Mukauyo Privacy Policy

Effective date: 2026-09-20

This policy applies to Mukauyo, offered in Japan and the United States. Mukauyo helps adults age 18 or older request an immediate pickup within a private group of people they trust. It is not an emergency or medical service.

The English policy is the controlling version. A Japanese reference translation is available. Both versions describe the same data practices.

Information we collect

We collect only information needed to operate the pickup group:

We do not request or store your Apple-provided name or email address, password, phone number, contacts, continuous location history, chat content, or call content. We do not use advertising SDKs or send location to analytics services. The Mukauyo in-app interface always uses Japanese; it does not offer or store an in-app language choice, and no language preference is added to the Mukauyo API database.

How we use information

We use this information to authenticate users, operate private pickup groups, send generic pickup notifications, show pickup and destination details inside the authenticated app, enforce plan limits, process subscriptions and subscription reporting, prevent abuse, keep the service reliable, and honor deletion requests.

Mukauyo requests location only after the requester taps 迎えを頼む (Request a pickup). It takes one foreground snapshot and does not continuously or silently track the requester. If location or network access is unavailable, Mukauyo does not create or queue the request for later delivery.

How information is shared

Pickup and destination information is visible only to authorized members of the same pickup group. A lock-screen notification contains a generic message and an opaque request identifier; it does not contain a nickname, destination, or coordinates.

We use these service providers to operate Mukauyo:

We do not sell location or other personal information and do not use it for advertising. We do not disclose information to unrelated third parties except when required by law or necessary to protect the service and its users.

Retention

Pickup coordinates are logically deleted from the active Mukauyo database when a request is completed, canceled, or expired. A secret-keyed request fingerprint used for safe retry detection is replaced with a non-derived terminal marker in the same database transaction. Terminal request metadata that does not contain pickup coordinates is deleted after 30 days. Registered destinations remain until they are edited or deleted, the group is deleted, or an account deletion removes the group.

Mukauyo stores invitation metadata (a one-way token hash, administrator-chosen nickname, internal creator/accepting IDs, status, and timestamps) without putting the raw token in the invitation table. Invitations created under the current model contain no pickup activity role. A temporary legacy-role field may remain only on still-valid invitations created before the role-model migration; it is not applied when the recipient joins and is deleted under the same invitation-retention rules. The complete response containing the token is encrypted at rest in a short-lived idempotency record and can be replayed safely for 24 hours. It then becomes ineligible for replay and is deleted by the next successful daily cleanup. Unaccepted invitation metadata, including revoked or expired invitations, becomes eligible for deletion 30 days after its original expiry and is removed by the next successful daily cleanup (normally less than 31 days after expiry). It may be deleted sooner when a replacement invitation is created. Accepted invitation metadata remains until the group is deleted; a deleted accepting user ID is cleared.

Account and group deletion removes associated application data. Rate-limit counter rows are deleted by a daily cleanup after a two-day cutoff and are retained for less than three days.

Cloudflare may retain earlier encrypted database states in managed Time Travel recovery history for up to 30 days. Those recovery snapshots are not used for ordinary Mukauyo requests. A restore must remain out of service until required account, group, request, and location deletions are reconciled.

Service-provider retention may also apply to purchase and platform records that Apple or RevenueCat must retain independently. Deleting Mukauyo data does not cancel an Apple subscription.

Your choices

You can review the information authorized for your activity role, manage notification and location permissions in iOS Settings, leave a group when the active-request safety rules permit it, and start account deletion inside the app. Deleting the fixed administrator account deletes the pickup group. Deleting a non-administrator requester account cancels an active request and removes that account while leaving the group without a requester. Deleting an assigned helper account withdraws or expires the request before removing the account. Before deleting an administrator account with an active subscription, Mukauyo provides a link to manage the Apple subscription and still allows immediate application-data deletion.

Security

We use access controls, server-side role checks, parameterized database queries, keyed hashing, secret management, encryption, and data minimization. No internet service can guarantee absolute security or notification delivery.

Age and availability

Mukauyo is for people age 18 or older and is offered only in Japan and the United States. It is not designed for children.

Destinations such as hospitals may reveal sensitive context. Mukauyo does not use that information for advertising or medical services.

Changes and contact

We will update this policy when the service or its data practices materially change and will publish the effective date with the updated policy.