Mikoshi
Pricing Sign in Get started

Privacy Policy

Last updated: June 30, 2026

1. Information We Collect

Account data: Your email address, display name, and password (bcrypt-hashed at rest). We use your email for authentication, verification, and account notices.

Usage data: Messages you send, personas you create, conversation history, token consumption, and associated cost records. This data powers the Service's memory, summarization, and billing features.

Technical data: IP address, request logs, and browser metadata for security, rate limiting, and abuse prevention.

2. How We Use Your Data

  • Provide the Service: process messages, manage personas, and display conversations.
  • Enforce limits: track usage for quota enforcement and billing.
  • Improve the Service: aggregate, anonymized analytics on feature usage.
  • Protect the Service: detect and prevent abuse, fraud, and unauthorized access.

3. Data Sharing and Third Parties

We do not sell your data. We share data with these service providers strictly to operate the Service:

  • OpenRouter: Processes your prompts and generates responses. Message content is sent to OpenRouter for inference.
  • Stripe: Processes payments. Stripe receives billing information; we never store full card numbers.
  • Hosting provider: Stores the database and application files.

We may disclose data when required by law or to protect our rights and safety.

4. Data Retention

We retain your data for as long as your account is active. When you delete your account, your messages, personas, facts, sessions, and uploads are removed from the database. Anonymized aggregate analytics may be retained indefinitely.

5. Your Rights

Depending on your jurisdiction (GDPR, CCPA, PIPEDA), you may have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of your data.
  • Export your data (available via account settings).
  • Withdraw consent or object to processing.

To exercise these rights, use the data export or account deletion features in settings, or contact us through your account.

6. Security

Passwords are hashed with bcrypt. Sessions use 256-bit entropy tokens stored hashed at rest. All database queries use parameterized statements (no SQL injection). The production deployment enforces CSP and HSTS headers. No method of transmission or storage is fully secure, but we follow industry best practices.

7. Cookies

We use a session cookie for authentication. We do not use third-party tracking or advertising cookies.

8. Children's Privacy

The Service is not intended for children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice. The "Last updated" date above reflects the most recent revision.

10. Contact

Questions about your privacy? Reach out via the support channels listed in your account settings.

Mikoshi
Pricing Terms Privacy Sign in