muffinbiter

Legal

Privacy Policy

Effective August 9, 2026 · version 2026-08-09

The short version: we collect only what the app needs to work, we don't sell or share your personal information, and we run no third-party advertising or analytics trackers. This page explains the details.

Who we are

MuffinBiter, Los Angeles, California, United States, is the business responsible for the personal information described here. Contact: privacy@muffinbiter.com.

What we collect, why, and where it comes from

This table is also our California “Notice at Collection.” We collect these categories and no others.

CategoryWhat, specificallySourceWhy we use it
IdentifiersName, email address, account IDYou, at signupCreate and secure your account, send account emails, show your first name to members of beacons you join
Approximate locationNeighborhood-level coordinates (rounded), or a neighborhood you type inYou — via browser geolocation permission or a text fieldSort parks and beacons by distance. Never shown to other members
User contentDog profiles and photos, beacon notes, chat messages within a beaconYouOperate the product — show your dog to a beacon's members, deliver beacon chat
Walking routes you choose to shareA line on a map with a name and an optional note. The first and last 150 metres of every route are discarded before it is stored — the endpoints never reach our databaseYou — by drawing on the map, or by recording a walk with your locationShow other members where people actually walk their dogs. You choose members-only or private, and you can delete a route at any time
Commercial informationWhether you made a supporter contributionStripe (payment processor)Recognise Founding Members. We never receive or store card numbers
Internet / network activityIP address, request logsAutomatically, via CloudflareSecurity, abuse prevention and rate limiting. Not used to profile you
InferencesNoneWe do not build profiles, score users, or infer characteristics about you

We do not collect sensitive personal information as defined by the CPRA — no government identifiers, no racial or ethnic origin, no health data, no biometrics, no contents of private communications outside the product's own beacon chat. We never store your precise location as your location: the point that sorts parks by distance is rounded before it is saved.

A walking route is the one place precise coordinates exist at all, and only because a line that isn't precise isn't a route. It is opt-in twice over — you have to draw or record it, and then choose to save it — and the two places it could point at you, where it began and where it ended, are cut out before the insert rather than hidden afterwards. An unstored point can't leak.

What we don't do

  • We don't sell your personal information, and we don't “share” it for cross-context behavioural advertising, as those terms are defined by California law. We never have.
  • We run no third-party trackers. No Google Analytics, no advertising pixels, no session recorders, no social embeds.
  • We don't show your precise location to anyone, including other members. We store a rounded point.
  • We don't use your content to train machine-learning models, and we don't sell it to anyone who would.
  • We don't send marketing email unless you explicitly opt in.

Who can see what

  • Other members of a beacon you join see your first name, the neighborhood you chose to display, your dogs' profiles and photos, and your messages in that beacon.
  • Other logged-in members see any walking route you save as “visible to members”, with your first name on it. Routes marked “only me” are visible to nobody else, and no route ever appears on the logged-out public site.
  • Everyone else sees nothing. There is no public profile page and no member directory.
  • Blocked members see nothing of yours, and you see nothing of theirs. Blocking is immediate and bidirectional.
  • Your email address and password are never shown to another member, ever.

Service providers

These are the only third parties that process personal information on our behalf:

  • Cloudflare — hosting, database (D1), photo storage (R2), network security. All data is processed in Cloudflare's network.
  • Resend — sends account emails (verification, password reset) when configured. Receives your email address and the message.
  • Stripe — processes supporter contributions if you make one. Stripe receives your payment details directly; we receive only a confirmation.
  • OpenStreetMap — serves the map images. Any page with a map loads those squares from OpenStreetMap's servers, so they see your IP address and which part of the map you looked at, the same as any image on any website. They receive nothing else: no account, no cookie, no route. Their policy is at osmfoundation.org.

Each acts as a service provider under contract, may only use the data to provide their service to us, and may not sell it. We disclose personal information for no other purpose, except where we're legally required to — a valid subpoena, court order, or to protect someone's safety.

How long we keep it

  • Account, dogs, photos: until you delete them or delete your account.
  • Beacons and chat messages: retained while the beacon exists; deleted with your account.
  • Walking routes: until you delete them or delete your account. Deleting the account removes every route with it.
  • Sessions: stored as a hash, expire automatically.
  • Verification and password-reset tokens: stored as a hash, single-use, expire in 3 days and 1 hour respectively.
  • Rate-limit records: IP-derived, in fixed windows, aged out automatically.
  • Backups: deleted data ages out of routine backups on our normal cycle.

Your rights

Wherever you live, you can access, correct, export and delete your information. Most of that is self-service: edit your profile and dogs any time, and delete your account from your profile page. Deletion is real — it cascades through your dogs, beacon memberships, messages and friendships, and purges your photos from storage.

If you're in California

Under the CCPA/CPRA you have the right to:

  • know what we collect, use and disclose (this page, plus a specific-pieces request);
  • delete personal information we hold about you;
  • correct inaccurate personal information;
  • opt out of sale or sharing — we don't do either, so there's nothing to opt out of;
  • limit use of sensitive personal information — we don't collect any;
  • not be discriminated against for exercising any of these rights. We don't offer financial incentives for data.

To exercise a right, use the in-app controls or email privacy@muffinbiter.com. We verify requests by confirming control of the account email. We respond within 45 days and may extend once by another 45 with notice. An authorised agent may act for you with written permission. See Your privacy choices for the summary version.

Global Privacy Control

We honour the Global Privacy Control signal. Because we don't sell or share personal information, it has no data to stop — but the signal is respected, not ignored.

If you're in the EU or UK

MuffinBiter is built for Los Angeles and isn't targeted at the EEA or UK, but if you're there: our lawful bases are performance of a contract (running your account), legitimate interests (security and abuse prevention), and consent (location access, optional emails). You have rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. Data is processed in the United States.

Security

  • Passwords are hashed with PBKDF2-SHA256 (200,000 iterations) and a per-user salt. We never see your password.
  • Session tokens and email tokens are stored only as SHA-256 hashes; tokens are single-use and expire.
  • A password reset revokes every existing session.
  • Login responses are timing-equalised so they can't be used to discover who has an account.
  • Signup, login and password reset are rate-limited per IP.
  • All traffic is served over HTTPS.

No system is perfectly secure. We minimise what we hold, which is the most reliable protection available.

Children

MuffinBiter is for adults. It's not directed at anyone under 18 and we don't knowingly collect personal information from children. If you believe a child has created an account, email privacy@muffinbiter.com and we'll delete it.

Cookies

We set one cookie: your login session. It's essential, it's HttpOnly, Secure and SameSite=Lax, and it carries an opaque token, not your identity. No advertising cookies, no analytics cookies, no third-party cookies. Details on the Cookie Policy page.

Changes

If we change this policy materially, we'll notify you in the app or by email before it takes effect and update the version at the top. Past versions are available on request.

Contact

Privacy questions or requests: privacy@muffinbiter.com
Security reports: security@muffinbiter.com
MuffinBiter, Los Angeles, California, United States

Plain-language note. These documents are written to be readable rather than impressive. If anything here is unclear, email hello@muffinbiter.com and we'll explain it — and probably rewrite it.

Other policies: Terms · Privacy · Cookies · Your privacy choices · Community guidelines · Accessibility