Legal

Privacy policy

Effective 29 August 2026 · Last reviewed 29 August 2026 · v2.4

Plain-language summary

mimi turns publicly observable social-platform activity into aggregated audience cohorts, then lets account holders run model-assisted message tests against those cohorts. We collect the account, study, security, and support information needed to provide that service. We do not sell personal data, run behavioural advertising, or expose named individuals in customer-facing cohorts. You can ask us to access, correct, delete, or exclude data by writing to the address below.

mimi at getmimi.xyz is operated by Social Intelligence Labs ("SIL," "we," "us," or "our"). This policy applies to the mimi website, iOS app, console, shared reports, and related support communications. mimi is an independent service and is not affiliated with or endorsed by TikTok, Instagram, YouTube, X, or any other social platform.

1. The information we process

Account and organisation information

We process your name, work email address, organisation, role, account status, password hash, and account settings. Passwords are hashed with bcrypt and are never stored in readable form.

Studies, prompts, and uploaded media

We process the stimuli, questions, study settings, links, images, video, audio, and other materials you choose to submit, together with the resulting simulations, analyses, exports, and share links. Do not submit material you are not authorised to use.

Security and service records

We record session identifiers, IP address, user agent, timestamps, requested routes, role and administrative changes, and other audit events needed to authenticate users, investigate misuse, and protect the service.

Communications

We process the information you include in contact forms, support or rights requests, and email correspondence so we can respond and maintain a record of the request.

Public behavioural data

mimi processes publicly observable profile and activity data from social platforms, including public posts, engagement counts, follower relationships, public comments, transcripts, and related derived signals. We do not intentionally collect private messages, private-account content, purchased contact lists, or content available only behind someone else's login.

2. How public behavioural data becomes a cohort

  • Customer-facing cohorts contain at least 100 real accounts.
  • Cohort descriptions use aggregate counts and unattributed examples; they do not display names, handles, or channel identifiers.
  • Account-level source records are access-controlled and retained so authorised operators can audit cohort construction and honor exclusion requests.
  • mimi outputs are model-assisted estimates, not statements made by the people whose public activity contributed to a cohort.

3. Why we use information

We use the information described above to:

  • provide accounts, studies, simulations, reports, exports, and support;
  • compile and maintain auditable audience cohorts;
  • secure the service, prevent abuse, and investigate incidents;
  • maintain legal, operational, and audit records; and
  • improve reliability and methodology using aggregated or de-identified findings.

Where data-protection law requires a legal basis, we rely on performance of a contract, compliance with legal obligations, and our legitimate interests in operating and securing an audience-research service. We ask for consent where the law requires it.

4. Model and infrastructure providers

mimi uses Convex for application data, Vercel for web hosting, Resend for contact-form email delivery, infrastructure we operate for the audience data plane, and OpenRouter to route model requests to the selected upstream model provider. A model request may contain your stimulus, questions, cohort aggregates, and uploaded media needed for the requested analysis. We do not intentionally include named account-level cohort source rows in simulation prompts.

Providers receive information only to perform services for us, under their applicable service terms and data-protection commitments. We may also disclose information when required by valid legal process or to protect rights, safety, and service integrity.

A limited number of authorised SIL personnel can access account details, study prompts (including notes or briefs you enter into a study), submitted materials, and results when needed to operate the service, investigate a security or reliability issue, provide support you request, or comply with law. Access is role-limited and privileged actions are logged. An unsent LAND pocket brief stored only on your iPhone is not available to SIL unless you open LAND and submit it to the service. Do not submit secrets or personal information that are not needed for the study.

5. What we do not do

  • We do not sell or rent personal data.
  • We do not use third-party advertising cookies or cross-site retargeting.
  • We do not use your confidential study content to train mimi for another customer.
  • We do not permit mimi outputs to be used for adverse decisions about an identified person, including employment, credit, housing, insurance, or access to services.

6. Retention

  • Account records: while the account is active, then up to 30 days.
  • Authentication cookies and session records: up to 14 days.
  • Studies, media, and results: until you delete them or request deletion.
  • Routine security logs: up to 90 days.
  • Privileged-action audit records: up to 24 months.
  • Public behavioural source data and derived cohorts: for as long as needed to keep the catalogue current, auditable, and subject to exclusion requests.

We may retain information longer when required by law, needed to resolve a dispute, or preserved for an active security investigation. Backups may take additional time to cycle out of service.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export personal data. You may also withdraw consent where consent is the basis for processing. We may need to verify your identity before completing a request.

Account holders can start account deletion from Account settings in the mimi console or iOS app. The account is disabled, active sessions are revoked, and public share links stop resolving immediately; final deletion of account data, studies, results, and uploaded files completes within 30 days. The iOS app also removes its locally saved LAND draft after an explicit sign-out or a successful deletion request. We may retain a limited, anonymised audit event or another record when required for law, security, or dispute resolution, as described above.

If your public account appears in mimi's source data and you want it excluded, include the platform and handle in your request. Verified exclusions remove the account from future cohort construction and applicable membership records; affected aggregates may be rebuilt rather than annotated.

8. Security

We use role-based access, bcrypt password hashing, cryptographically random sessions, hashed server-side session tokens, least-privilege service access, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

9. International processing

SIL and its providers may process information in the United States and other countries. Where required, we use contractual and other safeguards for international transfers.

10. Children

mimi is a business service for users aged 18 or older. We do not knowingly create accounts for children. Public-source exclusion requests can be made regardless of whether the requester is a customer.

11. Cookies and local storage

mimi uses strictly necessary authentication cookies, browser storage for interface choices and onboarding state, and app-scoped iPhone storage for the LAND pocket brief. These values are not used for advertising, cross-site tracking, or product analytics. Details and the current browser-storage roster are in our Cookie Policy.

12. Changes and contact

We will update the effective date when this policy changes. Material changes will be highlighted on the site or at sign-in where appropriate.

Privacy, security, support, and data-subject requests all go to contact@socialintelligencelabs.com.