🗓️

Privacy Policy

Mimiroid · Effective 24 August 2026

The short version. Mimiroid stores your email address, the username and emoji you pick, and the stickers you make — the photograph, the cut-out, and whatever you type on them. Its accounts system also keeps a sign-in security log, which includes your IP address. It shares them with exactly one person: whoever is in your calendar. There is no advertising, no analytics, no tracking, and nothing is sold. You can delete your account and everything in it from inside the app, at any time.

Who is responsible

Mimiroid is made by Haotian An, an individual developer. For anything in this policy, including a request about your data, write to mimiroidofficial@gmail.com.

The app is offered in the United States, and this policy is written to United States federal and state privacy law.

What the app collects

An account is required to use Mimiroid, because the app's purpose is a calendar shared between two people and there is no way to share without knowing who is sharing.

WhatWhy
Email address To create your account, sign you in, confirm the address is yours, and let you reset a forgotten password. Also used to send you the confirmation and reset messages themselves — nothing else. There is no newsletter and no marketing mail.
Username and emoji You pick both when you first sign in. They are what the other person in your calendar sees next to the stickers you add. Pick a username that is not your real name if you prefer.
Your photographs A sticker is made from a photo you choose. Both the cut-out and the original photograph are stored, so that the other person sees the same thing you do.
What you type on a sticker Its name, the day you put it on, any note, any category, and the place name if you enter one. The place is text you type — the app never reads your device's location and does not ask permission to.
An account identifier A random identifier for your account, which is how the database knows which stickers are yours. It is not derived from your device or from anything about you.
Sign-in records The accounts system keeps a security log of sign-ins, password changes and similar events, and that log includes the IP address the request came from. It exists so that account takeover can be investigated. It is not used for anything else, and never for analytics or advertising.
Invite codes, and timestamps An invite code you generate, until it is used or expires; and the times things were created or changed, which is how two devices agree on what is current. A short-lived record of rate-limited actions, so that invite codes cannot be guessed by brute force.

What the app does not collect

Photos are cut out on your device

Turning a photo into a sticker — finding the subject and separating it from the background — happens entirely on your iPhone, using Apple's on-device vision framework. Your photo is not sent anywhere to be processed. It is uploaded only so the other person in your calendar can see it.

Signing in with Google

If you choose "Continue with Google", Google tells the app your email address and a Google account identifier. The app deliberately discards the name, profile picture and locale that Google also offers, because it does not need them. Google's own handling of that sign-in is covered by Google's privacy policy.

Who your data is shared with

Nothing is sold, and nothing is shared for advertising. Your data is shared in exactly two ways:

The other person in your calendar

This is the point of the app. When you and one other person share a calendar, each of you can see — and can edit or delete — every sticker in it, including the photographs, whatever is typed on them, and the other's username and emoji. A calendar holds at most two people, joining requires an invite you generate, and either of you can end the arrangement: the person who joined can leave, and the owner can remove them.

If you leave a shared calendar, the stickers you added stay in it. They are that calendar's contents, and the other person keeps them.

Service providers

Companies that operate parts of the service on the developer's behalf. They process your data only to provide their service and are not permitted to use it for their own purposes.

WhoWhat they hold
Supabase (hosted on Amazon Web Services, United States) The database, the accounts system, and the stored photographs.
BrevoSends the confirmation and password-reset emails. Receives your email address and the message.
CloudflareServes this website and the invite links.
GoogleOnly if you choose to sign in with Google.
AppleDistributes the app. Apple's handling of your App Store purchase and download is covered by Apple's own privacy policy.

Data may also be disclosed if required by law, or to protect someone's safety or rights — and if that happens, only what is actually required.

How long it is kept

Deleting your account

In the app: Settings → Account → Delete account. It asks you to type DELETE, because it cannot be undone.

This removes your account, your profile, and everything you added, from the cloud. If you own a calendar someone else is still in, they keep the calendar and the stickers in it. Stickers stay on your own phone until you delete the app.

If you cannot reach the app, write to mimiroidofficial@gmail.com and it will be done for you.

Your rights

United States privacy laws differ by state. Rather than offer different rights to different people, every user of this app has all of the following, whichever state you are in:

To exercise any of them, write to mimiroidofficial@gmail.com. Requests are answered within 45 days. You may be asked to confirm you control the account's email address, which is the only way to be sure a request is really yours.

California

The categories of personal information collected are identifiers (email address, account identifier, username) and internet or other electronic network activity only in the narrow sense of the content you create in the app. The business purpose for collecting all of it is to operate the app. It is not used for profiling or automated decision-making.

Mimiroid does not sell or share your personal information, in any sense of "sell" or "share" — including the broad definitions used by California law, which cover sharing for cross-context behavioural advertising. There is no advertising in this app. Because nothing is sold or shared, there is no opt-out to offer; there is nothing to opt out of.

No sensitive personal information is collected. Your photographs are personal, and are treated as such, but the app does not collect the specific categories California defines as sensitive — no government identifiers, no financial accounts, no precise geolocation, no health data, and no contents of your mail or messages.

Children

Mimiroid is not directed to children under 13, and it does not knowingly collect information from them. If you believe a child under 13 has created an account, write to mimiroidofficial@gmail.com and it will be deleted.

Security, honestly stated

Your data is protected in transit and at rest by the hosting provider, and access to it is enforced by database rules that check, on every single request, that you are a member of the calendar you are asking about. That check is the app's main security boundary and it is covered by an automated test suite.

What no one can promise is perfect security. If a breach ever affects your data, you will be told, and told what actually happened.

Changes

If this policy changes, the date at the top changes with it. A change that meaningfully affects what is collected or who it goes to will be announced in the app before it takes effect, not after.