Hulaki Privacy Policy
Effective date: 11 July 2026
Hulaki is an offline-first field mapping app where each chat message is a
geotagged observation shared with a group. This policy explains what data the
app handles, why, and who it is shared with. It is written for the app as it
works today.
Summary
- Messages and photos are end to end encrypted. The server stores only
ciphertext and cannot read their content.
- The app uses your precise location to tag observations and show them on a
map. Location is used only while the app or its foreground service is
running. The app does not track your location in the background for
advertising or profiling.
- No name, email address, or phone number is required to use the app.
- The app contains no advertising, no analytics, and no third-party
tracking software.
Information the app handles
- Location. With your permission, the app reads your
device GPS position to attach a location to the observations you send and to
center the map. While you record a track, a foreground service reads location
so recording continues with the screen off. A persistent notification is
shown whenever that service runs.
- Messages and photos. The observations, text, and photos
you send are encrypted on your device before they leave it, using a group key
that is shared only through a group invite link. The server that relays and
stores them holds only encrypted data.
- Display name. You choose a username shown to other
members of your groups. It is not linked to a real identity by the app.
- Account identifier. The app signs in anonymously and is
assigned a random account identifier by the backend. This is not tied to an
email address or phone number.
- Device keys. The app generates cryptographic keys on your
device to sign and verify group control messages. Private keys stay in the
device secure keystore. Only public keys are shared with your group.
- Camera. If you attach a photo to an observation, the app
uses the camera. Photos are encrypted before upload.
Public groups
If you choose to make a group publicly discoverable, that group's name,
description, map area, quick tags, optional icon, and approximate center
location are published to a directory so that other people nearby can find and
join it. This information is stored in readable form so the directory can work.
Do not make a group public if you do not want its name and location to be
visible to other app users. Groups that are not made public are joined only
through an invite link and are not listed in the directory.
When you request to join a group that requires approval, your chosen display
name and public keys are stored with that request so an admin can approve you.
What the app does not collect
- No advertising identifiers and no ads.
- No analytics, crash reporting, or usage tracking software.
- No contacts, no call logs, no browsing history.
- No requirement to provide a name, email address, or phone number.
Service providers and third parties
The app relies on the following services to function:
- Supabase hosts the backend that relays and stores
encrypted messages, encrypted media, and the public group directory. Servers
are located in the European Union. Message and media content reaches Supabase
only as ciphertext.
- CARTO serves the default map tiles and fonts. When the
map loads, your device requests tiles from CARTO, which necessarily receives
your IP address and the map area being viewed.
- Esri serves satellite imagery tiles if you switch the map
to satellite view. The same request information applies while that view is
active.
- Your device platform (Apple or Google) resolves
coordinates to place names through the operating system geocoding service, so
a coordinate may be sent to that platform service to obtain a place name.
These providers process data to deliver their service. The app does not sell
personal data and does not share it for advertising.
Data retention and deletion
Encrypted messages and media remain on the backend so that group members can
sync history. Because content is end to end encrypted, it is not readable by
the operator. You can leave a group at any time. To request deletion of
server-stored data associated with your account or a group you administer,
contact us at the address below.
Security
Message and media content is end to end encrypted with keys that are never
sent to the server. Data in transit is protected with HTTPS. No method of
transmission or storage is perfectly secure, but the design keeps readable
content off the server.
A group has one key for its lifetime, and that key is what decrypts the
group's messages. Removing someone from a group removes them from its member
list, but it does not change the key. Anyone who already holds the key, and
who can still reach the server, can therefore decrypt the group's later
messages. If a group's key is exposed, create a new group.
Children
Hulaki is intended for general audiences and is not directed at children.
The app does not knowingly collect personal information from children.
Changes to this policy
This policy may be updated as the app changes. Material changes will be
reflected here with a new effective date.
Operator and governing law
Hulaki is provided by an individual as a personal, non-commercial project.
It is operated from Nepal, and this policy is governed by the laws of Nepal.
Contact
For privacy questions or data requests, contact
krschap@proton.me.