MIIU is designed to be a private and personal space for self-reflection, personal development and exploration. This Privacy Policy explains how personal data is stored, transmitted and processed when you use the MIIU mobile application, website and related services (“MIIU” or the “Service”).
The data controller responsible for MIIU is:
Greenster [FULL LEGAL ENTITY NAME]
CVR: [CVR NUMBER]
[REGISTERED ADDRESS]
Denmark
Email: [PRIVACY EMAIL]
In this Policy, “MIIU”, “we”, “us” and “our” refer to this entity.
MIIU is built around a local-first approach.
Your personal MIIU content — including your conversations, memories, journal entries, mood data, personality-test data and other information you create through MIIU — is stored locally on your device.
MIIU does not maintain a cloud copy of this personal MIIU history.
When a feature requires artificial-intelligence processing, only the information needed to provide that feature is transmitted for processing. Other service providers may process limited account, authentication, subscription, transaction or technical information where necessary to provide those functions.
Your personal MIIU content is not sold, used for advertising or used by MIIU to train AI models.
The sections below explain these practices in more detail.
Depending on how you use MIIU, you may create or provide different kinds of information.
This may include:
Because MIIU is designed for personal reflection, some of this information may be highly personal or sensitive.
You decide what you share with MIIU.
Your personal MIIU content is stored locally on your device.
This includes, where applicable:
This information is not automatically transmitted simply because it exists inside MIIU.
Some features require portions of this locally stored information to be temporarily transmitted for processing. This happens only where necessary to provide the feature you are using, as described below.
Certain MIIU functionality also operates directly on your device. For example, MIIU may perform local processing to retrieve relevant memories or context without transmitting your complete personal history to an external service.
MIIU uses external artificial-intelligence services to generate conversations, insights and other AI-powered features.
When you use a feature requiring AI processing, MIIU sends the information necessary to provide that feature.
Depending on what you are doing, this may include:
MIIU is designed to provide relevant context rather than transmit your entire locally stored history with every request.
Information sent for AI processing is transmitted for the purpose of providing the feature you requested. MIIU does not use your personal content to train AI models.
MIIU currently uses OpenAI to provide certain artificial-intelligence functionality.
Depending on the feature you use, information sent to OpenAI may include text, relevant contextual information, audio, speech information or AI-generated responses.
OpenAI states that inputs and outputs submitted through its API platform are not used to train its models by default.
Under OpenAI's standard API data-retention practices, API inputs and outputs may be retained for up to 30 days before being removed, unless longer retention is required by law or a different applicable service configuration applies.
MIIU does not opt in to using your personal MIIU content to train or improve OpenAI's models.
OpenAI processes information in accordance with its applicable contractual, privacy and data-protection obligations.
MIIU may process limited information necessary to create, authenticate and maintain your account.
This may include:
MIIU currently uses Clerk to provide account and authentication functionality.
Clerk may process information necessary to create accounts, authenticate users, manage sessions, verify email addresses, support sign-in methods and protect authentication systems against misuse.
Authentication credentials may be handled directly by Clerk or a third-party sign-in provider and are not necessarily accessible to MIIU in readable form.
If you choose to sign in using a third-party provider such as Google or Meta/Facebook, that provider may also process information associated with your authentication under its own privacy terms.
MIIU does not receive your Google, Facebook or other third-party account password.
If you purchase a MIIU subscription, information necessary to process and administer that subscription is handled by the relevant application marketplace and subscription infrastructure providers.
MIIU currently uses RevenueCat to manage subscription entitlements and related in-app purchase functionality.
Depending on the platform and transaction, RevenueCat may process information such as:
If you purchase through Apple's App Store, Apple independently processes information associated with your Apple account and purchase under Apple's own privacy practices.
MIIU does not receive or store your full payment-card details when purchases are processed through an application marketplace.
Because MIIU is designed for personal reflection, you may choose to discuss subjects that are sensitive or highly personal.
Depending on what you choose to share, this could include information concerning health, mental wellbeing, relationships, sexuality, beliefs, family circumstances or other private aspects of your life.
MIIU does not require you to disclose every type of sensitive information in order to use the Service.
Where information constitutes special-category personal data under the GDPR, MIIU processes that information only where an appropriate legal basis and applicable condition under data-protection law exists.
Where required, MIIU may ask for explicit consent before processing particular categories of sensitive personal data. Where processing is based on consent, you may withdraw that consent in accordance with applicable law.
Some technical information may necessarily be processed when you use online functionality within MIIU.
Depending on the service involved, this may include:
Such information may be processed by service providers involved in delivering online functionality even though your personal MIIU history remains stored locally on your device.
We use technical information only where reasonably necessary to operate, secure, maintain or troubleshoot MIIU, comply with legal obligations or prevent misuse.
Where personal data is processed by MIIU or on our behalf, we use it for purposes including:
We do not sell your personal MIIU content.
We do not use your personal MIIU content to create advertising profiles.
We do not provide advertisers with access to your private conversations, memories, journal entries, mood data or personality information.
We do not use your personal MIIU content to train AI models.
Where the General Data Protection Regulation (“GDPR”) applies, the legal basis for processing depends on the purpose and type of processing involved.
Performance of a contract — Article 6(1)(b)
We may rely on this basis where processing is necessary to provide MIIU or a feature you have requested.
Legitimate interests — Article 6(1)(f)
We may rely on legitimate interests where processing is reasonably necessary for purposes such as maintaining security, preventing fraud or abuse, troubleshooting the Service and protecting our legal rights, provided those interests are not overridden by your rights and interests.
Legal obligation — Article 6(1)(c)
We may process information where necessary to comply with an applicable legal obligation.
Consent — Article 6(1)(a)
We may rely on consent where we specifically ask you to consent to particular processing.
Where special-category personal data is processed, an additional condition under Article 9 GDPR will apply where required.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that occurred before consent was withdrawn.
MIIU does not distribute your personal information to third parties for their independent advertising or marketing purposes.
Information may, however, be processed by third parties where necessary to provide the Service.
Depending on the features you use, these may include:
Different providers receive different categories of information. Using one provider does not mean that provider receives access to your complete MIIU history.
Where service providers process personal data on our behalf, they are subject to applicable contractual and data-protection obligations.
Some providers used by MIIU may process information outside Denmark or the European Economic Area (“EEA”).
Where GDPR-regulated personal data is transferred outside the EEA and applicable law requires additional safeguards, appropriate transfer mechanisms are used.
Depending on the provider and destination, these may include:
The fact that your personal MIIU history is stored locally on your device substantially limits the information that needs to be transmitted to external providers.
Personal MIIU content stored on your device
Your locally stored MIIU information generally remains on your device until you delete the relevant information, clear MIIU's local data, delete the application or otherwise remove the data through available device or application functionality.
AI processing
Information transmitted to an AI provider is subject to the applicable provider's data-retention terms and MIIU's service configuration.
OpenAI currently states that standard API inputs and outputs may be retained for up to 30 days before deletion, subject to applicable exceptions.
Authentication information
Account and authentication information may be retained for as long as necessary to maintain your account and for applicable security, legal or administrative purposes.
Subscription and transaction information
Subscription providers and application marketplaces may retain transaction information according to their own legal, financial and operational requirements.
Certain records may also need to be retained where required by law or where reasonably necessary to prevent fraud, resolve disputes or establish, exercise or defend legal claims.
Because your personal MIIU content is stored locally, you have direct control over much of your information.
MIIU may provide functionality allowing you to delete individual information, clear locally stored MIIU data, export your information or delete your account.
Deleting locally stored information from your device does not necessarily immediately delete information that has previously been transmitted to a service provider. Such information remains subject to that provider's applicable retention and deletion procedures.
Account deletion may also require deletion or deactivation of information maintained by authentication, subscription or other operational providers.
Some limited information may be retained where required or permitted by law, including information necessary to maintain legally required transaction records, prevent fraud, resolve disputes or establish, exercise or defend legal claims.
If you export your MIIU data, the exported file may contain highly personal information. You are responsible for protecting exported copies after they leave MIIU's application environment.
Where the GDPR or other applicable data-protection law applies, you may have rights concerning personal data processed about you.
Depending on the circumstances, these may include the right to:
These rights may be subject to conditions and exceptions under applicable law.
An important consequence of MIIU's local-first architecture is that we may not possess or have access to personal information stored exclusively on your device. If we do not possess particular locally stored information, we cannot retrieve it from your device in response to a data-access request.
To exercise a privacy right concerning information processed by MIIU or its processors, contact [PRIVACY EMAIL].
We may need to verify your identity before fulfilling certain requests.
If you believe your personal data has been processed unlawfully, you also have the right to lodge a complaint with a competent supervisory authority.
In Denmark, the relevant authority is Datatilsynet (The Danish Data Protection Agency).
MIIU uses artificial intelligence and automated systems to personalize conversations, retrieve relevant context, identify patterns and generate insights or other content.
These systems may use information you have provided to determine which context is relevant to a particular interaction.
MIIU is not intended to make decisions producing legal effects concerning you, or similarly significantly affecting you, solely through automated processing within the meaning of Article 22 GDPR.
Personality results, Perspectives, mood patterns, journal insights and AI-generated observations are intended for personal reflection and development. MIIU does not use these features to determine employment, creditworthiness, insurance eligibility, healthcare access or similarly consequential decisions about you.
MIIU uses technical and organizational measures intended to protect personal information against unauthorized access, disclosure, alteration or destruction.
Depending on the system involved, these measures may include:
No electronic system, device, storage method or transmission method can guarantee absolute security.
Because your personal MIIU content is stored locally, the security of your device is an important part of protecting your information. You should protect your device with appropriate security measures and prevent unauthorized access to your MIIU account.
If a personal-data breach involving information for which MIIU is responsible occurs, we will investigate and respond in accordance with applicable data-protection law, including notifying authorities or affected individuals where legally required.
Your conversations, memories and journals may naturally contain information about people in your life.
Please be thoughtful when providing sensitive information about identifiable third parties.
You should not use MIIU to unlawfully collect, publish, disclose or misuse another person's personal information.
Where another person's information appears in private content you provide for your own personal use, it may be processed where necessary to provide the MIIU functionality you requested and otherwise as described in this Policy.
MIIU is not intended for children under 16 years of age.
If we become aware that personal data has been processed from a child in circumstances where parental consent or another legal requirement applies and has not been satisfied, we will take appropriate steps in accordance with applicable law.
If you believe a child is using MIIU contrary to these requirements, please contact [PRIVACY EMAIL].
We may disclose personal data where we are legally required to comply with a valid and binding legal request.
Where legally permitted and appropriate, we will seek to protect user privacy and limit disclosure to information reasonably necessary to comply with the applicable requirement.
Because personal MIIU content is stored locally on your device, we may simply not possess information requested by a third party or authority.
MIIU will evolve, and this Privacy Policy may be updated as our features, providers or legal obligations change.
The current version will display its effective date and last-updated date.
If we make material changes to how personal data is processed, we will provide appropriate notice and, where required by law, obtain consent before beginning the relevant processing.
We will not treat previously collected personal data as available for materially different purposes merely by changing this Policy where applicable law requires additional notice or consent.
For privacy questions, requests or concerns, contact: