Mipkin

Privacy Policy

Last updated 31 July 2026

Mipkin is operated by Eros Media LLC (“we”, “us” and “our”), 1000 Brickell Ave., Suite 715, Miami, Florida 33131, United States. It is built so your companion, Nook, check-ins and writing stay on your device by default. A few optional features need a service to work. This page says exactly what they send, what they do not send, and how to turn them off.

What we collect about you

We do not ask for a name, phone number, contacts, photos, location, date of birth or health data. The app has no advertising SDK, no configured behavioural analytics, and no configured crash-reporting SDK. Optional email sign-in necessarily handles an email address to deliver a code; we describe that separately below.

What is stored, and where

Everything the app knows lives in your device's own storage, in a private area belonging to the app. That includes:

  • A randomly generated identifier created on your device, which is not linked to you and is never sent anywhere.
  • Your companion — which one, their name, the room, how long you have known each other, and their bond and energy values.
  • What you have done in the app: the small things you have tended, quests, adventures, keepsakes, warmth earned and spent, decor owned and where you put it.
  • Your daily check-in answer, which is replaced each day.
  • The pages you write in your own journal, and any reflection returned for them.
  • Anything you shut in the worry box. This never leaves your device under any setting — there is no switch that sends it, and nothing in the app reads it except the screen that shows it back to you.

These things do not leave your device unless you choose one of the optional features below. Inside the app you can export the local information it holds, or delete it, at any time.

Optional features that send data

Reflections and visiting are off unless you turn them on. You can use the core companion, Nook and journal without either feature.

Reflections

When you turn reflections on and request one for a journal page, the page text is sent to our service. If you selected support areas during onboarding, up to six fixed choices such as “rest” or “connection” may accompany it. No companion name or identifier, mood, check-in, streak, warmth, keepsake, device identifier, advertising identifier, timestamp, or previous journal entry is sent.

Our service checks for crisis language before any model call. An entry that triggers that check is not sent to the model. An ordinary request is sent to OpenRouter for one short AI-generated reflection. We design our service not to persist or log the page text or the reply; OpenRouter's handling is governed by its privacy policy. A reflection is not medical or mental-health care, advice, diagnosis or a conversation with your companion.

You can turn reflections off at any time in Settings. The choice is read before each send, so turning it off stops future requests. Everything already written stays on your phone.

Visiting

When you turn on visiting, we publish only optional growth and wearable choices so someone holding the code you share can see a generic Mipkin visitor in their Nook. We never publish which companion you chose, the name you gave them, your mood, bond, energy, warmth, check-in, journal, Nook, outings, keepsakes or last-seen time.

A visiting record contains those two optional appearance fields, a hash of a secret write key, timestamps, and a small queue of fixed gestures. It expires after 90 days without an update. There is no public feed, no server-side friend list and no chat. Turning visiting off asks the service to revoke your code; if the phone cannot reach the service, the app tells you it is still on instead of claiming a code is gone when it is not.

Optional sign-in

Sign-in is not required to use Mipkin. If it is available in your build, Apple or Google gives us a short-lived identity token so our service can verify it against that provider. We do not store that token, your name, avatar or provider profile. Our service stores an opaque Mipkin account ID, the provider name, a hashed provider subject, a creation time and, only if you link it, your shareable hearth code. It does not store your companion, chosen companion name, journal, reflections, check-ins, Nook, purchases, device identifier or secret hearth key.

A short-lived account session is held in the app's memory after you sign in; it is not saved to device storage. It can recover and manage a linked hearth code after a reinstall, but it does not back up or restore your companion, journal or other device data. You can delete the account in the app after reconnecting it. Deletion withdraws the linked hearth code and removes the account record; deleting the account does not delete local app data.

Email sign-in sends your address to our email delivery service to send a six-digit code. Our service stores a hash of the normalised address, a salted code hash, a timestamp and an attempt count; it does not store the address or the code. A hashed email address and the temporary use of your address are personal data. Email codes expire after ten minutes, work once and are deleted after five wrong attempts.

Crisis language

Before any journal page reaches a language model, our service checks it for words that suggest somebody is in danger. If it finds them, the page is not sent to the model at all, and the app shows you a route to people who can help instead. That check happens on our service, in memory, and is not recorded.

Payments

Subscriptions and one-off purchases are handled by Apple's App Store or Google Play. We do not receive your card number or billing address. When purchases are enabled, RevenueCat processes the store purchase record and entitlement status using its own anonymous app user ID, so the app can tell whether an item is available. We do not send RevenueCat your companion, chosen companion name, journal, check-ins, Nook, visiting data, or optional account record, and we do not link its anonymous ID to that account.

Notifications

The app can schedule one gentle reminder, and it is scheduled by your own phone rather than sent from a server. We do not operate a push service, and no notification we schedule names your companion or your check-in on a lock screen.

Children

Mipkin is not directed to children under 13. Do not enable optional sign-in, reflections or visiting for a child without the required parental consent in their jurisdiction.

Your rights

You can exercise many rights directly in the app:

  • Access and portability — export your full local state from the app at any time.
  • Erasure — delete all local data from the app. The app also attempts to withdraw a visiting record before discarding its local key.
  • Account deletion — if you enabled optional sign-in, delete that separate account from Settings after signing in again. Our account-deletion page explains the same process if you cannot open the app.
  • Withdrawal of consent — turn reflections or visiting off in Settings.

If you are in the EEA or UK, our intended lawful basis for optional reflections and visiting is your explicit consent. You give it by turning the individual feature on and withdraw it by turning it off. Eros Media LLC is the controller for those optional features. The governing law in our terms is Florida law; legal review must be completed before public release.

We do not sell personal information or use it for cross-context behavioural advertising.

Changes

If this policy changes in a way that affects what leaves your device, the app will say so before it takes effect, and any new transfer will be off until you turn it on. This page's date is the record of when it last changed.

Contact

Questions about this policy: support@mipkin.app.