Legal · MiviaLabs LLC
Privacy Policy
Effective date: August 22, 2026 Last updated: August 22, 2026
This Privacy Policy explains how MiviaLabs LLC, a Wyoming limited liability company ("Mivia," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information when you use mivia.app and related Mivia services (collectively, the "Services").
This Policy should be read together with the Mivia Terms of Use and any applicable data processing agreement, product-specific notice, or privacy supplement.
1. Who We Are
Data controller / business: MiviaLabs LLC 30 N Gould St Ste N Sheridan, WY 82801 USA
Privacy contact: [email protected]
For some processing involving organization accounts, Mivia may act as a service provider, processor, or other equivalent role on behalf of an organization customer. In those cases, the organization customer's privacy arrangements may apply to the relevant processing.
2. Personal Information We Collect
The categories of information we collect depend on how you use the Services.
A. Account and profile information
This may include:
- name;
- email address;
- username;
- organization or company information;
- account identifiers;
- authentication and authorization information;
- account preferences and settings; and
- information you choose to provide to us.
B. Organization and workspace information
If you use an organization account, we may process:
- organization name and identifiers;
- membership and role information;
- administrator and billing contact information;
- workspace configuration; and
- access and authorization records.
C. Connected-service and integration information
When you connect a third-party service, such as a source-control or code-hosting provider, we may receive information made available through the permissions you authorize.
Depending on the integration and permissions, this may include:
- account or organization identifiers;
- repository metadata;
- repository names and access permissions;
- branch, issue, pull-request, workflow, or similar metadata;
- content or files that you explicitly authorize Mivia to access; and
- access tokens or credentials handled through supported authentication mechanisms.
We process only the information reasonably necessary for the integration and the features you use.
D. Customer Content
You or your organization may provide or authorize access to:
- prompts and instructions;
- source code and other files;
- repository or project content;
- workflow definitions;
- configuration;
- agent task information;
- outputs, feedback, and related logs; and
- other information submitted through the Services.
Customer Content may contain personal information or confidential information. You are responsible for ensuring that you have an appropriate legal basis and authority to provide it to Mivia.
E. Usage, device, and technical information
We may automatically collect:
- IP address;
- device and browser information;
- operating-system information;
- approximate location derived from IP address;
- log data;
- feature usage and interaction information;
- error, performance, and diagnostic information;
- security events; and
- identifiers used to maintain sessions and prevent abuse.
F. Communications and support information
If you contact us, we may collect the content of your communications and information needed to respond to you.
G. Billing and transaction information
For paid Services, we may collect subscription, invoice, tax, and transaction information.
Payment card information should generally be processed by our payment processor rather than stored directly by Mivia, depending on the payment flow we implement.
H. Information from other sources
We may receive information from:
- identity and authentication providers;
- third-party integrations you connect;
- organization administrators;
- payment processors;
- security and fraud-prevention providers; and
- publicly available or lawfully obtained business information.
3. How We Use Personal Information
We use personal information to:
- provide, operate, and maintain the Services;
- authenticate users and manage accounts;
- provide organization and workspace administration;
- process and perform requests made through integrations, workflows, agents, and other product features;
- process payments and manage subscriptions;
- provide support and communicate with you;
- secure the Services and investigate suspected fraud, abuse, security incidents, or violations;
- detect and prevent attempts to circumvent valid access restrictions;
- analyze performance, reliability, and usage;
- develop, maintain, and improve product features and operations;
- comply with legal obligations and respond to valid legal requests; and
- enforce our agreements and protect the rights, property, safety, and legitimate interests of Mivia, users, and others.
We do not use Customer Content to train or improve general-purpose AI models unless we clearly disclose that use and provide any required choice or consent.
4. Legal Bases Where GDPR or Similar Laws Apply
Where the GDPR, UK GDPR, or similar law applies, our legal bases may include:
- Performance of a contract: to provide the Services you request.
- Legitimate interests: to secure, operate, improve, and protect the Services, prevent fraud and abuse, enforce our terms, and defend legal claims, where those interests are not overridden by your rights.
- Legal obligation: to comply with applicable law and lawful requests.
- Consent: where required, including for certain cookies or processing where no other lawful basis applies.
Where we rely on legitimate interests, we consider the nature of the data, the processing context, and the rights and interests of affected individuals.
5. How We Disclose Personal Information
We may disclose personal information to:
Service providers and subprocessors
Providers that help us operate the Services, such as hosting, infrastructure, security, authentication, analytics, communications, support, AI/model providers, and payment services.
We require service providers to process personal information only as permitted by applicable agreements and law.
Organization customers and administrators
If you use an organization account, authorized administrators may be able to access or manage information associated with the organization account, subject to applicable law and the organization's configuration.
Third-party integrations
When you direct us to connect with or send information to a Third-Party Service, we may disclose information as necessary to perform your request and as authorized by you.
Professional advisers and corporate transactions
We may disclose information to professional advisers and in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business.
Legal and safety disclosures
We may disclose information where we reasonably believe disclosure is necessary to comply with law, enforce our agreements, protect security, investigate wrongdoing, or protect the rights, property, or safety of Mivia, users, or others.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless we clearly disclose that practice and provide any legally required notice and choice.
6. AI and Model Providers
Some AI-enabled features may process prompts, Customer Content, or other inputs using models or infrastructure operated by Mivia or third-party providers.
Where a third-party provider processes information on our behalf, we seek to use appropriate contractual and technical controls.
The specific provider used may vary by feature, configuration, availability, model selection, region, or customer settings.
7. International Data Transfers
Mivia is based in the United States and may process information in the United States and other countries where Mivia or its service providers operate.
Those countries may have data-protection laws that differ from the laws of your country.
Where legally required for transfers of personal data, we will use an appropriate transfer mechanism, such as contractual safeguards, an adequacy decision, or another lawful mechanism.
8. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Retention periods depend on the type of information and context.
For example:
- account information may be retained while your account is active and for a reasonable period afterward;
- security logs may be retained for a period appropriate to fraud prevention, incident response, and legal obligations;
- Customer Content may be deleted or made unavailable according to product settings, contractual commitments, or account-deletion procedures; and
- some information may be retained longer where required or permitted by law.
9. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information.
No system is completely secure. You are responsible for protecting your credentials and configuring access permissions appropriately.
If we become aware of a security incident involving personal information, we will take steps required by applicable law.
10. Cookies and Similar Technologies
We may use cookies, local storage, pixels, SDKs, and similar technologies for:
- authentication and session management;
- security and fraud prevention;
- remembering preferences;
- measuring performance and reliability; and
- analytics.
Where required by law, we will obtain consent before placing non-essential cookies or similar technologies.
You can control some cookies through browser settings and, where provided, our cookie preference tools.
11. Access Restrictions and Anti-Circumvention Processing
Mivia may process limited identity, account, organization, integration, billing, security, and relationship information to prevent fraud, abuse, unauthorized access, and circumvention of valid access restrictions.
We do not treat nationality, ethnicity, religion, or another protected characteristic as a standalone basis for access restriction, except where a restriction is required by applicable law.
We also do not automatically treat a person as restricted merely because they are or were an employee, contractor, friend, or other weakly associated person of an organization whose access is restricted.
Where we use automated signals, they may support security decisions, but ambiguous cases may be subject to human review.
You may contact [email protected] or [email protected] to request review of a restriction you believe resulted from incorrect identity or association information, subject to our need to protect security and prevent evasion.
12. Your Privacy Rights
Depending on applicable law, you may have rights to:
- access personal information;
- correct inaccurate information;
- delete personal information;
- receive a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- appeal certain privacy-rights decisions.
To submit a request, email [email protected] with the subject line "Privacy Request."
We may ask you to verify your identity and authority before responding. We will not discriminate against you for exercising applicable privacy rights.
Some information may be retained where permitted or required by law, including for security, fraud prevention, legal claims, or compliance.
13. Additional Information for EEA, UK, and Swiss Individuals
Where applicable, you may also have the right to lodge a complaint with a competent data-protection authority.
If Mivia is not established in the EEA or UK but becomes subject to an obligation to appoint an EU or UK representative, Mivia will provide the representative's details in an applicable regional privacy notice.
14. U.S. State Privacy Disclosures
Residents of certain U.S. states may have additional privacy rights, including rights to know, access, correct, delete, obtain a portable copy, opt out of certain processing, and appeal.
Mivia will honor applicable rights according to the law that applies to the request.
California notice
Where the California Consumer Privacy Act, as amended, applies, Mivia may collect the categories described in Section 2 for the business and commercial purposes described in Section 3.
Mivia does not knowingly sell or share personal information for cross-context behavioral advertising unless we clearly disclose that activity and provide the legally required opt-out mechanism.
California residents may exercise applicable rights by contacting [email protected].
15. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
If we learn that we collected personal information from a child under 13 without legally required authorization, we will take appropriate steps to delete it.
If applicable law imposes a higher minimum age or additional requirements in your jurisdiction, those requirements apply.
16. Changes to This Privacy Policy
We may update this Policy from time to time.
If we make a material change, we will provide notice through the Services, by email, or by another reasonable method where required by law.
The Last updated date above indicates when this Policy was most recently revised.
17. Contact Us
For privacy questions or requests:
MiviaLabs LLC 30 N Gould St Ste N Sheridan, WY 82801 USA
Email: [email protected]