Legal
Privacy Policy
Effective August 9, 2026 · version 2026-08-09
The short version: we collect only what the app needs to work, we don't sell or share your personal information, and we run no third-party advertising or analytics trackers. This page explains the details.
Who we are
MuffinBiter, Los Angeles, California, United States, is the business responsible for the personal information described here. Contact: privacy@muffinbiter.com.
What we collect, why, and where it comes from
This table is also our California “Notice at Collection.” We collect these categories and no others.
| Category | What, specifically | Source | Why we use it |
|---|---|---|---|
| Identifiers | Name, email address, account ID | You, at signup | Create and secure your account, send account emails, show your first name to members of beacons you join |
| Approximate location | Neighborhood-level coordinates (rounded), or a neighborhood you type in | You — via browser geolocation permission or a text field | Sort parks and beacons by distance. Never shown to other members |
| User content | Dog profiles and photos, beacon notes, chat messages within a beacon | You | Operate the product — show your dog to a beacon's members, deliver beacon chat |
| Walking routes you choose to share | A line on a map with a name and an optional note. The first and last 150 metres of every route are discarded before it is stored — the endpoints never reach our database | You — by drawing on the map, or by recording a walk with your location | Show other members where people actually walk their dogs. You choose members-only or private, and you can delete a route at any time |
| Commercial information | Whether you made a supporter contribution | Stripe (payment processor) | Recognise Founding Members. We never receive or store card numbers |
| Internet / network activity | IP address, request logs | Automatically, via Cloudflare | Security, abuse prevention and rate limiting. Not used to profile you |
| Inferences | None | — | We do not build profiles, score users, or infer characteristics about you |
We do not collect sensitive personal information as defined by the CPRA — no government identifiers, no racial or ethnic origin, no health data, no biometrics, no contents of private communications outside the product's own beacon chat. We never store your precise location as your location: the point that sorts parks by distance is rounded before it is saved.
A walking route is the one place precise coordinates exist at all, and only because a line that isn't precise isn't a route. It is opt-in twice over — you have to draw or record it, and then choose to save it — and the two places it could point at you, where it began and where it ended, are cut out before the insert rather than hidden afterwards. An unstored point can't leak.
What we don't do
- We don't sell your personal information, and we don't “share” it for cross-context behavioural advertising, as those terms are defined by California law. We never have.
- We run no third-party trackers. No Google Analytics, no advertising pixels, no session recorders, no social embeds.
- We don't show your precise location to anyone, including other members. We store a rounded point.
- We don't use your content to train machine-learning models, and we don't sell it to anyone who would.
- We don't send marketing email unless you explicitly opt in.
Who can see what
- Other members of a beacon you join see your first name, the neighborhood you chose to display, your dogs' profiles and photos, and your messages in that beacon.
- Other logged-in members see any walking route you save as “visible to members”, with your first name on it. Routes marked “only me” are visible to nobody else, and no route ever appears on the logged-out public site.
- Everyone else sees nothing. There is no public profile page and no member directory.
- Blocked members see nothing of yours, and you see nothing of theirs. Blocking is immediate and bidirectional.
- Your email address and password are never shown to another member, ever.
Service providers
These are the only third parties that process personal information on our behalf:
- Cloudflare — hosting, database (D1), photo storage (R2), network security. All data is processed in Cloudflare's network.
- Resend — sends account emails (verification, password reset) when configured. Receives your email address and the message.
- Stripe — processes supporter contributions if you make one. Stripe receives your payment details directly; we receive only a confirmation.
- OpenStreetMap — serves the map images. Any page with a map loads those squares from OpenStreetMap's servers, so they see your IP address and which part of the map you looked at, the same as any image on any website. They receive nothing else: no account, no cookie, no route. Their policy is at osmfoundation.org.
Each acts as a service provider under contract, may only use the data to provide their service to us, and may not sell it. We disclose personal information for no other purpose, except where we're legally required to — a valid subpoena, court order, or to protect someone's safety.
How long we keep it
- Account, dogs, photos: until you delete them or delete your account.
- Beacons and chat messages: retained while the beacon exists; deleted with your account.
- Walking routes: until you delete them or delete your account. Deleting the account removes every route with it.
- Sessions: stored as a hash, expire automatically.
- Verification and password-reset tokens: stored as a hash, single-use, expire in 3 days and 1 hour respectively.
- Rate-limit records: IP-derived, in fixed windows, aged out automatically.
- Backups: deleted data ages out of routine backups on our normal cycle.
Your rights
Wherever you live, you can access, correct, export and delete your information. Most of that is self-service: edit your profile and dogs any time, and delete your account from your profile page. Deletion is real — it cascades through your dogs, beacon memberships, messages and friendships, and purges your photos from storage.
If you're in California
Under the CCPA/CPRA you have the right to:
- know what we collect, use and disclose (this page, plus a specific-pieces request);
- delete personal information we hold about you;
- correct inaccurate personal information;
- opt out of sale or sharing — we don't do either, so there's nothing to opt out of;
- limit use of sensitive personal information — we don't collect any;
- not be discriminated against for exercising any of these rights. We don't offer financial incentives for data.
To exercise a right, use the in-app controls or email privacy@muffinbiter.com. We verify requests by confirming control of the account email. We respond within 45 days and may extend once by another 45 with notice. An authorised agent may act for you with written permission. See Your privacy choices for the summary version.
Global Privacy Control
We honour the Global Privacy Control signal. Because we don't sell or share personal information, it has no data to stop — but the signal is respected, not ignored.
If you're in the EU or UK
MuffinBiter is built for Los Angeles and isn't targeted at the EEA or UK, but if you're there: our lawful bases are performance of a contract (running your account), legitimate interests (security and abuse prevention), and consent (location access, optional emails). You have rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. Data is processed in the United States.
Security
- Passwords are hashed with PBKDF2-SHA256 (200,000 iterations) and a per-user salt. We never see your password.
- Session tokens and email tokens are stored only as SHA-256 hashes; tokens are single-use and expire.
- A password reset revokes every existing session.
- Login responses are timing-equalised so they can't be used to discover who has an account.
- Signup, login and password reset are rate-limited per IP.
- All traffic is served over HTTPS.
No system is perfectly secure. We minimise what we hold, which is the most reliable protection available.
Children
MuffinBiter is for adults. It's not directed at anyone under 18 and we don't knowingly collect personal information from children. If you believe a child has created an account, email privacy@muffinbiter.com and we'll delete it.
Cookies
We set one cookie: your login session. It's essential, it's HttpOnly, Secure
and SameSite=Lax, and it carries an opaque token, not your identity. No advertising
cookies, no analytics cookies, no third-party cookies. Details on the
Cookie Policy page.
Changes
If we change this policy materially, we'll notify you in the app or by email before it takes effect and update the version at the top. Past versions are available on request.
Contact
Privacy questions or requests: privacy@muffinbiter.com
Security reports: security@muffinbiter.com
MuffinBiter, Los Angeles, California, United States
Other policies: Terms · Privacy · Cookies · Your privacy choices · Community guidelines · Accessibility