on this page
01 · the short version

The short version.

Mikoyi is a personal journal. The things you write in it are yours. We collect the minimum needed to make the app work — your name, your email, your journal entries, and your subscription status.

We don't sell your data. We don't share it with advertisers. We don't run analytics that track you across other apps or websites. We don't share anything with your employer.

Your journal entries are processed by an AI provider (Anthropic) to generate the reflection and naming features. They are not used to train AI models. They are not seen by humans except as required for you to use the product or as required by law.

If you ever want to delete your account and everything in it, email us at support@mikoyi.ai and we'll do it within 30 days. No friction, no convincing-you-to-stay flow.
02 · what we collect

What we collect.

To make Mikoyi work, we collect:

03 · what we don't

What we don't collect.

To be specific about it:

04 · how we use your data

How your data is used.

Each piece of data we collect serves a specific function:

We don't use your data for anything beyond making Mikoyi work for you. We don't sell it. We don't share it with advertisers. We don't use it to build profiles about you for marketing.

05 · third parties

Who else touches your data.

A small number of third-party services help Mikoyi function. Each one has access only to what's necessary, and each has its own privacy policy you can read.

We do not share your data with any other third parties. We have not authorized any other service to access your journal or account information.

06 · where it's stored

Where your data lives.

Your account information and journal entries are stored on Supabase's secure cloud infrastructure, encrypted at rest and in transit.

Journal content sent to Anthropic for AI processing is transmitted over encrypted connections (HTTPS/TLS) and is not retained by Anthropic beyond the time needed to generate a response.

We retain your data as long as your account is active. If you delete your account, your data is removed from our systems within 30 days, with the exception of any information we're legally required to keep (such as records of payments processed by Apple).

07 · your rights

What you can do.

You have control over your data. At any time, you can:

These rights apply to all users worldwide. If you're in the European Union, the United Kingdom, or California, you also have specific legal rights under GDPR, UK GDPR, and CCPA respectively. To exercise any of these rights, email support@mikoyi.ai.

08 · children's privacy

Children's privacy.

Mikoyi is built for working adults and is not intended for anyone under 18. We do not knowingly collect data from children under 13. If we discover that we have collected information from a child under 13, we will delete it promptly.

If you believe a child has provided us with information, please contact us at support@mikoyi.ai.

09 · international users

International users.

Mikoyi is operated from the United States. If you use Mikoyi from outside the US, your data will be transferred to and stored in the United States.

By using Mikoyi, you consent to this transfer. We comply with applicable data protection laws in transferring your data, including GDPR for users in the European Union and UK GDPR for users in the United Kingdom.

10 · changes to this policy

If this policy changes.

We may update this privacy policy from time to time. If we make material changes — meaning changes that affect how we collect, use, or share your data — we will notify you by email and update the "Last updated" date at the top of this page.

Continuing to use Mikoyi after a policy update means you accept the updated terms. If you don't agree with a change, you can delete your account at any time.

11 · contact

Get in touch.

If you have questions about this policy, want to exercise any of the rights above, or want to report a concern about how we handle your data, email us at support@mikoyi.ai.

We read every message. We respond to privacy-related requests within 7 days, and act on data access or deletion requests within 30 days.