{"success":true,"message":"Content retrieved successfully","data":{"id":"6910224bf375651808b1c5fa","title":"Privacy Policy","content":"<h1>Privacy Policy</h1>\n<p><strong>Effective Date:</strong> November 9, 2025<br>\n<strong>Last Updated:</strong> November 9, 2025</p>\n\n<h2>1. Introduction</h2>\n<p>Welcome to Misk Social (\"we,\" \"our,\" or \"us\"). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect your information when you use our mobile application and web platform (collectively, the \"Service\").</p>\n\n<p>This policy applies to all users worldwide and complies with:</p>\n<ul>\n  <li><strong>GDPR</strong> (General Data Protection Regulation) for users in the European Economic Area</li>\n  <li><strong>CCPA/CPRA</strong> (California Consumer Privacy Act) for California residents</li>\n  <li><strong>COPPA</strong> (Children's Online Privacy Protection Act) for users under 13</li>\n  <li><strong>Apple App Store</strong> and <strong>Google Play Store</strong> privacy requirements</li>\n</ul>\n\n<h2>2. Information We Collect</h2>\n\n<h3>2.1 Information You Provide Directly</h3>\n<p><strong>Account Information:</strong></p>\n<ul>\n  <li>Full name</li>\n  <li>Nickname/username</li>\n  <li>Email address</li>\n  <li>Phone number</li>\n  <li>Date of birth (for age verification)</li>\n  <li>Profile picture</li>\n  <li>Bio/description</li>\n  <li>Location (country/city)</li>\n</ul>\n\n<p><strong>Content You Create:</strong></p>\n<ul>\n  <li>Posts (text, photos, videos)</li>\n  <li>Stories (temporary photo/video content)</li>\n  <li>Comments and reactions</li>\n  <li>Direct messages and chats</li>\n  <li>Shared content</li>\n</ul>\n\n<p><strong>Social Connections:</strong></p>\n<ul>\n  <li>Friend relationships (bidirectional connections)</li>\n  <li>Friend categories (Close Friends, Family, etc.)</li>\n  <li>Blocked users list</li>\n  <li>Contact list (with permission)</li>\n</ul>\n\n<h3>2.2 Information Collected Automatically</h3>\n<p><strong>Device Information:</strong></p>\n<ul>\n  <li>Device type and model</li>\n  <li>Operating system (iOS/Android version)</li>\n  <li>Device identifiers (IDFA, Android Advertising ID)</li>\n  <li>App version</li>\n  <li>Mobile network information</li>\n</ul>\n\n<p><strong>Usage Data:</strong></p>\n<ul>\n  <li>Features you use and how you use them</li>\n  <li>Time spent on different screens</li>\n  <li>Posts viewed, liked, and shared</li>\n  <li>Search queries</li>\n  <li>Error logs and crash reports</li>\n</ul>\n\n<p><strong>Location Data:</strong></p>\n<ul>\n  <li>Precise location (GPS) when you create posts with location tags (requires permission)</li>\n  <li>Approximate location based on IP address</li>\n  <li>Location shared in Google Maps integrations</li>\n</ul>\n\n<h3>2.3 Information from Third Parties</h3>\n<p><strong>Social Media Login:</strong> When you sign in using Google, Facebook, or Apple Sign-In, we receive:</p>\n<ul>\n  <li>Name</li>\n  <li>Email address</li>\n  <li>Profile picture</li>\n  <li>User ID from the provider</li>\n</ul>\n\n<p><strong>Contacts:</strong> With your permission, we access your device contacts to help you find and connect with friends.</p>\n\n<h2>3. Third-Party Services and SDKs</h2>\n<p>Our app integrates the following third-party services. Each service has its own privacy policy and data practices:</p>\n\n<h3>3.1 Firebase Services (Google LLC)</h3>\n<p><strong>Purpose:</strong> Core app infrastructure and features</p>\n<p><strong>Data Collected:</strong> Device identifiers, usage data, crash logs, performance metrics</p>\n<p><strong>Services Used:</strong></p>\n<ul>\n  <li><strong>Firebase Authentication:</strong> User authentication and session management</li>\n  <li><strong>Cloud Firestore:</strong> Real-time database for app data synchronization</li>\n  <li><strong>Firebase Cloud Messaging:</strong> Push notifications for new messages, likes, and comments</li>\n  <li><strong>Firebase Storage:</strong> Secure file storage for photos, videos, and profile pictures</li>\n  <li><strong>Firebase Crashlytics:</strong> Crash reporting and app stability monitoring</li>\n</ul>\n<p><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></p>\n\n<h3>3.2 Google Maps Platform</h3>\n<p><strong>Purpose:</strong> Location tagging, location-based post discovery, and maps display</p>\n<p><strong>Data Collected:</strong> GPS coordinates, map interactions, location searches</p>\n<p><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></p>\n\n<h3>3.3 OAuth Providers</h3>\n<p><strong>Google Sign-In:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name, email, profile photo, Google user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></li>\n</ul>\n\n<p><strong>Facebook Login:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name, email, profile photo, Facebook user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://www.facebook.com/privacy/policy\">https://www.facebook.com/privacy/policy</a></li>\n</ul>\n\n<p><strong>Apple Sign-In:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name (optional), email (real or private relay), Apple user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://www.apple.com/legal/privacy/\">https://www.apple.com/legal/privacy/</a></li>\n</ul>\n\n<h3>3.4 Content Delivery and Media</h3>\n<p><strong>Image and Video Processing:</strong></p>\n<ul>\n  <li>Camera access (with permission) for photos and videos</li>\n  <li>Photo library access (with permission) for uploads</li>\n  <li>Media compression and optimization on-device</li>\n</ul>\n\n<h3>3.5 Analytics and Performance</h3>\n<p>We DO NOT use any advertising or third-party analytics SDKs. All analytics are first-party and stored in our own database.</p>\n\n<h2>4. How We Use Your Information</h2>\n<p>We use the information we collect to:</p>\n\n<h3>4.1 Provide and Improve the Service</h3>\n<ul>\n  <li>Create and manage your account</li>\n  <li>Display your profile to friends</li>\n  <li>Enable posting, commenting, and messaging</li>\n  <li>Deliver push notifications</li>\n  <li>Provide customer support</li>\n  <li>Develop new features and improve existing ones</li>\n</ul>\n\n<h3>4.2 Safety and Security</h3>\n<ul>\n  <li>Verify user identity and prevent fraud</li>\n  <li>Detect and prevent abuse, spam, and prohibited content</li>\n  <li>Scan uploaded media for child sexual abuse material (CSAM) using PhotoDNA technology</li>\n  <li>Enforce our Terms of Service and Community Guidelines</li>\n  <li>Comply with legal obligations and law enforcement requests</li>\n</ul>\n\n<h3>4.3 Communications</h3>\n<ul>\n  <li>Send you service updates and notifications</li>\n  <li>Respond to your inquiries and support requests</li>\n  <li>Send important account and security alerts</li>\n</ul>\n\n<p><strong>We DO NOT use your data for advertising purposes. We do not display ads and do not share your data with advertisers.</strong></p>\n\n<h2>5. How We Share Your Information</h2>\n\n<h3>5.1 With Other Users</h3>\n<p><strong>Public Information:</strong></p>\n<ul>\n  <li>Your profile (name, nickname, profile picture, bio)</li>\n  <li>Your public posts and stories</li>\n  <li>Your friend list (if not set to private)</li>\n  <li>Comments and reactions on public posts</li>\n</ul>\n\n<p><strong>Friends-Only Information:</strong></p>\n<ul>\n  <li>Posts shared with friends only</li>\n  <li>Stories visible to friends</li>\n  <li>Your online status (if enabled)</li>\n</ul>\n\n<p><strong>You Control Sharing:</strong> You can adjust privacy settings to control who sees your content.</p>\n\n<h3>5.2 With Service Providers</h3>\n<p>We share data with trusted third-party service providers who help us operate the Service:</p>\n<ul>\n  <li><strong>Cloud Hosting:</strong> Firebase (Google) for database, storage, and authentication</li>\n  <li><strong>Push Notifications:</strong> Firebase Cloud Messaging</li>\n  <li><strong>Email Services:</strong> For account verification and password reset emails</li>\n</ul>\n\n<p>These providers are contractually obligated to protect your data and use it only for the purposes we specify.</p>\n\n<h3>5.3 Legal Requirements and Safety</h3>\n<p>We may disclose your information if required by law or in good faith belief that such action is necessary to:</p>\n<ul>\n  <li>Comply with legal obligations (court orders, subpoenas)</li>\n  <li>Protect the rights, property, or safety of Misk Social, our users, or the public</li>\n  <li>Report child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC)</li>\n  <li>Prevent fraud, abuse, or prohibited activities</li>\n</ul>\n\n<h3>5.4 Business Transfers</h3>\n<p>If Misk Social is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.</p>\n\n<h3>5.5 With Your Consent</h3>\n<p>We may share your information for other purposes with your explicit consent.</p>\n\n<h2>6. Data Retention</h2>\n<p>We retain your information for as long as your account is active or as needed to provide you the Service.</p>\n\n<h3>6.1 Account Deletion</h3>\n<ul>\n  <li><strong>Soft Delete:</strong> When you delete your account, it is marked as deleted and hidden from other users immediately</li>\n  <li><strong>30-Day Grace Period:</strong> Your data is retained for 30 days during which you can restore your account</li>\n  <li><strong>Hard Delete:</strong> After 30 days, your data is permanently deleted from our servers (except where we must retain it for legal compliance)</li>\n</ul>\n\n<h3>6.2 Legal Retention</h3>\n<p>We may retain certain data longer when required by law or for legitimate business purposes such as:</p>\n<ul>\n  <li>Fraud prevention and detection</li>\n  <li>Legal compliance and dispute resolution</li>\n  <li>Enforcing our Terms of Service</li>\n  <li>Safety investigations (e.g., CSAM reports)</li>\n</ul>\n\n<h2>7. Your Rights and Choices</h2>\n\n<h3>7.1 Access and Portability (GDPR, CCPA)</h3>\n<p>You have the right to:</p>\n<ul>\n  <li>Access your personal data</li>\n  <li>Download a copy of your data in a portable format (JSON/CSV)</li>\n  <li>Request data export from Settings → Privacy → Download My Data</li>\n</ul>\n\n<h3>7.2 Correction and Deletion</h3>\n<ul>\n  <li><strong>Update Information:</strong> Edit your profile, email, and account details anytime in Settings</li>\n  <li><strong>Delete Content:</strong> Delete individual posts, comments, and messages</li>\n  <li><strong>Delete Account:</strong> Permanently delete your account from Settings → Account → Delete Account</li>\n</ul>\n\n<h3>7.3 Privacy Settings</h3>\n<p>Control who sees your content:</p>\n<ul>\n  <li>Public, Friends Only, or Custom privacy for posts and stories</li>\n  <li>Hide your friend list</li>\n  <li>Disable online status</li>\n  <li>Block users from contacting you</li>\n  <li>Restrict who can message you</li>\n</ul>\n\n<h3>7.4 Marketing Communications (CCPA)</h3>\n<p>We do not send marketing emails. You can opt out of non-essential notifications in Settings → Notifications.</p>\n\n<h3>7.5 Do Not Sell My Information (CCPA)</h3>\n<p><strong>We DO NOT sell your personal information to third parties.</strong> We do not share your data for advertising or data brokerage purposes.</p>\n\n<h3>7.6 Cookie Preferences (Web Only)</h3>\n<p>Our web app uses only essential cookies for authentication and session management. We do not use advertising or tracking cookies.</p>\n\n<h2>8. Children's Privacy (COPPA Compliance)</h2>\n\n<h3>8.1 Age Requirements</h3>\n<ul>\n  <li><strong>Minimum Age:</strong> 13 years old</li>\n  <li><strong>Ages 13-17:</strong> Require verifiable parental consent before creating an account</li>\n  <li><strong>Age Verification:</strong> Date of birth is required during signup</li>\n</ul>\n\n<h3>8.2 Parental Consent for Users Under 18</h3>\n<p>For users aged 13-17, we require verifiable parental consent by:</p>\n<ul>\n  <li>Parent email address verification</li>\n  <li>Consent confirmation email sent to parent</li>\n  <li>Parent must click verification link to approve account</li>\n</ul>\n\n<h3>8.3 Minor Account Protections</h3>\n<p>Accounts for users under 18 have additional privacy protections:</p>\n<ul>\n  <li>Default private profile (friends-only visibility)</li>\n  <li>Restricted messaging (can only receive messages from friends)</li>\n  <li>Cannot be contacted by users over 18 unless they are friends</li>\n  <li>No location tagging by default</li>\n  <li>Parental access to account activity reports</li>\n</ul>\n\n<h3>8.4 Information Collected from Minors</h3>\n<p>For users under 18, we collect only:</p>\n<ul>\n  <li>Account information (name, email, date of birth)</li>\n  <li>Parent email address and consent status</li>\n  <li>Content they create (posts, messages)</li>\n  <li>Device and usage data necessary for the Service</li>\n</ul>\n\n<p>We do not knowingly collect data from children under 13 without verifiable parental consent.</p>\n\n<h3>8.5 Parental Rights</h3>\n<p>Parents of users under 18 can:</p>\n<ul>\n  <li>Review their child's account information</li>\n  <li>Request deletion of their child's account and data</li>\n  <li>Revoke consent and close the account</li>\n  <li>Receive monthly activity reports</li>\n</ul>\n\n<p>Contact us at parents@misksocial.com for parental access requests.</p>\n\n<h2>9. Security</h2>\n<p>We implement industry-standard security measures to protect your data:</p>\n\n<h3>9.1 Technical Safeguards</h3>\n<ul>\n  <li><strong>Encryption:</strong> All data transmitted between your device and our servers uses TLS/SSL encryption</li>\n  <li><strong>Secure Storage:</strong> Passwords are hashed using bcrypt; sensitive data encrypted at rest</li>\n  <li><strong>Authentication:</strong> JWT (JSON Web Tokens) for secure session management</li>\n  <li><strong>Two-Factor Authentication:</strong> Optional 2FA for added account security</li>\n</ul>\n\n<h3>9.2 Operational Safeguards</h3>\n<ul>\n  <li>Regular security audits and vulnerability assessments</li>\n  <li>Access controls limiting employee access to user data</li>\n  <li>Automated monitoring for suspicious activity</li>\n  <li>Incident response plan for data breaches</li>\n</ul>\n\n<h3>9.3 Content Safety</h3>\n<ul>\n  <li><strong>PhotoDNA Technology:</strong> Scans uploaded images for known CSAM hashes</li>\n  <li><strong>AI Moderation:</strong> Automated detection of prohibited content</li>\n  <li><strong>Human Review:</strong> Admin moderation team reviews flagged content 24/7</li>\n  <li><strong>User Reporting:</strong> Easy in-app reporting for inappropriate content</li>\n</ul>\n\n<h2>10. International Data Transfers</h2>\n<p>Misk Social is based in [Jurisdiction]. Your data may be transferred to and processed in countries outside your own, including the United States where our servers are hosted.</p>\n\n<p>For EU users: We rely on approved data transfer mechanisms such as Standard Contractual Clauses and ensure adequate data protection safeguards.</p>\n\n<h2>11. Changes to This Policy</h2>\n<p>We may update this Privacy Policy from time to time. When we make material changes, we will:</p>\n<ul>\n  <li>Notify you via email or push notification</li>\n  <li>Display a notice in the app</li>\n  <li>Update the \"Last Updated\" date at the top of this policy</li>\n</ul>\n\n<p>Your continued use of the Service after changes constitutes acceptance of the updated policy.</p>\n\n<h2>12. Contact Us</h2>\n<p>If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:</p>\n\n<p><strong>Email:</strong> privacy@misksocial.com<br>\n<strong>Parents/Guardians:</strong> parents@misksocial.com<br>\n<strong>Data Protection Officer:</strong> dpo@misksocial.com<br>\n<strong>Mailing Address:</strong> [Company Address]</p>\n\n<p><strong>Response Time:</strong> We will respond to all requests within 30 days.</p>\n\n<h2>13. Additional Rights by Jurisdiction</h2>\n\n<h3>13.1 European Economic Area (GDPR)</h3>\n<p>If you are in the EEA, you have additional rights:</p>\n<ul>\n  <li>Right to object to data processing</li>\n  <li>Right to restriction of processing</li>\n  <li>Right to lodge a complaint with your local data protection authority</li>\n  <li>Right to withdraw consent at any time</li>\n</ul>\n\n<h3>13.2 California Residents (CCPA/CPRA)</h3>\n<p>California residents have the right to:</p>\n<ul>\n  <li>Know what personal information is collected and how it's used</li>\n  <li>Request deletion of personal information</li>\n  <li>Opt-out of sale of personal information (we do not sell your data)</li>\n  <li>Non-discrimination for exercising privacy rights</li>\n</ul>\n\n<p><strong>California Privacy Rights Hotline:</strong> privacy@misksocial.com (Subject: \"California Privacy Rights\")</p>\n\n<h2>14. Your Responsibilities</h2>\n<p><strong>You are solely responsible for all content you post on Misk Social.</strong></p>\n\n<p>This includes but is not limited to:</p>\n<ul>\n  <li>Ensuring your content does not violate any laws or third-party rights</li>\n  <li>Obtaining necessary permissions before posting photos/videos of others</li>\n  <li>Not posting private information (yours or others')</li>\n  <li>Respecting intellectual property rights</li>\n  <li>Complying with our Terms of Service and Community Guidelines</li>\n</ul>\n\n<p>We act as a hosting platform. While we moderate content and remove violations, we are not responsible for the accuracy, legality, or appropriateness of user-generated content.</p>\n\n<hr>\n\n<p><strong>Effective Date:</strong> November 9, 2025<br>\n<strong>Version:</strong> 2.0<br>\n<strong>Last Reviewed:</strong> November 9, 2025</p>","htmlContent":"<h1>Privacy Policy</h1>\n<p><strong>Effective Date:</strong> November 9, 2025<br>\n<strong>Last Updated:</strong> November 9, 2025</p>\n\n<h2>1. Introduction</h2>\n<p>Welcome to Misk Social (\"we,\" \"our,\" or \"us\"). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect your information when you use our mobile application and web platform (collectively, the \"Service\").</p>\n\n<p>This policy applies to all users worldwide and complies with:</p>\n<ul>\n  <li><strong>GDPR</strong> (General Data Protection Regulation) for users in the European Economic Area</li>\n  <li><strong>CCPA/CPRA</strong> (California Consumer Privacy Act) for California residents</li>\n  <li><strong>COPPA</strong> (Children's Online Privacy Protection Act) for users under 13</li>\n  <li><strong>Apple App Store</strong> and <strong>Google Play Store</strong> privacy requirements</li>\n</ul>\n\n<h2>2. Information We Collect</h2>\n\n<h3>2.1 Information You Provide Directly</h3>\n<p><strong>Account Information:</strong></p>\n<ul>\n  <li>Full name</li>\n  <li>Nickname/username</li>\n  <li>Email address</li>\n  <li>Phone number</li>\n  <li>Date of birth (for age verification)</li>\n  <li>Profile picture</li>\n  <li>Bio/description</li>\n  <li>Location (country/city)</li>\n</ul>\n\n<p><strong>Content You Create:</strong></p>\n<ul>\n  <li>Posts (text, photos, videos)</li>\n  <li>Stories (temporary photo/video content)</li>\n  <li>Comments and reactions</li>\n  <li>Direct messages and chats</li>\n  <li>Shared content</li>\n</ul>\n\n<p><strong>Social Connections:</strong></p>\n<ul>\n  <li>Friend relationships (bidirectional connections)</li>\n  <li>Friend categories (Close Friends, Family, etc.)</li>\n  <li>Blocked users list</li>\n  <li>Contact list (with permission)</li>\n</ul>\n\n<h3>2.2 Information Collected Automatically</h3>\n<p><strong>Device Information:</strong></p>\n<ul>\n  <li>Device type and model</li>\n  <li>Operating system (iOS/Android version)</li>\n  <li>Device identifiers (IDFA, Android Advertising ID)</li>\n  <li>App version</li>\n  <li>Mobile network information</li>\n</ul>\n\n<p><strong>Usage Data:</strong></p>\n<ul>\n  <li>Features you use and how you use them</li>\n  <li>Time spent on different screens</li>\n  <li>Posts viewed, liked, and shared</li>\n  <li>Search queries</li>\n  <li>Error logs and crash reports</li>\n</ul>\n\n<p><strong>Location Data:</strong></p>\n<ul>\n  <li>Precise location (GPS) when you create posts with location tags (requires permission)</li>\n  <li>Approximate location based on IP address</li>\n  <li>Location shared in Google Maps integrations</li>\n</ul>\n\n<h3>2.3 Information from Third Parties</h3>\n<p><strong>Social Media Login:</strong> When you sign in using Google, Facebook, or Apple Sign-In, we receive:</p>\n<ul>\n  <li>Name</li>\n  <li>Email address</li>\n  <li>Profile picture</li>\n  <li>User ID from the provider</li>\n</ul>\n\n<p><strong>Contacts:</strong> With your permission, we access your device contacts to help you find and connect with friends.</p>\n\n<h2>3. Third-Party Services and SDKs</h2>\n<p>Our app integrates the following third-party services. Each service has its own privacy policy and data practices:</p>\n\n<h3>3.1 Firebase Services (Google LLC)</h3>\n<p><strong>Purpose:</strong> Core app infrastructure and features</p>\n<p><strong>Data Collected:</strong> Device identifiers, usage data, crash logs, performance metrics</p>\n<p><strong>Services Used:</strong></p>\n<ul>\n  <li><strong>Firebase Authentication:</strong> User authentication and session management</li>\n  <li><strong>Cloud Firestore:</strong> Real-time database for app data synchronization</li>\n  <li><strong>Firebase Cloud Messaging:</strong> Push notifications for new messages, likes, and comments</li>\n  <li><strong>Firebase Storage:</strong> Secure file storage for photos, videos, and profile pictures</li>\n  <li><strong>Firebase Crashlytics:</strong> Crash reporting and app stability monitoring</li>\n</ul>\n<p><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></p>\n\n<h3>3.2 Google Maps Platform</h3>\n<p><strong>Purpose:</strong> Location tagging, location-based post discovery, and maps display</p>\n<p><strong>Data Collected:</strong> GPS coordinates, map interactions, location searches</p>\n<p><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></p>\n\n<h3>3.3 OAuth Providers</h3>\n<p><strong>Google Sign-In:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name, email, profile photo, Google user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://policies.google.com/privacy\">https://policies.google.com/privacy</a></li>\n</ul>\n\n<p><strong>Facebook Login:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name, email, profile photo, Facebook user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://www.facebook.com/privacy/policy\">https://www.facebook.com/privacy/policy</a></li>\n</ul>\n\n<p><strong>Apple Sign-In:</strong></p>\n<ul>\n  <li><strong>Data Received:</strong> Name (optional), email (real or private relay), Apple user ID</li>\n  <li><strong>Privacy Policy:</strong> <a href=\"https://www.apple.com/legal/privacy/\">https://www.apple.com/legal/privacy/</a></li>\n</ul>\n\n<h3>3.4 Content Delivery and Media</h3>\n<p><strong>Image and Video Processing:</strong></p>\n<ul>\n  <li>Camera access (with permission) for photos and videos</li>\n  <li>Photo library access (with permission) for uploads</li>\n  <li>Media compression and optimization on-device</li>\n</ul>\n\n<h3>3.5 Analytics and Performance</h3>\n<p>We DO NOT use any advertising or third-party analytics SDKs. All analytics are first-party and stored in our own database.</p>\n\n<h2>4. How We Use Your Information</h2>\n<p>We use the information we collect to:</p>\n\n<h3>4.1 Provide and Improve the Service</h3>\n<ul>\n  <li>Create and manage your account</li>\n  <li>Display your profile to friends</li>\n  <li>Enable posting, commenting, and messaging</li>\n  <li>Deliver push notifications</li>\n  <li>Provide customer support</li>\n  <li>Develop new features and improve existing ones</li>\n</ul>\n\n<h3>4.2 Safety and Security</h3>\n<ul>\n  <li>Verify user identity and prevent fraud</li>\n  <li>Detect and prevent abuse, spam, and prohibited content</li>\n  <li>Scan uploaded media for child sexual abuse material (CSAM) using PhotoDNA technology</li>\n  <li>Enforce our Terms of Service and Community Guidelines</li>\n  <li>Comply with legal obligations and law enforcement requests</li>\n</ul>\n\n<h3>4.3 Communications</h3>\n<ul>\n  <li>Send you service updates and notifications</li>\n  <li>Respond to your inquiries and support requests</li>\n  <li>Send important account and security alerts</li>\n</ul>\n\n<p><strong>We DO NOT use your data for advertising purposes. We do not display ads and do not share your data with advertisers.</strong></p>\n\n<h2>5. How We Share Your Information</h2>\n\n<h3>5.1 With Other Users</h3>\n<p><strong>Public Information:</strong></p>\n<ul>\n  <li>Your profile (name, nickname, profile picture, bio)</li>\n  <li>Your public posts and stories</li>\n  <li>Your friend list (if not set to private)</li>\n  <li>Comments and reactions on public posts</li>\n</ul>\n\n<p><strong>Friends-Only Information:</strong></p>\n<ul>\n  <li>Posts shared with friends only</li>\n  <li>Stories visible to friends</li>\n  <li>Your online status (if enabled)</li>\n</ul>\n\n<p><strong>You Control Sharing:</strong> You can adjust privacy settings to control who sees your content.</p>\n\n<h3>5.2 With Service Providers</h3>\n<p>We share data with trusted third-party service providers who help us operate the Service:</p>\n<ul>\n  <li><strong>Cloud Hosting:</strong> Firebase (Google) for database, storage, and authentication</li>\n  <li><strong>Push Notifications:</strong> Firebase Cloud Messaging</li>\n  <li><strong>Email Services:</strong> For account verification and password reset emails</li>\n</ul>\n\n<p>These providers are contractually obligated to protect your data and use it only for the purposes we specify.</p>\n\n<h3>5.3 Legal Requirements and Safety</h3>\n<p>We may disclose your information if required by law or in good faith belief that such action is necessary to:</p>\n<ul>\n  <li>Comply with legal obligations (court orders, subpoenas)</li>\n  <li>Protect the rights, property, or safety of Misk Social, our users, or the public</li>\n  <li>Report child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC)</li>\n  <li>Prevent fraud, abuse, or prohibited activities</li>\n</ul>\n\n<h3>5.4 Business Transfers</h3>\n<p>If Misk Social is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.</p>\n\n<h3>5.5 With Your Consent</h3>\n<p>We may share your information for other purposes with your explicit consent.</p>\n\n<h2>6. Data Retention</h2>\n<p>We retain your information for as long as your account is active or as needed to provide you the Service.</p>\n\n<h3>6.1 Account Deletion</h3>\n<ul>\n  <li><strong>Soft Delete:</strong> When you delete your account, it is marked as deleted and hidden from other users immediately</li>\n  <li><strong>30-Day Grace Period:</strong> Your data is retained for 30 days during which you can restore your account</li>\n  <li><strong>Hard Delete:</strong> After 30 days, your data is permanently deleted from our servers (except where we must retain it for legal compliance)</li>\n</ul>\n\n<h3>6.2 Legal Retention</h3>\n<p>We may retain certain data longer when required by law or for legitimate business purposes such as:</p>\n<ul>\n  <li>Fraud prevention and detection</li>\n  <li>Legal compliance and dispute resolution</li>\n  <li>Enforcing our Terms of Service</li>\n  <li>Safety investigations (e.g., CSAM reports)</li>\n</ul>\n\n<h2>7. Your Rights and Choices</h2>\n\n<h3>7.1 Access and Portability (GDPR, CCPA)</h3>\n<p>You have the right to:</p>\n<ul>\n  <li>Access your personal data</li>\n  <li>Download a copy of your data in a portable format (JSON/CSV)</li>\n  <li>Request data export from Settings → Privacy → Download My Data</li>\n</ul>\n\n<h3>7.2 Correction and Deletion</h3>\n<ul>\n  <li><strong>Update Information:</strong> Edit your profile, email, and account details anytime in Settings</li>\n  <li><strong>Delete Content:</strong> Delete individual posts, comments, and messages</li>\n  <li><strong>Delete Account:</strong> Permanently delete your account from Settings → Account → Delete Account</li>\n</ul>\n\n<h3>7.3 Privacy Settings</h3>\n<p>Control who sees your content:</p>\n<ul>\n  <li>Public, Friends Only, or Custom privacy for posts and stories</li>\n  <li>Hide your friend list</li>\n  <li>Disable online status</li>\n  <li>Block users from contacting you</li>\n  <li>Restrict who can message you</li>\n</ul>\n\n<h3>7.4 Marketing Communications (CCPA)</h3>\n<p>We do not send marketing emails. You can opt out of non-essential notifications in Settings → Notifications.</p>\n\n<h3>7.5 Do Not Sell My Information (CCPA)</h3>\n<p><strong>We DO NOT sell your personal information to third parties.</strong> We do not share your data for advertising or data brokerage purposes.</p>\n\n<h3>7.6 Cookie Preferences (Web Only)</h3>\n<p>Our web app uses only essential cookies for authentication and session management. We do not use advertising or tracking cookies.</p>\n\n<h2>8. Children's Privacy (COPPA Compliance)</h2>\n\n<h3>8.1 Age Requirements</h3>\n<ul>\n  <li><strong>Minimum Age:</strong> 13 years old</li>\n  <li><strong>Ages 13-17:</strong> Require verifiable parental consent before creating an account</li>\n  <li><strong>Age Verification:</strong> Date of birth is required during signup</li>\n</ul>\n\n<h3>8.2 Parental Consent for Users Under 18</h3>\n<p>For users aged 13-17, we require verifiable parental consent by:</p>\n<ul>\n  <li>Parent email address verification</li>\n  <li>Consent confirmation email sent to parent</li>\n  <li>Parent must click verification link to approve account</li>\n</ul>\n\n<h3>8.3 Minor Account Protections</h3>\n<p>Accounts for users under 18 have additional privacy protections:</p>\n<ul>\n  <li>Default private profile (friends-only visibility)</li>\n  <li>Restricted messaging (can only receive messages from friends)</li>\n  <li>Cannot be contacted by users over 18 unless they are friends</li>\n  <li>No location tagging by default</li>\n  <li>Parental access to account activity reports</li>\n</ul>\n\n<h3>8.4 Information Collected from Minors</h3>\n<p>For users under 18, we collect only:</p>\n<ul>\n  <li>Account information (name, email, date of birth)</li>\n  <li>Parent email address and consent status</li>\n  <li>Content they create (posts, messages)</li>\n  <li>Device and usage data necessary for the Service</li>\n</ul>\n\n<p>We do not knowingly collect data from children under 13 without verifiable parental consent.</p>\n\n<h3>8.5 Parental Rights</h3>\n<p>Parents of users under 18 can:</p>\n<ul>\n  <li>Review their child's account information</li>\n  <li>Request deletion of their child's account and data</li>\n  <li>Revoke consent and close the account</li>\n  <li>Receive monthly activity reports</li>\n</ul>\n\n<p>Contact us at parents@misksocial.com for parental access requests.</p>\n\n<h2>9. Security</h2>\n<p>We implement industry-standard security measures to protect your data:</p>\n\n<h3>9.1 Technical Safeguards</h3>\n<ul>\n  <li><strong>Encryption:</strong> All data transmitted between your device and our servers uses TLS/SSL encryption</li>\n  <li><strong>Secure Storage:</strong> Passwords are hashed using bcrypt; sensitive data encrypted at rest</li>\n  <li><strong>Authentication:</strong> JWT (JSON Web Tokens) for secure session management</li>\n  <li><strong>Two-Factor Authentication:</strong> Optional 2FA for added account security</li>\n</ul>\n\n<h3>9.2 Operational Safeguards</h3>\n<ul>\n  <li>Regular security audits and vulnerability assessments</li>\n  <li>Access controls limiting employee access to user data</li>\n  <li>Automated monitoring for suspicious activity</li>\n  <li>Incident response plan for data breaches</li>\n</ul>\n\n<h3>9.3 Content Safety</h3>\n<ul>\n  <li><strong>PhotoDNA Technology:</strong> Scans uploaded images for known CSAM hashes</li>\n  <li><strong>AI Moderation:</strong> Automated detection of prohibited content</li>\n  <li><strong>Human Review:</strong> Admin moderation team reviews flagged content 24/7</li>\n  <li><strong>User Reporting:</strong> Easy in-app reporting for inappropriate content</li>\n</ul>\n\n<h2>10. International Data Transfers</h2>\n<p>Misk Social is based in [Jurisdiction]. Your data may be transferred to and processed in countries outside your own, including the United States where our servers are hosted.</p>\n\n<p>For EU users: We rely on approved data transfer mechanisms such as Standard Contractual Clauses and ensure adequate data protection safeguards.</p>\n\n<h2>11. Changes to This Policy</h2>\n<p>We may update this Privacy Policy from time to time. When we make material changes, we will:</p>\n<ul>\n  <li>Notify you via email or push notification</li>\n  <li>Display a notice in the app</li>\n  <li>Update the \"Last Updated\" date at the top of this policy</li>\n</ul>\n\n<p>Your continued use of the Service after changes constitutes acceptance of the updated policy.</p>\n\n<h2>12. Contact Us</h2>\n<p>If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:</p>\n\n<p><strong>Email:</strong> privacy@misksocial.com<br>\n<strong>Parents/Guardians:</strong> parents@misksocial.com<br>\n<strong>Data Protection Officer:</strong> dpo@misksocial.com<br>\n<strong>Mailing Address:</strong> [Company Address]</p>\n\n<p><strong>Response Time:</strong> We will respond to all requests within 30 days.</p>\n\n<h2>13. Additional Rights by Jurisdiction</h2>\n\n<h3>13.1 European Economic Area (GDPR)</h3>\n<p>If you are in the EEA, you have additional rights:</p>\n<ul>\n  <li>Right to object to data processing</li>\n  <li>Right to restriction of processing</li>\n  <li>Right to lodge a complaint with your local data protection authority</li>\n  <li>Right to withdraw consent at any time</li>\n</ul>\n\n<h3>13.2 California Residents (CCPA/CPRA)</h3>\n<p>California residents have the right to:</p>\n<ul>\n  <li>Know what personal information is collected and how it's used</li>\n  <li>Request deletion of personal information</li>\n  <li>Opt-out of sale of personal information (we do not sell your data)</li>\n  <li>Non-discrimination for exercising privacy rights</li>\n</ul>\n\n<p><strong>California Privacy Rights Hotline:</strong> privacy@misksocial.com (Subject: \"California Privacy Rights\")</p>\n\n<h2>14. Your Responsibilities</h2>\n<p><strong>You are solely responsible for all content you post on Misk Social.</strong></p>\n\n<p>This includes but is not limited to:</p>\n<ul>\n  <li>Ensuring your content does not violate any laws or third-party rights</li>\n  <li>Obtaining necessary permissions before posting photos/videos of others</li>\n  <li>Not posting private information (yours or others')</li>\n  <li>Respecting intellectual property rights</li>\n  <li>Complying with our Terms of Service and Community Guidelines</li>\n</ul>\n\n<p>We act as a hosting platform. While we moderate content and remove violations, we are not responsible for the accuracy, legality, or appropriateness of user-generated content.</p>\n\n<hr>\n\n<p><strong>Effective Date:</strong> November 9, 2025<br>\n<strong>Version:</strong> 2.0<br>\n<strong>Last Reviewed:</strong> November 9, 2025</p>","pageType":"privacy","platforms":{"web":true,"mobile":true},"metadata":{"author":"Misk Social Legal Team","category":"Legal","tags":["privacy","data protection","GDPR","CCPA","COPPA"],"language":"en","featured":true,"priority":10,"readingTime":10,"wordCount":1899},"lastModified":"2025-11-09T05:10:35.856Z"},"timestamp":"2026-04-18T10:49:14.765Z"}