PRIVACY POLICY MIO
Important information. This Privacy Policy applies only to users permanently residing outside of Russia. If you live in Russia, please read the Policy located at https://mio.baby/privacy .
Важная информация. Эта Политика конфиденциальности применяется только к пользователям, которые постоянно проживают за пределами России. Если вы проживаете в России – пожалуйста, ознакомьтесь с Политикой, размещенной по адресу: https://mio.baby/privacy .
This Privacy Policy (the “Policy”) describes how Tyk Myk Studio LLC (“MIO”, the “Company”, “we”, “us”, “our”) processes personal data and other information when you use the MIO Service. This Policy forms an integral part of the End User License Agreement (“EULA”) and applies together with it. The EULA is available at: https://mio.baby/terms .
The MIO Service includes the MIO Mobile Application, the Web Account and the Website. A Parent and a Second Parent may use the Service through the interfaces available to them. A Child uses only the child-facing interface of the MIO Mobile Application under the Parent’s supervision. A Child does not register independently using an email address or phone number: the Child’s profile is created and configured by the Parent.
Specific aspects of children’s data processing are additionally described in the separate “Children and Family Privacy Notice”. That notice applies together with this Policy and does not replace it. The notice is available at: https://mio.baby/children-privacy . • DATA CONTROLLER
Tyk Myk Studio LLC
Tax ID (INN) 2308305256; Primary State Registration Number (OGRN) 1262300027208
Address: 64/2 Krasnoarmeyskaya St., premises 1, Krasnodar, Krasnodar Krai, 350000, Russian Federation
Privacy contact: privacy@mio.baby
Support: support@mio.baby
2. AGE, CHILDREN AND PARENTAL CONSENT
MIO is a family service. A Child Account may be created only by a Parent or another legal representative. A Child does not enter into the EULA independently and does not register using an email address or phone number.
Regardless of the Child’s age within the age range supported by the Service, the MIO child profile is created and managed by a Parent or another legal representative. The Child does not create a standalone account and does not enter into the EULA in their own name.
Where applicable law requires consent, authorization or another affirmative action by a Parent or legal representative for the processing of a Child’s personal data or for the use of particular Service features, such processing will take place only after the applicable requirements have been satisfied.
If the law of the Child’s country of residence grants the Child independent rights in relation to their personal data upon reaching a certain age, those rights remain available and may be exercised in accordance with applicable law.
The Parent represents that they are the Child’s parent or legal representative, or otherwise have the authority required to create the child profile and provide the Child’s data. If you become aware that a child profile has been created without the required authority or consent, please contact us at privacy@mio.baby. We will review the request and take appropriate action in accordance with applicable law.
We recommend that Parents supervise the Child’s use of the Service and device permission settings, including location, microphone, notifications, and access to selected files or media.
3. SCOPE OF THIS POLICY
This Policy applies to the processing of data in connection with use of the MIO Service by users permanently residing outside the Russian Federation, regardless of the compatible device or platform used, unless expressly stated otherwise.
The Mobile Application may be distributed through third-party app stores, including Google Play and the App Store. Such platforms may independently process data under their own privacy policies and act as separate controllers for activities under their control, such as store account data, app downloads and certain payment transactions.
4. DEFINITIONS
Personal Data means any information relating to an identified or identifiable individual, directly or indirectly.
Data Subject means the individual to whom Personal Data relates. Within the MIO Service, Data Subjects may include a Parent, a Second Parent, a Child, and a Website visitor.
Controller means Tyk Myk Studio LLC (“MIO”, the “Company”, “we”), to the extent that the Company determines the purposes and means of processing Personal Data.
Processor means a natural or legal person, agency or other organization that processes Personal Data on behalf of and under the instructions of the Controller.
Processing of Personal Data means any operation or set of operations performed on Personal Data, by automated means or otherwise, including collection, recording, organization, storage, alteration, retrieval, use, transmission, disclosure, restriction, deletion and destruction.
End User License Agreement / EULA means the agreement between us and the User under which the User is granted access to our Mobile Application and other parts of the Service. The User enters into the EULA by accepting its terms when first launching the Mobile Application or accessing the Website. The EULA is available at: https://mio.baby/terms.
Cookie means a small piece of data stored by a website or the Web Account on the User’s device or in the User’s browser. Cookies may be used for authentication, maintaining sessions, saving settings, security and, where there is an appropriate legal basis, analytics relating to use of the Service.
Platform means an app store or other platform through which the Mobile Application is made available to users, including Google Play and the App Store.
Website means the website available at: https://mio.baby/ .
5. PROCESSING PRINCIPLES
We aim to process Personal Data lawfully, fairly and transparently; only for specific and stated purposes; only to the extent necessary for the relevant feature; to maintain reasonable accuracy and security; and to retain data no longer than necessary for the stated purposes or to comply with legal requirements.
We do not sell or rent Personal Data. We do not use children’s data for behavioral advertising and do not display third-party advertising in the child-facing interface. We do not use photographs or voice data for biometric identification of users.
6. WHY WE PROCESS DATA AND OUR LEGAL BASES
We obtain your consent to process Personal Data where such consent is required under applicable law and this Policy. Certain Service features, including features involving a Child’s data, location data, voice data, photographs or AI features, may require separate consent or another affirmative action by a Parent or legal representative.
If required consent is not provided or is withdrawn, we may have to stop providing the relevant Service feature or materially limit its functionality where the relevant processing of Personal Data is necessary for that feature to operate.
You may withdraw consent previously given and exercise other rights in relation to your Personal Data and the Child’s Personal Data in the circumstances and to the extent provided by applicable law. Further information on exercising these rights is set out in the “Your Rights” section.
Depending on the circumstances, we may rely on one or more of the following legal bases for Processing Personal Data:
Performance of a contract. Processing is necessary to provide the MIO Service, perform the EULA, and provide the User with selected Service features.
Consent. Where applicable law requires consent, we request it before the relevant Processing begins. The User may withdraw consent previously given in accordance with this Policy.
Consent or authorization of a Parent or other legal representative. Where a Child’s Personal Data is processed, we rely on the Parent’s or legal representative’s consent, authorization or other action in the cases and form required by applicable law. Certain Service features may require a separate consent or action by the Parent.
Legitimate interests of the Company or third parties. We may process Personal Data where necessary to secure the Service, prevent fraud and abuse, protect our rights and the rights of Users, improve the Service, diagnose technical issues and maintain Service stability, provided that the rights and legitimate interests of Data Subjects are respected.
Compliance with legal obligations. We may process and retain Personal Data where necessary to comply with applicable law, binding orders of public authorities, tax, accounting, financial or other legal obligations.
Withdrawal of consent does not affect the lawfulness of Processing carried out before withdrawal. If, after withdrawal, we have no other legal basis, we will stop the relevant Processing within the time limits required by law and this Policy. Refusal of optional Processing should not deprive you of basic Service features where that Processing is not objectively required to provide them.
7. WHAT TYPES OF INFORMATION DO WE COLLECT AND FOR WHAT PURPOSES
We process only those categories of data that are necessary for the features you use. If a feature is not used, the data associated with that feature should not be processed for that purpose. The table below describes the data we collect and the reasons and purposes for collecting it.
8. DATA WE DO NOT SEEK TO COLLECT
We do not ask users to provide information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, unless such information is required by law or by a separately disclosed feature. Please do not include such information in tasks, reports, support requests or other user content unless necessary.
Photographs are processed as user content. We do not use them to identify individuals by biometric characteristics. The Service does not access the entire address book or all files and photographs on a device: we process only materials that the user specifically selects or authorizes for a particular feature.
We do not process payment card details. There is no paid subscription.
9. AI FEATURES AND VOICE DATA
Certain features may use artificial intelligence, speech recognition and speech synthesis technologies. When you use such a feature, we may transmit the content of the specific request to an AI provider we engage-for example, task or reward text, a selected photo report, a voice message, its transcript, a voice sample or text to be voiced—only to the extent necessary to perform the requested feature.
We do not use voice data for biometric identification or authentication. We also do not use user requests or family content to train or fine-tune our own artificial intelligence models.
If Family Vault is enabled and provides end-to-end client-side encryption for the relevant family content, cloud AI features that require access to unencrypted content may be disabled.
10. COOKIES AND SIMILAR TECHNOLOGIES
The MIO Website and Web Account use cookies and similar technologies that are necessary for the proper operation of the Service, user authentication, maintaining sessions, security and saving selected settings.
Some cookies are strictly necessary for the Website and Web Account to operate. They are used solely to provide the relevant functionality and are not used for advertising profiling.
We may also use analytics cookies, including web analytics services, to obtain statistical information about use of the Website and Web Account, analyze traffic and improve the Service.
We may also use analytics cookies, including web analytics services, to obtain statistical information about use of the Website and Web Account, analyze traffic and improve the Service. You can restrict optional cookies through your browser settings.
11. SHARING DATA WITH THIRD PARTIES
We disclose Personal Data to third parties only where there is an appropriate legal basis and only to the extent necessary for the purposes described in this Policy. If applicable law requires separate consent for a particular disclosure, we will obtain that consent before the disclosure takes place. We use the following subprocessors (Processors):
- Hosting and cloud infrastructure providers. We use REG.RU LLC (Russia) to host the Service. Data is stored on servers located in the Russian Federation. Privacy Policy: https://img.reg.ru/faq/politika_konfidencyalnosti_221025.pdf
We take reasonable steps to ensure that third parties engaged by us that receive access to Personal Data in connection with providing the MIO Service maintain an appropriate level of protection and process Personal Data only to the extent and for the purposes necessary to perform the relevant functions.
Where a third party processes Personal Data on our behalf, our relationship with that party is governed by a contract or other legally binding instrument that includes requirements relating to confidentiality, security, permitted purposes of Processing and compliance with applicable data protection law.
We seek to engage service providers that implement appropriate technical and organizational measures to protect Personal Data against unlawful or accidental access, destruction, alteration, disclosure, dissemination and other unlawful Processing.
Third-party services we use implement technical and organizational measures designed to ensure secure Processing of Personal Data in accordance with their privacy policies.
12. DATA RECEIVED FROM THIRD PARTIES
We may receive limited data from Platforms and service providers. For example, a push notification service provides or uses a device token.
We do not expect third parties to provide us with more data than is necessary for the relevant feature. If you believe that data has been provided to us unlawfully, please contact privacy@mio.baby.
13. FAMILY VAULT
If you enable Family Vault:
- Task text, proof-of-completion photographs and the Child’s location coordinates are encrypted on your devices before upload. Our servers store only opaque encrypted blocks; without the family’s keys, we cannot read this content.
- Encryption keys are generated and stored exclusively on your devices (in the operating system’s secure storage). The server never receives the decryption keys.
- Geofence events are calculated on the Child’s device; the server receives the event type without precise GPS coordinates.
- Cloud AI features are disabled while Family Vault is active in order to prevent family data from being transmitted to third-party AI services.
- Data created before Family Vault was enabled remains in its previous (unencrypted) form; new confidential data is processed using the protections described above.
Disabling Family Vault means returning to the standard Processing described elsewhere in this Policy.
14. HOW LONG DO WE RETAIN DATA
We retain Personal Data no longer than necessary for the purposes of Processing, performance of contracts, protection of rights and compliance with mandatory legal requirements.
As a general rule, we process Personal Data for as long as you use the MIO Service and the relevant account or child profile exists. After an account or profile is deleted, we stop active Processing and delete the relevant Personal Data within 30 calendar days, unless longer retention is required by applicable law, for tax or accounting obligations, dispute resolution, fraud prevention, incident investigation or protection of our rights or the rights of Users.
Specific retention periods may apply to particular categories of data. In particular, a Child’s location history may be retained for up to 30 days; support request data for up to 3 years.
Data processed on the basis of consent may be deleted after that consent is withdrawn, the relevant feature is disabled or the account is deleted, unless we have another lawful basis for continued retention.
If applicable law changes and imposes different mandatory retention periods for Personal Data, we will retain the relevant data for the period required by those rules.
Please note that after Personal Data is deleted, it may no longer be possible to restore the account, Family Space, progress, task history, rewards, virtual coins, location data or other information associated with the Service.
For cookies, the retention period depends on their purpose. Session cookies are generally retained only for the current session, while certain persistent cookies may be retained for longer in accordance with their stated expiration period. Users can also delete or restrict cookies in their browser settings.
15. YOUR RIGHTS
Depending on the law of your country of residence, you may have the right to:
- find out whether we process your Personal Data and obtain information about the purposes, methods and other conditions of such Processing;
- access your Personal Data and, where provided by applicable law, obtain a copy of it;
- request correction, updating or completion of inaccurate or incomplete Personal Data;
- request deletion of your Personal Data in the circumstances provided by applicable law;
- request restriction of Processing or object to Processing in the circumstances provided by applicable law;
- withdraw at any time consent previously given to the Processing of Personal Data. Withdrawal does not affect the lawfulness of Processing carried out before withdrawal;
- receive the Personal Data you provided in a structured, commonly used and machine-readable format and/or request that it be transmitted to another operator, controller or other person, where such a right is provided by applicable law;
- obtain information about decisions based solely on automated Processing of Personal Data and contest such a decision, where applicable law provides such a right;
- lodge a complaint with the competent data protection authority or other supervisory authority, or seek judicial relief in accordance with the law of your country of residence;
- exercise any other rights in relation to Personal Data expressly provided by applicable law.
Rights relating to a Child’s Personal Data. A Parent or other legal representative may, in the circumstances and to the extent permitted by applicable law, exercise rights in relation to the Child’s Personal Data, including obtaining information about Processing, access, correction and deletion, withdrawal of consent previously given, and management of particular MIO Service features associated with Processing the Child’s data.
To exercise your rights or the Child’s rights, you may contact us at: privacy@mio.baby .
To protect Personal Data and prevent unauthorized access, we may request information necessary to verify the identity of the requester and, for requests concerning a Child’s Personal Data, information necessary to verify the authority of the Parent or other legal representative.
We will review the request and respond within the time limits and in accordance with the procedures required by applicable law.
If you withdraw consent, request that Processing be stopped or restricted, or object to Processing, we may limit or stop providing those MIO Service features that depend on Processing the relevant data.
16. RIGHT TO DELETE YOUR ACCOUNT AND DATA
You may request deletion of your account and associated Personal Data through the feature provided in the Application or by contacting privacy@mio.baby.
Deleting your account may result in permanent loss of access to the Family Space, progress, virtual coins, tasks, rewards, history and other Application data.
After an account is deleted, we may retain limited information where necessary to comply with law, for accounting or tax purposes, to prevent fraud, investigate violations, resolve disputes or protect legal rights. Such data will not be used for incompatible purposes.
17. PROTECTION OF PERSONAL DATA
We take appropriate legal, organizational and technical measures to protect your Personal Data against unlawful or accidental access, destruction, alteration, blocking, copying, disclosure, dissemination and other unlawful actions.
Taking into account the nature of the data processed, the functionality of the MIO Service and applicable legal requirements, we apply measures including the following:
- data transmitted between the Application, Web Account, Website and the Service’s technical infrastructure uses a secure HTTPS connection;
- Parents’ passwords and Children’s PIN codes are not stored in plaintext and are processed using cryptographic hashing;
- access to accounts and individual Service features is protected by authentication mechanisms, including JWT tokens and refresh tokens;
- access to Family Space data is restricted through role-based access controls: Family Space data is available only to members of the relevant Family within their role as Parent, Second Parent or Child/Children; a Child has access only to the child-facing interface of the MIO Mobile Application;
- media files and user uploads, including photographs proving task completion, are not intended for public publication; access to such materials is provided through Application mechanisms that verify access rights;
- protected URLs or other technical access-control mechanisms requiring authentication or authorization checks may be used for certain media files;
- the Controller takes measures to log and analyze technical events, limit unauthorized access attempts, prevent abuse and maintain the stable operation of the MIO Service;
- additional safeguards may apply when individual MIO Service features are used, including encryption of particular categories of data or Family Vault, where that feature is available and enabled by the user.
- The Controller regularly evaluates the safeguards in place and updates them as necessary in light of Service development, the nature of Personal Data security threats and applicable legal requirements.
- Users must also observe appropriate security practices, including keeping passwords, PIN codes and family invitation codes confidential and not granting third parties access to the Parent Profile, except where a Second Parent is added through the interface as intended.
Despite the safeguards we implement, no method of transmission or electronic storage can guarantee absolute security. In the event of an incident, we act in accordance with applicable requirements concerning assessment, mitigation and, where required, notification of users and supervisory authorities.
18. INFORMATION FOR EU/EEA RESIDENTS
If you reside in the European Union or European Economic Area, you may exercise the rights relating to your Personal Data under the GDPR as described in the “Your Rights” section.
You also have the right to lodge a complaint with the competent data protection authority in your country of residence or in the country where you believe your rights have been infringed.
For the protection of your rights concerning the collection, storage and Processing of Personal Data, you may lodge a complaint with the supervisory authority in your place of residence. A list of the relevant authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Please note that the Company is registered in the Russian Federation and the main infrastructure of the MIO Service may be located in the Russian Federation. Accordingly, when you use the Service, your Personal Data may be transferred to and processed outside the European Economic Area.
Although we and our third-party partners take reasonable and appropriate measures to protect your Personal Data against unauthorized access by third parties, we are required to inform you of the potential risks of storing Personal Data in jurisdictions outside the EEA in accordance with Article 49(1)(a) GDPR.
Such potential risks may include:
In such jurisdictions, rules and safeguards governing the Processing of Personal Data may differ from those available under the GDPR. Nevertheless, we provide Data Subjects with the safeguards described in this Policy and required by applicable law.
Your Personal Data may be disclosed to public authorities of the Russian Federation and other competent government bodies where permitted by applicable law and where a valid legal basis for such access exists. We will not disclose data without a lawful basis and will limit any disclosure to what is necessary.
Unauthorized attempts to access Personal Data. We take appropriate measures to prevent such attempts and unauthorized access to your Personal Data.
By expressly consenting to the Processing of your Personal Data in accordance with this Privacy Policy, you expressly consent to the transfer of your Personal Data to jurisdictions outside the EEA despite the potential risks of such transfers.
19. INFORMATION FOR CALIFORNIA RESIDENTS (USA)
In the United States, rights and obligations vary under federal law and the laws of individual states. If a state consumer privacy law applies to MIO, we will provide the rights required by that law, including, where applicable, access, correction, deletion, portability, the right to opt out of certain Processing and the right to appeal a denied request.
For children under 13, we take COPPA requirements into account where MIO is subject to that law. A child profile is created and managed by a Parent, children’s data is not used for behavioral advertising, and access to optional sensitive features is provided with Parent involvement and using any parental consent mechanism required by law.
For California residents: we do not sell Personal Data for monetary consideration and do not use child or family content for cross-context behavioral advertising.
20. CHANGES TO THIS POLICY
We may update this Policy to reflect changes to the Service, vendors, business processes or law. The current version will be posted at https://mio.baby/privacy or on a separate page for the international version, together with the revision date.
If changes materially affect your rights or the nature of Processing, we will take reasonable steps to provide additional notice – for example by email, through a Service message or via a pop-up notice. If applicable law requires renewed consent, the relevant Processing will not continue without that consent.
21. CONTACT US
For questions about this Policy, exercising rights, the Processing of a Child’s data or international data transfers, contact: privacy@mio.baby
Service support: support@mio.baby .
Postal address: 64/2 Krasnoarmeyskaya St., premises 1, Krasnodar, Krasnodar Krai, 350000, Russian Federation.