use the Hymn website, the Hymn Android app, and related services (together, the “Services”). It reflects how the product works today. It is not formal legal advice.

Last updated 21 August 2026

Who we are

Hymn is operated by Tech And Graphics. You can reach us at info@tag.mw or via tag.mw.

Services covered

This policy applies to:

  • The Hymn website (including public hymn browsing and admin tools)
  • The Hymn Android app (net.techandgraphics.hymn)
  • Our API and identity systems that support those clients

Information we collect

Website (public)

When you browse hymns without signing in, we do not require an account. The site may store preferences on your device only:

  • Theme preference (light / dark) in browser localStorage
  • Language preference in browser localStorage

We do not run advertising SDKs or third-party analytics pixels on the public website. We do not use cookies for authentication on the public site.

Website (admin)

Admin users sign in through Keycloak. Session tokens are kept in browser sessionStorage for the duration of the admin session. Through Keycloak and our API we may process identity details such as email, username, display name, and roles needed to manage hymn content.

Android app — on your device

The Android app stores data locally so you can use Hymn offline and personalise the experience, including:

  • Hymn catalog content synced to the device
  • Favourites
  • Search history
  • Visit / reading history and time spent reading
  • App settings (theme, accent colour, font, size, translation, keep-screen-on, and similar preferences)
  • Optional local backup files you create or restore yourself

Android app — network and Google Firebase

The Android app communicates with our content API (for example, to check content version and download hymn bundles). It also uses Google Firebase services:

  • Firebase Analytics — app usage events (for example screen views, searches, favourites, theme or language changes). Event payloads may include hymn titles or numbers and search keywords.
  • Firebase Crashlytics — crash and stability reports to help us fix bugs
  • Firebase Performance Monitoring — performance traces
  • Firebase Cloud Messaging (FCM) — push notifications (for example content updates), which involves a device messaging token and topic subscriptions

You can control notification permission in your device settings. Uninstalling the app or clearing app data removes local Hymn data on that device.

API and cloud features (when signed in)

If you use authenticated API features (for example a linked account, cloud backup, or device token registration), we may store:

  • Profile information from Keycloak (such as subject ID, email, preferred username, and display name)
  • Cloud backup of favourites, search history, reading time, visit timestamps, and settings
  • FCM device tokens linked to your profile

Public hymn catalog content itself is not personal data.

How we use information

We use information to:

  • Provide, sync, and improve hymn content and the Services
  • Remember your preferences and reading activity on device (and in cloud backup when enabled)
  • Diagnose crashes and performance issues
  • Understand aggregate product usage via Analytics
  • Send operational notifications such as content updates
  • Authenticate admins and protect the admin CMS
  • Respond to support requests you send us (for example by email or WhatsApp)

Sharing and processors

We do not sell your personal information. We use service providers that process data on our behalf or as independent platforms you interact with:

  • Google Firebase (Analytics, Crashlytics, Performance, Cloud Messaging)
  • Keycloak hosted for Hymn identity (currently at keycloak.tag.mw)
  • Hosting and database providers that run our API and MySQL datastore

Third-party sites we link to (for example Google Play, WhatsApp, or tag.mw) have their own privacy practices.

Cookies and similar technologies

The public website does not rely on tracking cookies for ads or analytics. Preference keys in localStorage and admin tokens in sessionStorage are used for functionality described above. The Android app uses local databases and preferences rather than browser cookies.

Retention

Local app and browser data remain on your device until you clear them, reset stats (where available), restore over them, or uninstall the app.

Server-side profile, backup, and device-token data are retained while needed to provide the Services or until we process a deletion request. We do not currently offer a fully self-serve account deletion flow in the app; contact us if you need server data removed.

Crash, analytics, and messaging data held by Google Firebase are also subject to Google’s retention practices for those products.

Security

We use industry-standard measures appropriate to our Services, including HTTPS for network traffic and token-based authentication for protected API routes. No method of transmission or storage is completely secure.

Children’s privacy

Hymn is a general-audience hymnal. We do not knowingly collect personal information from children for marketing. If you believe a child has provided personal data to us inappropriately, contact info@tag.mw and we will take reasonable steps to delete it.

Your choices

  • Notifications — manage or revoke notification permission in Android system settings
  • Local data — clear app storage, reset listening stats in Settings where available, or uninstall the app
  • Admin session — sign out to clear sessionStorage tokens on the website
  • Analytics / diagnostics — limited by OS and Firebase defaults; uninstalling stops further app-side collection from that install
  • Server data — email info@tag.mw to request deletion of profile, cloud backup, or device tokens we hold

International users

We are based in Malawi. Information may be processed in Malawi and in other countries where our processors (including Google) operate.

Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of the Services after an update means you acknowledge the revised policy.

Contact

Questions about privacy: info@tag.mw

Operator: Tech And Graphics · tag.mw