mivenn — privacy notice
Version 2026-06-18.1
Who is responsible (the controller)
This Mivenn network is operated by:
Mutega AB
Hantverksgatan 36
434 42 Kungsbacka, Halland, Sweden
info@mivenn.com
Mutega AB is the data controller under the EU General Data Protection Regulation (GDPR) for the personal
data processed on this network. All data is stored in a MySQL database on the operator's own server.
No data is sent to advertisers, analytics companies, data brokers or any other third party. Push
notifications to the Mivenn mobile app are delivered through Apple and Google, which act only as the
messenger for us (see Notifications and the mobile app).
Who can use Mivenn — ages 13 and over
Mivenn is intended for people aged 13 and over. You must be at least 13 years old to create an
account. If you are under 13 you may not use Mivenn, and parents or guardians should not create an account on
a young child's behalf. If we learn that an account belongs to a child under 13, we remove it and erase its
data.
Members who are under 18 are treated as younger members and are given stronger privacy and safety
settings by default — see Younger members and parents below. Because Mivenn shows no
advertising, sells no data and uses no third-party tracking or profiling, younger members are never targeted
or profiled.
What we store, and why
- Account data — your username, display name, a hashed password (Argon2id; we can never read it),
the invitation chain (who invited you, whom you invited), your join date, and the time and version of your
consent to this notice. Legal basis: contract (Art. 6.1.b) — this is what makes your account work.
- Optional email address — only if you choose to enter one in Settings, your email address and your
notification preference. It is used solely to notify you about new comments on your posts, incoming friend
requests, and your invitation being used. It is never shown to other members and never shared with anyone.
You can remove it at any time by saving an empty address.
Legal basis: consent (Art. 6.1.a).
- Optional profile details — a profile photo (resized to a small avatar and re-encoded so hidden
metadata such as GPS coordinates is removed), and, only if you choose to enter them, your birthday
(year optional), city and country. You choose who can see these details (only you, friends, or friends of
friends), and friends who can see your birthday are shown a small note on the day itself.
Legal basis: consent (Art. 6.1.a) — you may leave all of these empty, and you can erase them at any time.
- Posts and photos — what you publish, with your chosen audience (only me, friends, or friends of
friends, or a group), its optional fade timer, and an edit timestamp if you change a post during its first
5 minutes. Photos in posts are also re-encoded to strip hidden metadata. Posts with a fade timer are
deleted from the database when the timer runs out — not archived or hidden.
Legal basis: contract (Art. 6.1.b).
- Comments and likes — comments you write and likes you give on posts you are allowed to see.
Legal basis: contract (Art. 6.1.b).
- Groups — groups you create or belong to, and their member lists. Group posts and events are
visible only to group members. Legal basis: contract (Art. 6.1.b).
- Events and RSVPs — events you host (title, description, place, time, audience) and your answers
(going / maybe / no) to events you can see. You can download events as .ics files and subscribe to a
personal calendar feed protected by a private random token in its address; anyone who has that exact
address can read your event list, so treat the link like a password. Legal basis: contract (Art. 6.1.b).
- Messages — private messages are encrypted in your browser before they reach the server; the
database stores only the encrypted form. Legal basis: contract (Art. 6.1.b).
- Friendships, requests and blocks — who you are friends with, pending requests, and members you
have chosen to block. Blocking is mutual hiding: a blocked member and you no longer see each other's posts,
comments or events, and any friendship between you is removed. The block list is visible only to you.
Legal basis: contract (Art. 6.1.b).
- Feedback and reports — if you send feedback or report a post, the text you wrote (and, for a
report, a short excerpt of the reported post) is stored in the database and also emailed to the operator at
info@mivenn.com so it can be acted on. Legal basis: legitimate interest (Art. 6.1.f) — improving the
service and keeping it safe.
- Security log — a small log of security-relevant events (failed sign-ins, rate-limit hits) with
truncated IP addresses (the last part is removed), kept to protect the service against abuse.
Legal basis: legitimate interest (Art. 6.1.f) — keeping members' accounts safe.
- Calls and meetings — when you start or join a voice or video call, or schedule a meeting, we store
only what is needed to connect you: who is invited, the status, the timing, and RSVPs. The audio and video
themselves stream directly between participants (encrypted in transit) and are never recorded or
stored by Mivenn. Legal basis: contract (Art. 6.1.b).
- Notification tokens — if you use the Mivenn mobile app and allow notifications, we store the push
token your device provides so we can alert you to a new message or an incoming call. It is deleted when you
sign out, turn notifications off, or delete your account. Legal basis: consent (Art. 6.1.a).
- Parental and screen-time settings — for younger members and the parents linked to them, we store
the parent/child link and any screen-time limits, quiet hours and content filters (such as the blocked-word
list) that have been set. Legal basis: contract (Art. 6.1.b) and our legitimate interest in keeping
younger members safe (Art. 6.1.f).
How long we keep it
Your data is kept only while your account exists. Fading posts are deleted when their timer expires.
Rate-limit records are deleted after 24 hours. Remember-me tokens expire after 30 days and are deleted when
you sign out or change your password. Security log files are small, rotated, and contain only truncated IP
addresses. When you delete your account, everything listed above is erased immediately — including your email
address, your comments and likes, comments and likes others left on your posts, groups you own (with their
content), your events and all RSVPs to them, your feedback, your reports, your block list, your notification
tokens, your call and meeting records, any parent/child links and screen-time settings, and your remember-me
tokens. There are no backups of deleted content held by Mivenn itself.
Your rights
- Access & portability — the "Export my data" button in Settings downloads every record about
you as a JSON file, at any time, no questions asked.
- Rectification — change your display name, password, photo, email and personal details yourself in Settings.
- Erasure — the "Delete my account & data" button removes every record about you from the
database in one transaction. This is immediate and irreversible.
- Withdraw consent — optional details (email, photo, birthday, city, country) can be removed at any
time in Settings; deleting your account withdraws all consent.
- Complain — you can always contact info@mivenn.com, and you have
the right to lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY),
at www.imy.se.
Cookies
Mivenn sets at most two cookies, both strictly functional:
- MIVENNSESS — a session cookie that keeps you signed in. It contains a random identifier only and
expires when your session ends.
- MIVENNREMEMBER — set only if you tick "Keep me signed in" at sign-in. It contains a random
token (no personal data), lasts at most 30 days, can only be used once before being replaced, and is deleted
when you sign out or change your password.
Neither cookie is used for tracking. There are no analytics, advertising or third-party cookies.
Who can see what
Mivenn is invite-only. Members who are not your friends see only your name and username. Your posts are
visible to the audience you pick for each post — only you, your friends, your friends of friends, or one of
your groups; there is no public audience. Your optional details follow the visibility you choose in Settings.
Members you block, and members who block you, see none of your content. Your private messages are readable
only in your and your friend's browsers.
Calls, video and meetings
Mivenn lets you talk one-to-one or in a group by voice or video, share your screen, and schedule meetings
that others can RSVP to. To connect a call we store only what is needed to set it up and ring the right people
— who is invited, the status and the timing. The live audio and video stream directly between the
participants wherever possible and are encrypted in transit; Mivenn does not record, listen to, or store
the contents of any call. Your device asks for microphone and (for video) camera permission the first time,
and you can decline or revoke it in your device settings.
Notifications and the mobile app
The Mivenn mobile app wraps this same website and adds two native abilities: it can use your microphone and
camera for calls, and it can show push notifications. If you allow notifications, your device gives the app a
push token that we store so we can alert you to a new message or an incoming call. Those alerts are
delivered through Apple Push Notification service (iPhone/iPad) and Firebase Cloud Messaging
(Android), which act purely as the delivery channel. Because your private messages are end-to-end encrypted, a
notification only tells you who is contacting you — never the message text. You can turn notifications
off at any time in your device settings; the token is removed when you do, when you sign out, or when you delete
your account.
Younger members and parents
Mivenn is built to be a calmer, safer place for younger members (under 18), and especially for the youngest
who are 13 and over. By default, younger members get stronger privacy and safety settings:
- A smaller, invite-only world — there is no public feed and no strangers; younger members connect
only with people in their own circle, by invitation.
- No ads, no tracking, no data selling — ever, for anyone.
- Content filtering — a blocked-word filter can hide inappropriate language for younger members, and
moderators can remove posts that break the rules.
- Screen-time and quiet hours — parents can set healthy limits and quiet hours, and younger members
can see their own usage.
- Parental oversight — a parent or guardian can be linked to a younger member's account to help
manage these settings. Parents do not read end-to-end encrypted private messages, which stay
readable only on the participants' own devices.
Parents or guardians who want to review their child's information, adjust settings, or have an account
removed can contact us at info@mivenn.com at any time.
Changes to this notice
If this notice changes, the version number above changes and members are asked to review it. The version
you accepted is recorded with your account and included in your data export.
← Back to Mivenn