Last updated: 15 July 2026 | Effective: [EFFECTIVE DATE, set when you publish]
⚠️ TEMPLATE. NOT LEGAL ADVICE. This document is grounded in muukago's actual data flows (as of the audit date) but must be reviewed by a qualified privacy lawyer before publication. Placeholders in [BRACKETS] require your input. muukago is currently run by an individual (not a company): "muukago", "we", "us", "our" = [YOUR NAME], an individual based in [COUNTRY].
muukago is a free, non-commercial travel-planning application ("the App"), built and run by one individual in their own time. It helps you discover places, build multi-day itineraries, plan trips with groups, and share travel moments socially. This Policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have depending on where you live.
Note: Being a free, personal project does not exempt muukago from data protection law, GDPR, the UK GDPR, and India's DPDP Act apply because we process personal data, regardless of whether money changes hands. We take that seriously.
If you do not agree with this Policy, do not create an account or use the App.
We collect only what the App actually uses. Categories below map to real data flows in the product.
| Data | When | Purpose |
|---|---|---|
| Email address | Sign-up (email/password or Google) | Account identity, login, password reset, service emails |
| Password | Email sign-up | Authentication (stored/hashed by Firebase Authentication, we never see your plaintext password) |
| Display name | Sign-up / profile edit | Shown on your profile, posts, group membership |
| Username | Profile setup | Unique public handle; used for @mentions and profile URLs |
| Profile bio & photo | Profile edit / Google sign-in | Shown on your public profile |
| Travel tastes & preferences | Onboarding, trip planner | Personalising place recommendations and itineraries |
| Free-text trip preferences | Itinerary generator | Sent to our AI provider to generate a plan (see §4 and §5) |
| Group chat messages | Group chat | Delivering messages to your group members |
| Notes, ratings, votes | Planning / places | Your saved planning data and group decision-making |
| Story photos & captions | Posting a story | Sharing a travel moment (24-hour ephemeral) |
| Place/city tags on posts | Posting a story | Powering your profile "places I've been" map |
| Published itineraries | Publishing to Community | Sharing a plan with the community |
| Follows / followers / follow requests | Social actions | Building your social graph |
| Data | Source | Purpose |
|---|---|---|
| Authentication tokens / session | Firebase Auth | Keeping you signed in |
| Approximate location of tagged places | Place/city you tag on a post | Rendering your profile map. Note: we do not access your device GPS or real-time location. |
| Place view events | In-app browsing | Aggregate "Trending" counts (see §2.4) |
| Device/technical data | HTTP requests | IP address, browser/user-agent, timestamps, used for security, abuse prevention, and to operate the service. Retained in standard server/hosting logs. |
| Local cache | Your browser (localStorage) | Auth session, cached place descriptions/images/view data, stored on your device, not a server. |
The App is not intended for anyone under 18 years old. We do not knowingly collect data from under-18s. If you believe someone under 18 has provided us data, contact [privacy@yourdomain.com] and we will delete it.
NOTE: Minimum age is set to 18 to match the Terms & Conditions. This also aligns with India's DPDP Act, which treats all under-18s as children and bars behavioural tracking/targeted ads to them. Ensure the age gate is enforced at sign-up (see the compliance checklist).
Under GDPR/UK GDPR we rely on the following legal bases:
| Purpose | Legal basis (GDPR/UK GDPR) |
|---|---|
| Create & operate your account, deliver core features | Contract (Art. 6(1)(b)) |
| Group chat, social features, itinerary generation | Contract |
| Send AI trip-preference text to our AI provider to generate a plan | Contract (feature you requested) |
| Security, fraud/abuse prevention, service logs | Legitimate interests (Art. 6(1)(f)) |
| Product analytics / improvement (if enabled) | Consent or legitimate interests, [CONFIRM] |
| Service/transactional emails | Contract |
| Marketing emails (if any) | Consent (opt-in), [CONFIRM whether you send any] |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time (see §9).
We do not sell your personal data. We share it only with service providers ("processors") who help us run the App, under contract, and only as needed:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Hosting) | Core backend, database, authentication, hosting | Account, profile, chat, social graph, itineraries, story metadata | Google Cloud, [CONFIRM region: set Firestore location; e.g. eur3 for EU or nam5 for US] |
| [Render] | Backend API hosting | Data in transit through the API (trip prefs, uploads relay, logs incl. IP) | [CONFIRM Render region] |
| Cloudflare R2 | Story/post photo storage | Story image files + derived URLs | Cloudflare (global / [CONFIRM]) |
| [Groq] (default AI provider) | Generating itineraries from your preferences | Your free-text trip preferences, selected cities/places, trip context (dates, budget, themes). No account email/password is sent. | [CONFIRM, Groq is US-based] |
| Google (Sign-In) | Authentication | Email, name, photo | Global |
Configurable AI provider: The App can be pointed at a different AI provider (e.g. OpenAI) via server config. If you change providers, update this table and your sub-processor list, and re-assess transfer safeguards (§6).
We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and property of muukago, our users, or the public.
A current list of sub-processors is maintained in [legal/SUBPROCESSORS.md] / at [URL]. We will [notify registered users / update this page] before adding a new sub-processor that materially changes processing.
muukago uses providers located in the United States and other countries (e.g. Firebase/Google, the AI provider, Cloudflare R2). If you are in the EEA, UK, Switzerland, India, or elsewhere, your data may be transferred outside your country, including to the US.
Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards, such as:
ACTION (legal): Confirm the transfer mechanism for each provider above. Firebase and Cloudflare offer SCCs/DPF; verify your AI provider's transfer terms and DPA. For India's DPDP, the government may restrict transfers to certain countries by notification, monitor this.
| Data | Retention |
|---|---|
| Account & profile | Until you delete your account, then removed within [30–90] days (backups may persist briefly) |
| Group chat messages | Retained while the group exists; the App keeps only the most recent 100 messages per group and auto-prunes older ones. Deleted with the group. |
| Stories (photos) | Auto-deleted 24 hours after posting by a scheduled cleanup job (image file in R2 + Firestore record). |
| "Posted places" map entries | Persist beyond story expiry, they remain until you remove them or delete your account (this is by design, so your profile map stays populated). |
| Published itineraries | Until you unpublish/delete them or your account |
| Server/security logs (incl. IP) | [e.g. 30–90 days] then deleted/anonymised |
| Aggregate place-view counts | Indefinitely (non-identifying) |
| Local cache on your device | Until you clear browser storage or sign out |
No system is perfectly secure. We cannot guarantee absolute security, and you share content (stories, published itineraries, public profile) at your own discretion. We do not offer end-to-end encryption, content is readable by our systems and providers as needed to operate the service.
Breach notification: In the event of a personal-data breach, we will notify the relevant supervisory authority and affected users where required by law (e.g. GDPR 72-hour rule; India DPDP breach notification; US state laws).
Depending on where you live, you have some or all of these rights:
How to exercise: email [privacy@yourdomain.com] or use in-app [Settings → Delete account / Export data, BUILD/CONFIRM]. We respond within the timeframe your law requires (e.g. 30 days GDPR; 45 days CCPA/CPRA).
You may lodge a complaint with your data protection authority:
Legal bases are in §4; transfer safeguards in §6; rights in §9. Our controller and (if applicable) EU/UK representative are in §1.
Residents of these jurisdictions have comparable access/deletion/correction and opt-out rights; contact us at [privacy@yourdomain.com].
The App uses browser local storage (not advertising cookies) to keep you signed in and to cache content on your device for performance. Firebase Auth may set cookies/tokens necessary for authentication. We do not use third-party advertising or cross-site tracking cookies. See [legal/COOKIES.md] if a separate cookie notice is required in your region.
We may update this Policy. Material changes will be notified [in-app / by email] and the "Last updated" date will change. Continued use after changes means you accept the updated Policy.
Questions or privacy requests: [YOUR NAME] (individual operator, [COUNTRY]) at [YOUR CONTACT EMAIL].