Privacy Policy

We built Middl for the most vulnerable moments in relationships. We take what you share seriously, and this policy explains exactly how we handle it.

Effective: May 2026 Last updated: June 22, 2026 Applies to: iOS app
01

What We Collect

Middl collects information you provide directly, information generated through your use of the app, and limited technical information required to operate the service.

Data Type What It Includes Why We Collect It
Account information Email address, display name, username, date of birth, optional profile photo, password (hashed, never stored in plain text) To create and manage your account
Profile preferences Optional answers to the personalization questions (communication style, what brings you to Middl, hardest moments in conflict, love language, what makes you feel heard) To shape how Aria responds to you across sessions. Editable any time from My Profile
Session content Text messages exchanged during live mediation sessions with Aria To generate session summaries and enable Aria to mediate
Reflect conversations Messages between you and Aria during solo Reflect sessions, plus a structured per-space memory summary Aria uses to remember context across future Reflect sessions in the same space To provide continuity across sessions and generate insights
Commitments Follow-through commitments you make after sessions, optional due dates To track follow-through and show commitment history
Connection data Which users you're connected with, space assignments, relationship labels To enable mediation sessions with people you're connected with and organize your spaces
In-app notifications Records of partner requests received, requests sent, session invites, session summaries ready, and commitment due reminders. Each notification has a title, body, type, and read/dismissed status To power the in-app notification feed so you can return to important events without relying on the OS push layer
Communication insights "Aria's Observation" — a short, AI-generated summary of patterns Aria notices across your sessions within a single space (for example, themes you return to or how you tend to open hard conversations). Generated from your own session summaries, refreshed periodically, and visible only to you To give you a private reflective mirror of your communication over time. Only generated for spaces where you have memory enabled; never for Open Journal
Subscription information Your Middl Plus subscription status and entitlement, tied to your account. Payment is handled by Apple; we and our subscription provider (RevenueCat) receive your subscription state and a non-payment identifier, never your card or full payment details To unlock paid features, enforce free-tier limits, and restore purchases across your devices
Usage data Session dates, durations, feature usage, daily/monthly feature counts (used to apply free-tier limits), streak data To power Insights, apply free-tier usage limits, and improve the product
Device token Expo push notification token To send session invites, partner request alerts, and commitment due reminders when the app is closed
Error and telemetry data When the app or server hits an error, we capture a stack trace, the route, your user ID, and the device platform. We do not capture conversation content in error reports To diagnose bugs, monitor app reliability, and prioritize fixes
Sign in with Apple Apple-provided identity token and optional name/email relay To authenticate your account via Apple

What we do not collect: Audio recordings, location data, your contacts, browsing history, or any data from other apps on your device. Camera and photo-library access is used only if you choose to set an optional profile photo — only the single image you pick is uploaded, and we never browse or store anything else from your library.

02

How AI Processes Your Data

Aria, Middl's AI mediator, is powered by large language models from third-party providers. Here is exactly what happens with your conversation data.

Important: Aria is not a licensed therapist, counselor, or mental health provider. Middl is a communication support tool. If you are experiencing a mental health crisis, please contact a qualified professional or call 988 (Suicide & Crisis Lifeline).

03

Data Retention

We keep your data for as long as your account is active, with specific retention rules for sensitive content:

Data Type Retention Period
Session transcripts 90 days, automatically deleted after 90 days from session date. You can also delete individual transcripts at any time from the session detail screen. Deleting your transcript does not affect the other person's copy.
Session summaries & history Retained while your account is active. You can delete individual sessions at any time from the Sessions tab (swipe left or long-press). Deleting a session removes your summary and transcript but does not affect the other person's copies. All data deleted when you delete your account.
Partner removal data When you remove a partner using "Remove and hide history", your copies of shared session summaries, transcripts, and commitments are hidden immediately and permanently deleted after 30 days. Your partner's copies are not affected. You can restore within the 30-day window from Manage Partners.
Reflect conversations Retained while your account is active. You can delete your account at any time to remove all data.
Aria's Observation (communication insights) A single current note per space, recomputed periodically from your own session summaries and superseded each time it regenerates. Removed when you disable memory for the space, delete the underlying sessions, or delete your account.
Subscription information Retained while your account is active so your Middl Plus entitlement persists across devices. Cleared on account deletion. Apple and RevenueCat retain billing records under their own policies.
Open Journal content Never stored, Open Journal sessions are not saved to any database unless you explicitly choose "Save to My Mind."
Account data Retained until you delete your account. Deletion is immediate and permanent.
Push tokens Stored while your account is active. Cleared on account deletion.
04

Who We Share Data With

We do not sell your personal data. We do not share your data with advertisers. We share data only with the following service providers who help us operate Middl:

Supabase
Database, authentication, real-time infrastructure, file storage for profile photos
Privacy policy →
OpenAI
AI model for live sessions, session summaries, voice transcription (Whisper), and text polishing
Privacy policy →
Anthropic
AI model for Reflect chats and Help Me Say This reframes
Privacy policy →
OpenRouter
Model gateway that routes Reflect and Help Me Say This requests to Anthropic
Privacy policy →
Vercel
Server infrastructure and API hosting
Privacy policy →
Expo
Mobile app framework and push notifications
Privacy policy →
Sentry
Error monitoring and crash reporting (stack trace, route, user ID, device platform — no conversation content)
Privacy policy →
RevenueCat
Subscription management for Middl Plus (subscription status + account identifier; no card details)
Privacy policy →
Resend
Delivery of account emails such as verification and password reset (your email address)
Privacy policy →
Upstash
Rate limiting (briefly holds your user ID and the route called; no conversation content)
Privacy policy →
Apple
Sign in with Apple authentication and App Store subscription billing
Privacy policy →

We may also share data if required by law, to protect safety, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you.

Shared session data: When you and another user complete a live session together, each of you receives your own private copy of the session summary. The other user cannot access your personal Reflect conversations, your Open Journal sessions, or your individual communication insights.

Links to external resources: The Library tab inside Middl includes links to third-party websites such as crisis lines, mental health articles, and educational resources. When you tap one of these links, you leave Middl and any data you share with the third party is governed by their privacy policy, not ours. Middl is not responsible for the content, privacy practices, or availability of external sites.

Middl is not a crisis service. If you are in immediate distress, contact a qualified professional or call 988 (Suicide & Crisis Lifeline) in the US, or text HOME to 741741 (Crisis Text Line). Crisis links surfaced in Middl are pointers to these external services, not a Middl-operated support line.

05

Open Journal, Zero Persistence

Open Journal is Middl's incognito mode. It is designed to be a completely private space with no lasting record.

06

Your Rights

You have the following rights regarding your personal data:

Access
Request a copy of the personal data we hold about you.
Deletion
Delete your account and all associated data from within the app. Go to Profile → Delete Account.
Granular deletion
Delete individual sessions and transcripts from the Sessions tab or session detail screen, or remove a partner and all associated history from Manage Partners. Partner removal hides your data immediately with permanent deletion after 30 days and a restore option.
Correction
Update your display name and username from within the app at any time.
Portability
Request an export of your data by contacting us at the email below.
Opt out of AI processing
You can stop using AI features at any time by not using the app. Account deletion removes all data immediately.
Push notifications
Disable push notifications at any time in your iOS Settings.

To exercise any of these rights, use the in-app account deletion feature or contact us at privacy@joinmiddl.com. We will respond within 30 days.

If you are located in the European Union or California, you may have additional rights under GDPR or CCPA. Please contact us to learn more.

07

Security

We implement industry-standard security measures to protect your data:

No method of transmission over the internet or electronic storage is 100% secure. We strive to protect your data but cannot guarantee absolute security.

08

Children

Middl is not intended for users under the age of 18. We verify age during account creation and block accounts for users under 18. We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us at privacy@joinmiddl.com and we will delete the account immediately.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through the app or by email. The "Last updated" date at the top of this page reflects when the policy was last revised. Continued use of Middl after changes are posted constitutes your acceptance of the updated policy.

10

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: privacy@joinmiddl.com
App: Middl, available on the iOS App Store
For account deletion: Profile → Delete Account (in-app)

We are committed to resolving any privacy concerns promptly and transparently.