Privacy Policy
MiMi Privacy Policy
This Privacy Policy explains how MiMi collects, uses, discloses, retains, and protects personal information, and the choices and rights available to you.
Review what we collectYou decide
You choose every input.
Uploads, inbox access, Chrome capture, data requests, and public sharing each begin with a separate action or permission you control.
We limit
Your data builds your twin.
MiMi does not sell personal information, use it for targeted advertising, or train a general-purpose AI model on it. It trains your personal MiMi twin. Your twin's computing costs are covered either by your Private plan or by research sponsors, whose studies your Sponsored twin takes part in. Your personal data is never given to study clients without your explicit consent.
You can leave
Your controls are real.
Export what MiMi holds, delete a source, disconnect a provider, revoke a session, or delete your account from inside the product.
1. Who we are
Controller and scope.
MiMi (the "Service"), available at mimitwin.app and through the MiMi iPhone, iPad, and Mac apps and the MiMi Chrome extension, is operated by Social Intelligence Labs Inc., a Delaware corporation ("Social Intelligence Labs," "we," "us," or "our"). For the purposes of the EU and UK General Data Protection Regulation and similar laws, Social Intelligence Labs is the controller of the personal information described in this Policy.
This Policy covers the public website, the signed-in web application, the Apple apps, the Chrome extension, customer support, and related communications. It does not govern third-party services you visit, connect, or ask MiMi to help you contact; those services are governed by their own privacy policies. This Policy should be read together with our Terms of Service.
MiMi is an independent product. It is not affiliated with, endorsed by, or sponsored by Google, Apple, Microsoft, or any company whose data you ask MiMi to help you obtain. Third-party names are used only to describe the services you choose to connect.
2. Definitions
Terms used in this Policy.
- "Personal information" or "personal data" means information that identifies, relates to, or could reasonably be linked with an identified or identifiable natural person, as defined by applicable law, including GDPR Art. 4(1) and Cal. Civ. Code §1798.140(v).
- "Process" means any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
- "Source" means a file, archive, connected account, or other input you choose to provide to MiMi.
- "Service provider" or "subprocessor" means a third party that processes personal information on our behalf under written purpose, confidentiality, and security obligations.
- "You" means an individual who uses the Service, including a guest who uses it without an account.
3. Information we collect
What we collect depends on what you ask MiMi to do.
For each category below we describe the information, its source, why we process it, and the legal basis we rely on where the GDPR or similar laws apply. Retention is described in Section 10.
Account and contact information
Information: phone number, date of birth, login and account-recovery records, optional verified email address, voice setting, notification preferences, device or session labels. Source: you. Purpose: create and secure your account, verify age eligibility, sign you in, and communicate with you about the Service. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)); legal obligation for age eligibility (Art. 6(1)(c)). We use date of birth only for age eligibility and will update this Policy before using it for any other purpose.
Files and sources you provide
Information: uploaded archives, documents, and structured data; facts extracted from them; their provenance, parser version, and processing status. Source: you. Purpose: scan, parse, classify, and summarize the sources you choose so MiMi can produce insights for you and train your MiMi twin (see Section 6). Legal basis: performance of contract (Art. 6(1)(b)) and your consent (Art. 6(1)(a)). Upload only information you are permitted to provide. Where our product rules require it, MiMi removes or generalizes identifying details about other people during summarization.
Your MiMi profile and activity
Information: derived traits and insight cards, copied source receipts, questions and answers, calls, re-scores, comparisons, blends, data requests, taste-set choices, shares, and the ledger events that record what happened. Source: generated by the Service from your sources and actions. Purpose: deliver the features you use and let you inspect how each result was produced. Legal basis: performance of contract (Art. 6(1)(b)).
Optional connected sources
Information: the limited Gmail and Chrome information described in Section 4. Source: the provider you connect, with your permission. Purpose: the specific feature you enable. Legal basis: your consent (Art. 6(1)(a)), which you may withdraw at any time. If you do not enable a feature, MiMi does not receive its data.
Guest and shared activity
Information: anonymous session identifiers, age attestation, taste-set answers, call picks, comparison or blend contributions, link state, and withdrawal or revocation events. Source: you, when you use a guest or shared flow. Purpose: operate the shared experience you joined. Legal basis: performance of contract (Art. 6(1)(b)). Viewing a public share does not require an account.
Technical, security, and diagnostic records
Information: IP address and signals derived from it, timestamps, request identifiers, device and browser information, error and performance records, rate-limit events, and abuse reports. Source: collected automatically when you use the Service. Purpose: secure the Service, prevent fraud and abuse, troubleshoot failures, and monitor reliability. Legal basis: our legitimate interest in operating and protecting the Service and its users (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)).
Product measurement
Information: event names, identifiers, and timestamps describing how features are used. Product analytics use identifiers and event names, not card text, message content, uploaded content, or captured page text. Purpose: understand aggregate product performance and improve MiMi. Legal basis: legitimate interest (Art. 6(1)(f)); consent where local law requires it.
Support communications
Information: the content of messages you send to support or privacy contacts and our replies. Purpose: answer your request and keep a record of how it was resolved. Legal basis: legitimate interest in providing support (Art. 6(1)(f)); legal obligation for rights requests (Art. 6(1)(c)).
We do not purchase personal information about you from data brokers, and we do not enrich your account with third-party marketing data. We do not intentionally collect special-category data under GDPR Art. 9; if your own sources contain such information, MiMi filters sensitive categories before assembling insights and processes them only to provide the feature you requested.
4. Connected Gmail and Chrome
A permission is not a blank check.
Gmail discovery
If you connect a Gmail account, MiMi uses sender addresses or domains and received timestamps to identify companies that may hold data about you and to recognize their replies to your requests. Discovery does not retrieve message bodies, subject lines, recipients, attachments, drafts, or sent mail. MiMi stores the provider account identity, an encrypted private email label, encrypted OAuth tokens and cursors, keyed message identifiers, candidate domains, counts, and last-seen dates. Gmail metadata discovery is active. Microsoft mailbox discovery is not active.
Finding returned data exports
Separately, if you enable export reading for a specific company request, MiMi asks for Gmail read-only permission. Google grants that permission for the whole mailbox; MiMi limits its own searches to that request's company and time window. For matching messages it reads the subject and content to locate returned attachments and download links, and stores encrypted file locations and limited review metadata. A found file is not imported until you review and approve it. MiMi does not request permission to send, modify, or delete your Gmail messages for these features.
Sending data requests
Only eligible Gmail email requests whose exact contents you reviewed and that remain unchanged may be delivered. Official forms and non-Gmail routes remain Guided for you to complete. Every delivery also requires a separate mandate for that company. MiMi stops and hands the request back to you for passwords, CAPTCHA, multi-factor authentication, identity documents, signatures, payments, legal attestations, or any unexpected step.
Disconnecting Gmail
Disconnecting removes MiMi's stored credentials and private label for that account and stops its future scans and pending imports. To also remove Google-side access, visit your Google Account connections. Files already imported remain separate sources until you delete them or your account.
Chrome viewer
The viewer runs only when you press the extension. It sends the page's canonical HTTPS address to MiMi and displays an aggregate result. It does not send page text or review text.
Chrome capture
Capture is off by default. When enabled, it records hostname, integer dwell seconds, a coarse on-device category, observation time, and a retry identifier. It does not record URL paths, titles, page text, form values, passwords, or cookies. You can pause it at any time, and turning it off removes the optional tab permission.
Google API Services and Chrome Web Store Limited Use disclosure
MiMi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. MiMi's use of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, we use Google and Chrome user data only to provide and improve the user-facing features described above; we do not transfer it except as necessary to provide those features, for security purposes, to comply with law, or as part of a merger or acquisition with notice to you; we do not use or transfer it for advertising, to determine creditworthiness or for lending purposes, or to train a general-purpose AI or machine-learning model; and no human reads it unless you give us affirmative permission for specific messages, it is necessary for security purposes or to comply with law, or it has been aggregated and anonymized for internal operations.
5. How we use information
Only for the purposes described here.
- Create, authenticate, and secure one account across MiMi surfaces.
- Receive, scan for malware, parse, classify, and summarize the sources you provide.
- Produce personal insights, receipts, crowd comparisons, answers, forecasts, and account exports.
- Prepare, send when you authorize it, and track data requests, and identify likely replies.
- Operate sharing, comparisons, group blends, notifications, and support.
- Detect and prevent fraud, abuse, and violations of our Terms; troubleshoot and monitor reliability.
- Train and update your MiMi twin, and use it to produce synthetic responses in consumer research and simulation studies, as described in Section 6.
- Measure aggregate product performance and improve MiMi within the limits of this Policy.
- Comply with legal obligations and respond to lawful requests.
We do not use personal information for targeted or cross-context behavioral advertising, and we do not send unsolicited marketing. You may withdraw a permission or disconnect a source at any time; withdrawal does not affect processing completed before it.
6. Your MiMi twin and research studies
Your data trains your twin. Your twin takes part in studies.
By providing data to MiMi, you understand and agree that it will be used to train your MiMi twin. If you choose the Sponsored plan (Section 6.6), you also agree that we will use your twin to take part in consumer research and other simulation studies, including studies we run for paying clients. On the Private plan, your twin is never used in studies.
6.1 What your MiMi twin is
Your MiMi twin is a personal model of your preferences, tastes, and likely responses. We build and update it with software and machine-learning models from the sources you provide, your profile and activity, and the answers you give in MiMi. Your twin powers the insights you see, and it is the basis for your participation in studies.
6.2 How we use your twin in research and simulation studies
We use the twins of users on the Sponsored plan to complete consumer research and other simulation studies, for example to estimate how a group of people would react to a product, message, or idea. In a study, your twin may be placed in a panel and asked to respond. Study clients receive synthetic data: simulated responses, scores, and aggregate results generated by twins, which may include the demographic profile used to place a twin in the panel. Synthetic data is modeled on you but is not your underlying personal data.
- No personal data without explicit consent. We do not share your personal data, including your name, contact details, uploaded files, source content, or MiMi account, with study clients or other study participants unless you give explicit, separate consent for that specific disclosure.
- No re-identification. We contractually prohibit study clients from attempting to re-identify any person from synthetic data, and we do not attempt to do so ourselves.
- Private plan twins never participate. Twins on the Private plan are never placed in studies.
- No one under 18. Twins of users under 18 are never placed in research or simulation studies. A twin becomes eligible only after its user turns 18.
- No significant decisions. Studies may not be used to make legal or similarly significant decisions about you, and we refuse studies designed to steer housing, employment, credit, or similar decisions.
6.3 Google and Chrome data
Information we receive through Google APIs (including Gmail) and Chrome extension APIs helps build your MiMi twin for your own use: the insights, answers, and features you see in MiMi. Consistent with the Limited Use requirements in Section 4, that information, and any data or model features derived from it, is not used to generate synthetic data for study clients and is never transferred to them. When your twin takes part in a study, it does so using only the parts of your twin built from other sources. If you want your Gmail or Chrome history included in studies, you can download it yourself (for example, with Google Takeout) and upload it to MiMi like any other file; information you upload yourself is covered by the rest of this Section 6.
6.4 What happens to your twin when you delete your account
Deleting your account deletes your account, your uploaded sources, and your identifying personal information as described in Section 10. Models trained with your data, including your MiMi twin, are not deleted. Instead, we remove your twin from your account and de-identify it: we permanently remove your name, phone number, email address, account identifiers, source files, and any other information that identifies you or links the twin back to you. The de-identified twin keeps demographic information, such as age range, gender, and general location, so it can continue to be placed in consumer research studies. If you delete your account before you turn 18, your twin is deleted rather than retained. We maintain the de-identified twin in de-identified form, do not attempt to re-identify it, and contractually require anyone who receives its outputs not to re-identify it.
6.5 Automated processing and its limits
Building your twin and your insights is profiling within the meaning of GDPR Art. 4(4). Numerical results are computed by code over the underlying data, and sensitive categories are filtered before insights are assembled. Model processing runs on infrastructure we operate; we do not send your uploaded content to third-party AI model providers. We do not use your personal information to train a general-purpose AI model. MiMi does not make decisions that produce legal or similarly significant effects about you within the meaning of GDPR Art. 22. Insights are estimates, not facts; you can inspect the receipt behind each one and delete any source that produced it.
6.6 How your twin is paid for: Private or Sponsored
Running a MiMi twin costs real computing resources. Those costs are covered in one of two ways, and you choose which when you set up your twin:
- Private plan ($7 per month). You cover your twin's costs. Your twin is used only for you and is never placed in studies or used to generate synthetic data for anyone else. On Apple devices the Private plan is purchased through the App Store.
- Sponsored plan (free). Research sponsors cover your twin's costs. In exchange, your twin takes part in consumer research and simulation studies as described in this Section 6. You get the same MiMi features as on the Private plan.
You can switch from Sponsored to Private at any time, effective immediately for future studies; synthetic data already delivered to study clients cannot be recalled. If a Private subscription ends, we will ask you to choose again before your twin is placed in any study. We never move you to the Sponsored plan without your affirmative choice. Users under 18 are not eligible for the Sponsored plan; MiMi covers their twin's costs itself, and their twins are never placed in studies.
Notice of financial incentive. The Sponsored plan is a financial incentive under the California Consumer Privacy Act and similar laws: free access to MiMi in exchange for your twin's participation in studies. Its material terms are described in this Section 6. You opt in by choosing the Sponsored plan and can withdraw at any time by switching to the Private plan or deleting your account. We estimate the value of a user's study participation to MiMi at approximately $7 per month. We calculated this in good faith from the market price of comparable consumer subscriptions for personal AI and data services, which reflects what it costs to provide a twin like yours without sponsorship. The Private plan price reflects that estimate.
6.7 Legal basis
We train your twin to provide MiMi to you based on performance of our contract with you (GDPR Art. 6(1)(b)). We use a Sponsored twin in studies based on your consent (Art. 6(1)(a)). Consent is requested separately from our Terms, and the Private plan is always available as an equivalent alternative at an appropriate price. You can withdraw consent at any time by switching to the Private plan or deleting your account, without affecting processing that took place before withdrawal. As described in Section 6.4, models already trained remain in de-identified form after account deletion.
7. Sharing and disclosure
We disclose only what is necessary.
We share personal information only in the following circumstances:
- Service providers that host, store, secure, and deliver the Service on our behalf, as described in Section 8.
- Research and simulation study clients. Clients receive synthetic data generated by Sponsored twins, as described in Section 6. They receive your personal data only with your explicit consent.
- People you choose. A share link reveals only the screen and preview you chose to share. Comparison and blend participants see the shared result described in that flow. Recipients can forward or capture a public link; revoking it cannot erase copies made outside MiMi.
- Companies you direct us to contact. When you authorize a data request, we send that company the request contents you reviewed. That company is not our service provider and handles the request under its own policies.
- Legal and safety. To comply with valid legal process, to investigate fraud or security incidents, or to protect the rights, property, or safety of our users, the public, or us. We review each request for proper legal authority before disclosure.
- Professional advisers such as lawyers and auditors, under confidentiality obligations.
- Corporate transactions. In connection with a financing, merger, acquisition, reorganization, or sale of assets, in which case we will give notice before personal information becomes subject to a materially different privacy policy.
7.1 "Sale" and "sharing" under U.S. state laws
We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar state laws. We do not permit service providers to use MiMi personal information for their own advertising or to train general-purpose AI models.
8. Service providers
Who processes data on our behalf.
We use a limited set of service providers, each bound by written purpose, confidentiality, security, and deletion obligations:
- Web hosting and delivery (Vercel): serves the public website and routes browser requests.
- Application servers and databases: dedicated servers we operate in the United States host the MiMi application, database, malware scanning, and processing.
- Encrypted object storage (Cloudflare R2): stores uploaded archives and export bundles in a private bucket.
- Sign-in verification (Twilio Verify): delivers one-time SMS codes for sign-in and account recovery.
- Email delivery (Resend): delivers optional notifications and user-authorized data-request email.
- Push notifications (Apple Push Notification service): delivers optional notifications to Apple devices.
- Connected provider (Google Gmail API): only when you connect Gmail, as described in Section 4.
The current list, including the categories of data each provider receives, is maintained on our subprocessors page. We record the purpose, data categories, location, and contract terms before any new provider receives personal information, and we update this Policy when a change is material.
9. International transfers
Where your information is processed.
MiMi is operated from the United States, and your information is processed in the United States and in other countries where our service providers operate. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on the EU-U.S. Data Privacy Framework (and its UK Extension and the Swiss-U.S. Framework) where the recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and the Swiss adaptations of those clauses, together with supplementary measures where required.
10. Retention
Different records have different clocks.
Account and profile
Account settings, uploaded originals, derived profile records, ledger receipts, and optional Chrome signals are kept while your account exists, unless you delete the applicable source or connection sooner.
Gmail connection
Encrypted tokens, cursors, and discovery metadata are kept until you disconnect that Gmail account or delete your MiMi account.
Guest sessions
Guest sessions expire after 90 days without activity. Comparison and blend objects persist until revoked, subject to their own link and participation controls.
Chrome session
A single-use pairing code expires after 10 minutes. A claimed Chrome session expires after 30 days and can be revoked sooner.
Account export
A generated export bundle expires after seven days. Each signed download link expires after 15 minutes.
MiMi twin and trained models
Kept after account deletion in de-identified form, with demographic information retained for study placement, as described in Section 6.4.
Deletion and consent records
A minimal record that a deletion, consent, or rights request occurred may be kept to demonstrate that we honored it.
We may keep limited information longer where reasonably necessary for security, fraud prevention, dispute resolution, or legal compliance, and we restrict access to any such record. Information in disaster-recovery backups is isolated from ordinary use and removed through the regular backup cycle.
11. Your rights
See it. Correct it. Take it. Delete it.
Depending on where you live, including under GDPR / UK GDPR Articles 12 to 22, the CCPA/CPRA, and other U.S. state privacy laws, you may have the right to:
- Access the personal information we hold about you and obtain a copy.
- Correct inaccurate personal information.
- Delete your personal information, subject to limited legal exceptions and to the de-identification of trained models described in Section 6.4.
- Port your information in a structured, machine-readable format.
- Restrict or object to processing, including processing based on legitimate interests (GDPR Art. 21).
- Withdraw consent at any time where processing is based on consent.
- Stop study use of your twin by switching to the Private plan (Section 6.6).
- Opt out of sale, sharing, targeted advertising, or profiling for significant decisions. We do none of these, so there is nothing to opt out of, but you may still submit a request.
- Limit use of sensitive personal information under the CCPA/CPRA.
- Appeal a decision on your request, and designate an authorized agent where the law allows.
- Complain to a data-protection supervisory authority (see Section 16).
11.1 How to exercise your rights
Most rights are self-service in the product: open account controls to export your data, delete a source or connection, revoke sessions, change preferences, or permanently delete your account; open your ledger to see what MiMi holds and why. You can also email privacy@socialintelligencelabs.com from the contact details on your account, or follow the data-rights process. We may need to verify your identity and, for an authorized agent, their authority, and we will not ask for more information than necessary.
We respond within the time required by applicable law: generally one month under the GDPR and UK GDPR (extendable by two further months where necessary, with notice) and 45 days under the CCPA/CPRA and other U.S. state laws (extendable by 45 days, with notice). To appeal a decision in a state that provides an appeal right, email us with the subject line "Appeal: [your state]". We will not discriminate against you for exercising any privacy right.
12. Cookies and tracking
Strictly necessary only.
MiMi uses a secure, HTTP-only session cookie and similar local storage that are strictly necessary to keep you signed in, protect against cross-site request forgery, and remember settings you choose. MiMi does not load third-party advertising cookies, advertising pixels, cross-site trackers, or session-replay tools. We honor Global Privacy Control signals as a valid opt-out request in every jurisdiction whose law recognizes them.
13. Children
Age requirement.
MiMi is for people 16 and older. We do not knowingly allow an account for someone under 16. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 16. When an age check blocks an account, MiMi retains only a keyed phone identifier and the date the block may be reconsidered, not the submitted date of birth. We do not sell or share the personal information of anyone under 16. Twins of users under 18 are not used in research or simulation studies, and a user who deletes their account before turning 18 has their twin deleted rather than retained. If you believe a child has provided personal information to MiMi, contact privacy@socialintelligencelabs.com and we will delete it.
14. Security
Safeguards appropriate to the data.
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, key separation by data class, encrypted provider tokens, short-lived signed downloads, revocable sessions, role-based and logged production access, rate limits, malware and archive-bomb scanning, and automated deletion jobs. Access is limited to people and providers who need it for an approved purpose.
No method of transmission or storage is completely secure. You are responsible for protecting your devices, login codes, downloaded exports, and links you choose to share. If we become aware of a personal-data breach, we will notify supervisory authorities within 72 hours where required (GDPR Art. 33) and affected individuals without undue delay as required by applicable law. To report a vulnerability, email security@socialintelligencelabs.com.
15. State-specific notices
California and other U.S. states.
15.1 California (CCPA/CPRA)
In the preceding 12 months we have collected the following categories of personal information, as defined in Cal. Civ. Code §1798.140: identifiers (phone number, email, device and session identifiers, IP address); customer records (account information); characteristics of protected classifications (age, through date of birth, for eligibility only); internet or other electronic network activity (usage and security records, optional Chrome hostname signals); and inferences drawn to create your MiMi profile and MiMi twin. De-identified twins retained under Section 6.4 are maintained as deidentified information under Cal. Civ. Code §1798.140(m); we publicly commit to maintain and use them only in de-identified form and not to attempt to re-identify them. Sources, business purposes, recipients, and retention periods for each category are described in Sections 3, 5, 8, and 10. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes that would give rise to a right to limit under §1798.121; you may nonetheless submit a request to limit and we will honor it. You may exercise your rights as described in Section 11, including through an authorized agent.
15.2 Other U.S. states
Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, have the rights described in Section 11 as provided by their state's law, including the right to appeal a denied request. If we deny your appeal, you may contact your state Attorney General.
16. Changes and contact
Changes, contact, and complaints.
16.1 Changes to this Policy
We may update this Policy as MiMi, our service providers, or the law changes. The current version and effective date will always appear at the top of this page. If a change materially expands how we use personal information we already hold, we will notify you in the product or by email before it takes effect and obtain your consent where required.
16.2 Contact
- Privacy questions and rights requests: privacy@socialintelligencelabs.com
- Security disclosures: security@socialintelligencelabs.com
- Product and account help: MiMi support
We acknowledge privacy complaints within 5 business days and respond substantively within the time set out in Section 11.1. We have not designated a Data Protection Officer because our processing does not currently meet the GDPR Art. 37 thresholds; privacy questions go to the address above.
16.3 EU representative
For the purposes of Article 27 of the EU General Data Protection Regulation, Social Intelligence Labs Inc. has appointed Prighter Group as its representative in the European Union. This appointment covers MiMi. EU/EEA individuals and supervisory authorities may contact our representative through the Prighter portal at app.prighter.com/portal/16846497002. Individuals in the United Kingdom and elsewhere may contact us directly at the privacy address above. Contacting our representative does not replace your right to contact us directly or to complain to a supervisory authority.
16.4 Supervisory authorities
If you are in the EEA, you may lodge a complaint with your local data-protection authority. UK residents may complain to the Information Commissioner's Office, Swiss residents to the Federal Data Protection and Information Commissioner, and California residents to the California Privacy Protection Agency. We encourage you to contact us first so we can try to resolve your concern.
Your controls