MIVIA

Legal · MiviaLabs LLC

Privacy Policy

Effective date: August 22, 2026 Last updated: August 22, 2026

This Privacy Policy explains how MiviaLabs LLC, a Wyoming limited liability company ("Mivia," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information when you use mivia.app and related Mivia services (collectively, the "Services").

This Policy should be read together with the Mivia Terms of Use and any applicable data processing agreement, product-specific notice, or privacy supplement.

1. Who We Are

Data controller / business: MiviaLabs LLC 30 N Gould St Ste N Sheridan, WY 82801 USA

Privacy contact: [email protected]

For some processing involving organization accounts, Mivia may act as a service provider, processor, or other equivalent role on behalf of an organization customer. In those cases, the organization customer's privacy arrangements may apply to the relevant processing.

2. Personal Information We Collect

The categories of information we collect depend on how you use the Services.

A. Account and profile information

This may include:

  • name;
  • email address;
  • username;
  • organization or company information;
  • account identifiers;
  • authentication and authorization information;
  • account preferences and settings; and
  • information you choose to provide to us.

B. Organization and workspace information

If you use an organization account, we may process:

  • organization name and identifiers;
  • membership and role information;
  • administrator and billing contact information;
  • workspace configuration; and
  • access and authorization records.

C. Connected-service and integration information

When you connect a third-party service, such as a source-control or code-hosting provider, we may receive information made available through the permissions you authorize.

Depending on the integration and permissions, this may include:

  • account or organization identifiers;
  • repository metadata;
  • repository names and access permissions;
  • branch, issue, pull-request, workflow, or similar metadata;
  • content or files that you explicitly authorize Mivia to access; and
  • access tokens or credentials handled through supported authentication mechanisms.

We process only the information reasonably necessary for the integration and the features you use.

D. Customer Content

You or your organization may provide or authorize access to:

  • prompts and instructions;
  • source code and other files;
  • repository or project content;
  • workflow definitions;
  • configuration;
  • agent task information;
  • outputs, feedback, and related logs; and
  • other information submitted through the Services.

Customer Content may contain personal information or confidential information. You are responsible for ensuring that you have an appropriate legal basis and authority to provide it to Mivia.

E. Usage, device, and technical information

We may automatically collect:

  • IP address;
  • device and browser information;
  • operating-system information;
  • approximate location derived from IP address;
  • log data;
  • feature usage and interaction information;
  • error, performance, and diagnostic information;
  • security events; and
  • identifiers used to maintain sessions and prevent abuse.

F. Communications and support information

If you contact us, we may collect the content of your communications and information needed to respond to you.

G. Billing and transaction information

For paid Services, we may collect subscription, invoice, tax, and transaction information.

Payment card information should generally be processed by our payment processor rather than stored directly by Mivia, depending on the payment flow we implement.

H. Information from other sources

We may receive information from:

  • identity and authentication providers;
  • third-party integrations you connect;
  • organization administrators;
  • payment processors;
  • security and fraud-prevention providers; and
  • publicly available or lawfully obtained business information.

3. How We Use Personal Information

We use personal information to:

  1. provide, operate, and maintain the Services;
  2. authenticate users and manage accounts;
  3. provide organization and workspace administration;
  4. process and perform requests made through integrations, workflows, agents, and other product features;
  5. process payments and manage subscriptions;
  6. provide support and communicate with you;
  7. secure the Services and investigate suspected fraud, abuse, security incidents, or violations;
  8. detect and prevent attempts to circumvent valid access restrictions;
  9. analyze performance, reliability, and usage;
  10. develop, maintain, and improve product features and operations;
  11. comply with legal obligations and respond to valid legal requests; and
  12. enforce our agreements and protect the rights, property, safety, and legitimate interests of Mivia, users, and others.

We do not use Customer Content to train or improve general-purpose AI models unless we clearly disclose that use and provide any required choice or consent.

Where the GDPR, UK GDPR, or similar law applies, our legal bases may include:

  • Performance of a contract: to provide the Services you request.
  • Legitimate interests: to secure, operate, improve, and protect the Services, prevent fraud and abuse, enforce our terms, and defend legal claims, where those interests are not overridden by your rights.
  • Legal obligation: to comply with applicable law and lawful requests.
  • Consent: where required, including for certain cookies or processing where no other lawful basis applies.

Where we rely on legitimate interests, we consider the nature of the data, the processing context, and the rights and interests of affected individuals.

5. How We Disclose Personal Information

We may disclose personal information to:

Service providers and subprocessors

Providers that help us operate the Services, such as hosting, infrastructure, security, authentication, analytics, communications, support, AI/model providers, and payment services.

We require service providers to process personal information only as permitted by applicable agreements and law.

Organization customers and administrators

If you use an organization account, authorized administrators may be able to access or manage information associated with the organization account, subject to applicable law and the organization's configuration.

Third-party integrations

When you direct us to connect with or send information to a Third-Party Service, we may disclose information as necessary to perform your request and as authorized by you.

Professional advisers and corporate transactions

We may disclose information to professional advisers and in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business.

Legal and safety disclosures

We may disclose information where we reasonably believe disclosure is necessary to comply with law, enforce our agreements, protect security, investigate wrongdoing, or protect the rights, property, or safety of Mivia, users, or others.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless we clearly disclose that practice and provide any legally required notice and choice.

6. AI and Model Providers

Some AI-enabled features may process prompts, Customer Content, or other inputs using models or infrastructure operated by Mivia or third-party providers.

Where a third-party provider processes information on our behalf, we seek to use appropriate contractual and technical controls.

The specific provider used may vary by feature, configuration, availability, model selection, region, or customer settings.

7. International Data Transfers

Mivia is based in the United States and may process information in the United States and other countries where Mivia or its service providers operate.

Those countries may have data-protection laws that differ from the laws of your country.

Where legally required for transfers of personal data, we will use an appropriate transfer mechanism, such as contractual safeguards, an adequacy decision, or another lawful mechanism.

8. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Retention periods depend on the type of information and context.

For example:

  • account information may be retained while your account is active and for a reasonable period afterward;
  • security logs may be retained for a period appropriate to fraud prevention, incident response, and legal obligations;
  • Customer Content may be deleted or made unavailable according to product settings, contractual commitments, or account-deletion procedures; and
  • some information may be retained longer where required or permitted by law.

9. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information.

No system is completely secure. You are responsible for protecting your credentials and configuring access permissions appropriately.

If we become aware of a security incident involving personal information, we will take steps required by applicable law.

10. Cookies and Similar Technologies

We may use cookies, local storage, pixels, SDKs, and similar technologies for:

  • authentication and session management;
  • security and fraud prevention;
  • remembering preferences;
  • measuring performance and reliability; and
  • analytics.

Where required by law, we will obtain consent before placing non-essential cookies or similar technologies.

You can control some cookies through browser settings and, where provided, our cookie preference tools.

11. Access Restrictions and Anti-Circumvention Processing

Mivia may process limited identity, account, organization, integration, billing, security, and relationship information to prevent fraud, abuse, unauthorized access, and circumvention of valid access restrictions.

We do not treat nationality, ethnicity, religion, or another protected characteristic as a standalone basis for access restriction, except where a restriction is required by applicable law.

We also do not automatically treat a person as restricted merely because they are or were an employee, contractor, friend, or other weakly associated person of an organization whose access is restricted.

Where we use automated signals, they may support security decisions, but ambiguous cases may be subject to human review.

You may contact [email protected] or [email protected] to request review of a restriction you believe resulted from incorrect identity or association information, subject to our need to protect security and prevent evasion.

12. Your Privacy Rights

Depending on applicable law, you may have rights to:

  • access personal information;
  • correct inaccurate information;
  • delete personal information;
  • receive a portable copy of certain information;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent; and
  • appeal certain privacy-rights decisions.

To submit a request, email [email protected] with the subject line "Privacy Request."

We may ask you to verify your identity and authority before responding. We will not discriminate against you for exercising applicable privacy rights.

Some information may be retained where permitted or required by law, including for security, fraud prevention, legal claims, or compliance.

13. Additional Information for EEA, UK, and Swiss Individuals

Where applicable, you may also have the right to lodge a complaint with a competent data-protection authority.

If Mivia is not established in the EEA or UK but becomes subject to an obligation to appoint an EU or UK representative, Mivia will provide the representative's details in an applicable regional privacy notice.

14. U.S. State Privacy Disclosures

Residents of certain U.S. states may have additional privacy rights, including rights to know, access, correct, delete, obtain a portable copy, opt out of certain processing, and appeal.

Mivia will honor applicable rights according to the law that applies to the request.

California notice

Where the California Consumer Privacy Act, as amended, applies, Mivia may collect the categories described in Section 2 for the business and commercial purposes described in Section 3.

Mivia does not knowingly sell or share personal information for cross-context behavioral advertising unless we clearly disclose that activity and provide the legally required opt-out mechanism.

California residents may exercise applicable rights by contacting [email protected].

15. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

If we learn that we collected personal information from a child under 13 without legally required authorization, we will take appropriate steps to delete it.

If applicable law imposes a higher minimum age or additional requirements in your jurisdiction, those requirements apply.

16. Changes to This Privacy Policy

We may update this Policy from time to time.

If we make a material change, we will provide notice through the Services, by email, or by another reasonable method where required by law.

The Last updated date above indicates when this Policy was most recently revised.

17. Contact Us

For privacy questions or requests:

MiviaLabs LLC 30 N Gould St Ste N Sheridan, WY 82801 USA

Email: [email protected]