Privacy Policy
Who Operates Mivo
Mivo is operated by the individual developer identified as the Seller on Mivo’s App Store product page (“Mivo,” “we,” or “us”). This policy covers the Mivo iOS app, its first-party gateway, account and cloud-memory services, and the public legal pages. Contact: [email protected]. Mivo is local-first, has no advertising or third-party behavioral analytics SDK, and does not track you across apps or websites. Most features stay on your device; AI network processing occurs only after the separate permission described below.
1. Photo Library and On-Device Processing
With the Photos permission you choose, Mivo reads photos, videos, metadata, thumbnails, favorite status, and library identifiers to show memories, compare items, calculate storage, find possible similar or duplicate photos, group bursts and screenshots, and carry out deletions you confirm. Browsing, cleanup analysis, general visual feature caches, and full conversation history are stored or processed on device by default. Mivo does not run human face detection, create faceprints or biometric templates, cluster people, recognize identities, or determine whether the user appears in a photo. It never deletes media automatically; deletion requires Apple’s system confirmation.
2. Pet Recognition
Mivo may use Apple’s Vision framework on device to detect cats or dogs, crop the animal region, and create general image feature representations that help distinguish pets after you confirm a pet name in conversation. Pet feature representations stay on the device and are not uploaded or included in cloud memory. A limited text label, such as a user-confirmed pet name or an uncertain match, may be included in an AI request. You can remove this local data with Clear AI Memory. This is animal matching, not human face recognition.
3. Optional AI Data Sharing
AI is optional. Before Mivo sends the first AI request, it presents a separate disclosure and asks you to agree. Only when you deliberately invoke AI for the current photo does Mivo create a JPEG copy reduced to about 512 pixels and send it through Mivo’s encrypted gateway to Alibaba Cloud Model Studio’s Qwen service in the United States (Virginia). The request can also include capture time, favorite status, and a coarse city or place label derived locally from the photo’s GPS metadata. Mivo does not send precise coordinates or access live location. Qwen returns a temporary text visual summary. Mivo then sends that summary, prompts, the current conversation, and selected AI memory or profile clues to the DeepSeek API for the opening, later replies, and memory distillation. DeepSeek does not receive the photo copy. Photos for which you do not invoke AI, and all videos, are not uploaded for AI.
4. Account, Purchase, and Security Data
Sign in with Apple provides Mivo with an app-specific Apple user credential; Mivo does not request your Apple name or email scopes. Mivo creates an internal account identifier and processes session tokens, account status, deletion requests, and login timestamps. For subscriptions and usage limits, Mivo processes verified StoreKit transaction or entitlement information, product and tier, quota counters, and billing-related status; Apple handles payment details. Security and delivery data can include IP address, an app-scoped random installation identifier, App Attest proofs and challenges, request timestamps, hashed photo-session identifiers, and authentication or abuse signals. Tokens are stored in Apple’s Keychain.
5. AI Memory and Local Data
Full AI conversations, detailed browsing and deletion history, favorites, raw PhotoKit identifiers, and visual feature caches remain on the device. To restore My Memories achievements across devices, Mivo stores account-level viewed-photo and viewed-video counts together with double-hashed deduplication keys derived from library identifiers; those keys do not include photo or video content. To continue personalization across devices, Mivo may also sync a deliberately limited document tied to your Mivo account: distilled stable facts from conversation, inferred preferences, persona parameters, and pet names. Cloud memory excludes photos, videos, full transcripts, raw PhotoKit identifiers, and pet visual feature representations. On-device AI data is isolated to the signed-in Mivo account; signing out or switching accounts clears that local AI data before the next account is loaded. The current version deletes any legacy human-face feature records left by an older version and no longer creates them.
6. Operations and Analytics
Mivo uses a small allowlist of first-party events to measure activation, reliability, cost, subscription conversion, and feature availability. Records may include salted or hashed identifiers, event name, count, entitlement tier, quota state, model/provider route, token usage, latency, and failure category. They do not include photo pixels, full prompts, full AI responses, full conversation text, or precise tap coordinates. Mivo does not use IDFA, third-party behavioral analytics, advertising profiles, or cross-app tracking.
7. Why We Process Information
Mivo processes information to provide features you request; authenticate accounts; protect subscriptions and enforce quotas; personalize conversations and sync limited memory; secure, debug, and improve service reliability; communicate about support or material service changes; prevent fraud and abuse; and comply with legal obligations. Depending on applicable law, the legal basis is performance of the service contract, your consent for optional AI sharing, our legitimate interests in security and operation, or compliance with law. You may withdraw AI permission for future requests at any time by turning AI off.
8. Recipients and International Transfers
Information is disclosed only as needed to: (a) Apple for Sign in with Apple, StoreKit, App Attest, and platform services; (b) Mivo’s hosting, database, and security infrastructure for accounts, memory, and gateway delivery; (c) Alibaba Cloud Model Studio’s Qwen service for the compressed photo and limited clues described above; and (d) DeepSeek’s Open Platform API for the text inputs described above. These recipients can process information outside your country. Qwen is currently routed to a U.S. Virginia region; DeepSeek processing may occur in China or other locations used for its API. We may also disclose information when legally required, to protect rights and safety, or as part of a business transfer with continued privacy obligations.
9. Sale, Advertising, and Model Training
Mivo does not sell or rent personal information, share it for cross-context behavioral advertising, or use AI request content to train a Mivo model. Mivo submits AI content to obtain the requested output, not for Mivo advertising. Provider-side retention, service improvement, and model-use practices depend on the provider’s current API terms and the Developer’s account configuration; Mivo does not promise a provider-side no-training rule unless its applicable terms expressly provide one. Mivo will not affirmatively authorize a materially broader use of your content without updating this policy and obtaining any consent required by law or Apple rules.
10. Retention and Deletion
Ordinary local data remains until you clear it or remove the App, subject to iOS Keychain behavior. Mivo’s gateway does not intentionally log AI request bodies or persist AI photo copies; the on-device visual summary cache is session memory. Limited cloud AI memory remains until you clear AI memory or delete the account; account-level My Memories achievements remain until the account is deleted. Account deletion removes the account, profile-achievement deduplication keys, associated cloud memory, and sessions. Security, quota, transaction, fraud-prevention, backup, and aggregate records may remain for the period reasonably necessary for service integrity, accounting, disputes, or law. AI providers may retain inputs or logs under their API terms; deleting Mivo data may not erase copies they must or are permitted to retain.
11. Your Choices and Privacy Rights
You can limit Photos access in iOS Settings; turn off AI and withdraw future AI-sharing permission; clear local and cloud AI memory; reset browsing history; sign out; or permanently delete the account in Mivo. You may email [email protected] to request access, correction, deletion, or a copy of account-level personal information, or to appeal a denied request. We may verify the request and retain information where an exception applies. Authorized agents may submit requests where law permits. Mivo does not discriminate for exercising privacy rights. Because Mivo does not sell personal information or conduct cross-context behavioral advertising, “Do Not Track” and Global Privacy Control signals do not change the App’s current behavior.
12. Children and Security
Mivo is not directed to children under 13 and does not knowingly collect their personal information. Users who are 13 but under the age of majority should use Mivo with a parent or guardian’s approval. Contact us if you believe a child’s information was processed. Mivo uses transport encryption, access controls, app attestation, token protection, and other reasonable safeguards, but no internet or storage system is completely secure. Avoid submitting highly sensitive documents or information to AI.
13. Changes, Language, and Contact
We may update this policy as features, providers, or law change and will display the new date. Material changes will be presented conspicuously; if a new use requires consent, Mivo will ask before that use begins. The English text is the primary version for the U.S. release, and the Chinese text is provided as a faithful translation; mandatory law controls. Operator: the individual developer identified as Seller on Mivo’s App Store product page. Privacy and support contact: [email protected].
隐私政策
运营者与政策范围
Mivo 由其 App Store 产品页面中标示为“销售方”的个人开发者运营(以下简称“Mivo”或“我们”)。本政策适用于 Mivo iOS App、第一方网关、账号与云记忆服务以及公开法律页面。联系邮箱:[email protected]。Mivo 坚持本地优先,不含广告或第三方行为统计 SDK,也不跨 App 或网站追踪你。绝大多数功能留在设备上;AI 联网处理仅在取得下述单独许可后发生。
一、相册与本机处理
在你选择授予的照片权限范围内,Mivo 会读取照片、视频、元数据、缩略图、收藏状态和图库标识,用于展示回忆、比较内容、计算空间、查找可能的相似或重复照片、整理连拍和截图,并执行你确认的删除。本地浏览、清理分析、通用视觉特征缓存和完整对话历史默认在设备上存储或处理。Mivo 不执行人物人脸检测,不创建人脸特征或生物识别模板,不聚类人物、不识别身份,也不判断用户是否出现在照片中。媒体不会被自动删除,删除必须经过 Apple 系统确认。
二、宠物识别
Mivo 可能在本机使用 Apple Vision 框架检测猫或狗、裁剪动物区域,并生成通用图像特征表示,以便在你于对话中确认宠物名字后区分宠物。宠物特征表示仅留在设备上,不上传,也不进入云记忆。已由用户确认的宠物名字或不确定匹配等有限文字标签,可能随 AI 请求发送。你可通过“清空 AI 记忆”删除这些本地数据。该能力属于动物匹配,不是人物人脸识别。
三、可选的 AI 数据共享
AI 功能完全可选。首次发送 AI 请求前,Mivo 会展示单独说明并征得你的同意。只有当你对当前照片主动召唤 AI 时,Mivo 才会生成一份长边约 512 像素的 JPEG 副本,并经 Mivo 加密网关发送给阿里云百炼位于美国弗吉尼亚的千问服务。请求还可能包含拍摄时间、收藏状态,以及在本机根据照片 GPS 元数据解析出的粗粒度城市或地点标签。Mivo 不发送精确坐标,也不访问实时位置。千问返回临时的纯文字视觉摘要;随后,Mivo 将该摘要、提示词、当前对话和筛选出的 AI 记忆或画像线索发送给 DeepSeek API,用于开场、后续回复和记忆提炼。DeepSeek 不接收照片副本。未主动召唤 AI 的照片以及所有视频不会为 AI 上传。
四、账号、购买与安全数据
“通过 Apple 登录”会向 Mivo 提供仅限本 App 的 Apple 用户凭据;Mivo 不申请 Apple 姓名或邮箱权限。Mivo 会创建内部账号标识,并处理会话令牌、账号状态、注销请求和登录时间。为管理订阅和用量限制,Mivo 会处理已验证的 StoreKit 交易或权益信息、产品与层级、额度计数和账单相关状态;支付信息由 Apple 处理。安全与传输数据可能包括 IP 地址、仅限本 App 的随机安装标识、App Attest 证明与挑战、请求时间、经哈希处理的照片会话标识,以及认证或滥用信号。令牌存储在 Apple 钥匙串中。
五、AI 记忆与本地数据
完整 AI 对话、详细浏览与删除历史、珍藏、原始 PhotoKit 标识和视觉特征缓存留在设备上。为跨设备恢复“我的回忆”成就,Mivo 会保存账号级已回看照片和视频数量,以及由图库标识派生并经过客户端与服务端双重哈希的去重键;这些键不包含照片或视频内容。为在设备间延续个性化,Mivo 还可能向账号同步一份严格受限的文档,包括从对话中提炼的稳定事实、推断偏好、人格参数和宠物名字。云记忆不包含照片、视频、对话全文、原始 PhotoKit 标识或宠物视觉特征表示。本机 AI 数据与当前登录的 Mivo 账号隔离;退出或切换账号时,会先清除该账号在本机的 AI 数据,再载入下一账号。当前版本会删除旧版本可能遗留的人物人脸特征记录,并且不再创建此类数据。
六、运行与统计
Mivo 仅使用少量白名单第一方事件衡量激活、可靠性、成本、订阅转化和功能可用性。记录可能包括加盐或哈希标识、事件名称、次数、权益层级、额度状态、模型或服务商路由、token 用量、延迟和失败类别;不包含照片像素、完整提示词、完整 AI 回复、完整对话正文或精确点击坐标。Mivo 不使用 IDFA、第三方行为统计、广告画像或跨 App 追踪。
七、处理目的与依据
Mivo 处理信息用于提供你请求的功能、验证账号、保护订阅并执行额度、个性化对话并同步有限记忆、保障安全与排障并改善可靠性、处理支持或重大服务变更通知、防止欺诈与滥用,以及履行法律义务。根据适用法律,处理依据可能是履行服务合同、你对可选 AI 共享的同意、我们在安全与运营方面的合法利益,或遵守法律。你可随时关闭 AI,撤回对未来请求的许可。
八、接收方与跨境传输
信息仅在必要范围内提供给:(a) 用于“通过 Apple 登录”、StoreKit、App Attest 和平台服务的 Apple;(b) 用于账号、记忆和网关传输的 Mivo 托管、数据库和安全基础设施;(c) 接收上述照片压缩副本与有限线索的阿里云百炼千问服务;以及 (d) 接收上述文字输入的 DeepSeek 开放平台 API。这些接收方可能在你所在国家以外处理信息。千问当前路由到美国弗吉尼亚区域;DeepSeek API 处理可能发生在中国或其使用的其他地点。法律要求、保护权利与安全,或在继续承担隐私义务的业务转让中,我们也可能披露必要信息。
九、出售、广告与模型训练
Mivo 不出售或出租个人信息,不为跨场景行为广告共享信息,也不使用 AI 请求内容训练 Mivo 自有模型。Mivo 提交 AI 内容是为了取得你请求的输出,而不是用于 Mivo 广告。服务商侧的留存、服务改进和模型使用规则取决于其现行 API 条款及开发者账号配置;除非适用条款明确承诺,否则 Mivo 不承诺服务商侧绝不用于训练。未经更新本政策并取得法律或 Apple 规则要求的同意,Mivo 不会主动授权对你的内容作实质更广泛的使用。
十、留存与删除
普通本地数据会保留到你主动清除或删除 App,Apple 钥匙串行为由 iOS 控制。Mivo 网关不会主动记录 AI 请求正文,也不会持久保存 AI 照片副本;设备上的视觉摘要缓存仅存在于会话内存。有限云端 AI 记忆会保留到你清空 AI 记忆或注销账号;账号级“我的回忆”成就会保留到账号注销。注销会删除账号、成就去重键及关联云记忆,并撤销会话。安全、额度、交易、反欺诈、备份和聚合记录可能在维护服务完整性、财务、争议或法律所合理需要的期限内保留。AI 服务商可能依其 API 条款保留输入或日志;删除 Mivo 数据不一定能清除其依法或依条款必须、可以保留的副本。
十一、你的选择与隐私权利
你可以在 iOS 设置中限制照片权限,关闭 AI 并撤回未来 AI 共享许可,清除本机和云端 AI 记忆,重置浏览记录,退出登录,或在 Mivo 内永久注销账号。你可发送邮件至 [email protected],请求访问、更正、删除或获取账号级个人信息副本,或对被拒请求提出申诉。我们可能验证请求,并在存在法定例外时保留信息。法律允许时,授权代理人也可提交请求。Mivo 不会因你行使隐私权而歧视你。由于 Mivo 不出售个人信息,也不进行跨场景行为广告,“Do Not Track”和全球隐私控制信号不会改变 App 当前行为。
十二、儿童与安全
Mivo 不面向 13 周岁以下儿童,也不会在知情情况下收集其个人信息。年满 13 周岁但尚未达到法定成年年龄的用户,应在父母或监护人同意下使用。若你认为儿童信息被处理,请联系我们。Mivo 使用传输加密、访问控制、App Attest、令牌保护和其他合理安全措施,但任何互联网或存储系统都无法保证绝对安全。请避免向 AI 提交高度敏感的文件或信息。
十三、变更、语言与联系
我们可能随功能、服务商或法律变化更新本政策,并标示新日期。重大变化会以醒目方式提示;新增用途需要同意时,Mivo 会在开始前征求。英文文本是美国发布版本的主要文本,中文为忠实译文;强制性法律优先。运营者:Mivo App Store 产品页面中标示为“销售方”的个人开发者。隐私与支持邮箱:[email protected]。