Mukauyo Privacy Policy
Effective date: 2026-09-20
This policy applies to Mukauyo, offered in Japan and the United States. Mukauyo helps adults age 18 or older request an immediate pickup within a private group of people they trust. It is not an emergency or medical service.
The English policy is the controlling version. A Japanese reference translation is available. Both versions describe the same data practices.
Information we collect
We collect only information needed to operate the pickup group:
- a random internal user identifier and a keyed hash derived from the Sign in with Apple subject identifier;
- an Apple authorization credential, encrypted at rest, so Mukauyo can attempt to revoke Sign in with Apple access when the account is deleted;
- fixed group-administrator authority, exclusive pickup activity role, group nickname, membership, helper plan status, and notification readiness;
- an APNs device token for each registered installation;
- destination labels, Apple Maps place summaries that may contain a physical address, and coordinates registered by the group administrator;
- one pickup-location snapshot when the requester sends a pickup request;
- request state, timestamps, selected ETA, and assigned helper identifier;
- RevenueCat subscription entitlement and purchase-history status associated with the internal user identifier;
- secret-keyed request fingerprints used for safe retry detection;
- short-lived rate-limit identifiers derived from internal user IDs for authenticated operations; and
- a short-lived keyed network abuse identifier derived from the connection IP for unauthenticated authentication and webhook traffic. Mukauyo processes the connection IP to create this identifier but does not store the raw IP in its application database or application logs.
We do not request or store your Apple-provided name or email address, password, phone number, contacts, continuous location history, chat content, or call content. We do not use advertising SDKs or send location to analytics services. The Mukauyo in-app interface always uses Japanese; it does not offer or store an in-app language choice, and no language preference is added to the Mukauyo API database.
How we use information
We use this information to authenticate users, operate private pickup groups, send generic pickup notifications, show pickup and destination details inside the authenticated app, enforce plan limits, process subscriptions and subscription reporting, prevent abuse, keep the service reliable, and honor deletion requests.
Mukauyo requests location only after the requester taps 迎えを頼む (Request a pickup). It takes one foreground snapshot and does not continuously or silently track the requester. If location or network access is unavailable, Mukauyo does not create or queue the request for later delivery.
How information is shared
Pickup and destination information is visible only to authorized members of the same pickup group. A lock-screen notification contains a generic message and an opaque request identifier; it does not contain a nickname, destination, or coordinates.
We use these service providers to operate Mukauyo:
- Apple for Sign in with Apple, APNs, Maps, App Store distribution, and in-app purchases. Test versions are distributed through TestFlight;
- Cloudflare for API processing, database storage, domain delivery, and operational infrastructure; and
- RevenueCat for purchase validation, subscription entitlement management, and subscription reporting using the internal user identifier. Pickup and destination coordinates are not sent to RevenueCat.
We do not sell location or other personal information and do not use it for advertising. We do not disclose information to unrelated third parties except when required by law or necessary to protect the service and its users.
Retention
Pickup coordinates are logically deleted from the active Mukauyo database when a request is completed, canceled, or expired. A secret-keyed request fingerprint used for safe retry detection is replaced with a non-derived terminal marker in the same database transaction. Terminal request metadata that does not contain pickup coordinates is deleted after 30 days. Registered destinations remain until they are edited or deleted, the group is deleted, or an account deletion removes the group.
Mukauyo stores invitation metadata (a one-way token hash, administrator-chosen nickname, internal creator/accepting IDs, status, and timestamps) without putting the raw token in the invitation table. Invitations created under the current model contain no pickup activity role. A temporary legacy-role field may remain only on still-valid invitations created before the role-model migration; it is not applied when the recipient joins and is deleted under the same invitation-retention rules. The complete response containing the token is encrypted at rest in a short-lived idempotency record and can be replayed safely for 24 hours. It then becomes ineligible for replay and is deleted by the next successful daily cleanup. Unaccepted invitation metadata, including revoked or expired invitations, becomes eligible for deletion 30 days after its original expiry and is removed by the next successful daily cleanup (normally less than 31 days after expiry). It may be deleted sooner when a replacement invitation is created. Accepted invitation metadata remains until the group is deleted; a deleted accepting user ID is cleared.
Account and group deletion removes associated application data. Rate-limit counter rows are deleted by a daily cleanup after a two-day cutoff and are retained for less than three days.
Cloudflare may retain earlier encrypted database states in managed Time Travel recovery history for up to 30 days. Those recovery snapshots are not used for ordinary Mukauyo requests. A restore must remain out of service until required account, group, request, and location deletions are reconciled.
Service-provider retention may also apply to purchase and platform records that Apple or RevenueCat must retain independently. Deleting Mukauyo data does not cancel an Apple subscription.
Your choices
You can review the information authorized for your activity role, manage notification and location permissions in iOS Settings, leave a group when the active-request safety rules permit it, and start account deletion inside the app. Deleting the fixed administrator account deletes the pickup group. Deleting a non-administrator requester account cancels an active request and removes that account while leaving the group without a requester. Deleting an assigned helper account withdraws or expires the request before removing the account. Before deleting an administrator account with an active subscription, Mukauyo provides a link to manage the Apple subscription and still allows immediate application-data deletion.
Security
We use access controls, server-side role checks, parameterized database queries, keyed hashing, secret management, encryption, and data minimization. No internet service can guarantee absolute security or notification delivery.
Age and availability
Mukauyo is for people age 18 or older and is offered only in Japan and the United States. It is not designed for children.
Destinations such as hospitals may reveal sensitive context. Mukauyo does not use that information for advertising or medical services.
Changes and contact
We will update this policy when the service or its data practices materially change and will publish the effective date with the updated policy.
- Operator: Masaki Kubota
- Privacy contact: masaki.apple.dev827@gmail.com
- Public policy URL: https://pickup.mklabos.dev/privacy