Muqun

Muqun Privacy Policy

Last updated: July 22, 2026

Muqun is a mobile client for Herdr Gateway instances that you control. It has no Muqun account, advertising, analytics, or tracking SDKs.

Data stored on your device

Muqun stores the information needed to provide its features:

  • Gateway names, addresses, pairing times, and access tokens.
  • App preferences and your custom quick commands.
  • The currently selected Gateway.

Gateway records are encrypted and stored using the operating system’s secure credential storage. They are marked as device-only so they do not sync to another device or restore from a backup.

Gateway connections

Terminal sessions go directly between Muqun and the Gateway address you pair. Osuki does not relay, receive, or store terminal output, commands, source code, conversations, Gateway addresses, or access tokens.

Requests to your Gateway may contain the access token, workspace and pane identifiers, terminal input, commands, and agent output required for the feature you use. If notifications are enabled, Muqun also sends the Gateway a device notification token, device name, and platform.

You control the Gateway and its network. We strongly recommend running Muqun and the Gateway on the same Tailscale tailnet, preferably with Tailscale Serve providing a private HTTPS address. Muqun supports HTTP on user-managed private networks, but HTTP itself does not encrypt traffic; only use it inside a trusted encrypted network such as Tailscale.

Camera and App Lock

Camera access is requested only when you open the QR scanner. Frames are processed on the device to read a pairing code and are not saved or uploaded. You can pair by entering a Gateway address manually instead.

If App Lock is enabled, the operating system performs Face ID, Touch ID, fingerprint, face unlock, or passcode authentication. Muqun receives only whether authentication succeeded and never receives or stores biometric data or your passcode.

Notifications

Gateway notifications are optional. When enabled, the notification service processes the device notification token, platform, minimal notification content, and delivery metadata needed to deliver the alert. This information is used only for app functionality, not advertising or tracking. Turning notifications off unregisters the device from the paired Gateway.

Retention and deletion

Local Gateway data remains until you remove that Gateway or uninstall Muqun. App preferences and quick commands remain until changed or the app is uninstalled. Gateway-side data is controlled by the Gateway operator; revoke a device from the Gateway to invalidate its token.

If you contact Osuki for support, we use the information you provide only to respond to your request.

Changes and contact

We may update this policy when Muqun’s features or service providers change. The current version and revision date will remain available at this URL.

Questions about this policy may be sent to [email protected].