MUGSHOT Privacy Policy
Document version: 3
Effective and last updated: July 11, 2026
株式会社MIZUKICHI Lab (the registered Japanese company name; “we,” “us,” or “our”) establishes this Policy for information handled by the MUGSHOT application (the “App”) and its official website.
This is a reference translation. The Japanese version is authoritative, subject to mandatory law.
1. Basic approach
The App is designed to be local-first and does not require an account, advertising SDK, behavioral analytics SDK, location data, or contacts. Information is nevertheless processed off-device when a user enables ntfy text notifications and when the CDN serves the website. Those flows are described below.
2. Information handled by the App
2.1 Passcode and device authentication
- The App stores a salted verification value derived with PBKDF2-HMAC-SHA256, rather than the passcode, in OS secure storage such as Keychain or Keystore. It does not store or transmit the plaintext passcode.
- It does not obtain biometric data; it uses only the authentication result returned by the OS.
2.2 Camera and on-device evidence photos
- Camera use is off by default. It is used only after the user reviews the explanation, grants OS permission, and explicitly opts in.
- While the App is armed with camera capture enabled, the camera session remains active and the OS camera-use indicator may remain visible, but the settings preview is stopped and detached when arming. When a supported breach occurs, the App requests one still photo (using
AVCapturePhotoOutputon the current macOS build and the platform camera capture API on other supported builds) and writes that photo temporarily to the App’s private area; it does not continuously save preview frames. The App does not perform face recognition or face matching and does not record video or audio. The purpose is to let the user review a supported breach involving their device. A photo from which a person can be identified may be personal information; users must also respect facility rules and third-party privacy and likeness rights. Public distribution builds disable uploading evidence photos to ntfy or any other destination; the saved breach photo is processed only on the device. - The App attempts to delete temporary photos on a normal disarm or reset and during cleanup on the next launch. Immediate or complete erasure may be prevented by an abnormal termination, OS or file-system behavior, backups, or copies already received elsewhere.
- Photos are designed to be retained only for the short period needed for that purpose and deleted when no longer needed.
2.3 ntfy text notifications
- Only after the user explicitly enables notifications and sets a topic does the App send the topic, notification title and body, and communication metadata such as the source IP address to the fixed endpoint
https://ntfy.sh. The App currently does not let users select another notification server. - Treat the topic as a secret that identifies the subscription. We do not collect it on an App-specific server, but ntfy.sh processes it to deliver messages.
- Public builds send
Cache: no, requesting that ntfy.sh not cache the message body, and do not attach photos. The ntfy.sh defaults (up to approximately 12 hours for a body without that request and 3 hours for an attachment) may apply to older, development, non-public, or third-party posts.Cache: nodoes not erase ntfy/FCM delivery processing, security or access logs, or copies on the receiving side. - ntfy.sh may process topics, source IP addresses, timestamps, and other communication metadata for delivery and abuse prevention. Delivery to some clients, including the Google Play build of the ntfy Android client, may use Firebase Cloud Messaging (Google). Processing may take place outside Japan.
- Copies can remain on receiving devices, in OS notification history, or in an ntfy client. The App cannot remotely delete those copies.
- See ntfy privacy information and the ntfy public service terms.
2.4 Settings and custom audio
- Sensor, volume, duration, sound, camera, and notification settings are stored on the device.
- On Android, macOS, and Windows, the App may temporarily change the system output volume to the user’s configured alarm level during a breach and attempts to restore the previous value on disarm or alarm stop. OS or device behavior, audio-route changes, permissions, conflicts, or abnormal termination can prevent the change or restoration and may temporarily affect playback volume in other apps. The App does not change system output volume on iOS.
- If a user selects custom audio, the App decodes it locally and saves in its private persistent area only a derived PCM/WAV file covering at most the first 60 seconds; it does not persist the whole source file there. The OS document picker may create a temporary ingress copy, which the App attempts to delete after conversion. After the new derived file has been saved successfully, the App replaces and deletes its previous derived or legacy app-managed custom-audio copy. It does not use the microphone or transmit the source or derived audio. Users should select only audio they have the right to process and play.
2.5 Permissions
- Camera: explicitly enabled on-device evidence capture
- Biometric/device authentication: identity confirmation for arming or disarming
- Network: explicitly enabled ntfy text notifications
- System volume setting (supported platforms): temporary alarm-volume change during a breach and attempted restoration on disarm or stop
3. Information processed by the website
The official website does not use cookies, advertising, or behavioral analytics. To deliver and protect the site, our CDN provider Cloudflare may process access-log data such as IP address, User-Agent, request time and path, and response status. We use such data only for delivery, security, and troubleshooting. See the Cloudflare Privacy Policy.
4. Third parties and international processing
We do not sell information. We do not provide personal data to third parties except for user-directed ntfy notifications, Cloudflare website delivery, or compliance with law. Processing by ntfy, Google (where FCM is used), and Cloudflare may occur outside Japan and is governed by each provider’s terms and policies.
5. Retention and deletion limits
- App settings and derived custom audio remain until changed or deleted. The App attempts to delete temporary photos at the times described in 2.2.
- Uninstalling normally removes ordinary App storage, but an OS may retain Keychain entries, backups, or synchronized data. The current version has no single all-data deletion screen; delete available settings and custom audio individually and review OS permissions, backup, and secure-storage settings.
- Disarming, deleting, or uninstalling the App cannot erase copies in ntfy.sh caches, receiving devices, notification history, or backups.
6. Security and children
We take reasonable measures, including not retaining plaintext passcodes and limiting external transmission to user choices, but cannot guarantee complete security. The App is not directed to children; minors should use it only with a parent or guardian’s confirmation.
7. User choices and contact
Users may leave camera and notifications disabled, revoke OS permissions, and individually delete available settings and custom audio. The current version has no single all-data deletion screen. Requests concerning access, correction, or deletion will be handled under applicable law at:
- Operator: 株式会社MIZUKICHI Lab
- Contact: yamamoto@mizukichilab.com
8. Changes to this Policy
We may change this Policy for reasonable reasons such as changes in law, features, or data flows. We will announce the reason, content, and effective date on the website or in the App before the change takes effect. Where required by law, we will seek renewed consent for a change that materially affects user rights or external transmission.
9. Governing law and language
This Policy is governed by Japanese law. The Japanese version is authoritative in the event of a discrepancy, to the extent consistent with mandatory law.