Муушиг · Muushig
Privacy Policy
Effective and last updated: 26 August 2026
Muushig has no ads, advertising SDKs, cross-app tracking, or data sales. You can practise offline, or create a guest profile for online play without giving us an email address, phone number, or social account.
Who operates Muushig
Muushig is operated by Bayarbileg Bayarsaikhan. Questions, safety concerns, account help, and privacy requests can be sent to bbayarbileg@gmail.com.
Data we process
When you create a guest profile or use online play, the Muushig service processes:
- a generated player ID, immutable random friend code, chosen display name, bundled avatar selection, and social-points total;
- one-way session-token digests, session dates, and a one-way recovery-key digest when recovery is enabled;
- matchmaking tickets, recent-presence timestamps, room and invitation state, friendships, blocks, reports, and supported participant chat or reaction events;
- table seats, game state, actions, retry identifiers, scores, turn deadlines, rounds, tricks, played cards, winners, and timestamps; and
- source IP addresses used temporarily at the network boundary for security and request-rate limiting. Reverse-proxy access paths are not retained in access logs.
The Android release does not request access to contacts, precise or approximate location, advertising identifiers, the photo library, camera, microphone, or payment information. It does not currently provide custom-photo upload or free-text chat. The shared service also supports social features used by the iOS release, described below.
Optional photos and participant chat on supported versions
On a version that offers a custom profile photo, the app centre-crops the selected image, reduces it to at most 512 by 512 pixels, removes source metadata by drawing a new image, and uploads a JPEG no larger than 512 KiB. The service stores the prepared JPEG, not the original photo-library file. Choosing a bundled avatar does not upload a photo.
Supported versions can let authenticated match participants send fixed phrases, emotes, and typed messages. Typed messages are bounded, normalised, and stored with the sender, match, retry identifier, and timestamp. Public spectators never receive participant-written message text. Muushig has no voice messages or chat attachments.
Public Quick Match and spectating
An active public Quick Match may appear in the public live-match list and may be watched without spectator sign-in. A public listing or spectator view can include display names, avatar or prepared profile photo, seats, scores, card counts, face-up and played cards, timers, round history, results, and fixed reactions. It never includes private hands, stock order, legal moves, friend codes, internal player IDs, credentials, private-room links, or participant-written chat text. Private rooms are never listed.
A custom photo shown at a public table is delivered from an opaque image address. Spectators can view, download, or cache an image they receive. Replacing or removing the photo, or deleting the account, removes the service's stored copy.
Safety, reports, and blocks
Muushig filters a small set of severe terms from display names. A seated player can report or block another human seat. Supported versions can also report an exact typed event. Reports store the reported player, match, seat, fixed reason, random retry identifier, status, and time; a message report also stores a bounded snapshot of the reported message as evidence. There is no user-written report comment or attachment. Reports are handled through a private operator process.
Private rooms, friends, and invitations
A private room is visible only to its members. Members can see one another's display name, friend code, avatar or profile photo, and room status. Opaque room invitation links act like temporary capabilities; anyone receiving a still-valid link may try to use it, so keep it private. The server stores only a SHA-256 digest of the invitation token.
Apple Game Center
Game Center Friends mode is available only on supported Apple versions and is provided by Apple under Apple's privacy terms. Muushig reads the Game Center identity and match data needed to create and play those matches. Temporary, unlisted spectator relay snapshots omit provider identifiers, private hands, and credentials.
Data stored on your device
On Android, the guest credential is encrypted with a non-exportable Android Keystore key and stored in private app preferences excluded from backup. On iOS, credentials and unfinished recovery operations are stored in the Keychain. Non-secret recovery state can be stored in private app preferences. Removing the app or clearing local storage removes the local credential but does not by itself delete the server profile.
Why we use data
We use the data only to create and restore guest profiles; provide multiplayer, rooms, invitations, friends, reports, blocks, supported chat and reactions; operate and reconnect games; prevent conflicting or repeated actions; provide public or requested spectating; enforce safety controls; maintain security; diagnose failures; and keep the service available.
Sharing and service providers
Muushig does not sell personal data and does not use it for advertising. Game state and profile information are shown to other players or spectators as described above because that is part of the multiplayer service. Data is otherwise processed on infrastructure used to host and protect Muushig, and may be disclosed when required by law or necessary to protect the service and its users. Apple separately processes Game Center and TestFlight data.
External account linking
Apple, Google, and Facebook account linking is unavailable and hidden in the current Android release. Muushig therefore does not collect provider identity credentials through account linking in this release. Game Center and TestFlight remain separate Apple services.
Retention
Guest sessions expire after 30 days. One-way token-digest rows are deleted 30 days after expiry or revocation; during that post-expiry period, the exact unrevoked token can be used only to request account deletion.
Waiting rooms and their invitations last no more than 24 hours. Cancelled or expired room, membership, invitation, and terminal matchmaking records are deleted after seven days. Fixed reactions and typed chat events are deleted after seven days. Completed or abandoned match state, actions, card and round history, reports, and message-evidence snapshots are deleted 30 days after the match's last update. Pending friend requests are deleted after 30 days.
Guest profiles, friend codes, display names, avatars or profile photos, recovery-key digests, accepted friendships, blocks, and social-points totals remain until changed, removed where a control is available, or the account is deleted. Replacing a profile photo removes the previous service copy. Unlisted Game Center relay snapshots expire within minutes.
Delete your account and data
In Android: open Muushig, choose Online, open your guest profile, choose Delete account and data, and confirm. Supported iOS versions provide the equivalent control in the online profile.
Deletion removes the player profile, friend code, custom profile photo, sessions, recovery-key digest, matchmaking data, rooms and invitations, friendships and blocks involving the player, reports involving the player, and authoritative tables containing that player. Deleting those tables also removes their stored actions, history, chat and reaction events, reports, and message evidence. This cannot be undone and can end a shared active table.
If you cannot access the app, email bbayarbileg@gmail.com with “Muushig account deletion request.” We may ask for the active guest credential or MUU1 recovery key to verify that you control the account. Never send a social-account password. Apple-controlled Game Center and TestFlight data must be managed through Apple.
Security and your choices
Connections use HTTPS. Bearer tokens, recovery keys, and invitation tokens are stored server-side only as one-way digests. Keep any MUU1 recovery key or private-room link private. You can practise offline, use online play without recovery, use a bundled avatar, block or report another human seat, remove a supported custom photo, or delete the guest profile.
Changes
Material changes will be reflected here with a new effective date. This policy applies to the Muushig Android and iOS apps and the Muushig guest multiplayer, social, room, matchmaking, safety, and spectator services.