1. Information we collect
- Account information: your name, email address, sign-in provider, and provider-specific account identifier.
- Photos and creative inputs: selfies, optional reference images, feeling descriptions, generation prompts, and related metadata.
- Generated content: Minis, moods, variants, titles, subtitles, and selected images.
- Partner and communication data: partner connections, Moments, short messages, replies, timestamps, and selected variants.
- Safety reports: report reasons, reported content and related account, connection, and technical information needed to review a report and prevent repeated abuse.
- Subscription data: plan status, product, billing period, entitlement status, transaction references, and credit balances. We do not receive complete payment-card details.
- Device and technical data: platform, push and widget tokens, app activity needed for synchronization, network requests, errors, security events, and diagnostic logs.
2. How we use information
We use information to authenticate accounts; create and store Minis; deliver Moments, widgets, and notifications; connect partners; process entitlements and credits; provide support; diagnose failures; prevent abuse; review reports; protect accounts; and comply with legal obligations.
When you ask Mini Us to generate a Mini or mood, the selected photos and descriptions may be securely shared with one or more AI processors—OpenAI, Google, and Hugging Face—solely to produce the result you request. Mini Us may select and use these processors individually, sequentially, or in parallel depending on the requested generation.
Mini Us content is not public and is shared only with the connected partner when the user chooses to send it.
3. Service providers
We use service providers that process information on our behalf, including:
- Apple and Google for authentication, app distribution, and store purchases;
- RevenueCat for subscription and entitlement management;
- OpenAI, Google, and Hugging Face as AI processors for the image and text generation you request;
- Cloudflare R2 for private media storage and signed media delivery;
- Firebase Cloud Messaging and Apple Push Notification service for notifications and widget synchronization; and
- hosting, database, monitoring, and security providers used to operate the service.
These providers may process information in countries other than your own and are governed by their own terms and privacy commitments. We require service providers that process personal information on our behalf to use it only for their authorized operational role and to provide the same or equivalent protection described in this policy.
4. What your partner receives and what providers process
Your connected partner receives the Mini, Moment text, reply, and related delivery information only when you choose to send or reply. Your unshared reference photos and generation prompts are not automatically shown to your partner.
Service providers receive only the information needed for their operational role. For example, one or more of OpenAI, Google, and Hugging Face may process the selected photos and descriptions needed to create a requested Mini or mood, a storage provider holds private media, and notification providers process device tokens and notification payloads needed for delivery.
We may also disclose information when required by law, to protect users and the service, or as part of a corporate transaction subject to appropriate safeguards. We do not sell your personal information for money.
5. Reporting, blocking, and moderation
A recipient can report a received Moment or generated image using the in-app report control. Reporting hides the reported item from the reporting user's Moment history where the app indicates that result. Disconnecting a partner blocks future sharing through that connection unless the users deliberately pair again.
We may review the report reason, the reported content, relevant account and connection identifiers, and related technical information to enforce our Community & Safety Guidelines, investigate abuse, protect users, and respond to valid legal requests. Limited report evidence may be retained when reasonably needed for those purposes even if the reported item is no longer shown in the app.
6. Storage and security
Private media is stored in non-public object storage and delivered through time-limited signed URLs. The app may cache images on your device to improve performance and reduce data usage. We apply technical and organizational safeguards, but no storage or transmission method can be guaranteed completely secure.
A push notification that has already been delivered to a device cannot be remotely erased by Mini Us. The device owner can clear it or manage notification history and permissions in system settings.
7. Retention and account deletion
We retain account and service data while your Mini Us account is active and as needed to provide the service. Limited records may remain where reasonably required for security, fraud prevention, report review, legal compliance, dispute resolution, or backup integrity.
Deleting your account permanently removes the personal information and content associated with it from Mini Us active systems. This includes your account and sign-in identifiers, uploaded photos, stored private media, Minis, moods and variants, generation records, Moments and replies involving your account, partner connections and invitations, device and notification tokens, subscription and credit records, and other account-linked service data. The remaining account record is stripped of your identity and cannot be used to restore or relink the deleted account.
If you have an active partner, the account-deletion flow disconnects that partnership as part of the deletion request; you do not need to visit Partner settings first. Mini Us does not require separate Apple or Google reauthentication for this deletion flow. Deleting your Mini Us account does not cancel an Apple App Store or Google Play subscription. You can open the store's subscription-management page before deletion or delete immediately and manage the subscription separately through the store.
How to delete your account
- In Mini Us, open Settings.
- Choose Delete account.
- Review the effect on your partner connection, content, and any active subscription, then confirm deletion.
If you no longer have the app, email contact@codesharks.store from the email address used to sign in and use the subject “Delete my Mini Us account.” You do not need to reinstall the app. We will verify the request before completing deletion.
Apple, Google, and other processors may retain their own transaction or legal records under their respective policies.
8. Your choices
- You can edit your display name and remove individual reference photos in the app. Removing a reference photo deletes the associated private media from Mini Us active storage.
- You can withdraw consent for future third-party AI processing by not starting another generation and by contacting contact@codesharks.store. Withdrawing consent disables future AI generation unless you consent again; it does not automatically delete Minis already generated. Account deletion remains available separately.
- You can disconnect a partner to stop future sharing without deleting your account.
- You can report received content and contact us about a safety or moderation decision.
- You can manage notification permission in device settings.
- You can manage or cancel subscriptions in the applicable app store.
- You can permanently delete your account and associated data by following the steps in Retention and account deletion.
9. Children
Mini Us is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can review it.
10. Changes and contact
We may update this policy as the service changes. The effective date above identifies the latest version.
For privacy questions, account-deletion requests, AI-consent requests, moderation appeals, or support, email contact@codesharks.store.