Skip to main content
MYTHOS
ConnectionsCONNECTIONSRole universeARCHETYPESHow it worksFLOWTrust & safetyTRUST
Open the app
ConnectionsCONNECTIONSRole universeARCHETYPESHow it worksFLOWTrust & safetyTRUST
Join the MYTHOS beta
Back to websitePRIVACY BY DESIGN

Privacy Policy

This policy explains what MYTHOS processes, why it is needed, how it is protected, and how you can access, correct, export, or delete your information.

Effective · 2026-07-27Version · 1.0-betaAbout 9 minutes
Key points
  • Exact birth details are used only to create and refine your role and are never shown to other users.
  • Nearby experiences show approximate distance. Precise coordinates are used transiently and no movement trail is stored.
  • MYTHOS does not sell personal information, build ad profiles from private messages, or use hosted IM.
  • You can remove birth details, leave nearby visibility, revoke devices, export data, or delete your account.
On this page
1. Scope and who we are2. Information we process3. Why we process it4. Role generation, AI, and automation5. Processors and international handling6. Retention and deletion7. How we protect information8. Your choices and rights9. Updates and contact

1. Scope and who we are

This policy applies to the MYTHOS website, iOS and Android apps, and services tied directly to your account. The operations console is restricted to authorized staff, and its handling of user data is governed by this policy.

MYTHOS is for adults aged 18 and over. It is not directed to children.

2. Information we process

  • Account and device data: email, verification status, device identifiers, sessions, language, push tokens, and necessary security logs.
  • Private birth profile: date, optional time, standardized birth city, and the gender expression you select.
  • Role and expression data: role name, visual, inner signals, AWAI posts, comments, relationship intent, and interests you choose to share.
  • Connection and location data: a location you provide when enabling Connections. Coordinates are coarsened and only approximate distance and shared context are shown.
  • Messages and safety data: mutually accepted conversations, read state, reports, blocks, appeals, and evidence snapshots tied to safety events.
  • Service data: crash, performance, request status, abuse signals, and diagnostics that do not contain message text.

3. Why we process it

  • Create and protect accounts, deliver email codes, and keep device sessions consistent.
  • Generate a role and everyday explanation through a private deterministic role engine; internal reasoning is not exposed in the interface.
  • Support AWAI expression and show up to three role connections within a shared activity, theme, or time.
  • Provide consent-based anonymous messaging, offline delivery, read sync, and notifications.
  • Prevent harassment, fraud, impersonation, and abuse; handle reports and appeals; maintain operator audits.
  • Measure registration, first expression, meaningful response, and return use to improve the core experience—not to sell advertising profiles.

4. Role generation, AI, and automation

A private deterministic engine uses the birth profile you submit to generate role results. The result supports expression and self-exploration; it is not used for medical, legal, financial, employment, education, insurance, or other high-impact decisions, and it never decides a relationship for you.

If an AI provider is configured, AI may assist with everyday wording, explanations of public common ground, or moderation triage. Generative AI cannot independently select candidates, make final safety decisions, or dispose of an account.

5. Processors and international handling

MYTHOS does not sell personal information. We use processors only where needed to operate the service, meet legal duties, or protect users.

  • Resend for email codes after operators configure a verified sending identity.
  • Apple Push Notification service and Firebase Cloud Messaging after you explicitly enable notifications; lock screens do not contain message text or birth data.
  • Open-Meteo for city-scale weather context without account identity or location history.
  • A configured AI provider receives only allowlisted, minimized inputs—never exact coordinates, birth records, private messages, or internal role-engine snapshots.
  • Infrastructure and security providers operate under access controls, contracts, and confidentiality obligations.

6. Retention and deletion

We keep information while your account is active and as needed to provide the service. After deletion, online copies are removed or de-identified; encrypted disaster-recovery backups expire through their regular rotation.

First-party evidence snapshots created from reports are retained for 90 days by default. Law, an active appeal, or a serious safety risk may require longer restricted retention. Codes and short-lived security tokens are retained only as long as verification and abuse prevention require.

7. How we protect information

  • Birth records, provider keys, and push tokens use AES-256-GCM application-layer encryption.
  • Exact birth data, location, and private messages are excluded from ordinary operations analytics; privileged access is minimized and audited.
  • Our first-party IM separates authorization, persistence, and real-time delivery; every conversation requires server-side relationship authorization.
  • We use rate limits, device revocation, reporting, evidence hashes, and dependency security scanning.

8. Your choices and rights

  • Access and correct account, role, and public profile information.
  • Withdraw nearby visibility, notifications, or permissions without affecting earlier lawful processing.
  • Delete birth details, AWAI content, conversation relationships, or the entire account.
  • Export portable information and request an explanation of material account actions.
  • Appeal account or content actions; the Safety Center remains available to restricted accounts.
  • Exercise access, correction, deletion, restriction, objection, or complaint rights available under local law.

9. Updates and contact

We will update this policy when data uses, product scope, or applicable law materially changes. Material changes will be communicated in the app or by registered email before they take effect.

Submit privacy, data, or safety requests through Settings → Help & Safety Center in the app. Do not post identity documents, exact addresses, or other highly sensitive data in public AWAI content.

Need to exercise a right or report a problem?

Open Settings → Help & Safety Center in the MYTHOS app. The Safety Center remains available if an account is restricted.

Open the app
Related policies
TERMS FOR REAL CONNECTIONSTerms of ServiceA ROLE CAN BE FREE · A PERSON MUST BE SAFECommunity Guidelines18+ COMMUNITY · SAFETY FIRSTMinor Protection Policy
MYTHOS

Inner spirit · Parallel self · Real connections

INNER SPIRIT · PARALLEL SELF · REAL CONNECTIONS
ProductHomeRole universeHow it worksOpen the app
SafetyTrust & safetyCommunity GuidelinesMinor Protection Policy
Rules & policiesPrivacy PolicyTerms of ServiceCommunity GuidelinesMinor Protection Policy
© 2026 MYTHOS. All rights reserved.18+ · ROLE-ANONYMOUS · CONSENT-BASED