Mipkin

Privacy Policy

Last updated 28 August 2026

Mipkin is operated by Eros Media LLC (“we”, “us” and “our”), 1000 Brickell Ave., Suite 715, Miami, Florida 33131, United States. Eros Media LLC is the controller of personal information processed for Mipkin. The app is built so your Mipkin, Nook, check-ins and writing stay on your device by default. A few optional features need a service to work, and production builds use limited Firebase diagnostics and analytics described below.

What we collect about you

We do not ask for a name, phone number, contacts, photos, location or date of birth. Production builds use Firebase Crashlytics and Firebase Analytics for the limited purposes below. They are not used for advertising and are not linked to Google Ads. Optional email sign-in uses Firebase Authentication to verify an email address; we describe that separately below.

What is stored, and where

The core Mipkin data the app keeps by default lives in your device's own storage, in a private area belonging to the app. That includes:

  • A randomly generated identifier created on your device, which is not linked to you and is never sent anywhere.
  • Your Mipkin — which one, their name, the room, how long you have known each other, and their bond and energy values.
  • What you have done in the app: the small things you have tended, quests, adventures, keepsakes, warmth earned and spent, decor owned and where you put it.
  • Your daily check-in answer, which is replaced each day.
  • Any Personal Rhythm you choose to make: its label, gentle time preference, whether you pause it, whether you chose “done” or “not today” today, and whether you choose to show completed choices in a private seven-day look-back. This stays on your device; it is not a streak, score, notification signal, account backup, or analytics data. The look-back cannot see your writing, check-ins, Mipkin, friends, health data, or anything you did not choose to include.
  • A bundled activity-soundscape choice, if you make one. Focus sessions themselves are not saved. Neither is listening history, account backup, analytics data, or a notification signal.
  • The pages you write in your own journal, and any reflection returned for them.
  • Anything you shut in the worry box. This never leaves your device under any setting — there is no switch that sends it, and nothing in the app reads it except the screen that shows it back to you.

This core content does not leave your device unless you choose one of the optional features below. Limited anonymous diagnostics and product-interaction events do not contain that core content. Inside the app you can export the local information it holds, or delete it, at any time.

Apple Health mindful minutes

On iPhone, only after you choose to connect Apple Health, Mipkin can write the duration of breathing, grounding, wind-down and focus activities as mindful minutes. Mipkin never reads Apple Health. The mindful-minute record is written directly by iOS and is not sent to Mipkin, Firebase, OpenRouter, or RevenueCat. You can control or revoke this access in Apple Health or iPhone Settings.

Optional features that send data

Reflections, visiting, care cues, private friends and account backup are separate choices. You can use the core Mipkin, Nook and journal without any of them.

Reflections

When you turn reflections on and request one for a journal page, the page text is sent to our service. If you selected support areas during onboarding, up to six fixed choices such as “rest” or “connection” may accompany it. No Mipkin name or identifier, mood, check-in, streak, warmth, keepsake, device identifier, advertising identifier, timestamp, or previous journal entry is sent.

Our service checks for crisis language before any model call. An entry that triggers that check is not sent to the model. An ordinary request is sent to OpenRouter for one short AI-generated reflection. We design our service not to persist or log the page text or the reply; OpenRouter's handling is governed by its privacy policy. A reflection is not medical or mental-health care, advice, diagnosis or a conversation with your Mipkin.

You can turn reflections off at any time in Settings. The choice is read before each send, so turning it off stops future requests. Everything already written stays on your phone.

Visiting

When you turn on visiting, we publish only optional growth and wearable choices so someone holding the code you share can see a generic Mipkin visitor in their Nook. We never publish which Mipkin you chose, the name you gave them, your mood, bond, energy, warmth, check-in, journal, Nook, outings, keepsakes or last-seen time.

A visiting record contains those two optional appearance fields, a hash of a secret write key, timestamps, and a small queue of fixed gestures. It expires after 90 days without an update. Visiting has no public feed, searchable list or chat. Turning visiting off asks the service to revoke your code; if the phone cannot reach the service, the app tells you it is still on instead of claiming a code is gone when it is not.

Private friends

Private friends are optional and require an account. You create a blank, expiring invitation and the other person has to accept before a connection exists. Our service stores only two opaque account IDs, the connection state, a time, and—until read—a small queue of one of three fixed gestures. An active pair can also choose one reviewed shared-rhythm label, such as “Take a breather”; there is no custom goal text, completion record, schedule, streak, reminder, history or score. It does not store names, profiles, selected Mipkins, journal pages, reflections, aliases or free-form social text. There is no directory or discovery feature.

Either connected person can propose, accept, decline or remove that one shared rhythm, and it never sends a notification or tracks whether either person does it. You can remove or block a friend in Settings. Removing deletes the connection and shared rhythm for both people. Blocking also prevents a future invitation between those two accounts. Deleting your account removes your pending invitations, connections, current shared rhythm, blocks and queued gestures.

Optional sign-in

Sign-in is not required to use Mipkin. If it is available in your build, Apple or Google gives us a short-lived identity token so our service can verify it against that provider. We do not store that token, your name, avatar or provider profile. Our service stores an opaque Mipkin account ID, the provider name, a hashed provider subject, a creation time and, only if you link it, your shareable hearth code. It does not store your Mipkin, chosen Mipkin name, journal, reflections, check-ins, Nook, purchases, device identifier or secret hearth key.

A short-lived account session is held in the app's memory after you sign in; it is not saved to device storage. It can recover and manage a linked hearth code after a reinstall. You can delete the account in the app after reconnecting it. Deletion withdraws the linked hearth code, removes the account record and clears the account-backed friends and backup described here; deleting the account does not delete local app data.

Email sign-in uses Firebase Authentication to send a passwordless sign-in link. Firebase receives and holds the email address and a Firebase account identifier for that optional sign-in. Mipkin does not receive your address to send the link. When you open the link in the app, Firebase provides a signed identity token; our service verifies it and stores only an opaque Mipkin account ID, provider name and a hash of Firebase’s account identifier. The link and token are held only in memory in the app.

Deleting a Firebase email account in Mipkin also asks Firebase Authentication to remove that optional Firebase identity. If you cannot use the app, contact us through the account-deletion process below so we can verify ownership before acting.

Optional account backup

Account backup is off until you explicitly turn it on and press Back up now. It copies Mipkin progress, Nook choices, inventory and settings to the account so you can choose to restore them on another device. It does not copy journal pages, reflection text or replies, worry-box entries, onboarding acquaintance answers, local friend aliases, visiting codes, secret keys, provider tokens or payment records.

Turning account backup off stops new copies. To delete the existing account copy and account-backed friendship records, delete the optional account from Settings or use the account-deletion process below.

Optional care cues

Care cues are off until you turn them on in Settings and allow notifications on your phone. A signed-in account can then use Firebase Cloud Messaging and our Google Cloud service to deliver at most one practical, complete cue per local day. The app sends and stores an FCM delivery token, device platform, consent time, primary-device status, your selected care-cue categories, frequency, timezone, quiet hours, visual-art choice, temporary pause, category-level feedback such as “later” or “less like this,” and the category of a care action you choose to mark complete. It does not send the action text or an action ID. Short delivery receipts prevent duplicates, apply non-response backoff, and expire. Before a queued cue is sent, our worker checks the current consent, selected category, pause, quiet hours, safe time window and local day again.

Care cues do not use your journal, reflection text, chosen Mipkin, Mipkin name, social activity, location, contacts, steps, sleep, calendar, health data, or notification opens. We do not use a lack of app activity as a reason to notify you. Lock-screen art, if you separately turn it on, is one public Mipkin illustration and never shows your goal, check-in, or chosen Mipkin.

You can turn care cues off, pause them for a week, choose categories and frequency, remove lock-screen art, or reset category learning in Settings. Turning care cues off removes the device registration from our service. Deleting your optional account removes its care-cue preferences, devices, category learning, schedule and delivery receipts.

Crash diagnostics and limited analytics

Firebase Crashlytics and Firebase Analytics are always on in production. Crashlytics receives native crash diagnostics and sanitized JavaScript error type, redacted message, and shortened file-and-line frames. Firebase Analytics receives only a small fixed set of events for onboarding, a revealed Mipkin, opening and completing an authored daily moment, an art load or fallback, purchase state, and startup, storage, network or rendering reliability.

These reports never include your writing, journal, worry-box content, check-in answer, chosen Mipkin or name, social data, Apple Health data, account ID, product ID, price, advertising identifier, or advertising signals. Automatic screen reporting is disabled. Mipkin does not include advertising or an advertising SDK. Firebase Analytics is not used for advertising, has no Google Ads linkage, and advertising-related consent signals are denied.

Firebase creates an anonymous app-instance identifier and may attach coarse app and device information such as app version, platform and device model. Choosing Delete everything resets the Analytics app-instance on that device. Reports already uploaded contribute to anonymous aggregate reporting; because Mipkin does not attach your account or identity, we cannot find or delete an individual anonymous aggregate after upload.

Crisis language

Before any journal page reaches a language model, our service checks it for words that suggest somebody is in danger. If it finds them, the page is not sent to the model at all, and the app shows you a route to people who can help instead. That check happens on our service, in memory, and is not recorded.

Payments

Subscriptions and one-off purchases are handled by Apple's App Store or Google Play. We do not receive your card number or billing address. When purchases are enabled, RevenueCat processes the store purchase record and entitlement status using its own anonymous app user ID, so the app can tell whether an item is available. We do not send RevenueCat your Mipkin, chosen Mipkin name, journal, check-ins, Nook, visiting data, or optional account record, and we do not link its anonymous ID to that account.

Notifications

The app can schedule one gentle local reminder on your own phone. That reminder is separate from optional account-backed care cues. Neither names your Mipkin or shows your check-in on a lock screen. Care cues use Firebase Cloud Messaging only after the separate in-app and phone-permission choices described above.

Age and children

Mipkin is a general-audience service for adults and older teens. You must be at least 13 to use it, and it is not directed to children under 13. We do not knowingly collect personal information through Mipkin from a child under 13. If you are a parent or guardian and believe a child under 13 used an online feature, contact us so we can investigate and delete the information.

In the EEA and other places where the age for a child to consent to online processing may be between 13 and 16, a parent or guardian must provide parental permission when local law requires it before the child uses a consent-based online feature. Mipkin is not marketed as a children's product and does not use child-focused advertising.

Legal bases

Where privacy law requires a legal basis, we rely on consent for reflections, visiting, care cues and other optional features you deliberately turn on; performance of our contract to provide an account, backup, private-friend, purchase-entitlement and support functions you request; our legitimate interests in keeping Mipkin secure, reliable and understandable through tightly limited diagnostics and product measurement; and compliance with legal obligations when we must keep or disclose a record. We balance those interests against your privacy, do not use these reports for advertising, and do not attach them to a Mipkin account.

Service providers and recipients

We use service providers only where needed to operate the feature: Google and Firebase for hosting, authentication, delivery, crash reporting and limited analytics; OpenRouter for a reflection you request; RevenueCat and Apple or Google for purchase entitlements; and Apple or Google for optional sign-in. They process information under their own terms and applicable data-processing commitments. We may also disclose information when required by law, to protect people or the service, or as part of a corporate transaction subject to appropriate protections. We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising.

Retention

Local content remains on your device until you delete it or the app. Visiting records expire after 90 days without an update; blank invitations expire after 48 hours; and short care-cue delivery receipts expire after 30 days. Optional account, backup, friendship and care-cue records remain until you delete the account or the record is no longer needed to provide the feature, subject to limited legal, security and backup retention. Mipkin is designed not to persist or log reflection text or the generated reply on its service. Firebase, OpenRouter, RevenueCat, Apple and Google retain information under their own policies and configured service periods. We choose retention according to the feature's purpose, the amount and sensitivity of the information, security needs, and legal requirements.

International transfers

Eros Media LLC and some providers process information in the United States and other countries that may have different privacy laws from your home country. Where required for a transfer from the EEA, UK or Switzerland, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses with the applicable UK addendum, or another legally recognized safeguard used by the relevant provider. Contact us if you would like information about the safeguard that applies to your information.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, obtain portability of, or object to processing of your personal information. You may withdraw consent at any time without affecting earlier lawful processing. You may also appeal a decision where applicable and complain to your local data protection authority. We may need to verify your request, and legal exceptions can apply.

These rights include the GDPR and UK GDPR rights described above for people in the EEA and UK. Depending on local law, people in Switzerland, Canada, Brazil, Australia, New Zealand and US states with comprehensive privacy laws may also request access, correction or deletion, receive information about processing, withdraw consent, object or appeal. You may complain to the authority where you live, including an EEA or UK data protection authority, Brazil's ANPD, Canada's privacy commissioners, Australia's OAIC, or New Zealand's Privacy Commissioner. Mipkin does not sell personal information or process it for targeted advertising, so there is no sale or targeted-advertising opt-out to exercise.

You can exercise many of these choices directly in the app:

  • Access and portability — export your full local state from the app at any time.
  • Erasure — delete all local data from the app. The app also attempts to withdraw a visiting record before discarding its local key and resets the local Firebase Analytics app-instance.
  • Account deletion — if you enabled optional sign-in, delete that separate account from Settings after signing in again. Our account-deletion page explains the same process if you cannot open the app.
  • Withdrawal of consent — turn reflections, visiting, care cues or account backup off in Settings. Turning backup off stops new copies; delete the optional account to erase the existing account copy.

To exercise another right, email support@mipkin.app. We will respond within the period required where you live.

Automated decisions

Mipkin makes no solely automated decision that produces a legal or similarly significant effect about you. Reflections are brief wellbeing content, not eligibility, employment, credit, insurance, housing, medical or other consequential decisions.

Changes

If this policy changes in a way that affects what leaves your device, we will update this page and the in-app disclosure before release. This page's date is the record of when it last changed.

Contact

Questions about this policy: support@mipkin.app.