Mida collects and processes data under a tiered model. The scope, destination, and toggle state of each tier:
| Data category | Contents | Can it be turned off |
|---|---|---|
| Account information | Login credentials (email / phone number / WeChat / Apple account binding); date of birth (day granularity only, used for age verification) | Required for the account |
| Sensitive birth data | Birth time and place (used for chart calculation to build your profile); stored with field-level encryption, every read leaves an audit trail | Withdrawable anytime; withdrawal deletes time and place |
| Derived products | Reports, daily cards, synastry records and other derived content; products store only derived hashes, no originals to restore | Deleted with the account |
| Crash & performance diagnostics | Crash reports and device performance data (device-level anonymous identifier; no birth data or personal data) | Cannot be turned off separately (see Section 8) |
| Anonymous aggregate statistics | Truly anonymized statistics such as page views and feature usage (no user identifier, no device identifier) | Cannot be turned off (not individually identifiable) |
| Usage analytics | User-level behavioral events (event names and context properties; the user identifier is a server-generated UUID — no email / phone number / birth data) | Turn off anytime (see Section 6) |
Minors: the service is provided only to users aged 18 or above; age is verified from the date of birth at registration. We do not knowingly collect personal data from anyone under 18.
| Processing activity | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account & age verification | Providing the service; enforcing the 18+ threshold | Contract performance (6(1)(b)) / legitimate interests |
| Sensitive birth data processing | Chart calculation and profile generation | Explicit consent (Art. 9(2)(a), withdrawable anytime) |
| Crash & performance diagnostics | Keeping the service stable (necessary for service operation) | Legitimate interests (6(1)(f), see Section 8) |
| Anonymous aggregate statistics | Analyzing feature usage | Legitimate interests (truly anonymized data is no longer personal data) |
| Usage analytics | User-level behavioral analysis (see Section 4 for the cross-border note) | Consent (6(1)(a)) — default off at first launch in the EEA/UK; starts only if you turn it on |
| Payment records | Order handling and statutory accounting | Contract performance / legal obligation |
We engage third-party processors only within the following scope:
PostHog (product analytics, only while usage analytics is on)
GlitchTip (crash & error monitoring, always on)
sendDefaultPii=false; screenshot and view-hierarchy capture disabled)Other processors (each touches only the minimum data its function requires):
Usage analytics (PostHog Cloud US) constitutes a transfer of personal data outside the EEA/UK. The safeguard we rely on is the Standard Contractual Clauses (SCCs), incorporated in the Data Processing Agreement (DPA) executed with PostHog, Inc. (see posthog.com/dpa). The self-hosted GlitchTip instance is deployed in the same region as the service and does not constitute a cross-border transfer (see Section 4).
For users located in the European Economic Area (EEA) or the United Kingdom, usage analytics is off by default at first launch — this is the GDPR opt-in requirement for user-level behavioral analytics going to an overseas third party: nothing is collected by default; collection starts only if you actively turn it on. Outside the EEA/UK the default may be on, and you can still turn it off anytime. The default is decided by your region when the app fetches configuration; after cross-region travel, returning to the foreground triggers a fresh fetch.
| Data | Retention |
|---|---|
| Account & derived products | Deleted with account deletion (irreversible deletion within 15 working days) |
| Data export files | Expire and are deleted 72 hours after generation |
| Crash & performance events | Auto-deleted after 90 days |
| Usage analytics data (PostHog side) | Deletion request issued at account deletion; PostHog clears asynchronously (cleared within 30 days; backup media rotate out under their subsequent backup cycles) |
| Consent records | Retained in de-identified form for evidence; deleted after 3 years |
| Payment & order records | Statutory accounting period (generally 5 years or more); deleted on expiry |
| Phone number hashes | Retained 30 days after deletion for anti-abuse, then deleted |
You have the right to: access your personal data; obtain a portable copy (in-app "Me" → Privacy → export data; the export file is valid for 72 hours); rectify inaccurate data; erase your data (triggered by deleting your account); restrict or object to specific processing; withdraw consent at any time (withdrawal does not affect the lawfulness of processing before it); and lodge a complaint with a supervisory authority. You may exercise these rights via in-app self-service features or the contact details in Section 11.
We take appropriate technical and organizational measures to protect personal data under GDPR Art. 32, including: field-level envelope encryption of sensitive fields (birth data, name, date of birth) with keys managed separately from data; audit records on every read of sensitive data; least-privilege database accounts; TLS for all transport; code-level gatekeeping of third-party egress channels (new outbound endpoints must pass a CI gate).
Material changes to this policy (new data categories, new third-party processors, changes to purposes or retention) will be announced in-app before taking effect; changes adding sensitive processing or third-party processors will apply to existing data only after your renewed explicit consent.
The mainland-China distribution track (cn track) is additionally governed by PIPL (Personal Information Protection Law of the PRC) and its implementing rules; see the policy text applicable to that track.