MukjahMukjah

Privacy policy

Effective Date: 09/29, 2026

At Mukjah, we believe great restaurants are built on great relationships. Our mission is to help restaurants build and maintain meaningful relationships with their customers while helping people discover, remember, and share exceptional dining experiences.

Your privacy matters to us. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices you have regarding your personal information when using the Mukjah mobile application and related services (collectively, the "Service"). By creating an account, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Who We Are

Mukjah is operated by A&K Systems, Inc., a California software company focused on building technology that strengthens the relationship between restaurants and their customers.

Contact: yo@mukjah.com

2. Information We Collect

Account Information: Email address, password, display name, profile photo, and biography for account management and authentication.

Onboarding & Taste Preferences: During onboarding, we ask a short taste quiz (which becomes your taste profile, including how strong you like flavors), your favorite cuisine, how often you eat out, what you find hardest about eating out, and how you usually discover restaurants. Every onboarding question can be skipped. We use these answers — together with the cards you write, the visits you verify, and the places you save — to match dishes to your taste and to order what we show you. We never use them for advertising.

Location Information: With your permission, we collect precise or approximate location to display nearby restaurants, verify visits, improve recommendations, and power map features. You may disable location permissions at any time. Background location is not collected unless explicitly required and authorized. Precise location may be treated as sensitive personal information under California law — see Section 10.

Photos and Media: We only access photos and videos you explicitly choose to upload. Photo metadata such as capture time and GPS coordinates is removed from the image before it is stored. Videos are uploaded as you selected them, so any audio they contain — and any location metadata the recording device embedded in the file — is uploaded with them. Photos and videos attached to a card are publicly viewable. Do not upload a video containing someone's voice or likeness without their consent.

Visit Verification Evidence: When you verify a visit, the image you submit (a receipt or a photo taken in the app) is stored separately from your public content, in a private location that other users cannot access. We compute a fingerprint (a one-way hash) of that image and compare it against fingerprints of images submitted by other accounts, in order to detect the same evidence being reused. When you submit a receipt, we also send the receipt image to Microsoft Azure AI Document Intelligence, a cloud OCR provider, solely to extract the date, amount, and merchant name printed on it; Microsoft processes this image on our behalf as a service provider and does not use it for its own purposes. A member of our team may view a submitted image when an automated check is inconclusive; reviewers see a pseudonymous identifier rather than your name or profile. Receipts may contain information printed by the merchant, such as the last four digits of a payment card, the time of purchase, and the store location — please avoid submitting a receipt if you do not want that information stored. Verification evidence is retained only as long as needed to make and support the verification decision, and is queued for deletion when you delete your account (see Section 9). Once an image is deleted we keep the verification decision and the fingerprint, but not the image.

User-Generated Content: Reviews, Insider Order Cards, ratings, comments, notes, lists, saved restaurants, favorite dishes, profile information, photos, and videos (including any audio they contain). You retain ownership of your content while granting Mukjah a limited, non-exclusive license to host, display, and promote it in order to operate and improve the Service. This license ends when you delete the content or your account.

Transfer Handles: You may optionally add your username or identifier for a third-party money transfer service — Venmo, PayPal, or Zelle — to your profile, so that a friend splitting a bill with you can send you money directly in that service. This is off by default; we store a handle only for the services you fill in, and clearing a field deletes it. Mukjah does not process, hold, route, or have any visibility into a payment. We do not connect to these services, we do not verify that a handle is valid or belongs to you, and we never learn whether — or how much — money changed hands. Note that a Zelle identifier is normally the email address or phone number registered with your bank, so filling in that field means storing that email address or phone number. A handle you add is visible to other signed-in Mukjah users who open your profile; it is not readable by anyone who is not signed in, it is never shown to a user you have blocked or who has blocked you, it is not shown to restaurants, and it is not used for recommendations. Because a handle is visible to other users, do not add one you do not want other members to see — clearing the field removes it.

Reports and Blocks: When you report content or another user, or block another user, we store that record to enforce our Community Guidelines and keep the Service safe.

Search and Recommendation Text: When you describe what you are craving in your own words, we send that text to Google's Gemini generative AI service so it can be turned into structured filters (a dish keyword, a food category, a price ceiling, a meal time, an occasion). Only the text you typed and your language setting are sent — your saved places, visit history, taste profile, and account identity are not. The result is a set of filters; it is not a ranking, a score, or an explanation of why something suits you. Mukjah does not store this text and does not use it to train any model. However, we currently use Google's free service tier, and under Google's terms for that tier Google may use the text you submit and the response it returns to provide, improve, and develop Google's products, services, and machine learning technologies, and Google's human reviewers may read and annotate it. Google states that it disconnects this data from your account, API key, and project before a human reviewer sees it. Please do not type anything into this box that you would not want a person to read. This feature is optional — you can browse restaurants and use the filters on the home screen without it. Nothing you type is sent until you agree: the app shows who receives the text and asks for your permission before the text box appears, and the quick-pick buttons on the same screen work without it. You can turn it off at any time from that screen or in Settings, after which no further text is sent.

Technical Information: Device type, operating system, app version, IP address, and language settings, used to operate, secure, and troubleshoot the Service. We do not currently use third-party analytics or crash-reporting SDKs; if we add them in the future, we will update this Policy and our App Store privacy disclosures beforehand.

Push Notifications: If you turn notifications on, we register a push token — an identifier for your specific device, issued by Apple's Push Notification service (APNs) or Google's Firebase Cloud Messaging (FCM) and relayed through Expo's push service — so we can deliver the alerts you have enabled (for example friend requests, meetup updates, comments on your cards, and announcements). We store this token with your account and remove it when you turn notifications off, sign out, or delete your account. You can turn notifications off at any time in the app's notification settings or in your device's system settings. A notification may include another user's display name or a short preview of their message, and is sent only to your device.

Usage Information: When you tap a photo or video in the app, we record which item it belonged to (a card, a restaurant, or a menu item), which screen you were on, what the tap opened, and the time. These records are linked to your account. We collect them only to understand which content people open. They are first-party — kept in our own systems, not sent to a third-party analytics provider — and they are never shown to other users, never shown to restaurants, and never used to rank, sort, or recommend anything.

3. How We Use Your Information

We use your information to manage accounts, authenticate users, recommend restaurants and dishes, match you with users who share your taste preferences, verify visits, provide Insider Order Cards, personalize recommendations, improve search, detect fraud, moderate content, deliver the push notifications you turn on, respond to support requests, understand which photos and videos people open so we can improve the Service, and comply with legal obligations. We do not sell personal information or use it for third-party behavioral advertising.

4. What Other Users Can See

Your display name, handle, profile photo, bio, taste badges, and your Eater/Regular level for each restaurant are visible to other users of the Service. Insider Order Cards you write — including your taste badges and level at the time of writing — are visible to other users and to the restaurant you wrote about. Do not include information in your profile or content that you do not want to be public.

A saved restaurant is narrower than that: it is private unless you turn on visibility for that particular place. A transfer handle (Section 2) is visible to other signed-in users who open your profile, but not to anyone who is not signed in. Neither is visible to a user you have blocked or who has blocked you.

5. Restaurant Relationships

In addition to the public visibility described in Section 4, restaurants may receive aggregated, anonymized, or user-authorized information that helps them improve customer experiences. We do not provide private personal information (such as your email or precise location history) unless you authorize it, a requested feature requires it, or the law requires it.

6. Sharing Your Information

We share information only with trusted providers necessary to operate the Service, including authentication, hosting, storage, database, and mapping providers, or when legally required to protect users, prevent fraud, or enforce our Terms. We do not sell personal information.

7. Third-Party Service Providers

Current providers include Supabase (authentication, database, storage), Google Maps Platform (maps and location services), Microsoft Azure AI Document Intelligence (optical character recognition for receipt-based visit verification), Google Gemini (turning the free-text description of what you are craving into structured search filters), Expo (Expo Application Services, which relays push notifications), and Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging), which deliver push notifications to your device. Additional providers may be added as the Service evolves; this Policy will be updated accordingly.

8. Data Retention

We retain personal information only as long as necessary. When you delete your account from the Profile screen, your profile, taste badges, visit history, content, and saved lists are deleted or anonymized in our active systems immediately. Usage Information (the photo and video taps described in Section 2) is de-identified at the same time: the record of the tap remains, but the link to you is removed. Limited records may remain in secure backups for up to 30 days after deletion, after which they are permanently purged, except where longer retention is required for legal, fraud-prevention, dispute resolution, or security purposes. We do not set a fixed retention period for de-identified Usage Information.

9. Your Privacy Rights

You may access, update, correct, delete, or request a copy of your information where applicable. You can delete your account at any time from Profile → Delete account in the app, or by contacting us at yo@mukjah.com.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it (see Sections 2, 3, 6, and 7 above).
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information. We treat precise geolocation as sensitive personal information. We only use it for the purposes described in Section 2 (nearby restaurants, visit verification, recommendations, map features) and do not use it to infer characteristics about you or for advertising, so no opt-out is required — but you may still disable location permissions at any time.
  • Non-discrimination: We will not deny you goods or services, charge different prices, or provide a different level of service because you exercised any of these rights.

Mukjah does not sell personal information or share it for cross-context behavioral advertising.

To exercise these rights, contact yo@mukjah.com. We will respond within the time required by law (generally 45 days, extendable once by an additional 45 days with notice). You may designate an authorized agent to make a request on your behalf; we may require verification of the agent's authority and your identity.

11. Children's Privacy

Mukjah is intended for users age 14 and older. By creating an account, you confirm that you are 14 or older, consistent with our Terms of Service. We do not knowingly collect information from children under 14 and will promptly delete such information if discovered.

We set the minimum at 14 rather than 13 so that a single threshold satisfies both the U.S. Children's Online Privacy Protection Act, which attaches at 13, and the Republic of Korea's Personal Information Protection Act, which requires a legal guardian's consent below 14.

12. Security

We use HTTPS/TLS encryption, secure authentication, password hashing, Row Level Security where applicable, access controls, secure cloud infrastructure, and ongoing security improvements.

13. Community Integrity and Moderation

We use automated systems and human review to identify spam, fake visits, fraud, impersonation, abuse, and Community Guideline violations.

Visit verification is decided on our servers. It uses the image you submit, the time our server issued your verification session, and patterns in your own account activity (for example, visits recorded at two locations too far apart to have traveled between). Where location is used, your device compares your position to the restaurant and sends us only the result of that comparison — we do not receive or store your coordinates. Declining location permission does not count against you. A verification may be approved automatically and later revoked if we find it was not genuine.

Users may appeal moderation decisions by contacting yo@mukjah.com.

14. International Users

Mukjah is distributed in the United States and the Republic of Korea. Our service area — the neighborhood whose restaurants, menus, and cards you can actually browse — remains limited to LA Koreatown. We do not currently cover restaurants in any other city or country, including in Korea.

Wherever you use Mukjah from, your information is processed and stored in the United States, which may not offer the same level of data protection as your home country. Section 7 lists the service providers that process your information on our behalf.

If we make Mukjah available in additional countries, or extend our service area beyond LA Koreatown, we will update this Policy before doing so.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be communicated through the app or by updating the Effective Date.

16. Contact Us

Mukjah Operated by A&K Systems, Inc. Email: yo@mukjah.com

We appreciate the trust you place in Mukjah and are committed to protecting your privacy while helping restaurants and customers build lasting relationships.