Data & Privacy Policy

Last updated August 8, 2026. This page summarizes MMIPS's current public/private data boundaries and safety controls.

MMIPS separates private intake, subscriber, and moderation data from approved public profile data so public awareness does not require exposing contact details, unsafe exact locations, or internal review records.

Need immediate help?

If someone is in immediate danger, call 911.

MMIPS is a public-awareness and family-support resource. It is not law enforcement and it is not a tip line. File official reports with the appropriate Tribal, local, state, or federal agency. NamUs and the BIA Missing and Murdered Unit may also be important official resources.

Private intake and review data

Approved public profile data

Public profiles contain only reviewed fields intended for public awareness. Public pages do not intentionally expose private submitter or subscriber contact data, moderator-only notes, exact private locations, or unverified accusations.

Public map and ZIP-distance data are separate

The visual map and ZIP-distance search do not derive coordinates from private case-location fields. Moderator-approved public map points are stored in a separate relation and are deliberately approximate. A published profile may exist without any map point and therefore may not appear in ZIP-distance results.

For subscriber and profile ZIP-distance functions, MMIPS sends only a five-digit ZIP code from the server to the U.S. Census Bureau TIGERweb service to obtain a generalized ZIP Code Tabulation Area reference point. MMIPS does not request a street address or browser/device GPS location for this function.

Urgent community alert separation

The community alert list is separate from family/profile-management correspondence. A raw submission cannot automatically send an urgent public alert. A moderator must first approve and publish the profile, approve a deliberately approximate public map point, mark the case for urgent public awareness, review the matched audience, and explicitly confirm the send.

Photo protections

Private photo intake is limited by file count, size, image type, signature, image dimensions, and metadata checks. Images with embedded EXIF/XMP/text metadata that could expose location or device information are rejected before storage. Public use still requires moderator approval.

Access and database controls

Third-party infrastructure

Current infrastructure includes Vercel, Supabase, Resend, Cloudflare Turnstile, MapTiler/MapLibre, and the U.S. Census Bureau TIGERweb geography service. These providers receive only the information required for their role in hosting, storage/authentication, email delivery, anti-abuse verification, public map rendering, or generalized ZIP-area lookup.

Retention, correction, and removal

MMIPS retains records as needed to document moderation, consent, safety decisions, alert delivery, correction/removal handling, and service security. Short-lived abuse counters are designed for limited retention. Families and authorized contacts may request correction, hiding, or removal of public information. Alert subscribers may unsubscribe without an account or explanation.

Contact

Privacy/legal notices: legal@mmips.com
Corrections/removals: corrections@mmips.com
General questions: contact@mmips.com

Request correction/removalSafety Policy