Privacy Policy

Data Protection Declaration according to GDPR (EU General Data Protection Regulation)

1. Controller and Privacy Contact

The controller responsible for data processing on this website is:

Victor Gulchenko
Mimiq AI
Email: victor@mimiqai.com

2. General Information on Data Processing

2.1 Scope of Personal Data Processing

We process personal data only to the extent needed to operate, secure, support, and improve the service, using the legal basis that applies to each purpose. Consent is required for optional analytics; service delivery, security, billing, and legal compliance may rely on other applicable bases described below.

2.2 Legal Basis for Personal Data Processing

We process personal data based on the following legal bases:

  • Art. 6(1)(a) GDPR - User consent
  • Art. 6(1)(b) GDPR - Contract performance and pre-contractual measures
  • Art. 6(1)(c) GDPR - Legal obligation
  • Art. 6(1)(f) GDPR - Legitimate interests

2.3 Data Deletion and Storage Duration

Personal data is deleted or blocked as soon as the purpose of storage no longer applies. Storage may continue if required by EU or national law.

3. Website Usage and Log Files

3.1 Description and Scope

When you visit our website, our delivery and application infrastructure may collect the following data:

  • Browser type and version
  • Operating system
  • Referrer URL (previously visited page)
  • Hostname of accessing computer
  • Time of server request
  • IP address

3.2 Legal Basis and Purpose

The legal basis for temporary storage is Art. 6(1)(f) GDPR. The data is necessary to deliver website content to users and ensure website functionality, security, and system stability.

3.3 Storage Duration

Infrastructure logs are retained according to the active AWS and application logging configuration and may be kept longer when required for security, fraud prevention, or legal obligations. Ask us for the current retention schedule before submitting regulated data; a single enforced retention policy is still being formalized.

4. User Accounts and Registration

4.1 Data Collected

When you create an account, we collect:

  • Email address (required)
  • Name (optional)
  • Profile information (optional)
  • Account creation date
  • Last login date

4.2 Legal Basis

Required account processing is based primarily on Art. 6(1)(b) GDPR for contract performance or pre-contractual steps. Separate consent applies only where it is specifically requested, such as optional analytics.

4.3 Storage Duration

Account data is kept while the account is active and as needed for billing, security, and legal obligations. Account-wide deletion is currently handled by request at victor@mimiqai.com; we respond and act within the periods required by applicable law.

5. Simulation Data

5.1 Data Collected

When you use our AI simulation service, we collect and process:

  • Product ideas and descriptions you submit
  • Publicly reachable URLs, screenshots, and other content you choose to test
  • Selected audience parameters
  • Optional customer or analytics rows you choose to import
  • Generated simulation results
  • Interaction data with personas
  • Usage timestamps

5.2 Purpose

This data is processed to recruit a simulated audience, run the requested page, flow, or question test, produce a decision brief, preserve the report, prevent abuse, and provide support. Submitted prompts and content may be sent to model providers through AWS Bedrock. Mimiq does not recruit real study participants for a standard simulation.

5.3 Storage Duration

Simulation and report data is retained until it is deleted through an available product control or an account-level deletion request, subject to security, backup, billing, and legal requirements. Do not submit personal or sensitive data unless you are authorised to process it and it is necessary for the test.

6. Third-Party Services and Data Processors

We use the following third-party services that process data on our behalf:

6.1 Clerk (Authentication)

For user authentication and account management, we use Clerk, Inc.

  • Data processed: Email, name, authentication tokens
  • Location/transfer terms: See Clerk's current privacy terms and request Mimiq's current sub-processor list
  • Privacy policy: https://clerk.com/privacy

6.2 Stripe (Payment Processing)

For payment processing, we use Stripe, Inc.

  • Data processed: Payment information, billing address, transaction data
  • Location/transfer terms: See Stripe's current privacy terms and request Mimiq's current sub-processor list
  • Privacy policy: https://stripe.com/privacy

6.3 AWS and AWS Bedrock

We use Amazon Web Services for application delivery, compute, queues, data storage, logs, and model inference through AWS Bedrock.

  • Data processed: Account identifiers, submitted test content, generated personas and results, application data, and logs
  • Location: The launch stack and configured model inference profiles use United States regions
  • Purpose: Hosting, persistence, browser-worker execution, and model inference
  • Privacy policy: https://aws.amazon.com/privacy/

6.4 PostHog (Optional Product Analytics)

If you explicitly allow analytics and PostHog is configured, we use PostHog to measure the activation funnel and product reliability.

  • Data processed: Pseudonymous activation ID, route, mode, milestone, latency, aggregate counts, and normalized failure class
  • Not collected by Mimiq analytics: Session replay, DOM text, raw URLs with queries, prompts, goals, answers, or raw error messages
  • Worker boundary: Terminal simulation events are sent only when the browser attached an activation ID after opt-in; account and guest identifiers are excluded
  • Legal basis: Your consent; analytics remains disabled until you choose “Allow” in the analytics banner
  • Privacy policy: https://posthog.com/privacy

7. Cookies and Local Storage

Our website uses cookies and local storage to improve functionality and user experience.

7.1 Essential Cookies (No Consent Required)

These are technically necessary for basic website functionality and are loaded without consent based on Art. 6(1)(b) and (f) GDPR:

  • Authentication cookies (Clerk): Session management and login functionality
  • Guest identity: A random browser identifier that lets an anonymous visitor reopen the test they created
  • Application state: Local or session storage for preferences, in-progress runs, deduplication, and recovery
  • Consent choice: Local storage remembers whether you allowed optional analytics

You can block or clear these technologies in your browser, but authentication, recovery, saved preferences, or other core functions may then stop working.

7.2 Analytics Cookies (Consent Required)

If PostHog is configured, it is not initialized until you explicitly allow analytics in the preference banner.

  • Provider: PostHog
  • Data collected: Explicit page and activation events, pseudonymous identifiers, route, mode, aggregate counts, normalized failure class, and latency
  • Data excluded: Session replay, automatic click capture, DOM text, test prompts/content, URL queries, and raw errors
  • Purpose: Understand whether people reach a clean decision brief and where the service fails
  • Legal basis: Art. 6(1)(a) GDPR (consent)
  • Persistence: PostHog local storage and cookies after opt-in

Your choice: Declining keeps analytics disabled. Allowing analytics initializes PostHog. You can change that choice here at any time.

No choice saved

7.3 Your Cookie Rights

You can control cookies through:

  • Browser settings (block all cookies or specific domains)
  • Opt-out links provided by analytics services

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

8.1 Right to Information (Art. 15 GDPR)

You can request confirmation about whether and which personal data we process.

8.2 Right to Rectification (Art. 16 GDPR)

You can request correction of incorrect personal data.

8.3 Right to Erasure (Art. 17 GDPR)

You can request deletion of your personal data if legal requirements are met.

8.4 Right to Restriction (Art. 18 GDPR)

You can request restriction of data processing under certain conditions.

8.5 Right to Data Portability (Art. 20 GDPR)

You can request to receive your data in a structured, commonly used format.

8.6 Right to Object (Art. 21 GDPR)

You can object to processing based on legitimate interests (Art. 6(1)(f) GDPR).

8.7 Right to Withdraw Consent (Art. 7(3) GDPR)

You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe your data is being processed unlawfully.

To exercise these rights, please contact: victor@mimiqai.com

9. Data Security

We use appropriate technical and organizational measures to protect your data from unauthorized access, loss, or alteration:

  • TLS from your browser to CloudFront and for provider API calls; the restricted CloudFront-to-ALB origin hop uses HTTP with an AWS-managed CloudFront network allowlist and secret origin header
  • AWS-managed encryption for DynamoDB storage
  • Owner and verified-organization access checks, including read-only sanitized public-share payloads
  • Secrets Manager and scoped task roles in the AWS launch stack
  • Automated cross-tenant, share, and regression tests as release gates

Mimiq has not completed a SOC 2 audit or third-party penetration test. Those controls are described as roadmap work, not current certifications.

10. International Data Transfers

The launch architecture uses United States AWS regions and some providers may process data outside the EEA. Before submitting personal data, request the current sub-processor list and DPA so you can assess the applicable transfer mechanism, such as Standard Contractual Clauses or an adequacy framework where available.

11. Children's Privacy

Our service is not directed to persons under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.

12. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or through our service.

Last updated: July 18, 2026

13. Contact

If you have questions about this privacy policy or data processing, please contact:

Victor Gulchenko
Mimiq AI
Email: victor@mimiqai.com