Your data
Privacy Notice
Effective and last updated: 30 July 2026
Miluma uses your information to run your workspace, understand authorised project activity, create content, publish approved posts, manage subscriptions and keep the Service secure. We do not sell your personal data.
1. Who controls your data
The operator of Miluma.app is the controller of personal data used to provide the Service. For privacy questions or rights requests, contact mapadocrew@gmail.com.
If a studio uses Miluma to process personal data about its team or community, that studio may also be a controller of that information. Contact the studio first when your question concerns its project or Discord community.
2. Information we collect
- Account and studio data: your name, email address, password hash, studio details, contact information, projects and calls to action.
- Connected-service data: identifiers, permissions and protected access credentials for Discord, GitHub and the social accounts you connect.
- Project context: authorised Discord-channel activity, repository README content and recent commit summaries when those integrations are connected.
- Content: prompts, conversations with Miluma, drafts, revisions, approvals, schedules, posts, links, uploaded media, generated images and accessibility text.
- Subscription data: plan, payment status, Stripe customer and subscription identifiers, invoices and usage allowances. Miluma does not receive your full payment-card number.
- Technical and usage data: session identifiers, page impressions, feature usage, timestamps, device and network information, error records, security events and publishing results.
3. Why we use it
We process information where needed to perform our contract with you: creating and securing your account, maintaining project memory, generating requested content, scheduling and publishing approved posts, and managing your subscription.
We also rely on legitimate interests to prevent abuse, diagnose errors, measure and improve the Service, provide support and protect users and connected platforms. We process data to meet legal obligations such as accounting, fraud prevention and responding to lawful requests. Where consent is the appropriate basis, you can withdraw it at any time.
4. AI processing and automated suggestions
Relevant project context and your instructions may be sent to the configured AI provider to create text or images. Miluma’s suggestions do not make legal or similarly significant decisions about people. You choose whether to revise, dismiss, schedule or publish them. Avoid placing unnecessary sensitive personal data in prompts, community channels selected for monitoring or uploaded media.
5. Who receives information
We share information only where needed to operate the Service, follow your instructions or meet legal obligations. Recipients may include:
- Hetzner for application hosting and storage;
- OpenAI for requested text and image generation;
- Stripe for checkout, subscriptions and payment administration;
- Discord and GitHub when you connect those services; and
- the social networks you select when you authorise or publish a post, including Bluesky, Mastodon, LinkedIn and X.
These providers process data under their own terms and privacy notices. A Mastodon server is independently operated, so its privacy practices depend on the instance you choose. We may also disclose information to professional advisers, regulators or authorities where reasonably necessary and lawful.
6. International transfers
Some providers may process information outside the United Kingdom. Where data-protection law requires it, we use an adequacy regulation, approved contractual safeguards or another valid transfer mechanism. Connected platforms may make information public or process it internationally according to the choices you make and their own terms.
7. Retention
We keep account, workspace and content data while your account is active and for a reasonable period afterwards to support recovery, security and legal requirements. Session data expires; short-lived authorisation requests are time-limited; operational logs and monitored source material are kept only as long as reasonably needed for security, context and troubleshooting. Billing records may be retained for the period required by tax and accounting law.
You may request deletion. We may retain limited information where required by law, to resolve disputes, prevent abuse or enforce agreements. Data published to a social network remains subject to that network’s controls and retention practices.
8. Cookies and telemetry
Miluma uses an essential, secure session cookie to keep you signed in. We record basic page impressions and product events for service administration and improvement. We do not currently use third-party advertising cookies or sell browsing profiles.
9. Security
We use measures designed to protect information, including HTTPS in production, password hashing, restricted administration, protected credentials and encryption for supported OAuth tokens. No internet service can guarantee absolute security. Tell us promptly if you believe your account or a connected token has been compromised.
10. Your rights
Depending on the circumstances, UK data-protection law may give you rights to be informed, access your data, correct it, erase it, restrict its use, object to processing and receive portable data. You may withdraw consent where processing relies on consent.
Send a request to mapadocrew@gmail.com. We may need to verify your identity. You can also complain to the Information Commissioner’s Office.
11. Children
The Service is intended for people aged 18 or over and is not directed to children. Contact us if you believe a child has provided personal data through Miluma without proper authority.
12. Changes and contact
We will update this notice when our processing, providers or legal obligations materially change and will bring significant changes to users’ attention where appropriate. Questions and requests can be sent to mapadocrew@gmail.com.