Privacy Policy
Version: 2026-08-21
This Privacy Policy explains how Mushukistan collects, uses, stores, shares, and deletes personal data. It applies to the Mushukistan Android app and web app.
Who is responsible for your data
Mushukistan is operated by Sardor Muxtorov, an individual developer.
Data controller: Sardor Muxtorov
Privacy contact: sardor.datascience@gmail.com
Data Mushukistan collects
Mushukistan collects only the data needed to operate a social map for street cats in Tashkent.
- Account data, including email address, password hash for password accounts, Google Sign-In email/name when Google Sign-In is used, registration time, last login time, coarse last-active time, preferred language, and accepted legal-document version.
- Profile data, including name, avatar URL, phone number, Telegram username, bio, and public activity visibility preference.
- User content, including cat sightings, cat photos, cat profile information, descriptions, comments, likes, reports, lost-pet posts, and adoption/rehoming posts.
- Location data, including current location when used for nearby search, observation location, cat canonical location, place-search location, lost-pet last-seen location, and a private alert point only when explicitly saved for nearby Lost Pet alerts.
- Contact data published by the user when explicit publication consent is given for lost-pet or adoption/rehoming posts.
- Technical and security data used for authentication, rate limiting, abuse prevention, security, troubleshooting, and operational logs; plus encrypted Android push tokens, token hashes, notification preferences, inbox read state, and delivery status.
Photos and media
Photos are validated, resized, compressed, thumbnailed, and processed without preserving EXIF metadata. This reduces unintended location and device metadata exposure.
Binary image files are stored in Cloudflare R2 when configured, or in local media storage during development. PostgreSQL stores media URLs.
When an account is deleted, Mushukistan attempts best-effort cleanup of uploaded profile, post, lost-pet, and adoption/rehoming media associated with that account. Media cleanup can fail if storage is unavailable, if a URL cannot be mapped to a stored object, or if the storage provider rejects the deletion request.
How Mushukistan uses data
- Create and manage accounts.
- Authenticate users and verify email addresses.
- Publish and display user content.
- Show nearby cats, places, and map content.
- Operate lost-pet and adoption/rehoming contact features.
- Enable comments, likes, reports, moderation, and account settings.
- Deliver structured in-app notifications and permitted Android push alerts.
- Prevent abuse, rate-limit requests, and secure the service.
- Comply with legal obligations and enforce policies.
Public information
Some information may be visible to other users or visitors, depending on the feature and account settings. Public information may include cat sightings, photos, descriptions, locations, cat profile information, comments, public profile summaries, lost-pet photos, lost-pet last-seen locations, and contact details when the user explicitly consented to publish them.
Do not publish another person's private information, photo, phone number, address, or location unless you have permission.
Third-party services
- DigitalOcean for hosting and database infrastructure.
- Cloudflare R2 for uploaded media and object metadata when configured.
- Google when a user chooses Google Sign-In.
- Google Firebase Cloud Messaging for Android push delivery when configured and permitted.
- OpenStreetMap for map tiles and map/place data.
Email provider: not configured in the verified repository.
Backup provider: not configured in the verified repository.
Mushukistan does not include analytics SDKs, advertising SDKs, crash reporting SDKs, or AI features. Android push uses Firebase Cloud Messaging (Google) after notification permission is granted. Web has an in-app inbox without browser push.
The notification inbox stores structured event and target identifiers, recipient/actor references, creation and read times. Android delivery stores encrypted device tokens, token hashes, preferences, and bounded retry state. Push payloads omit phone numbers, Telegram handles, exact pet and alert coordinates, and full comment text.
Nearby Lost Pet alerts require an explicitly saved private alert point and opt-in. New active Lost Pets within a fixed 500 m radius may generate inbox and Android push alerts. The point can be chosen on a map or from a one-time current-location action. No background or continuous notification location tracking is used. Disabling nearby alerts removes the point.
Inactivity reminders are off by default, push-only, and sent once after seven full days away. A coarse authenticated launch/resume timestamp is written at most every 15 minutes. Separate settings control comments, replies, existing pet follow-ups, nearby alerts, and inactivity pushes.
Cookies and browser storage
The Android app does not use cookies.
The web app does not intentionally set advertising, analytics, or tracking cookies. The web app may use browser storage through the Flutter secure storage integration to keep the user's access token for authentication.
Account deletion and retention
Users can delete their Mushukistan account directly inside the app: Settings -> About account -> Delete account.
Users who cannot access the app can start account deletion from https://mushukistan.uz/delete-account. The website asks for the account email address and, if an active account exists, sends a time-limited confirmation link to that email address. The website does not reveal whether the submitted email address has an account. The account is deleted only after the confirmation link is opened and deletion is explicitly confirmed.
When account deletion is confirmed, Mushukistan deactivates and anonymizes the account. Login is disabled, authentication credentials are removed, and profile personal information is removed, including email address, password hash, name, avatar URL, phone number, Telegram username, bio, legal acceptance records, last-login and last-active data, device push tokens, notification preferences, and the private alert point. Inbox rows received by the deleted account are removed; its actor reference on other users' notifications becomes anonymous.
Mushukistan also removes the user's likes, removes account-related blocking records, removes affected leaderboard cache entries, hides and anonymizes user-owned posts, comments, lost-pet posts, and adoption/rehoming posts, clears copied contact details from lost-pet and adoption/rehoming posts, and removes the user as creator/reporter/handler where possible.
Some non-public or anonymized records may remain after account deletion where they are needed for service integrity, moderation, safety, abuse prevention, or legal compliance. For example, Mushukistan may retain anonymized content records, cat records, content locations attached to retained records, timestamps, moderation/report records, and a non-personal internal tombstone identifier for the deleted account. These retained records are not intended to identify the deleted user and the deleted account is not publicly accessible or usable for authentication.
The verified repository does not define a guaranteed automatic deletion period for all retained records.
Backups are not configured in the verified repository. If backups are enabled later, backup retention and deletion schedules must be documented before production release.
Your rights and choices
Users may request access, correction, deletion, restriction, objection, portability, and withdrawal of consent where applicable by contacting sardor.datascience@gmail.com.
Users can manage some profile and privacy settings inside the app, including public activity visibility and account deletion.
International processing
Data may be processed outside the user's country by service providers such as DigitalOcean, Cloudflare, Google, and OpenStreetMap. Mushukistan should use provider data-processing terms or data-processing agreements where available.
Security
Mushukistan uses authentication, rate limiting, image validation, EXIF stripping, structured storage, and access controls to protect the service and user data. No system can be guaranteed completely secure.
Changes to this Privacy Policy
Mushukistan may update this Privacy Policy when the service, legal requirements, or operational practices change. If changes are material, Mushukistan should provide notice in the app or require renewed acceptance where appropriate.