Mimko ← Back to Mimko

Privacy Policy

Last updated: September 23, 2026

Mimko ("we", "us", "our") is a family coordination app designed to help families organize their daily lives, operated by Stooj SRL. This Privacy Policy explains what personal data we collect, how we use it, and your rights under applicable data protection laws including the EU General Data Protection Regulation (GDPR).

1. Data Controller

Stooj SRL

Via Alfredo Panzini 71, 09045 Quartu Sant'Elena (CA), Italy

P.IVA: 03932870920

REA: CA - 350185

PEC: stooj.srl@legalmail.it

Email: privacy@mimko.app

We have not appointed a Data Protection Officer (DPO) as we do not currently meet the criteria under GDPR Art. 37. For all privacy-related inquiries, please contact us at privacy@mimko.app.

2. Data We Collect

2.1 Account Data

2.2 Family Data

2.3 Children's and Pet Profiles

2.4 Health Information (Special Category Data)

2.5 Calendar and Events

2.6 Location Data

2.7 Lists and Tasks

2.8 Chat Messages

2.9 Documents and Kids Growth Photos

2.10 Activity Log

2.11 Subscription and Payments

2.12 Technical Data

2.13 On-Device Storage

2.14 Email Preferences and Consent Log

3. How We Use Your Data

We use your data exclusively to provide the Mimko app service:

PurposeLegal Basis (GDPR)
Account creation and authenticationContract performance (Art. 6(1)(b))
Family coordination features (calendar, lists, chat)Contract performance (Art. 6(1)(b))
Health data storage for children/pets (entered by parents/admins, encrypted, not accessed by us)Parental consent on behalf of the child (Art. 8 + Art. 9(2)(a)), with informational prompt before first use
Push notificationsLegitimate interest (Art. 6(1)(f))
Children's profile managementParental consent (Art. 8)
Operational metrics (API performance, error rates, storage usage)Legitimate interest (Art. 6(1)(f))
Onboarding emails (educational tips during first 4 weeks)Legitimate interest (Art. 6(1)(f))
Marketing emails (product news, feature announcements, upgrade offers)Consent (Art. 6(1)(a))
We do NOT:

4. Data Sharing and Third Parties

We use the following service providers to operate Mimko:

ServicePurposeData SharedLocation
SupabaseDatabase, authentication, file storageAll app dataEU (Ireland)
ExpoPush notifications, app updatesPush tokens, notification contentUnited States
AppleSign-in (iOS), app distributionAuthentication tokensUnited States
GoogleSign-in (Android), app distributionAuthentication tokensUnited States
Apple App StoreSubscription payments (iOS)Subscription status onlyUnited States
Google Play StoreSubscription payments (Android)Subscription status onlyUnited States
Google Maps Static APIMap preview images for saved placesPlace coordinatesUnited States
RevenueCatSubscription management, receipt validation, entitlement statePseudonymous user ID (Supabase UUID), purchase receipts/tokens, product IDs, device telemetry (device model, OS version, app version, locale, country, IP address)United States

We have Data Processing Agreements (DPA) in place with our key processors where required.

We never sell your personal data and we do not share it for advertising. Beyond the processors listed above, we disclose personal data only where we are legally required to do so (for example, in response to a binding order from a competent authority or court), or where necessary to establish, exercise or defend legal claims. Where the law permits, we will inform you of such a request.

5. Data Security

6. Data Retention

Data TypeRetention Period
Account and family dataUntil you delete your account
Chat messages30 days (free tier), 12 months (paid tier), then automatically deleted
Voice messagesSame as chat messages (deleted together)
DocumentsUntil you delete them or delete your account
Activity log48 hours in-app; 90 days on server for admin audit purposes
Deleted accounts30-day recovery period, then permanently deleted
Invitation codes7 days after creation
Push tokensUntil logout or account deletion
Email consent logDeleted together with the account

7. Automated Decision-Making

Mimko does not use automated decision-making or profiling as defined by GDPR Art. 22. No decisions with legal or similarly significant effects are made about you based on automated processing.

8. Legitimate Interest — Push Notifications

We rely on legitimate interest (Art. 6(1)(f)) as the legal basis for sending push notifications. Our legitimate interest is ensuring that family members receive timely updates about shared events, tasks, and messages — which is the core purpose of the Service. We have balanced this interest against your rights and determined that the impact is minimal because:

You may object to this processing at any time by disabling push notifications in your device settings or within the app.

8.2 Legitimate Interest — Onboarding Emails

We rely on legitimate interest (Art. 6(1)(f)) to send a limited series of educational emails during your first 4 weeks after account creation. These emails help you get the most out of Mimko by explaining key features (e.g., shared calendar, lists, health profiles).

We have balanced this interest against your rights and determined that the impact is minimal because:

After the 4-week period, any further emails require your explicit marketing consent.

9. Data Breach Notification

In the event of a personal data breach, we will:

Health data is encrypted with AES-256-CBC before storage, which provides an additional layer of protection in the event of a breach. We assess the severity of any breach and notify affected users and the competent supervisory authority as required under Articles 33 and 34 GDPR.

10. Your Rights (GDPR)

You have the right to:

- Marketing emails: unsubscribe via the link in any marketing email, or toggle off in Settings > Notifications & Email

- Onboarding emails: unsubscribe via the link in any onboarding email, or toggle off in Settings > Notifications & Email

We will respond to data subject requests within 30 days, extendable by 60 days for complex requests (with prior notice).

11. Children's Privacy and Minimum Age

You must be at least 14 years old to create a Mimko account, in accordance with Italian law (D.Lgs. 101/2018, Art. 2-quinquies). Users between 14 and 18 must have their parent's or guardian's awareness and consent to use the Service.

Mimko is designed for family use. Children's profiles (for those under 14) are created and managed by parents or guardians. We do not knowingly collect data directly from children under 14. All children's data (profiles, health information) requires parental action to create, view, or modify.

If we become aware that we have collected personal data from a child under 14 without parental consent, we will take steps to delete that data promptly.

12. International Data Transfers

Your primary data (account, family, calendar, lists, chat, documents, health profiles) is stored in the EU (Ireland) by Supabase. However, some data is transferred to the United States for the following services:

ServiceData TransferredTransfer Mechanism
Expo (push notifications)Push tokens, notification contentEU-US Data Privacy Framework (DPF)
Google (authentication, Play Store)Authentication tokens, subscription statusEU-US Data Privacy Framework (DPF)
Apple (authentication, App Store)Authentication tokens, subscription statusStandard Contractual Clauses (SCCs)
RevenueCat (subscription management)Pseudonymous user ID, purchase tokens, product IDs, device telemetryStandard Contractual Clauses (SCCs)

The EU-US Data Privacy Framework was confirmed valid by the EU General Court in September 2025. Where we rely on SCCs (Apple, RevenueCat), we have assessed the legal framework in the US and determined that, combined with the technical measures described in Section 5 (including encryption of health data), the transfer provides adequate protection for your personal data.

You can request a copy of the relevant transfer safeguards by contacting privacy@mimko.app.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app. The "Last updated" date at the top indicates the most recent revision.

14. Contact Us

For any privacy-related questions or requests:

Stooj SRL

Via Alfredo Panzini 71, 09045 Quartu Sant'Elena (CA), Italy

Email: privacy@mimko.app

PEC: stooj.srl@legalmail.it