Effective: 22 July 2026
Mugula is built to be private by design. There is no account system,
no ads, no analytics, and no tracking. We never see the media you send: it is encrypted on
your device before it leaves, and we do not hold the keys.
Photos & Camera
Mugula uses your camera and photo library only so you can capture or choose a photo or
video to edit. All editing (drawing, stickers, captions, and filters) happens
entirely on your device.
Face Data
Some Mugula camera effects (face filters and face-warp effects) need to know where a face
is on screen in order to place a sticker or distortion correctly.
- What is collected: Mugula uses Apple's on-device Vision
framework (
VNDetectFaceLandmarksRequest) to compute the on-screen positions of
facial landmarks (the outlines of eyes, nose, and mouth) for the current camera frame or
the photo you are editing.
- How it is used: solely to draw the visual effect you selected. It is
used for positioning graphics only.
- No identification: Mugula does not perform face
recognition or identity matching, and does not create, derive, or store a
faceprint, face template, or any other biometric identifier.
- Where it is processed: entirely on your device. Face
data is never transmitted off the device, never uploaded to our servers or to iCloud, and is
never shared with any third party.
- Retention: none. Landmark positions exist only in
memory while the frame is being drawn and are discarded immediately afterward, typically
within a fraction of a second. They are never written to disk. Only the finished picture or
video you choose to send is saved or sent; the underlying face data is not included in it.
How Your Media Is Sent
- When you send a photo or video, it is encrypted on your device
(AES-256-GCM) before it leaves. The encrypted file is delivered through
Apple iCloud (CloudKit). The decryption key travels only inside the
end-to-end-encrypted message, not with the stored file, so only your recipient can open
it. We cannot read your media.
- Media is temporary. It automatically deletes after the sender's chosen
availability window (default 48 hours), and "view once" media is removed as soon as it is
viewed. Deletion is client-driven: the encrypted iCloud copy is removed the next time a
participating device opens Mugula after the window passes.
- Universal mode (an option you turn on per send) instead sends
your media as a standard message attachment so any recipient can view it. In
this mode the media is not encrypted by Mugula and does not auto-delete.
the app tells you this before you turn it on.
Data We Collect
No personal information, no contacts, no location, and no identifiers. We do not use
analytics or tracking SDKs, we do not sell or share data with advertisers or third parties,
and we do not build a profile of you. The only data that leaves your device is the encrypted
media you explicitly choose to send.
Data Retention
Encrypted media stored in iCloud (CloudKit) is pruned at its availability expiry (default
48 hours, or sooner for view-once media). Local cached copies on your device are removed on
the same per-send expiry; any local file without a recorded expiry is cleared after a 14-day
fallback limit at the latest. You can shorten this or clear the cache at any time from the
Mugula app's Storage settings.
Children
Mugula is not directed at children under 13 and does not knowingly collect personal
information from them.
Changes
If this policy changes, the updated version will appear on this page with a new effective
date.
Contact
Questions? Email ddilanchian@gmail.com.