What Mivy is
Mivy is a wellness role-playing game. You complete quests, earn progression, and can add friends and join guilds. Connecting wellness data is optional, but Movement and Sleep quests require the relevant provider data. Focus Session works without Health or Screen Time access.
What Mivy holds about you
Account and public identity
| Data | Why | Visibility |
|---|---|---|
| Authentication identity (email address, or an Apple or Google sign-in) | Sign you in and keep your account yours | Held by Supabase Auth; never shown to other players |
| Handle (3–20 lowercase characters, unique, immutable once set) | Your public name in search, friends, guilds, and moderation | Public to other players |
| Display name (optional, up to 50 characters) | A friendlier label beside your handle | Shown to your friends and to members of guilds you join; profile search returns handles only |
| Character class, evolution stage, achievements, and cosmetics you wear | The character other players see | Public to other players; achievement badges only when you enable sharing |
| Adult indicator and onboarding state | Route age-appropriate flows and finish setup | Not shown to other players |
Handles are checked against a reserved list and a look-alike skeleton so an account cannot impersonate Mivy or a moderator.
Wellness data
Wellness sync is off by default for every metric. When you turn a metric on and grant the platform permission, Mivy reads it in the foreground only and synchronizes a minimal daily aggregate:
- Steps — today's step count.
- Workouts — today's completion flags plus counts and non-overlapping minutes, in total and for the cardio and strength categories.
- Sleep — the duration of your latest completed night, keyed to the day you woke up.
Each aggregate is stored with its local date, IANA timezone, unit, source, and observation time.
What never leaves your device: individual health records and their identifiers, workout routes, distance, energy, heart rate, intensity, sleep stages, and the on-device sleep score. Mivy reads only today's activity and the latest completed-night sleep window; it does not query arbitrary history or backfill a missed day, so a day you did not sync cannot be reconstructed. Mivy never writes to Apple Health or Health Connect.
Screen Time (iOS only)
If you use a Focus session with app shielding, the apps you select are held by iOS in an opaque selection that Mivy stores in a shared App Group container on your device, together with the three Screen Time extensions that draw and act on the shield. That selection never leaves your device and is never sent to Mivy's servers. Declining Screen Time leaves Focus quests usable without shielding.
Gameplay, social, and safety
Quest assignments and progress, progression and stat ledgers, wallet balances, inventory, loadout, achievements, and the 90-day Activity projection are stored against your account. Friendships, friend check-ins, guild membership and contributions, and any report or appeal you file are stored so those features work and so moderation decisions are auditable.
Friends see a wellness aggregate only when two separate switches allow it: sync for that metric, which is what puts the aggregate on your account at all, and the matching sharing preference. Sync is off until you turn it on, so with the shipped defaults a friend sees nothing; sharing starts on so that turning sync on does not ask you to consent twice, and you can switch either off at any time. The defaults are:
| Preference | Default |
|---|---|
| Steps, sleep, and workout sync | Off |
| Share Steps, sleep, or workout summaries with friends | On — nothing is shared until you also turn on sync for that metric |
| Share achievements | Off |
| Profile discovery (your handle findable in search) | On — existing friends are unaffected if you turn it off |
| Notification categories | On, but nothing is sent until you allow notifications |
Exact wellness values and precise location are never inputs to any ranking. The one ranking Mivy has is inside a guild: it lists each member of that guild with the number of days in the current week — a whole number from 0 to 7 — on which they finished a step quest, and it resets every Monday at 00:00 UTC. It is built from quest completions, not from your stored wellness aggregates, so joining a guild never reveals your step counts or sleep durations to anyone and never bypasses your sharing preferences.
Purchases
Cosmetic purchases are recorded as an immutable receipt against your account, and subscription and purchase state is verified through RevenueCat and the App Store. Mivy never receives or stores your payment card. Real-money currency packs are disabled for this release, so no pack can be offered or bought.
Diagnostics and product measurement
- Crash and error diagnostics (Sentry). Disabled unless a Sentry DSN is configured for the build. When enabled, events are tagged with a random Sentry-only pseudonymous identifier that is unrelated to your account id, cleared when you sign out, and never joined to gameplay data. Crash events are retained for 30 days.
- Feedback. Only when you send it. The message is retained for 90 days. Screenshots are never captured automatically; you can attach one, and the form asks you to review it first.
- Product analytics. A small allowlist of interaction events (which screens were opened, which audio preference changed) written against a random analytics-purpose identifier, with no health value, stat, text, or location. The event rows carry no account id, but Mivy keeps a service-role-only mapping from your account to that identifier so the events can be attributed to one account over time — treat product analytics as linked to your identity, not anonymous. It is separate from the Sentry pseudonym above, and everything is purged after 90 days, or sooner if you delete your account.
- Push notifications. A device push token is registered so notifications can reach you. Every registration is deleted when you sign out or delete your account.
Who processes data for Mivy
| Processor | What it handles |
|---|---|
| Supabase | Authentication, the database, and the Edge Functions behind it |
| Apple and Google | Sign-in, and revoking Mivy's access when you delete your account |
| Apple HealthKit / Android Health Connect | The on-device source of the wellness metrics you opt in to; both stay under the platform's own permission controls |
| Expo | Push notification delivery and over-the-air JavaScript updates |
| RevenueCat and the App Store | Purchase verification and entitlement state |
| Sentry | Crash diagnostics and feedback, only when diagnostics are enabled for the build |
Mivy runs no advertising SDK, does no cross-app or cross-site tracking, and declares no tracking domains in its iOS privacy manifests.
Retention and deletion
You can delete your account from Settings. Deleting is a seven-day, recoverable flow:
- Mivy re-authenticates each linked Apple or Google account, which is both the confirmation step and how it obtains the grant needed to revoke Mivy's access later.
- Your profile is immediately deactivated: push registrations are deleted, your data becomes inaccessible, you disappear from search and social surfaces, and every session is signed out.
- Signing in during the seven days offers recovery. After the deadline, deletion is final.
- Finalization revokes the Apple and Google grants, deletes the RevenueCat subscriber, and deletes your authentication identity, after which gameplay, wellness, and social data cascade away.
Other retention periods:
| Data | Period |
|---|---|
| Activity projection, product analytics, and completed-deletion audit rows | 90 days |
| Crash diagnostics / submitted feedback | 30 days / 90 days |
| Guild moderation records once resolved | 1 year |
| Administrative operation receipts (wallet, stat, and cosmetic corrections) | 2 years, with your identifiers cleared by the deletion cascade |
| Payment records kept for refund, chargeback, fraud, tax, and reconciliation duties | Pseudonymized at deletion, then retained for the applicable store and legal period |
Wellness aggregates can be deleted on their own, without deleting your account, from Settings. Deleting them in Mivy does not touch the source records Apple Health or Health Connect holds; those stay under your control on the device.
Your choices
- Turn each wellness metric's sync and sharing on or off, and delete the stored aggregates.
- Turn profile discovery and achievement sharing off.
- Choose which notification categories you receive, or deny notifications entirely.
- Deny Health and Screen Time permission. Focus Session and non-sensor app features remain available, while provider-backed Movement and Sleep quests cannot progress without their data.
- Delete your account, with a seven-day window to change your mind.
Children
Mivy is intended for adults and is not directed to children. If you believe a child has provided personal data to Mivy, use the contact channels below so the account and data can be reviewed.
Contact
- In the app: Settings → Support → Send feedback (or shake your device). This reaches the maintainers with redacted diagnostics attached.
- Privacy or data questions: TODO: add a public support email before publication.
- Security vulnerabilities: TODO: add a public security reporting URL before publication.
Changes
We may update this policy as Mivy, the law, or our data practices change. The published policy shows its effective date. If a change materially affects your privacy rights, we will provide reasonable notice through Mivy or another appropriate channel before it takes effect.