Mewgshot privacy policy
Last updated: 12 September 2026
Mewgshot is the campus cat register for NUST H-12, Islamabad. The developer can be reached at mewgshotapp@gmail.com for privacy, account deletion and abuse reports.
Your account
Google sign-in connects your account to a random keeper identifier. Where Apple sign-in is offered, it serves the same purpose. Supabase Auth stores the provider identity and email address. Your email is not shown to other keepers or used for marketing. You choose a public nickname and an optional profile photo; neither needs to identify you. These appear alongside your contributions and can be changed in Settings.
Older beta installations may have an anonymous account. Link that account using the in-app account flow before uninstalling or changing phones. Signing in with the same linked provider restores the same keeper; using a different provider or account may create a different keeper.
Information we store
- Contributions: cat cards, sightings, grades, reviews, votes, pets, feeds and collar tags, associated with your keeper identifier. Cat photographs and profile photographs are public to anyone with their image address.
- Photographs and matching: scanning computes a 384-number image description on your device. Opening the camera alone does not upload the picture. Confirming an enrolment or sighting uploads the chosen photo and its description. Photos are resized and re-encoded before upload.
- Location: with permission, a confirmed sighting sends its exact coordinate to private database tables for matching and deriving a campus block. Other keepers and clients using the public app key cannot read those coordinates; public records expose a block or a coarse map position. Location is not collected in the background. The app works without location permission.
- Your private shelf: achievements and keeper totals are available to you. Other keepers cannot query another keeper's shelf through the public app API.
- Feedback: messages you submit, their category, time, app version, device software, current screen and chosen nickname. Optional screenshots are held in private storage for the development team. Feedback does not automatically attach location.
- Reports and blocks: the content you report, your selected reason and optional details, and the accounts or content you hide. These support moderation and are not exposed as a public list. The development team can investigate reports and remove content or suspend abusive accounts.
- Basic activity: one private row per keeper stores first and most recent activity, app version and platform. It is updated at most once per minute while the app is open, with no history of screens or locations.
Website measurement
The landing website records page views, download and outbound-link clicks, demo interactions and time while the page is visible. A random browser identifier in local storage and a session identifier in session storage estimate repeat visits. We store the page path, referral domain, campaign labels, browser and operating-system family, device class and approximate country supplied by Cloudflare. We do not store raw IP addresses, full referral URLs or fingerprints in this dataset, and do not link website browser identifiers to keeper accounts. Anonymous visitors cannot be identified by name. Browser Do Not Track and Global Privacy Control preferences disable this measurement. Clearing website storage resets the browser identifier.
These records are visible only in the developer's protected monitoring dashboard and are used to understand website usage. Records older than 90 days are removed during the next collection or dashboard refresh, with cleanup checked once a day; clearing local storage does not remove previously collected records. You can request deletion by supplying your browser identifier from website storage. The dashboard also displays private account activity, contribution totals and feedback already described above.
Data on your device
The app stores your sign-in session, settings and cached content locally. If a confirmed scan cannot finish uploading, its photo and submission details, including a coordinate you permitted, stay on that device until saved or removed. The app retries while it is open and the correct account is signed in. Settings shows outstanding saves. Uninstalling, clearing app data or clearing browser storage can erase these unsent copies; finish pending saves before doing so.
Service providers
- Supabase hosts authentication, the shared database and image storage.
- Open-Meteo supplies weather for the centre of campus, not your personal location.
- OpenStreetMap supplies map tiles; its tile service receives requests from your device.
- Sentry, when configured in a release, receives crash diagnostics, session information and sampled performance traces. Default personal-information collection is disabled. Releases without a Sentry connection log errors locally.
- Expo supplies app code updates using the app version and release channel.
- Cloudflare and GitHub host the website, release information and direct Android downloads. The direct Android edition downloads an installer when you choose Download update. Store editions use their store for full app updates.
These providers may process network information such as an IP address to deliver their services, and their infrastructure may be outside your country. Nothing is sold. Mewgshot has no advertising or advertising trackers.
Retention and deletion
Your account and contributions remain while you use the register unless you delete them or moderation requires removal. Settings → Delete my account deletes your authentication account, profile, activity row and associated personal records such as sightings, grades, reviews and votes. It removes the provider connection. Signing in again afterwards creates a fresh keeper. Sign out does not delete your account.
Community cat cards remain. Photos and other community records may remain without the deleted keeper association where they are part of the shared cat register. Feedback remains to resolve issues, with the account link and nickname removed; identifying details you typed into the message may remain. Reports may be retained to investigate abuse. To request removal of identifying content, contact the address below.
If you cannot use the app, email mewgshotapp@gmail.com with the subject Delete my Mewgshot account, your in-app nickname and the sign-in email or provider you used. We will verify account ownership before acting. Never send your password. You can also request access, correction or deletion of your personal information by email.
Restricted backups may retain a copy until replaced under the backup retention cycle. They are used for recovery, not to republish deleted accounts.
Children and changes
Mewgshot is intended for a university community and is not directed at children under 13. If you believe a child supplied personal information, contact us so we can investigate and remove it. We update this policy and its date when our data practices change.