Privacy Policy

Last updated: December 26, 2024

Introduction

Middly ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service").

We understand that the information you share through Middly is deeply personal. Relationship conflicts and emotions are sensitive topics, and we have designed our Service with your privacy as a core principle.

Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Information You Provide Directly

  • Account Information: When you create an account, we collect your name, email address, and optional profile photo.
  • Session Content: The perspectives, thoughts, and feelings you share during mediation sessions. This includes written responses to session prompts.
  • Partner Connection: Information needed to connect you with your partner, such as invite codes and partnership status.
  • Feedback and Communications: Any feedback, questions, or communications you send to us.

Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers, and mobile network information.
  • Usage Data: Information about how you use the Service, including session timestamps, feature usage, and interaction patterns.
  • Log Data: IP address, browser type, pages visited, time spent, and other diagnostic data.

Sensitive Personal Information

The content you share in mediation sessions may include sensitive personal information about your relationships, emotions, and personal experiences. We treat this information with the highest level of care and protection. We do not sell this information, and it is only used to provide and improve the Service.

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide the Service: To create and manage your account, connect you with your partner, facilitate mediation sessions, and generate AI-powered summaries and insights.
  • AI Processing: Your session content is processed by our AI system (powered by Google Gemini) to generate neutral summaries, identify common ground, and suggest action steps. This processing is essential to the core functionality of Middly.
  • Improve the Service: To understand how users interact with our Service and to develop new features and improvements.
  • Communicate with You: To send you updates, security alerts, and support messages.
  • Safety and Security: To detect and prevent fraud, abuse, and security incidents. Our system includes safety monitoring to identify content that may indicate serious harm.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

AI Processing Disclosure

Middly uses artificial intelligence to help couples find common ground. Here's how it works:

  • Your session content is sent to Google's Gemini AI for processing.
  • The AI generates summaries, identifies shared values, and suggests next steps.
  • AI outputs are not human-reviewed unless you report an issue.
  • We do not use your content to train AI models.
  • AI processing is essential to provide the Service and cannot be opted out of while using Middly.

How We Share Your Information

With Your Partner

When you participate in a mediation session, certain information is shared with your partner by design:

  • AI-generated summaries and outputs from completed sessions
  • Your agreement or disagreement with session outcomes
  • Session status (whether you have submitted your turn)

Important: Your raw session input is never directly shared with your partner. They only see the AI-generated neutral summary.

With Service Providers

We share information with third-party service providers who help us operate the Service:

  • Clerk: Authentication and user management
  • Convex: Database and backend infrastructure
  • Google (Gemini): AI processing for mediation outputs
  • Apple: App distribution and in-app purchases (if applicable)

These providers are contractually obligated to protect your information and only use it to provide services to us.

Legal Requirements

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account Information: Retained until you delete your account
  • Session Content: Retained until you delete the session or your account
  • Usage Data: Retained for up to 24 months for analytics purposes
  • Backup Data: May be retained for up to 90 days after deletion for disaster recovery

Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

For All Users

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Export: Request your data in a portable format

For California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising your rights

We do not sell your personal information.

For European Users (GDPR)

If you are in the European Economic Area, you have additional rights:

  • Right to object to processing
  • Right to restrict processing
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

Our legal basis for processing your information includes: performance of our contract with you, your consent, our legitimate interests, and compliance with legal obligations.

Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of data at rest
  • Regular security assessments
  • Access controls and authentication
  • Secure cloud infrastructure with industry-standard providers

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Children's Privacy

Middly is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately so we can delete that information.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. When we transfer your information, we ensure appropriate safeguards are in place, including standard contractual clauses approved by relevant authorities.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the app and updating the "Last Updated" date. We encourage you to review this policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:

Middly

Email: privacy@middly.app

We will respond to your request within 30 days (or sooner if required by applicable law).

How to Delete Your Data

You can request deletion of your account and all associated data at any time:

  1. Open the Middly app
  2. Go to Settings
  3. Select "Delete Account"
  4. Confirm your request

Alternatively, you can email us at privacy@middly.app with your deletion request. We will process your request within 30 days.