Privacy Policy
This site holds your health data, so you should know exactly what is stored, why, who can see it, and how to get it back or erase it.
1. Who holds your data, and how to reach them
https://mylamduan.com/ is operated by Lamduan, the data controller under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
For anything to do with your personal data, write to admin@mylamduan.com — access requests, corrections, deletion, or withdrawing consent.
2. Exactly what is stored
Account data
- Username, email and password (the password is stored as a one-way hash — nobody can read it back, not even the site owner)
- Your display name and the gender you selected
- Your language choice and the date you registered
Health data (sensitive personal data under PDPA section 26)
- Weight, body fat percentage, cycle day and daily notes
- Carbs, protein, fat, times, meal types and the names of foods you ate
- Activity types, training times and minutes spent in each heart-rate zone
- Your fasting and eating windows
Technical data
- Your IP address temporarily, for at most 15 minutes, purely to rate-limit failed logins, then deleted automatically
- Mobile app tokens, stored only as hashes — never the token itself
What is never collectedNo location. No cross-site tracking. No Google Analytics. No advertising pixels. No card or bank details.
3. Why it is collected, and the legal basis
- Account data — necessary to provide the service; without it there is no way to tell whose rows are whose
- Health data — held on the basis of the explicit consent you give at registration, as PDPA section 26 requires. You may withdraw it at any time
- Technical data — legitimate interest in keeping the system secure
Everything is used only to show you your own history, averages and charts. It is never used for advertising, never sold, never traded. No automated decision-making with legal effect is performed on it.
4. Who can see it
- You — you see only your own data; every query is scoped to your account
- The site owner — technically has database access as the server owner, but only looks when a system problem requires it
- The hosting provider — keeps the server the data sits on
- Google Fonts — the site loads fonts from Google, so Google sees visitors' IP addresses. This is the only thing that leaves the system, and it never includes health data
Beyond that, data is disclosed only where the law compels it.
5. How long it is kept
- Health and account data are kept as long as the account exists — long-term history is the entire point of the service
- Deleting your account deletes every row in every system immediately and permanently. No copy is retained
- Rate-limiting IP records are deleted automatically within 15 minutes
- App tokens expire automatically after 30 days of no use
Host backupsThe hosting provider may run its own backups covering a rolling window. Deleted data can persist in those backups until they are overwritten in the normal cycle.
6. Your rights, and how to use them
Under the PDPA you have the rights below, and most of them are wired into the site so you can exercise them yourself:
- Access and get a copy — do it yourself on the export page, as CSV or a full backup. No permission needed
- Correct your data — every row is editable from its own page; name and gender from your profile
- Erasure — delete rows yourself, delete the whole account permanently from the mobile app, or ask by email
- Withdraw consent — new health data then stops being recorded, and you can ask for the existing data to be deleted
- Object to or restrict processing
- Complain — to Thailand's Personal Data Protection Committee office if you believe this site is in the wrong
Email requests are handled within 30 days.
7. Cookies and browser storage
Only cookies the site needs to function. None for advertising or behavioural tracking:
lamduan_lang — remembers your language, one year
lamduan_app — remembers you opened the site as an installed app, one year
- WordPress's standard login cookies — keep you signed in
- Browser storage holds one thing only: whether you dismissed the install banner
8. Security, and users under 20
- HTTPS on every page
- Passwords are one-way hashes; so are app tokens. A database leak cannot be replayed as a login
- More than 10 failed logins from one IP triggers a 15-minute lockout
No system is completely safe. Use a password you do not reuse elsewhere, and download your own backup from time to time.
Minors — under the PDPA, anyone under 20 needs a guardian's consent before providing personal data. This site is not designed for children under 13; if data from a child under 13 is found to have been collected without guardian consent, it will be deleted immediately.
9. Changes to this policy
If the substance changes, the version number at the foot of this page moves and members are asked to consent again before continuing. Minor wording fixes only update the effective date.