Privacy Policy
Last updated: September 23, 2026Mimko ("we", "us", "our") is a family coordination app designed to help families organize their daily lives, operated by Stooj SRL. This Privacy Policy explains what personal data we collect, how we use it, and your rights under applicable data protection laws including the EU General Data Protection Regulation (GDPR).
1. Data Controller
Stooj SRLVia Alfredo Panzini 71, 09045 Quartu Sant'Elena (CA), Italy
P.IVA: 03932870920
REA: CA - 350185
PEC: stooj.srl@legalmail.it
Email: privacy@mimko.app
We have not appointed a Data Protection Officer (DPO) as we do not currently meet the criteria under GDPR Art. 37. For all privacy-related inquiries, please contact us at privacy@mimko.app.
2. Data We Collect
2.1 Account Data
- Email address — used for authentication (magic link sign-in)
- Full name — displayed to family members
- Profile photo — optional, displayed to family members
- Language preference — to show the app in your language (Italian, English, French)
2.2 Family Data
- Family name — chosen by the family creator
- Family membership — who belongs to which family, roles (owner, co-admin, member)
- Invitation codes — used to invite new members (expire after 7 days)
2.3 Children's and Pet Profiles
- Name, date of birth, sex, photo — for kids and pets in the family
- This data is entered by parents/guardians and is only visible to family members
2.4 Health Information (Special Category Data)
- Medical conditions, allergies, medications, vaccinations, doctor name and phone, blood type, height, weight, and notes
- This data is entered voluntarily by users for their own family's convenience. We do not access, process, analyze, or use this data in any way — we only store it
- Health data is encrypted on your device using AES-256-CBC before being stored on our servers. Access is restricted to members of your family, and we do not access this data
- Access to health data in the app is limited to members of your family
- You may choose not to use this feature at all — no health data is required to use Mimko
- Health profiles exist only for children and pets, not for adult users
- Before entering health data for the first time, the user will be shown an informational consent prompt explaining that the data will be encrypted and stored, and that Stooj SRL does not access it. This prompt is separate from accepting the Terms of Service
- Health data is entered and managed by admins (Owner and Co-admins) on behalf of children/pets. Any admin can add, edit, or delete health data entries, reflecting that both parents may share responsibility for managing their children's information
- Only the Owner can delete the entire family account and all associated health data
- Documents attached to health profiles are stored securely but are not encrypted on your device
2.5 Calendar and Events
- Event details — title, date, time, location, notes, assigned family members
- Saved places — addresses and coordinates of frequently used locations
- Event reminders — scheduled locally on your device
2.6 Location Data
- Saved place coordinates — stored to display static map previews and enable geofencing notifications
- Geofencing — if you enable location-based notifications and grant "Always Allow" location permission, your device uses OS-level geofencing to notify you about relevant lists when you arrive at a saved place. Your location is processed on your device by the operating system — we do not track, store, or receive your real-time location
- Static map previews — when you save a place, coordinates are sent to Google Maps Static API to generate a map image. Google receives the coordinates for this purpose only. See Google's Privacy Policy
- Geofencing and location-based notifications are entirely optional. You can disable them in Settings or deny location permission at any time
2.7 Lists and Tasks
- List items — text, due dates, assignments, completion status
- List visibility settings — who can see each list
2.8 Chat Messages
- Message content — text messages and voice messages (up to 2 minutes) between family members
- Messages are stored on our servers and visible to all family members
- Voice messages are stored as audio files and count toward your storage limit
- Chat messages and voice messages are automatically deleted after the retention period (30 days for free tier, 12 months for paid tier)
2.9 Documents and Kids Growth Photos
- Uploaded files — PDF, images, Word documents, text files (max 10 MB each)
- Document metadata — file name, folder category (medical, school, legal, insurance, or custom folders created by you)
- Kids Growth photos — photos uploaded to the Kids Growth folder are automatically compressed (max 1024×1024 pixels) to save storage. A notice is shown on first upload. These photos are intended for milestone tracking by the family
- Documents and photos are stored securely but are not encrypted on your device
- Documents are retained until you delete them or delete your account
2.10 Activity Log
- Actions performed — event creation, task completion, member changes
- Used to show family members what happened recently
- Retained for 48 hours in the app
2.11 Subscription and Payments
- Payments are processed entirely by Apple (App Store) or Google (Play Store)
- We do NOT collect, store, or have access to your payment information (credit card, billing address, etc.)
- We use RevenueCat to manage subscriptions, validate purchase receipts, and determine your entitlement status across platforms. RevenueCat receives a pseudonymous user ID (not your name or email), purchase tokens, product identifiers, and standard device telemetry (device model, OS version, app version, locale, country, IP address). RevenueCat acts as a data processor under a DPA with Standard Contractual Clauses (SCCs) for data transfers to the United States
2.12 Technical Data
- Push notification token — to send you notifications via Expo Push service
- Device information — platform (iOS/Android), app version
- Notification preferences — which notification types are enabled
2.13 On-Device Storage
- Mimko stores a local copy of your data on your device using a SQLite database to enable offline functionality
- Authentication tokens are stored in your device's secure storage (iOS Keychain / Android Keystore)
- This data remains on your device and is deleted when you log out or uninstall the app
2.14 Email Preferences and Consent Log
- Onboarding email preference — whether you wish to receive educational tips about using Mimko during your first 4 weeks. Enabled by default; you can opt out at any time in Settings > Notifications & Email or via the unsubscribe link in any onboarding email
- Marketing email consent — whether you consent to receive product news, feature announcements, and upgrade offers. Disabled by default; you may opt in during registration or later in Settings > Notifications & Email. You can withdraw consent at any time via the unsubscribe link in any marketing email or in Settings
- Consent log — each time you change an email preference, we record a timestamped log entry including: the preference changed, your IP address, user-agent string, and the version of our Privacy Policy in effect. This data is collected to demonstrate valid consent as required by GDPR Art. 7(1) and is deleted together with your account
3. How We Use Your Data
We use your data exclusively to provide the Mimko app service:
| Purpose | Legal Basis (GDPR) |
|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
|---|---|
| Family coordination features (calendar, lists, chat) | Contract performance (Art. 6(1)(b)) |
| Health data storage for children/pets (entered by parents/admins, encrypted, not accessed by us) | Parental consent on behalf of the child (Art. 8 + Art. 9(2)(a)), with informational prompt before first use |
| Push notifications | Legitimate interest (Art. 6(1)(f)) |
| Children's profile management | Parental consent (Art. 8) |
| Operational metrics (API performance, error rates, storage usage) | Legitimate interest (Art. 6(1)(f)) |
| Onboarding emails (educational tips during first 4 weeks) | Legitimate interest (Art. 6(1)(f)) |
| Marketing emails (product news, feature announcements, upgrade offers) | Consent (Art. 6(1)(a)) |
- Sell your data to third parties or run third-party advertising
- Use your data for behavioral advertising or share it with ad networks
- Profile you for marketing segmentation — all marketing emails are the same for all recipients who have consented
- Use third-party analytics or tracking services. We may collect limited self-hosted operational metrics (API latency, error rates, storage usage) via Supabase Analytics to maintain and improve the Service. If enabled, this data is technical only — no behavioral tracking or user profiling takes place, and you can opt out in Settings
- Share your data with anyone outside your family
4. Data Sharing and Third Parties
We use the following service providers to operate Mimko:
| Service | Purpose | Data Shared | Location |
|---|
| Supabase | Database, authentication, file storage | All app data | EU (Ireland) |
|---|---|---|---|
| Expo | Push notifications, app updates | Push tokens, notification content | United States |
| Apple | Sign-in (iOS), app distribution | Authentication tokens | United States |
| Sign-in (Android), app distribution | Authentication tokens | United States | |
| Apple App Store | Subscription payments (iOS) | Subscription status only | United States |
| Google Play Store | Subscription payments (Android) | Subscription status only | United States |
| Google Maps Static API | Map preview images for saved places | Place coordinates | United States |
| RevenueCat | Subscription management, receipt validation, entitlement state | Pseudonymous user ID (Supabase UUID), purchase receipts/tokens, product IDs, device telemetry (device model, OS version, app version, locale, country, IP address) | United States |
We have Data Processing Agreements (DPA) in place with our key processors where required.
We never sell your personal data and we do not share it for advertising. Beyond the processors listed above, we disclose personal data only where we are legally required to do so (for example, in response to a binding order from a competent authority or court), or where necessary to establish, exercise or defend legal claims. Where the law permits, we will inform you of such a request.
5. Data Security
- Health data is encrypted with AES-256-CBC before leaving your device
- Authentication tokens are stored in your device's secure storage (Keychain/Keystore)
- Database access is controlled by Row-Level Security — users can only access their own family's data
- All communications use HTTPS/TLS encryption in transit
- Biometric unlock (Face ID/Touch ID) is optional and processed entirely on your device by the operating system. Biometric data is never transmitted to our servers — we only receive a yes/no authentication result from your device's secure enclave
6. Data Retention
| Data Type | Retention Period |
|---|
| Account and family data | Until you delete your account |
|---|---|
| Chat messages | 30 days (free tier), 12 months (paid tier), then automatically deleted |
| Voice messages | Same as chat messages (deleted together) |
| Documents | Until you delete them or delete your account |
| Activity log | 48 hours in-app; 90 days on server for admin audit purposes |
| Deleted accounts | 30-day recovery period, then permanently deleted |
| Invitation codes | 7 days after creation |
| Push tokens | Until logout or account deletion |
| Email consent log | Deleted together with the account |
7. Automated Decision-Making
Mimko does not use automated decision-making or profiling as defined by GDPR Art. 22. No decisions with legal or similarly significant effects are made about you based on automated processing.
8. Legitimate Interest — Push Notifications
We rely on legitimate interest (Art. 6(1)(f)) as the legal basis for sending push notifications. Our legitimate interest is ensuring that family members receive timely updates about shared events, tasks, and messages — which is the core purpose of the Service. We have balanced this interest against your rights and determined that the impact is minimal because:
- You can disable any or all notification categories in Settings at any time
- Notifications contain only information from your own family group
- We do not use notifications for marketing or advertising
- New Parent Mode provides a gentler notification experience
You may object to this processing at any time by disabling push notifications in your device settings or within the app.
8.2 Legitimate Interest — Onboarding Emails
We rely on legitimate interest (Art. 6(1)(f)) to send a limited series of educational emails during your first 4 weeks after account creation. These emails help you get the most out of Mimko by explaining key features (e.g., shared calendar, lists, health profiles).
We have balanced this interest against your rights and determined that the impact is minimal because:
- Emails are time-bounded — they stop automatically after 4 weeks, regardless of your preference setting
- They are purely educational — no marketing, upselling, or product promotions
- All recipients receive the same content — no segmentation or profiling
- You can opt out at any time via the unsubscribe link in any onboarding email or in Settings > Notifications & Email
After the 4-week period, any further emails require your explicit marketing consent.
9. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Garante per la protezione dei dati personali within 72 hours of becoming aware of the breach, as required by GDPR Art. 33
- Notify affected users without undue delay if the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34), via email and/or in-app notification
- Document the breach, its effects, and the remedial actions taken
Health data is encrypted with AES-256-CBC before storage, which provides an additional layer of protection in the event of a breach. We assess the severity of any breach and notify affected users and the competent supervisory authority as required under Articles 33 and 34 GDPR.
10. Your Rights (GDPR)
You have the right to:
- Access your data — family owners can use the "Export Data" feature in Settings; individual members can request their personal data by contacting privacy@mimko.app
- Delete your data — individual members can request deletion of their personal data by contacting privacy@mimko.app; family owners can delete the entire family account in Settings (30-day recovery period)
- Rectify your data — edit your profile, events, lists, and health data directly in the app
- Restrict processing — contact us at privacy@mimko.app
- Data portability — the Export Data feature (available to family owners) provides data in JSON format; individual members can request their personal data in JSON via privacy@mimko.app
- Object to processing — contact us at privacy@mimko.app
- Withdraw consent — you can disable specific features or delete your account at any time. Specifically:
- Onboarding emails: unsubscribe via the link in any onboarding email, or toggle off in Settings > Notifications & Email
- Lodge a complaint — with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it, protocollo@pec.gpdp.it
We will respond to data subject requests within 30 days, extendable by 60 days for complex requests (with prior notice).
11. Children's Privacy and Minimum Age
You must be at least 14 years old to create a Mimko account, in accordance with Italian law (D.Lgs. 101/2018, Art. 2-quinquies). Users between 14 and 18 must have their parent's or guardian's awareness and consent to use the Service.
Mimko is designed for family use. Children's profiles (for those under 14) are created and managed by parents or guardians. We do not knowingly collect data directly from children under 14. All children's data (profiles, health information) requires parental action to create, view, or modify.
If we become aware that we have collected personal data from a child under 14 without parental consent, we will take steps to delete that data promptly.
12. International Data Transfers
Your primary data (account, family, calendar, lists, chat, documents, health profiles) is stored in the EU (Ireland) by Supabase. However, some data is transferred to the United States for the following services:
| Service | Data Transferred | Transfer Mechanism |
|---|
| Expo (push notifications) | Push tokens, notification content | EU-US Data Privacy Framework (DPF) |
|---|---|---|
| Google (authentication, Play Store) | Authentication tokens, subscription status | EU-US Data Privacy Framework (DPF) |
| Apple (authentication, App Store) | Authentication tokens, subscription status | Standard Contractual Clauses (SCCs) |
| RevenueCat (subscription management) | Pseudonymous user ID, purchase tokens, product IDs, device telemetry | Standard Contractual Clauses (SCCs) |
The EU-US Data Privacy Framework was confirmed valid by the EU General Court in September 2025. Where we rely on SCCs (Apple, RevenueCat), we have assessed the legal framework in the US and determined that, combined with the technical measures described in Section 5 (including encryption of health data), the transfer provides adequate protection for your personal data.
You can request a copy of the relevant transfer safeguards by contacting privacy@mimko.app.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app. The "Last updated" date at the top indicates the most recent revision.
14. Contact Us
For any privacy-related questions or requests:
Stooj SRLVia Alfredo Panzini 71, 09045 Quartu Sant'Elena (CA), Italy
Email: privacy@mimko.app
PEC: stooj.srl@legalmail.it