Effective: July 24, 2026
Last updated: July 24, 2026
1. Scope
This Privacy Policy applies to the Midian website, Windows and macOS desktop clients, Android and iOS mobile clients, and the account, message synchronization, file transfer, device management, and support services directly related to those products.
Third-party websites, app stores, operating-system services, and external services accessed through Midian are responsible for their own information-handling practices. Review their privacy terms before using those services.
2. Information we handle
2.1 Account and authentication information
When an account is registered, accessed, or recovered, we may handle a phone number or other account identifier, verification status, sign-in time, account security status, and authorized-device information. This information is used to establish accounts, verify identity, prevent unauthorized access, and provide account security features.
2.2 Device and operational information
To keep clients working, identify compatibility issues, and prevent abnormal activity, we may handle device type, operating system and version, client version, language, network type, IP address, crash records, and necessary diagnostic logs. Diagnostic logs should not include message bodies. Before voluntarily attaching logs or screenshots to a support request, users should check them for information they do not wish to provide.
2.3 Communication and content data
To deliver messages, files, images, or other content selected by a user, the service must handle that data for the period necessary for delivery, together with service metadata such as sender, recipient, send time, and delivery status. Retention varies by feature, device state, and user action.
2.4 Support requests
When a user contacts support, we handle the contact details, problem description, device and version information, screenshots, or logs the user chooses to provide so that we can investigate and respond. Do not submit identity documents, payment details, or other sensitive information unrelated to the request.
3. Device permissions
Clients request system permissions only when required by a feature. Camera and microphone permissions support capture, scanning, voice, or calling; photo and file permissions allow users to select, send, or save content; notifications deliver message alerts; contacts are used only if the user enables a related contact feature.
Permissions can be withdrawn through operating-system settings. A feature that directly relies on a withdrawn permission may stop working, while unrelated core features should remain available. Clients should not continuously access the camera, microphone, or precise location without authorization.
4. Purposes and principles
We handle information lawfully, fairly, transparently, and only as necessary. Main purposes include providing registration and sign-in, delivering messages and files, synchronizing authorized-device status, maintaining reliability, detecting spam, attacks, and account abuse, responding to users, and complying with applicable law.
If information is required for a new purpose that is not directly related to the original purpose, we will provide any notice required by law and obtain consent where necessary. Refusing optional processing will not by itself prevent access to unrelated core services.
5. Retention and security
Personal information is retained only for as long as necessary for the purposes described in this Policy. Required account information remains active while an account is in use. After account closure or completion of a processing purpose, relevant information is deleted or anonymized when legal retention, dispute-resolution, and security-audit periods expire.
We use access controls, authentication, transmission safeguards, logging, separation of duties, and security updates to reduce the risk of unauthorized access, disclosure, alteration, or loss. No network or storage system can be guaranteed absolutely secure, and users should also protect verification codes, credentials, and signed-in devices.
If a security incident may affect user rights, we will assess its impact, take remedial action, and provide notice through the website, client, or another reasonable channel when required by applicable law.
6. Sharing, service providers, and international transfers
We do not sell personal information. Vetted providers may process limited information only when necessary to supply infrastructure, deliver messages, diagnose failures, or support users. Contracts, access limits, and security requirements restrict those providers' activities.
We do not disclose personal information to other independent third parties unless the user chooses to do so, separately consents, a business reorganization requires it, or disclosure is lawfully required by a competent authority. In a merger, acquisition, or asset transfer, the recipient must continue to honor this Policy or obtain new authorization.
If a service requires an international transfer, we will use assessments, contractual commitments, and safeguards required by applicable law and provide legally required information and choices.
7. User privacy rights
Subject to applicable law, users may request access, correction, completion, a copy, or deletion of personal information; withdraw consent; restrict or object to certain processing; manage device permissions; and close an account.
We may verify identity before acting on a request. A request may be limited or refused where it is manifestly repetitive or unreasonable, affects another person's rights, or concerns information that must be retained by law. We will explain the reason where required. Withdrawal of consent does not affect processing lawfully completed before withdrawal.
8. Children
Children should read and use the service with guidance from a parent or guardian. Where applicable law requires parental authorization, we will take reasonable steps to obtain it before handling a child's personal information. A guardian who believes a child submitted information without permission may contact us through the Help Center.
9. Cookies, logs, and Policy updates
The website may use local storage or cookies necessary for language preferences, security state, and basic visit measurement. We do not require non-essential cross-site advertising tracking. Browsers allow users to clear or restrict this data, although some preferences may then be lost.
We may update this Policy to reflect product features, processing activities, or legal requirements. Material changes will be highlighted through the website, client, or another reasonable channel with a new effective date. Users should review this page periodically.