Murlz App

Leave your message
to the world

Privacy Policy

Privacy Policy

Last updated: 2026-07-12

Draft status: developer draft. Replace all bracketed placeholders before release and publish this as an active, public, non-PDF URL if distributing through Google Play.

This Privacy Policy explains how [Developer Legal Name] (“Murlz”, “we”, “us”, or “our”) handles information when you use the Murlz mobile application and related services (the “App”).

If you do not agree with this Privacy Policy, do not use the App.

1. Short version

Murlz is an AR app for placing virtual text graffiti in real-world locations. To make that work, the App uses camera access, device sensors, location, ARCore/Geospatial processing, cloud storage, anonymous authentication, moderation systems, and user-generated content.

Marks you create are public or semi-public by design. Other users nearby may see your Mark text, its placement, your generated display name, rank, and social signals such as Sparks.

We do not currently sell personal data. We do use service providers such as Supabase, Google/ARCore, and OpenAI to operate the App.

2. Information we collect or process

AR, camera, sensor, and location data

The App uses your device camera, sensors, and location so AR features can work. This may include:

  • camera access for AR tracking and visual placement;

  • device motion and sensor data;

  • current GPS/location data and location accuracy;

  • ARCore Geospatial/VPS processing;

  • geospatial anchors for Marks, including latitude, longitude, altitude, orientation, surface normal, scale, and related placement data.

When you place a Mark, its geospatial placement data is stored so the Mark can appear in the same real-world location for you and other users.

Google Play Services for AR (ARCore), provided by Google, may process camera, sensor, and location data to power AR sessions. Learn more: https://support.google.com/ar?p=how-google-play-services-for-ar-handles-your-data

User-generated content

We collect and store content and metadata needed to provide App features, including:

  • Mark text;

  • color, font, scale, bounds, timestamp, and placement metadata;

  • author ID, generated display name, rank, and profile-related display data;

  • edit and delete events, moderation state, and related Mark activity;

  • Sparks, counts, and related social interactions;

  • reports and report reasons.

Account and profile data

The App may create an anonymous account through Supabase Auth when you take an intentional action such as creating a Mark, giving a Spark, reporting content, or opening your profile.

We may store:

  • anonymous user UUID;

  • generated display name;

  • access and refresh tokens stored locally on your device;

  • rank, Presence, Author and Explorer achievement progress, and related progression data;

  • NSFW display preference, moderation strike total, and shadowban status;

  • a one-way hashed (SHA-256) device identifier linked to your profile, used only for abuse prevention (see “Moderation and safety data” below); the raw device identifier does not leave your device;

  • local settings in PlayerPrefs or similar local storage, including the accepted terms/privacy version and acceptance timestamp (stored only on your device).

If cloud mode is unavailable, the App may use local fallback storage on your device. Local fallback data may include Mark data in a local JSON file and device-linked author identifiers.

Moderation and safety data

To keep the App safer and comply with platform requirements, we process moderation data, including:

  • text submitted for publication or edit;

  • text snapshots in moderation queues;

  • automated moderation decisions;

  • OpenAI moderation outputs or classifier summaries;

  • report history, report weights, censorship state, strike weights, and shadowban records;

  • a hashed device identifier used to detect accounts created to evade a shadowban or other moderation sanctions, including accounts created after a sanctioned account was deleted;

  • logs needed to investigate abuse, spam, safety incidents, or technical failures.

Media capture

If you use screenshot or video recording features, the App may capture the current screen or AR camera view and save the image or video to your device gallery, usually in a “Murlz” folder. We do not intentionally upload these captures to our backend unless a future feature clearly says so and obtains any required consent.

Your device operating system, gallery app, app store, or sharing apps may process media according to their own terms and privacy policies.

Support and communications

If you contact us, we may receive your email address, message, attachments, and other information you choose to provide.

3. How we use information

We use information to:

  • provide AR placement and geospatial persistence;

  • show nearby Marks;

  • save, load, edit, delete, moderate, and report Marks;

  • operate profiles, ranks, Author and Explorer achievements, Presence, and Sparks;

  • prevent spam, abuse, unsafe AR anchoring, harassment, and prohibited content;

  • run automated and human moderation;

  • investigate reports, legal requests, and safety incidents;

  • debug, maintain, secure, and improve the App;

  • provide support and respond to requests;

  • comply with laws, app store rules, ARCore requirements, and this Privacy Policy.

4. How information is shared

Public or visible to other users

The following may be visible to other users:

  • Mark text after moderation;

  • Mark location or AR placement in the relevant real-world area;

  • generated display name and rank;

  • social signals such as Sparks and their counts;

  • moderation labels such as masked profanity or censored status.

Do not place personal data, exact addresses, contact details, private information, or anything confidential in Marks.

Service providers

We share or process information with service providers that help operate the App:

  • Supabase: backend database, authentication, PostgREST/RPC, storage of App data, Edge Functions, and server-side logic.

  • Google Play Services for AR / ARCore: AR tracking, sensor/camera/location processing, Geospatial API, and related AR functionality.

  • OpenAI: automated text moderation. Text submitted for moderation and relevant metadata may be sent to OpenAI to classify content.

  • App store and OS providers: app distribution, platform permissions, crash/system behavior, and device-level media/gallery features.

These providers process data according to their own terms, privacy policies, and data-processing commitments.

OpenAI API data is not used to train OpenAI models by default unless the API account opts in. OpenAI may retain API inputs and outputs for abuse monitoring for up to 30 days unless a different retention configuration or legal requirement applies. See: https://platform.openai.com/docs/guides/your-data

Legal, safety, and business reasons

We may disclose information if we believe it is necessary to:

  • comply with law, legal process, or valid requests;

  • enforce our terms;

  • protect users, the public, property owners, third parties, or the App;

  • investigate abuse, security incidents, fraud, or safety issues;

  • complete a merger, acquisition, financing, sale of assets, or similar business transaction, subject to appropriate protections.

5. Data retention

We retain information for as long as reasonably necessary for the purposes described in this policy.

Current expected retention:

  • Marks and geospatial placement data: retained while the Mark remains stored or is needed for App features, unless deleted or removed.

  • Account/profile/progression data: retained while your App account exists and for a reasonable period after deletion where needed for backups, safety, legal compliance, or dispute resolution.

  • Reports, moderation penalties, and safety records: retained as long as needed to enforce rules, prevent abuse, protect users, and comply with legal obligations. Reports you submitted may be kept in anonymized form (detached from your identity) after you delete your account, so that moderation decisions about other users’ content remain valid.

  • Hashed device identifiers of sanctioned accounts: if your account is shadowbanned or has significant moderation strikes at the time you delete it, the hashed device identifier may be retained after account deletion to prevent ban evasion. It is not used for any other purpose.

  • Moderation jobs and AI decision logs: backend design may retain clean/profane jobs for about 7 days and censored/failed jobs for about 30 days, while durable moderation state may remain attached to Marks and profiles.

  • Local device data: retained until you delete it, clear App data, or uninstall the App, except for data stored in your device gallery or by third-party apps.

  • Screenshots and videos saved to your gallery: retained on your device until you delete them.

  • Backups and logs: retained for a reasonable period and then deleted or overwritten according to operational needs.

We may retain limited information longer if required or permitted by law, needed for security, fraud prevention, dispute resolution, or to enforce our terms.

6. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of certain personal information.

You can:

  • delete your own Marks where the App allows it;

  • change local NSFW display settings;

  • disable camera or location permissions in your device settings, although this may break core App features;

  • delete local App data through your device settings;

  • permanently delete your account and associated data from within the App: Profile → Delete Account;

  • request deletion without the App installed by contacting [privacy email] or using [account deletion URL].

What account deletion does

When you delete your account (in-app or by request), we:

  • delete your account and authentication identity, so your access tokens stop working;

  • delete your profile, generated display name, rank, Presence, Author and Explorer achievement progress, and related account data;

  • delete your Marks and their geospatial placement data, together with Sparks, reports, and moderation records attached to those Marks;

  • delete records linking you to other users’ content, such as Sparks you gave and places you discovered;

  • anonymize reports you submitted about other users’ content (the report is kept, your identity is removed), so moderation decisions about that content remain valid;

  • clear authentication tokens and cached profile data from your device.

Limited information may be retained where necessary for safety, legal compliance, moderation integrity, backups, fraud prevention, dispute resolution, or to protect others. In particular, if your account is shadowbanned or has significant moderation strikes when it is deleted, we retain a one-way hashed device identifier to prevent banned users from evading sanctions by deleting and re-creating accounts (see “Data retention”).

7. Children

Murlz is not directed to children. You must be at least 13 years old, or older if your jurisdiction requires a higher age to use online services without parental consent. If you are under the age of majority where you live, you may use the App only with permission from a parent or legal guardian.

Do not use the App to create or share content involving minors in a sexual, exploitative, harassing, identifying, or unsafe way. Such content may be removed and reported where appropriate.

8. Security

We use reasonable technical and organizational measures to protect information, such as HTTPS, Supabase security features, row-level security where configured, authentication tokens, and access controls.

No system is perfectly secure. You use the App knowing that data transmission, storage, AR processing, and cloud services carry risk.

9. International processing

Your information may be processed in countries other than where you live. Those countries may have different data protection laws. Where required, we use appropriate legal mechanisms for cross-border processing.

10. Changes

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as in-app notice or requesting renewed consent where required.

11. Contact

Developer: [Developer Legal Name] Address: [Developer Address or business address] Privacy contact: [privacy email] Support: [support email] Account deletion URL: [public deletion URL]

Last updated: 2026-07-12

Draft status: developer draft. Replace all bracketed placeholders before release and publish this as an active, public, non-PDF URL if distributing through Google Play.

This Privacy Policy explains how [Developer Legal Name] (“Murlz”, “we”, “us”, or “our”) handles information when you use the Murlz mobile application and related services (the “App”).

If you do not agree with this Privacy Policy, do not use the App.

1. Short version

Murlz is an AR app for placing virtual text graffiti in real-world locations. To make that work, the App uses camera access, device sensors, location, ARCore/Geospatial processing, cloud storage, anonymous authentication, moderation systems, and user-generated content.

Marks you create are public or semi-public by design. Other users nearby may see your Mark text, its placement, your generated display name, rank, and social signals such as Sparks.

We do not currently sell personal data. We do use service providers such as Supabase, Google/ARCore, and OpenAI to operate the App.

2. Information we collect or process

AR, camera, sensor, and location data

The App uses your device camera, sensors, and location so AR features can work. This may include:

  • camera access for AR tracking and visual placement;

  • device motion and sensor data;

  • current GPS/location data and location accuracy;

  • ARCore Geospatial/VPS processing;

  • geospatial anchors for Marks, including latitude, longitude, altitude, orientation, surface normal, scale, and related placement data.

When you place a Mark, its geospatial placement data is stored so the Mark can appear in the same real-world location for you and other users.

Google Play Services for AR (ARCore), provided by Google, may process camera, sensor, and location data to power AR sessions. Learn more: https://support.google.com/ar?p=how-google-play-services-for-ar-handles-your-data

User-generated content

We collect and store content and metadata needed to provide App features, including:

  • Mark text;

  • color, font, scale, bounds, timestamp, and placement metadata;

  • author ID, generated display name, rank, and profile-related display data;

  • edit and delete events, moderation state, and related Mark activity;

  • Sparks, counts, and related social interactions;

  • reports and report reasons.

Account and profile data

The App may create an anonymous account through Supabase Auth when you take an intentional action such as creating a Mark, giving a Spark, reporting content, or opening your profile.

We may store:

  • anonymous user UUID;

  • generated display name;

  • access and refresh tokens stored locally on your device;

  • rank, Presence, Author and Explorer achievement progress, and related progression data;

  • NSFW display preference, moderation strike total, and shadowban status;

  • a one-way hashed (SHA-256) device identifier linked to your profile, used only for abuse prevention (see “Moderation and safety data” below); the raw device identifier does not leave your device;

  • local settings in PlayerPrefs or similar local storage, including the accepted terms/privacy version and acceptance timestamp (stored only on your device).

If cloud mode is unavailable, the App may use local fallback storage on your device. Local fallback data may include Mark data in a local JSON file and device-linked author identifiers.

Moderation and safety data

To keep the App safer and comply with platform requirements, we process moderation data, including:

  • text submitted for publication or edit;

  • text snapshots in moderation queues;

  • automated moderation decisions;

  • OpenAI moderation outputs or classifier summaries;

  • report history, report weights, censorship state, strike weights, and shadowban records;

  • a hashed device identifier used to detect accounts created to evade a shadowban or other moderation sanctions, including accounts created after a sanctioned account was deleted;

  • logs needed to investigate abuse, spam, safety incidents, or technical failures.

Media capture

If you use screenshot or video recording features, the App may capture the current screen or AR camera view and save the image or video to your device gallery, usually in a “Murlz” folder. We do not intentionally upload these captures to our backend unless a future feature clearly says so and obtains any required consent.

Your device operating system, gallery app, app store, or sharing apps may process media according to their own terms and privacy policies.

Support and communications

If you contact us, we may receive your email address, message, attachments, and other information you choose to provide.

3. How we use information

We use information to:

  • provide AR placement and geospatial persistence;

  • show nearby Marks;

  • save, load, edit, delete, moderate, and report Marks;

  • operate profiles, ranks, Author and Explorer achievements, Presence, and Sparks;

  • prevent spam, abuse, unsafe AR anchoring, harassment, and prohibited content;

  • run automated and human moderation;

  • investigate reports, legal requests, and safety incidents;

  • debug, maintain, secure, and improve the App;

  • provide support and respond to requests;

  • comply with laws, app store rules, ARCore requirements, and this Privacy Policy.

4. How information is shared

Public or visible to other users

The following may be visible to other users:

  • Mark text after moderation;

  • Mark location or AR placement in the relevant real-world area;

  • generated display name and rank;

  • social signals such as Sparks and their counts;

  • moderation labels such as masked profanity or censored status.

Do not place personal data, exact addresses, contact details, private information, or anything confidential in Marks.

Service providers

We share or process information with service providers that help operate the App:

  • Supabase: backend database, authentication, PostgREST/RPC, storage of App data, Edge Functions, and server-side logic.

  • Google Play Services for AR / ARCore: AR tracking, sensor/camera/location processing, Geospatial API, and related AR functionality.

  • OpenAI: automated text moderation. Text submitted for moderation and relevant metadata may be sent to OpenAI to classify content.

  • App store and OS providers: app distribution, platform permissions, crash/system behavior, and device-level media/gallery features.

These providers process data according to their own terms, privacy policies, and data-processing commitments.

OpenAI API data is not used to train OpenAI models by default unless the API account opts in. OpenAI may retain API inputs and outputs for abuse monitoring for up to 30 days unless a different retention configuration or legal requirement applies. See: https://platform.openai.com/docs/guides/your-data

Legal, safety, and business reasons

We may disclose information if we believe it is necessary to:

  • comply with law, legal process, or valid requests;

  • enforce our terms;

  • protect users, the public, property owners, third parties, or the App;

  • investigate abuse, security incidents, fraud, or safety issues;

  • complete a merger, acquisition, financing, sale of assets, or similar business transaction, subject to appropriate protections.

5. Data retention

We retain information for as long as reasonably necessary for the purposes described in this policy.

Current expected retention:

  • Marks and geospatial placement data: retained while the Mark remains stored or is needed for App features, unless deleted or removed.

  • Account/profile/progression data: retained while your App account exists and for a reasonable period after deletion where needed for backups, safety, legal compliance, or dispute resolution.

  • Reports, moderation penalties, and safety records: retained as long as needed to enforce rules, prevent abuse, protect users, and comply with legal obligations. Reports you submitted may be kept in anonymized form (detached from your identity) after you delete your account, so that moderation decisions about other users’ content remain valid.

  • Hashed device identifiers of sanctioned accounts: if your account is shadowbanned or has significant moderation strikes at the time you delete it, the hashed device identifier may be retained after account deletion to prevent ban evasion. It is not used for any other purpose.

  • Moderation jobs and AI decision logs: backend design may retain clean/profane jobs for about 7 days and censored/failed jobs for about 30 days, while durable moderation state may remain attached to Marks and profiles.

  • Local device data: retained until you delete it, clear App data, or uninstall the App, except for data stored in your device gallery or by third-party apps.

  • Screenshots and videos saved to your gallery: retained on your device until you delete them.

  • Backups and logs: retained for a reasonable period and then deleted or overwritten according to operational needs.

We may retain limited information longer if required or permitted by law, needed for security, fraud prevention, dispute resolution, or to enforce our terms.

6. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of certain personal information.

You can:

  • delete your own Marks where the App allows it;

  • change local NSFW display settings;

  • disable camera or location permissions in your device settings, although this may break core App features;

  • delete local App data through your device settings;

  • permanently delete your account and associated data from within the App: Profile → Delete Account;

  • request deletion without the App installed by contacting [privacy email] or using [account deletion URL].

What account deletion does

When you delete your account (in-app or by request), we:

  • delete your account and authentication identity, so your access tokens stop working;

  • delete your profile, generated display name, rank, Presence, Author and Explorer achievement progress, and related account data;

  • delete your Marks and their geospatial placement data, together with Sparks, reports, and moderation records attached to those Marks;

  • delete records linking you to other users’ content, such as Sparks you gave and places you discovered;

  • anonymize reports you submitted about other users’ content (the report is kept, your identity is removed), so moderation decisions about that content remain valid;

  • clear authentication tokens and cached profile data from your device.

Limited information may be retained where necessary for safety, legal compliance, moderation integrity, backups, fraud prevention, dispute resolution, or to protect others. In particular, if your account is shadowbanned or has significant moderation strikes when it is deleted, we retain a one-way hashed device identifier to prevent banned users from evading sanctions by deleting and re-creating accounts (see “Data retention”).

7. Children

Murlz is not directed to children. You must be at least 13 years old, or older if your jurisdiction requires a higher age to use online services without parental consent. If you are under the age of majority where you live, you may use the App only with permission from a parent or legal guardian.

Do not use the App to create or share content involving minors in a sexual, exploitative, harassing, identifying, or unsafe way. Such content may be removed and reported where appropriate.

8. Security

We use reasonable technical and organizational measures to protect information, such as HTTPS, Supabase security features, row-level security where configured, authentication tokens, and access controls.

No system is perfectly secure. You use the App knowing that data transmission, storage, AR processing, and cloud services carry risk.

9. International processing

Your information may be processed in countries other than where you live. Those countries may have different data protection laws. Where required, we use appropriate legal mechanisms for cross-border processing.

10. Changes

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as in-app notice or requesting renewed consent where required.

11. Contact

Developer: [Developer Legal Name] Address: [Developer Address or business address] Privacy contact: [privacy email] Support: [support email] Account deletion URL: [public deletion URL]