Privacy notice
Updated 6 October 2026
Who we are
MUPAS Worldwide (MUPAS LLC) runs this portal, the MUPAS Mobile Portal app and the MUPAS devices: a support and wellness service built on scientific methods and research. If you enrolled in the earlier MUPAS study, the enrollment agreement you signed still applies and this notice does not change it.
What we collect
Account. Your member id, password, screen name, avatar and email address.
Instrument readings. Everything a MUPAS device or the mobile app sends: sensor readings, camera captures and spectrum captures, with the device's timezone and, for devices registered from the app, its location. Location from the MUPAS phone app is rounded on the phone to about 110 metres (three decimal places of latitude and longitude) before it is sent; MUPAS never receives a finer position from the app. The rounded location is kept while your account is active. When the account is closed it is removed from the systems that show it to you or answer questions from it. An offline archive of these readings is kept for MUPAS's research records; it is not shown to anyone and is never used to answer questions.
What you write. Memos, observations, case narratives, board posts, comments, and messages to a Peer Support Specialist, with the time you say each one happened and how sure you are of that time.
Purchases and billing. Orders, subscription and card references from our payment provider. We never see or store card numbers.
Use of the portal. Sign-ins, page views and which features you use, tied to your member id, kept for a limited period and then summarised.
Visits to the public site. A daily anonymous count of visitors by country. No cookie is set and no IP address is stored.
How you found us. When you create an account or place an order, we keep where that visit began - the campaign tag on the link you followed (for example a podcast's) or the site that sent you, and the first page you opened - so we know which of our efforts reach people. It is kept with your account and is not shared. Nothing is recorded if your browser sends Global Privacy Control.
Who else processes it
Stripe - payments, cards on file and subscriptions.
BoldSign - electronic signature of agreements.
Google Workspace - sending email from support@mupas-worldwide.com.
OpenAI - generating the answers and reports in Ask MUPAS about your records and the AI Insights Report, and checking those answers. Your question is sent as you typed it. The records it is answered from had your identity removed and names, phone numbers and addresses redacted before they were stored. Ranking and redaction run on MUPAS's own server and send nothing to OpenAI. MUPAS's OpenAI organisation has sharing of inputs and outputs with OpenAI switched off, so neither your question nor the records are used to train their models.
Anthropic - the portal's own screening of AI questions, messages in peer support and posts on the boards for content that needs a human to look at. Anthropic's terms for its API do not use inputs or outputs to train their models by default, and MUPAS has not opted in.
OpenSky, N2YO, OpenWeatherMap and USGS - when you record an entry from a device that has a location, that device's coordinates are sent to these services so we can note the aircraft, satellites, weather and earthquakes at that moment. Only counts, distances and bands are kept - never your coordinates.
We do not sell personal information and we do not share it for advertising.
If you use the MUPAS Mobile Portal app
What the app sends, and only when you turn it on. The app sends MUPAS readings only from what you choose to use: this phone's motion, magnetic-field and step-count sensors, with location rounded as described under "What we collect"; heart rate and motion from a Bangle.js or Wear OS watch you pair; brain-activity (EEG) and motion readings from a Muse headband; and, if you turn on radiation counting, the counts the phone's camera records - the camera images themselves never leave the phone. For a MUPAS Mini or EnviroDot, the app sets up the device and its Wi-Fi, and the device then sends its own readings. You can stop any of these at once on the Devices tab.
What the app does not collect. The app does not read your contacts, calendar, text messages, call history, files or browsing, and it has no access to your microphone. It contains no advertising or analytics code, and it does not record which screens you open or what you tap.
Permissions, and why. Bluetooth, to find and connect to your sensors. Location, to stamp readings from this phone with where they were taken (rounded before sending); some versions of Android also require it for Bluetooth scanning. Physical activity, to count steps. Camera, only for radiation counting if you turn it on, and for photos you choose to attach. Notifications, to show that recording is on and to tell you about your devices and records. Refusing a permission switches off the feature that needs it and nothing else.
Device identifiers. To keep each device's readings separate, the app gives each one an identifier that includes a short code derived from the phone or from the sensor's Bluetooth address. It is not your advertising ID, and it is not shared.
On your phone. Your sign-in details are stored encrypted on the phone and are excluded from cloud backup. Screens that show private conversations block screenshots and screen recording.
Code from other makers. The software that talks to a Muse headband is supplied by its maker, Interaxon. We tested it in October 2026: it contains no networking of its own, and while a headband was streaming, the app connected to nothing but MUPAS. Location on the phone comes from Google Play services, under your phone's own location settings.
The watch. The Wear OS watch app sends its readings to your phone, and the phone sends them to MUPAS as described above. The watch does not contact MUPAS directly.
Who inside MUPAS can see what
Other members can see what you choose to share: a device you share with them, and posts on the public boards. Entries are stripped of identifying details and kept under a pseudonymous key, not linked to your account. They form the research corpus the AI answers from; an answer to another member may draw on an entry of yours, and yours on theirs.
Peer Support Specialists see you by screen name only. Specialists may keep private notes about a session for MUPAS.
MUPAS staff can see your account and entries to operate the service.
How long we keep it
Instrument readings and what you write are kept for as long as your account exists, because the value of the record is in comparing it over time. Usage records of the portal are kept in detail for a limited period and then only as daily totals.
When an account is closed, your readings and location are removed and your account details are deleted. What you wrote stays in MUPAS's research records, kept without your name and no longer linked to your account, and an offline archive of your readings is kept but never shown and never used to answer questions.
Your choices
Email. Every notification email can be turned off under Notification Settings; the weekly summary and announcements carry a one-click unsubscribe.
Sharing. You decide which devices are shared and with whom, under Share Your Data.
Deletion. You can ask for your account to be deleted from the avatar menu in the portal, from the account menu in the Mupas Mobile Portal app, or by writing to support@mupas-worldwide.com from the address on your account. We carry out a deletion request within 30 days. What is removed and what is kept is set out at Deleting your account. If you enrolled in the earlier MUPAS study, that enrollment agreement governs what is retained.
A copy of your record. You can ask for a copy of what you recorded by writing to support@mupas-worldwide.com from the address on your account.
Contact
Questions about this notice: support@mupas-worldwide.com.