Privacy Policy

We built Middl for the most vulnerable moments in relationships. We take what you share seriously — and this policy explains exactly how we handle it.

Effective: May 2026 Last updated: May 2026 Applies to: iOS app
01

What We Collect

Middl collects information you provide directly, information generated through your use of the app, and limited technical information required to operate the service.

Data Type What It Includes Why We Collect It
Account information Email address, display name, username, date of birth, password (hashed — never stored in plain text) To create and manage your account
Session content Text messages exchanged during live mediation sessions with Aria To generate session summaries and enable Aria to mediate
Reflect conversations Messages between you and Aria during solo Reflect sessions To provide continuity across sessions and generate insights
Commitments Follow-through commitments you make after sessions To track follow-through and show commitment history
Connection data Which users you're connected with, space assignments, relationship labels To enable partner sessions and organize your spaces
Usage data Session dates, durations, feature usage, streak data To power Insights and improve the product
Device token Expo push notification token To send session invites and reminders when the app is closed
Sign in with Apple Apple-provided identity token and optional name/email relay To authenticate your account via Apple

What we do not collect: Audio recordings, location data, contacts, camera access, browsing history, or any data from other apps on your device.

02

How AI Processes Your Data

Aria — Middl's AI mediator — is powered by large language models from third-party providers. Here is exactly what happens with your conversation data.

Important: Aria is not a licensed therapist, counselor, or mental health provider. Middl is a communication support tool. If you are experiencing a mental health crisis, please contact a qualified professional or call 988 (Suicide & Crisis Lifeline).

03

Data Retention

We keep your data for as long as your account is active, with specific retention rules for sensitive content:

Data Type Retention Period
Session transcripts 90 days — automatically deleted after 90 days from session date. You can also delete individual transcripts at any time from the session detail screen. Deleting your transcript does not affect your partner's copy.
Session summaries & history Retained while your account is active. You can delete individual sessions at any time from the Sessions tab (swipe left or long-press). Deleting a session removes your summary and transcript but does not affect your partner's copies. All data deleted when you delete your account.
Reflect conversations Retained while your account is active. You can delete your account at any time to remove all data.
Open Journal content Never stored — Open Journal sessions are not saved to any database unless you explicitly choose "Save to My Mind."
Account data Retained until you delete your account. Deletion is immediate and permanent.
Push tokens Stored while your account is active. Cleared on account deletion.
04

Who We Share Data With

We do not sell your personal data. We do not share your data with advertisers. We share data only with the following service providers who help us operate Middl:

Supabase
Database, authentication, real-time infrastructure
Privacy policy →
OpenAI
AI model for live sessions and session summaries
Privacy policy →
Anthropic
AI model for Reflect and Help Me Say This
Privacy policy →
Vercel
Server infrastructure and API hosting
Privacy policy →
Expo
Mobile app framework and push notifications
Privacy policy →
Apple
Sign in with Apple authentication
Privacy policy →

We may also share data if required by law, to protect safety, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you.

Partner data: When you and a partner complete a live session, each of you receives your own private copy of the session summary. Your partner cannot access your personal Reflect conversations, your Open Journal sessions, or your individual communication insights.

05

Open Journal — Zero Persistence

Open Journal is Middl's incognito mode. It is designed to be a completely private space with no lasting record.

06

Your Rights

You have the following rights regarding your personal data:

Access
Request a copy of the personal data we hold about you.
Deletion
Delete your account and all associated data from within the app. Go to Profile → Delete Account.
Correction
Update your display name and username from within the app at any time.
Portability
Request an export of your data by contacting us at the email below.
Opt out of AI processing
You can stop using AI features at any time by not using the app. Account deletion removes all data immediately.
Push notifications
Disable push notifications at any time in your iOS Settings.

To exercise any of these rights, use the in-app account deletion feature or contact us at privacy@joinmiddl.com. We will respond within 30 days.

If you are located in the European Union or California, you may have additional rights under GDPR or CCPA. Please contact us to learn more.

07

Security

We implement industry-standard security measures to protect your data:

No method of transmission over the internet or electronic storage is 100% secure. We strive to protect your data but cannot guarantee absolute security.

08

Children

Middl is not intended for users under the age of 18. We verify age during account creation and block accounts for users under 18. We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us at privacy@joinmiddl.com and we will delete the account immediately.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through the app or by email. The "Last updated" date at the top of this page reflects when the policy was last revised. Continued use of Middl after changes are posted constitutes your acceptance of the updated policy.

10

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: privacy@joinmiddl.com
App: Middl — available on the iOS App Store
For account deletion: Profile → Delete Account (in-app)

We are committed to resolving any privacy concerns promptly and transparently.