Mise — Privacy Policy
Effective date: June 12, 2026 · Last updated: June 12, 2026
Mise is a calm place for your mind — and your thoughts deserve calm treatment. This policy explains, in plain language, what data Mise collects, why, where it goes, and the rights you have over it. No tricks, no fine-print surprises.
1. Who we are
Mise is operated by Taha Valikhani, an individual based in France (the “we” in this policy, and the data controller under the EU General Data Protection Regulation).
Questions, requests, or concerns: tahavalikhani2010@gmail.com
2. What we collect
Information you give us:
- Account information — your email address and name when you sign up (including via Google sign-in).
- Your content — the notes, tasks, ideas, reminders, and conversations with Weaver that you capture in Mise, in any language you write them. This is the heart of the product, and we treat it as private by default.
- Telegram data — if you connect the Mise Telegram bot, your Telegram user ID and the messages you send to the bot.
- Calendar data — if you enable Google Calendar sync, the reminders Mise creates in your calendar and the permissions needed to create them.
- Payment information — if you subscribe, your payment details are collected and processed by our payment provider, not by us. We never see or store your full card number. No payment information of any kind is collected during the free trial.
Information collected automatically:
- Technical data — basic log and device information (such as IP address, browser type, and timestamps) needed to keep the service running and secure.
- Analytics (future) — we may later add privacy-respecting analytics to understand how Mise is used in aggregate (for example, which features are popular). If we do, we will update this policy first, and any analytics will never read the content of your notes.
We do not collect data for advertising. Mise has no ads and never will sell your personal data.
3. How Mise uses AI (and what that means for your data)
When you capture a thought, Mise sends it to an AI model — currently Google’s Gemini — to understand it: deciding whether it’s a note, task, idea, or reminder; detecting dates; assigning it to projects; clustering related thoughts; and powering Weaver, your AI companion.
Three commitments, regardless of which AI provider we use now or in the future:
- Your content is never used to train AI models — not ours, not the provider’s.
- AI processing happens only to provide Mise’s features to you, nothing else.
- If we change AI providers, this never-for-training commitment travels with us.
Mise’s automated classification only organizes your thoughts. It makes no decisions with legal or similarly significant effects on you.
4. Why we process your data (legal bases under GDPR)
- To provide Mise (storing, organizing, and syncing your thoughts; AI processing; Telegram and calendar integrations) — performance of our contract with you.
- To keep Mise secure and running (logs, abuse prevention) — our legitimate interests.
- To process payments and manage subscriptions — performance of contract and legal obligations.
- Optional features and future analytics — your consent, which you can withdraw at any time.
- To comply with the law or defend legal claims — legal obligation and legitimate interests.
5. Who can access your data
Your data lives in a private Supabase database. The only human with access to it is the operator of Mise (Taha Valikhani), and access happens only when strictly necessary — for example, to fix a problem you’ve reported or to comply with the law. We don’t browse your notes.
We share data only with service providers (processors) who help run Mise, and only what each needs:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and storage |
| Google (Gemini API) | AI understanding of your thoughts — never for training |
| Google Calendar | Creating reminders you’ve asked to sync (only if you connect it) |
| Telegram | Capture via the Mise bot (only if you connect it) |
| Payment provider (to be announced) | Subscription billing |
| Analytics provider (possible, future) | Aggregate usage statistics, never note content |
We may also disclose data if legally required (for example, a valid court order), or to protect Mise’s rights, safety, or users.
We never sell or share your personal data for advertising. For California residents: Mise does not “sell” or “share” personal information as defined by the CCPA/CPRA.
6. International transfers
Mise is operated from France, and some of our providers (such as Google and Supabase, depending on region) may process data in the United States or elsewhere. When data leaves the European Economic Area, we rely on safeguards recognized under GDPR, such as the EU–US Data Privacy Framework and Standard Contractual Clauses.
7. How long we keep your data
- While your account is active — we keep your content so Mise can be your second mind.
- After you delete your account — all of your data is deleted within 1 month (30 days). We keep it briefly only to handle accidental deletions, security investigations, or the establishment, exercise, or defense of legal claims. After that, it’s gone.
- Logs and technical data — kept for short, rolling periods needed for security.
- Some minimal records (for example, payment and invoicing records) may be kept longer where the law requires it.
8. Your rights
Wherever you live, we extend the strongest set of rights to you:
- Access — get a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your account and data (you can do this yourself, in-app, anytime).
- Portability — receive your data in a usable format.
- Restriction and objection — limit or object to certain processing.
- Withdraw consent — at any time, for anything based on consent.
- No discrimination — exercising your rights never affects the service you receive.
To exercise any of these, use the in-app controls or email tahavalikhani2010@gmail.com. We respond within one month (GDPR) or 45 days (CCPA).
If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority. In France, that is the CNIL (www.cnil.fr).
9. Security
We use industry-standard measures to protect your data: encrypted connections (TLS), encrypted storage, access limited to a single authorized person, and provider-level security from Supabase and Google. No system is perfectly secure, but your thoughts are treated with the care they deserve. If a breach ever affects your personal data, we will notify you and the relevant authorities as required by law.
10. Children
Mise is for people 16 and older. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has created an account, contact us and we will delete it.
11. Languages
Mise speaks many languages, and so should its promises. This policy is written in English; where Mise is offered in other languages, we will make this policy available in those languages too. If versions ever differ, the English version controls, except where local law requires otherwise.
12. Changes to this policy
If we change this policy in a meaningful way — for example, adding analytics or changing AI providers — we will update the date at the top and let you know in the app or by email before the change takes effect. Quiet, but never silent.
13. Contact
Taha Valikhani France tahavalikhani2010@gmail.com