Miorly ID
Legal & Safety Center

Privacy Policy

What Miorly ID processes for identity, safety, and connected products.

Updated 3 August 2026Draft 2026-08-03

This is a product-ready draft for the current Miorly ID service. It is not legal advice and must be reviewed by qualified counsel before legal reliance or a public launch. The Miorly Group legal entity, registered address, governing law, and dedicated legal contacts have not yet been published.

1.

Data Miorly ID processes

Miorly ID may process account identifiers, email address, display name, username, profile media, language and theme preferences, privacy choices, consent records, security events, sign-in sessions, and product membership records.

Connected products may process their own product data. Miorly ID should receive only what is needed for shared identity, account access, security, and the settings you choose to share.

2.

Why data is used

We use account data to create and protect accounts, authenticate you, prevent abuse, operate account controls, maintain sessions, record required consents, and connect your account to Miorly products you choose to use.

Final legal bases, controller details, international transfer mechanisms, and retention periods require legal review for each applicable region before launch.

3.

Service providers and sharing

The current service architecture uses Supabase for authentication, database, and private storage, and Vercel for application hosting. Sign-in providers such as Google process data according to their own terms when you choose to use them.

Miorly does not sell account data. Data should be shared with a connected Miorly product only when required to provide that product or when your settings permit it.

4.

Your controls

You can review profile, privacy, security, session, and data controls from Account Center. Miorly ID includes account export and deletion-request flows; product data may have separate retention and deletion rules.

A public privacy contact and a process for rights requests, complaints, and identity verification must be published before public launch.

5.

Keeping this notice current

This notice must be updated before adding analytics, advertising technology, new identity providers, a new storage provider, or a material new sharing purpose.

Privacy notices should clearly identify the organisation responsible for processing, explain relevant purposes, and be reviewed as the product changes.

Reference material