← Back

Privacy Policy

Last updated: 2026 · Data controller: MNS

Who We Are

Mímir is operated by MNS ("MNS", "we", "us"), acting as the data controller for the personal data described in this notice. Contact: hello@mimiroracle.com.

Personal Data We Collect

  • Account data: email, password hash, optional display name and business name.
  • Usage data: niches and areas you research, research results returned to you, outreach drafts you create, and manual status updates (drafted, marked sent, replied, closed).
  • Technical data: IP address, device / browser identifiers, and operational logs needed to run and secure the service.
  • Billing data: handled directly by our Merchant of Record (see below); we receive only the subscription status and customer identifier — not your full card details.

Purposes & Legal Basis

We process personal data on the following bases (GDPR Art. 6 where applicable):

  • Performance of a contract — to create and operate your account, deliver research results, and provide the drafting tools you paid for.
  • Legitimate interests — to secure the service against fraud and abuse, prevent spam, monitor performance, and improve the product.
  • Legal obligation — to keep tax, billing, and compliance records required by law.
  • Consent — where explicitly requested (e.g. optional product updates).

What We Do Not Do

  • We do not sell, rent or share contact lists or research outputs with third parties.
  • We do not send messages on your behalf — Mímir is a drafting tool only.
  • We do not run mass outbound marketing from your data.

Public Information

Research returned by Mímir is drawn from publicly visible sources for your on-demand prospecting use only. Where you save a researched business in your workspace, that record is stored only against your account.

Service Providers & Recipients

We share personal data only with the following categories of recipients, and only as needed to run the service:

  • Supabase — authentication, database and file storage (data processor).
  • AI gateway providers — to generate research summaries and outreach drafts on your instruction (data processor).
  • Polar — our Merchant of Record. Polar independently processes payment data (card details, billing address, tax data) as an independent controller for order processing, fraud prevention, tax compliance, invoicing, refunds and chargebacks. See Polar's privacy notice.
  • Professional advisers and authorities — where required by law.

Data Retention

We keep account data for as long as your account is active. If you close your account, personal data is deleted or fully anonymised within 90 days, except records we are legally required to keep (e.g. Polar-issued invoices and tax records, retained for up to 7 years). Operational logs are retained for a maximum of 12 months.

Security

We apply industry-standard technical and organisational measures to protect personal data, including encryption in transit (TLS) and at rest, hashed passwords, role- and row-level access controls, principle-of- least-privilege for staff access, audit logging, and hardened cloud infrastructure. No system is 100% secure; we notify affected users of any material breach without undue delay.

International Transfers

Some processors (including Polar and cloud infrastructure providers) may process data outside your region. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

Your Rights

You can access, correct, export, restrict, or delete your data at any time from Settings, or by emailing hello@mimiroracle.com. You may also withdraw consent at any time and, where you are in the UK/EEA, lodge a complaint with your local supervisory authority. We respond to rights requests within one month.

Cookies

We use only essential cookies for authentication and session security. We do not use advertising cookies or cross-site tracking.