Privacy Policy

    Last updated: July 28, 2026

    Gunaso ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights when you use the Gunaso mobile app or website.

    1. Information We Collect

    1.1 Account Information

    When you sign in with Google or Apple, we receive:

    • Your name
    • Your email address
    • Your profile photo (optional, from your social account)

    We do not store your social account password. Authentication is handled entirely by Google or Apple.

    1.2 Location Information

    • District and Municipality — You choose this manually when setting up your profile or submitting a report. We store it to pre-fill your location on future reports.
    • GPS coordinates — Only collected when you choose to pin a precise map location while creating a report. We do not track your location in the background at any time.
    • Ward number — Optionally provided when submitting a lost & found report.

    1.3 Civic Issue Reports

    When you submit an issue, we store:

    • Title, description, and category
    • Location (district, municipality, optional GPS pin)
    • Up to 3 photos you attach
    • Timestamp and your user ID

    1.4 Lost & Found Reports

    When you submit a lost & found report, we store:

    • Document type (citizenship card, license, passport, transcript, blue book, or other)
    • Owner name (as written on the found document)
    • Description and location where found
    • Custodian contact information you choose to share
    • Police station details (if the document was handed to police)
    • Photos of the document and proof-of-handover photos
    • Status history (found → handed to police → resolved)

    Lost & found reports are automatically archived after 30 days (if handed to police) or 7 days (if resolved/returned) and permanently deleted thereafter.

    1.5 Comments and Interactions

    • Comments you post on issues
    • Votes you cast on issues
    • Likes you give to comments
    • Users you have blocked

    1.6 Notifications

    • Your notification preferences (comments, votes, comment likes)
    • Firebase Cloud Messaging (FCM) token — used to deliver push notifications to your device

    1.7 Feedback

    • Bug reports and feature requests you submit through the app

    1.8 Technical and Diagnostic Information

    • App version and operating system version
    • Device model and platform (iOS/Android)
    • Anonymized crash reports and error traces via Firebase Crashlytics (no personal data included in crash reports)
    • Firebase-generated user ID (internal only, never exposed publicly)
    • Anonymous product-usage events via Firebase Analytics, limited to a fixed list of in-app actions (for example: a report was submitted, a feed filter was applied, a search was run, sign-in was prompted or completed). These events record that an action happened, never its contents — no report text, names, phone numbers, or search terms are ever sent.
    • App performance measurements via Firebase Performance Monitoring (for example: how long the feed takes to load)

    2. How We Use Your Information

    PurposeData Used
    Create and manage your accountName, email, profile photo
    Display your issues, comments, and profileName, profile photo, submitted content
    Pre-fill location when creating reportsStored district and municipality
    Send push notificationsFCM token, notification preferences
    Power the Lost & Found searchDocument type, owner name, location, status
    Facilitate document returnsCustodian contact info (visible to signed-in users)
    Investigate abuse and moderation reportsAccount info, submitted content, activity
    Fix bugs and improve app stabilityAnonymized crash reports (Firebase Crashlytics)
    Admin oversight and platform healthAggregated usage metrics (no individual targeting)
    Understand which features are usedAnonymous usage events (Firebase Analytics)
    Diagnose slow screens on weak connectionsPerformance timings (Firebase Performance)

    We do not use your data for advertising, behavioral profiling, or any purpose not listed above.

    3. What We Do Not Do

    • We do not sell your personal information to anyone, ever.
    • We do not track your location in the background.
    • We do not build advertising profiles or share data with ad networks.
    • We do not read your private messages or emails.
    • We do not share your data with government bodies unless required by the laws of Nepal via a formal, verified legal process.
    • We do not use your data to train AI or machine learning models.

    4. Lost & Found Data — Special Notice

    Lost & found reports contain third-party personal data (the document owner's name). We treat this data with additional care:

    • Custodian contact information is visible only to signed-in users, not to the public.
    • Reports are automatically archived and permanently deleted after their TTL expires (7–30 days post-resolution).
    • We rely on reporters to handle found documents lawfully and to accurately record handover to police where applicable.

    If you believe a lost & found report contains your personal data and you want it removed, contact us at [email protected].

    5. How We Store Your Data

    All data is stored on Firebase (Google Cloud infrastructure), which provides:

    • Data encrypted at rest and in transit (TLS/SSL)
    • SOC 2, ISO 27001, and GDPR-compliant infrastructure
    • Firestore security rules — only authenticated users can read/write their own data
    • Role-based admin access — only authorized team members can access the database directly

    Photos you upload are stored in Firebase Storage and are deleted when you delete the associated report or your account.

    6. Third-Party Services

    We use a minimal, trusted set of third-party services:

    ServicePurposePrivacy Policy
    Firebase (Google)Authentication, database, file storage, push notificationsLink
    Apple Sign-IniOS authenticationLink
    Google Sign-InAuthenticationLink
    Firebase Analytics (Google)Anonymous product-usage measurementLink
    Firebase Performance (Google)App performance measurementLink

    We use Firebase Analytics and Firebase Performance Monitoring, from Google, solely to understand which features are used and where the app is slow. We do <strong>not</strong> use advertising SDKs, and we do not use these tools for behavioral profiling, ad targeting, or sale of data. No third-party analytics platforms (for example Mixpanel or Amplitude) are used.

    Crash reporting note: Crash reports are anonymized. Firebase Crashlytics receives only stack traces, device model, OS version, and app version — never your name, email, or the contents of anything you wrote.

    7. Data Sharing

    We do not sell, rent, or share your personal information with third parties except:

    • Service providers listed in Section 6, who process data on our behalf under data processing agreements
    • Legal requirements — if required by Nepali law via a formal, verified legal process
    • Safety — if we believe disclosure is necessary to prevent imminent harm

    8. Your Rights

    Access

    You can view all data tied to your account directly within the app (profile, submitted issues, comments, lost & found reports).

    Correction

    You can update your display name and profile photo through your Google or Apple account settings.

    Deletion

    You can permanently delete your account from Profile → Delete Account. This will:

    • Remove your authentication credentials
    • Delete all your submitted issues, comments, lost & found reports, and uploaded photos
    • Remove your profile, votes, and likes

    Deletion is irreversible and completed within 30 days.

    Data Export

    To request a copy of your personal data, email [email protected] with the subject line "Data Export Request". We will respond within 14 days.

    Lost & Found Removal

    If a lost & found report contains your personal data (e.g. your name on a found document) and you want it removed, contact us at [email protected] and we will remove it within 48 hours.

    9. Data Retention

    DataRetention
    Account and profile dataUntil account is deleted
    Civic issue reports and photosUntil deleted by user or account deletion
    Comments and votesUntil deleted by user or account deletion
    Lost & found (handed to police)Auto-archived 30 days after status update, then deleted
    Lost & found (resolved/returned)Auto-archived 7 days after resolution, then deleted
    Push notification tokens (FCM)Until account is deleted or token is refreshed
    Firebase auth logs30 days (per Firebase policy)
    Anonymized crash logs (Crashlytics)90 days (per Firebase default retention)
    Anonymous usage events (Analytics)14 months (per Firebase default retention)
    Performance timings (Performance)90 days (per Firebase default retention)

    10. Children's Privacy

    Gunaso is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly.

    If you believe a child has registered, please contact [email protected].

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. When we make material changes, we will notify you within the app. The latest version is always available at gunaso.dev/privacy.

    Your continued use of Gunaso after notification constitutes acceptance of the updated policy.

    12. Contact

    For privacy questions, data requests, or concerns:

    We aim to respond to all privacy-related inquiries within 5 business days.