Legal

Privacy Policy

How Miya handles your data — what stays on your device, what is processed for AI features, and the choices you have.

1. Who is responsible for your data?

The controller of personal data processed through the Service is:

Lumi Zone Łukasz Blania
ul. Zabrska 15
40-083 Katowice
Poland
NIP: 1990132289
REGON: 528880848

Privacy and legal contact: lukasz.b@lumizone.pl
General support: support@miyacompanion.com

We have not appointed a Data Protection Officer. Privacy enquiries and requests should be sent to the privacy and legal contact above.

In this Policy, “Miya,” “we,” “us,” and “our” refer to the controller identified above.

2. Scope

This Policy applies to:

  • the Miya application for iOS and Android;
  • Miya-operated APIs and account, entitlement, usage, and billing services;
  • the Miya marketing and support website; and
  • communications you send to us for support, privacy, billing, or legal purposes.

This Policy does not govern a third-party AI service or custom endpoint that you independently select and use with your own API key. Those services process data under their own terms and privacy notices, as explained in Section 8.

3. Important summary

  • Local-first storage. Your full chats, memories, companion profiles, relationship state, local embeddings, gallery, and most preferences are stored on your device, not in Miya’s server database.
  • Cloud processing is still required. Selected conversation context, prompts, and any image you deliberately attach or use as a reference may leave your device when you use a cloud AI feature.
  • Pseudonymous device account. The current app creates a device-linked account automatically. No email address or password is required for this flow.
  • Billing is handled by the stores. Apple or Google processes your payment details. Miya and RevenueCat receive purchase and entitlement metadata, not your full payment-card number.
  • No sale of personal data. We do not sell personal data, share it for cross-context behavioural advertising, or use chat content for targeted advertising.
  • No third-party advertising trackers. The current website does not use advertising cookies, tracking pixels, or third-party analytics. The current app does not send chat content to advertising analytics.
  • You control local content. You can review or delete individual content, delete locally stored companions, chats, memories, media, account-session data, and AI configuration, and create an encrypted local backup from within the app. App-lock settings are managed separately in the Security screen.
  • The Service is for adults. Miya is intended only for people aged 18 or older.

4. Data we process

4.1 Data stored primarily on your device

Depending on the features you use, Miya may store the following in the app’s private local storage, SQLite database, secure storage, or app-owned media directory:

  • Profile information: your chosen display name and information you enter in the “About You” area;
  • Companion information: companion names, gender or custom gender label, avatar, biography, personality traits, custom instructions, appearance, chat style, relationship type, and related settings;
  • Conversations: messages, generated replies, message status, chat titles, timestamps, reactions, and locally referenced attachments;
  • Memory and continuity data: extracted memories, lorebook entries, open loops, summaries, relationship events, relationship metrics, mood state, tone state, and local knowledge representations;
  • Media: companion portraits, wallpapers, images you select, images attached to chats, and AI-generated images saved to the local gallery;
  • Local AI data: on-device memory embeddings and background-processing state;
  • Notification data: scheduled check-in text, schedule, notification identifiers, quiet hours, preview preference, and deep-link information;
  • Preferences: theme, language, text size, notification choices, memory settings, and AI routing choices;
  • Feedback: thumbs-up or thumbs-down reactions associated with local messages;
  • Security information: an optional app-lock PIN hash and salt, app-lock state, biometric-unlock preference, failed-attempt counters, and lockout timing; and
  • AI credentials: API keys and optional custom-endpoint credentials saved in the operating system’s secure storage when you choose direct API-key mode.

Miya does not receive a copy of your app-lock PIN or biometric template. Biometric matching is performed by your device’s operating system, and the app receives only the authentication result.

4.2 Data processed by Miya’s servers

When the app can connect to Miya’s backend, we may process:

  • Pseudonymous account identifiers: a randomly assigned user ID, device/account ID, and a one-way hashed representation of the installation identifier;
  • Device and connection metadata: platform (iOS, Android, or unknown), account creation and last-seen timestamps, the most recent IP address associated with device provisioning or attachment, request IP address, request ID, route, response status, timing, and limited security diagnostics;
  • Session information: a protected session-token hash, token expiry, session status, and revocation timestamps;
  • Eligibility information: an access-policy value and policy version. Current device-first accounts are ordinarily assigned the unknown or protected category. The current app does not collect or verify your birth date or exact age. The backend can support minor or adult categories if a separate age-declaration flow is introduced, but under the present Terms anyone under 18 is not permitted to use the Service;
  • Subscription and entitlement data: RevenueCat app-user ID, store, product and entitlement identifiers, subscription status, purchase and expiry timestamps, renewal status, transaction identifiers, billing environment, and relevant cancellation or refund information;
  • Usage records: operation type (for example, chat, memory extraction, or image generation), request identifier, plan/budget period, provider/model routing metadata, token counts, generated-image quantity, cost/usage units, and settlement status;
  • Security and anti-abuse information: IP-based rate-limit state and, where enabled, app-integrity verification results or related request metadata; and
  • Billing webhook records: normalized purchase, renewal, cancellation, refund, transfer, and entitlement events received from RevenueCat.

The current consumer app uses a seamless device-first account and does not require an email address or password. The backend contains reserved support for possible future email/password, Google sign-in, and server-stored provider credentials. Those features are not part of the current consumer flow. If activated, we will provide the required user-facing disclosures before or when the feature is enabled.

4.3 Content processed transiently to provide AI features

When you request an AI operation, some or all of the following may be transmitted from your device:

  • your current message;
  • a bounded selection of recent messages;
  • the companion profile and instructions;
  • selected memories, lorebook material, open loops, and relationship context;
  • a system prompt created by the app;
  • a memory-extraction input containing the current exchange and relevant existing memories;
  • an image-generation prompt and negative prompt;
  • an image attachment or companion/reference portrait that you deliberately submit; and
  • technical fields needed to route, meter, secure, and return the request.

We configure Miya’s gateway to minimize storage of prompt and reply content. The current application database does not intentionally store raw chat prompts, full replies, uploaded images, or full memory content, and ordinary gateway logs redact request bodies and authorization headers. Content is nevertheless processed in memory while the request is completed and is transmitted to the applicable AI provider. The provider’s contract, configuration, and privacy terms determine any temporary retention, abuse monitoring, legal-compliance processing, or model-improvement use at the provider level.

One deliberate exception: content reports. When you flag a single AI reply through the in-app report control, Miya stores only that reported reply text, the category you choose, an opaque local message identifier, and the timestamp on its servers so the operator can review the flagged content and respond to store safety requests. Your own message, the rest of the conversation, and any images are not included in the report. See Section 7 for retention.

Do not submit passwords, payment-card numbers, government identifiers, precise private addresses, medical records, or other information that is not necessary for your use of Miya.

4.4 Photos and other sensitive content

You decide whether to select a photo, attach an image, or use a reference portrait. Miya requests photo-library access only when needed for a feature you choose. The app is not configured to request camera or microphone access for the current feature set.

Images and conversations may incidentally reveal sensitive information, including health information, beliefs, sexuality, ethnicity, or biometric characteristics. Miya does not require this information and does not use images for identity recognition or biometric identification. If you deliberately submit sensitive information, it is processed only to provide the feature you request and subject to the safeguards described in this Policy. Where Article 9 GDPR or another law requires explicit consent, the applicable feature must obtain that consent separately before such processing; if no separate consent is presented, do not submit special-category or similarly sensitive personal data.

4.5 Support and communications

If you email us, we process the information you include, such as your name, email address, account ID, message, attachments, and support history. Please do not send full chat exports or private images unless they are necessary to resolve your request and we specifically ask for them.

4.6 Data we do not intentionally collect

The current Service is not designed to collect:

  • your precise GPS location;
  • contacts or address-book data;
  • microphone recordings or camera footage;
  • your full payment-card or bank-account details;
  • biometric templates used by Face ID, Touch ID, or Android biometrics; or
  • advertising identifiers for behavioural advertising.

5. How and why we use data

For people in the European Economic Area (EEA) or United Kingdom, the table below also identifies the principal legal bases under the GDPR or UK GDPR.

Purpose Typical data Principal legal basis
Provide the app, device account, AI responses, memory operations, image features, local backup tools, and requested functionality Account/session identifiers, selected content, feature settings, request metadata Performance of a contract or steps requested before entering a contract; Article 6(1)(b) GDPR
Validate purchases, grant entitlements, restore access, enforce usage allowances, and maintain billing records User ID, RevenueCat/store metadata, product, transaction, entitlement, and usage records Performance of a contract; Article 6(1)(b); compliance with legal duties where applicable, Article 6(1)(c)
Secure the Service, prevent fraud and trial abuse, rate-limit requests, investigate errors, and protect users and infrastructure IP address, device/platform metadata, request IDs, integrity signals, security logs Our legitimate interests in (i) detecting and preventing fraud, trial farming, credential abuse, and misuse, (ii) protecting the security and availability of our infrastructure and other users, and (iii) metering usage to keep the Service sustainable; Article 6(1)(f)
Enforce the 18+ rule and apply content safeguards Eligibility value, policy version, submitted request content Performance of the service, compliance with legal duties, and our legitimate interests in user safety and enforcing the Terms; Articles 6(1)(b), 6(1)(c), and 6(1)(f), as applicable
Respond to support, privacy, billing, and legal enquiries Contact details, correspondence, account and diagnostic data Performance of a contract, legal obligations, and our legitimate interests in resolving requests, maintaining support records, and improving service reliability; Articles 6(1)(b), 6(1)(c), and 6(1)(f)
Establish, exercise, or defend legal claims and comply with valid legal requests Relevant account, billing, security, and correspondence records Legal obligation or our legitimate interests in protecting legal rights, handling disputes, and preventing abuse; Articles 6(1)(c) and 6(1)(f)
Process optional data where the law specifically requires consent The data and feature identified in the consent request Consent; Article 6(1)(a), and Article 9(2)(a) where applicable

Where we rely on legitimate interests, we assess whether the processing is necessary and proportionate, balance those interests against your rights and reasonable expectations, minimize the data used, and apply access, retention, and security controls. The relevant processing generally uses limited account, IP, device, request, entitlement, or security metadata rather than full local conversation history. You may object as explained in Section 12.

5.1 Sources of data

Some data is collected directly from you, while other data is received from the stores, RevenueCat, AI providers, and integrity services identified below. We obtain data:

  • directly from you when you enter content, choose settings, contact us, or request a feature;
  • automatically from the app, device, network connection, and Miya gateway when the Service is used;
  • from Apple, Google, and RevenueCat in connection with purchases and entitlements;
  • from an AI provider when it returns output, usage information, identifiers, or an error; and
  • from an app-integrity service when that safeguard is enabled.

5.2 Required and optional data

Pseudonymous installation, platform, session, request, and limited connection data are required to create and secure the device account and use Miya-operated cloud features. Selected prompt or context data is required to perform the particular AI operation you request. Purchase and entitlement metadata is required to provide a paid plan.

Profile details, custom companion information, photos, direct-provider API keys, notifications, biometrics, and support communications are optional. If you do not provide optional data or permission, the related optional feature may not work, but unrelated features should remain available. If you do not provide data required for a cloud operation, we cannot perform that operation.

Operating-system permission prompts, such as photo-library, notification, or biometric permission, control technical access on your device. A permission prompt is not necessarily the same as consent under data-protection law.

6. Local storage, backups, and deletion

6.1 Local data

Local conversations, memories, companion information, media, and preferences remain on your device until you delete them, clear the app’s data, restore a backup that replaces them, or the operating system removes them.

The app includes controls to:

  • delete individual chats, memories, companions, and media where the relevant screen provides that action;
  • delete locally stored companions, chats, memories, media, AI configuration, and device-account session data through the “Delete all data” flow;
  • disable and remove app-lock PIN and biometric settings separately in the Security screen;
  • export an encrypted .myyumi backup; and
  • restore an encrypted backup.

An exported backup contains the local database and app-owned media. It is encrypted using a password you choose. We do not receive or store that password and cannot recover it. Once you export or share the backup, you are responsible for its location, password, recipients, and deletion.

The app-owned database and media are configured to be excluded from ordinary device-cloud backup where supported. Operating-system behaviour may vary. Some secure-storage items on iOS may survive an uninstall, so use Miya’s deletion controls before uninstalling if you want to remove local credentials and identifiers as fully as the platform permits.

6.2 Server account deletion

Deleting local app data, uninstalling Miya, and deleting a server-side device account are separate actions. Likewise, deleting an account does not cancel an App Store or Google Play subscription.

To request deletion of your server-side Miya account and associated personal data, use Account → Delete account in the app, or contact lukasz.b@lumizone.pl or support@miyacompanion.com. If you write by email, include the Miya Account ID shown in the app and enough information to demonstrate control of the relevant account. Do not send your session token or API keys.

A server-side deletion request may enter a 14-day grace period during which the request can be cancelled. Active sessions are revoked and any reserved server-stored provider credential is disabled when the request is accepted. After the grace period, account-linked user, device, session, entitlement, subscription, usage, and credential records are automatically eligible for permanent deletion from the active database, normally during the next scheduled deletion sweep. Separate billing-webhook audit records are not deleted through the same account-table cascade and are retained only under the criteria below.

7. Retention

We retain data only for as long as reasonably necessary for the purposes described in this Policy, taking account of service operation, account status, legal duties, security, billing reconciliation, dispute resolution, and applicable limitation periods.

Typical criteria are:

  • Local app data: until you delete it, replace it through restore, clear app data, or the operating system removes it;
  • Encrypted backups: controlled by you after export; Miya does not receive the exported file unless you send it to us;
  • Active account, session, entitlement, and usage data: while the account is active and as needed to operate the Service. The current backend configuration does not automatically purge settled usage-ledger entries solely because a fixed number of days has passed; they remain account-linked and are removed through the account-deletion process unless a shorter operational retention window is configured;
  • Most recent device IP address: while the device/account record remains active and as needed for trial-abuse and fraud prevention, then through the account-deletion process;
  • Expired sessions: according to operational security needs; session credentials are normally issued with a limited validity period and may be revoked earlier;
  • Account deletion: account-linked records become eligible for automatic permanent deletion after the 14-day grace period, normally during the next scheduled sweep. Content reports you submit are account-linked and are removed through the same account-deletion process; they are otherwise kept while needed for safety review of the flagged content;
  • Content reports: the flagged reply text, category, message identifier, and timestamp are retained while needed to review the reported content and handle store safety requests, and are deleted with the account as described above. There is no separate fixed purge period for current reports;
  • Billing and webhook audit records: these may remain after the main account-table deletion because they are maintained separately. We keep them only for as long as needed to reconcile purchases, prevent fraud, meet tax/accounting requirements, respond to chargebacks, and establish or defend legal claims. Depending on the record and applicable law, this may extend for the relevant statutory retention or limitation period;
  • Security and gateway logs: short-term rolling retention appropriate to incident detection, abuse prevention, and troubleshooting. Normal logs are configured to redact authorization headers and request bodies;
  • Support correspondence: while the request is open and afterwards for a period reasonably needed for follow-up, service improvement, dispute handling, or legal compliance; and
  • Backups of Miya-operated systems: until overwritten under the applicable rolling backup cycle, unless longer retention is required for security or law.

We may retain de-identified or aggregated information that no longer identifies you.

8. AI processing modes and third-party services

8.1 Miya Subscription mode

In Subscription mode, the app sends selected content to Miya’s gateway. The gateway authenticates the request, applies entitlements and usage limits, and routes the request to a configured provider. Depending on the feature, plan, capacity, safety configuration, and current routing, providers may include:

  • OpenAI — text generation in the current Miya-managed routing;
  • DeepSeek — text generation;
  • Google Cloud / Vertex AI / Gemini — memory-related processing in the current Miya-managed routing;
  • fal.ai — image generation and image-reference processing;
  • RevenueCat — subscription entitlement and purchase-status management;
  • Apple App Store and Google Play — purchases, subscription management, refunds, and store-account services; and
  • Google Play Integrity, where enabled — app-integrity and anti-abuse verification on supported Android devices.

The provider actually used may change as models, availability, safety requirements, and plan features evolve. We do not use your conversation content to train any Miya model. Upstream providers process content under the applicable commercial configuration, data-processing terms, and privacy notice; those terms determine whether the provider may retain content for abuse monitoring, legal compliance, service operation, or model improvement. We will not intentionally enable provider training on Subscription content unless it is disclosed and any consent required by law has been obtained.

8.2 Direct API-key mode

If you choose direct API-key mode, the app sends requests from your device directly to the provider or endpoint you select, generally without routing the content through Miya’s gateway. Supported choices may include OpenAI, DeepSeek, Google Gemini, Anthropic Claude, OpenRouter, Mistral, xAI, Groq, Cerebras, Fireworks AI, Together AI, DeepInfra, Perplexity, fal.ai, and a custom OpenAI-compatible endpoint.

In this mode:

  • your provider API key is stored in device secure storage;
  • the selected provider receives the prompt, relevant context, and any attachment required for the request;
  • the provider may charge your provider account directly;
  • the provider’s own terms, privacy notice, data location, retention, and training choices apply; and
  • a custom-endpoint operator is selected by you and is not controlled or audited by Miya.

Review the provider’s policies before enabling this mode. Do not use a custom endpoint you do not trust. Miya is not responsible for how an independently selected provider or endpoint processes your data.

8.3 Generated-image delivery

An image provider may return a temporary hosted URL or inline image data. The app downloads or writes the image into Miya’s local media directory when you save or display it. The provider may retain prompts, inputs, generated media, or request metadata under its own service terms or our applicable service agreement.

9. When we disclose data

We may disclose personal data:

  • to the service providers described above, only as needed for their function;
  • to hosting, infrastructure, security, professional-adviser, and support providers acting for us;
  • when you direct us to disclose it, including through a system share sheet or selected AI provider;
  • to comply with law, a court order, or a valid request from a competent authority;
  • to investigate fraud, abuse, security incidents, or violations of the Terms of Use;
  • to protect the rights, safety, and property of users, the public, Miya, or others; and
  • as part of a merger, financing, acquisition, restructuring, or transfer of all or part of the business, subject to appropriate safeguards and notice where required.

We do not sell your personal data. We do not share personal data for cross-context behavioural advertising.

10. International transfers

We are established in Poland. Some providers may process data in the EEA, the United States, or other countries whose laws may not provide the same level of protection as the law where you live. Depending on the configured provider and its current processing locations, this may include the People’s Republic of China.

Where we are responsible for a restricted international transfer:

  • for a United States recipient validly certified under the EU–US Data Privacy Framework, we may rely on the applicable adequacy decision;
  • for other restricted transfers, we use the European Commission’s Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum or another legally recognized mechanism; and
  • we apply supplementary technical, contractual, and organizational safeguards where appropriate.

Transfers made directly to a provider or custom endpoint you independently select in API-key mode are made at your direction and are also governed by that provider’s privacy terms. Contact us to ask which safeguard applies to a specific Miya-operated transfer or to request a copy of the relevant contractual clauses, subject to appropriate redactions.

11. Security

Security measures reflected in the Service include, as applicable:

  • encrypted network transport for production connections;
  • one-way protection of installation identifiers, session tokens, and passwords where those features apply;
  • operating-system secure storage for session credentials, API keys, and app-lock information;
  • encrypted storage for any supported server-side provider credential;
  • request-body and authorization-header redaction in ordinary gateway logs;
  • server-side request validation, rate limits, usage budgets, and optional app-integrity checks;
  • optional PIN and device-biometric app lock;
  • encrypted user-controlled local backups; and
  • controls that attempt to prevent screen capture on sensitive app screens.

No method of storage or transmission is completely secure. Protect your device with a strong device passcode, enable Miya’s app lock if appropriate, keep your operating system updated, safeguard exported backups, and never share API keys or session tokens.

If a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected individuals as required by law.

12. Your privacy rights

Depending on where you live and subject to legal conditions and exceptions, you may have the right to:

  • obtain confirmation that we process your personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • request deletion of personal data;
  • restrict processing;
  • receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing already carried out lawfully;
  • complain to a data-protection authority; and
  • receive information about applicable safeguards for international transfers.

Miya derives limited mood, tone, memory-relevance, and relationship-state signals from conversations stored on your device to personalize responses and continuity. This is profiling for the companion features you request. It is not used for advertising or third-party scoring and does not produce legal or similarly significant effects.

Miya does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR. AI responses and automated entitlement or safety checks are features of the Service, not decisions about employment, credit, insurance, housing, education, or other comparable rights.

How to exercise your rights

Email lukasz.b@lumizone.pl. Because the current account may not contain your name or email address, provide your Miya Account ID and information reasonably necessary to verify control of the account. We may ask for additional verification, but we will not request your password, API key, full session token, or unnecessary identity documents.

We normally respond within one month where the GDPR applies. That period may be extended by up to two additional months for complex or numerous requests, and we will explain any extension.

Complaint to a supervisory authority

If you are in Poland, you may complain to:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych)
ul. Stawki 2
00-193 Warsaw
Poland
https://uodo.gov.pl/

You may also complain to the competent authority where you habitually live, work, or where an alleged infringement occurred.

13. California and other regional disclosures

Where the California Consumer Privacy Act or a similar law applies, you may have rights to know, access, correct, delete, and obtain a copy of covered personal information, and to receive equal service when exercising those rights.

During the preceding 12 months, the categories described in Section 4 may have been collected and disclosed for the business purposes described in Sections 5, 8, and 9. We do not sell personal information and do not share it for cross-context behavioural advertising. We do not offer financial incentives in exchange for personal information.

Residents of other jurisdictions may exercise any additional rights granted by their local law by contacting us. We will not discriminate against you for making a valid privacy request.

14. Children

Miya is intended only for users aged 18 or older. We do not knowingly offer or maintain the Service for anyone under 18. The current device-first flow does not independently verify age. If we learn that a person under 18 has used the Service or provided personal data, we will restrict the account and delete or de-identify the affected data as required by law. If you believe this has occurred, contact lukasz.b@lumizone.pl.

16. Changes to this Policy

We may update this Policy when the Service, providers, laws, or processing practices change. We will post the updated version, change the “Last updated” date, and provide additional notice in the app or by another appropriate method when a change is material or consent is required.

A Privacy Policy describes data practices; it does not reduce rights granted to you by applicable law.

17. Contact

For privacy requests, questions, or complaints, contact:

Lumi Zone Łukasz Blania
ul. Zabrska 15, 40-083 Katowice, Poland
Email: lukasz.b@lumizone.pl
Support: support@miyacompanion.com