Privacy Notice
Mimir Storage is the data controller for personal data processed through Mimir Storage. This notice explains what we collect, why, who we share it with, and the rights you have.
Last updated 17 August 2026
Categories of personal data we collect
- Account data — email address, display name, authentication identifiers (including a Google account ID if you sign in with Google), account creation date.
- Billing data — subscription plan, status, renewal dates and the customer/subscription identifiers issued by Paddle. Card numbers never reach us.
- File metadata — file name, MIME type, size, fragment count and integrity digests. File contents are encrypted in your browser and unreadable to us.
- Host data — for host operators: node name, region, pledged capacity, uptime measurements and accrued earnings.
- Security logs — timestamped records of sign-ins, uploads, downloads, deletions and storage-proof results, used to detect abuse.
What we cannot see
Encryption keys are derived from your passphrase inside your browser and are never transmitted. We hold ciphertext fragments and metadata only, so the contents of your files are outside our access — and outside the access of the host machines storing them.
Why we process it
To provide the service and perform our contract with you (accounts, storage, retrieval, host payouts), to take payment, to keep the network secure and to comply with legal and accounting obligations. Where we rely on legitimate interests, it is to prevent abuse of a network built out of other people's machines.
Who we share it with
- Paddle.com — our Merchant of Record and payment processor; receives the data needed to bill you, issue receipts and handle refunds and tax.
- Our infrastructure providers — hosting, database and authentication providers acting as processors under contract.
- Host operators — receive only encrypted fragments and opaque fragment identifiers. They receive no personal data about you.
- Authorities — only where legally compelled; we can supply ciphertext and metadata, never plaintext.
We do not sell personal data or use it for advertising.
Retention
Account and file metadata are kept while your account is active and for 30 days after deletion. Billing records are retained as long as tax law requires (typically 7 years). Security logs are kept for 12 months.
Your rights
You may request access, correction, deletion, restriction, portability, or object to processing, and you may withdraw consent where consent is the basis. Contact Mimir Storage through the details on your receipt. You may also complain to your local data protection authority.
International transfers and changes
Data may be processed outside your country by our processors under appropriate safeguards such as Standard Contractual Clauses. If this notice changes materially we will announce it in-app before the change takes effect.