1. Scope and who we are
This policy applies to the MYTHOS website, iOS and Android apps, and services tied directly to your account. The operations console is restricted to authorized staff, and its handling of user data is governed by this policy.
MYTHOS is for adults aged 18 and over. It is not directed to children.
2. Information we process
- Account and device data: email, verification status, device identifiers, sessions, language, push tokens, and necessary security logs.
- Private birth profile: date, optional time, standardized birth city, and the gender expression you select.
- Role and expression data: role name, visual, inner signals, AWAI posts, comments, relationship intent, and interests you choose to share.
- wakaru and location data: a location you provide when enabling wakaru. Precise coordinates are used transiently; only an approximate 5 km presence area is retained for up to 24 hours and used for recommendations within that range. The interface shows approximate distance and the selected scene.
- Messages and safety data: mutually accepted conversations, read state, reports, blocks, appeals, and evidence snapshots tied to safety events.
- AI assistance metadata: task type, a request fingerprint that contains no user content, provider/model, and completion state. Only when you explicitly request message polishing is the current unsent draft transiently sent to the configured AI provider; MYTHOS does not store that draft, the prompt, a content digest, or generated text in its AI audit table.
- Support requests: the contact email, category, subject, description, ticket number, and handling status you submit through the Support Center.
- Service data: crash, performance, request status, abuse signals, and diagnostics that do not contain message text.
3. Why we process it
- Create and protect accounts, deliver email codes, and keep device sessions consistent.
- Generate a role and everyday explanation through a private deterministic role engine; internal reasoning is not exposed in the interface.
- Support AWAI expression and show up to three role connections within a shared activity, theme, or time.
- Provide consent-based anonymous messaging, offline delivery, read sync, and notifications.
- Prevent harassment, fraud, impersonation, and abuse; handle reports and appeals; maintain operator audits.
- Measure registration, first expression, meaningful response, and return use to improve the core experience—not to sell advertising profiles.
4. Role generation, AI, and automation
A private deterministic engine uses the birth profile you submit to generate role results. The result supports expression and self-exploration; it is not used for medical, legal, financial, employment, education, insurance, or other high-impact decisions, and it never decides a relationship for you.
If an AI provider is configured, AI may assist with everyday wording, explanations of public common ground, or moderation triage. Generative AI cannot independently select candidates, make final safety decisions, or dispose of an account.
Role calibration, AWAI, connection openings, message polishing, event plans, and event reflections produce editable drafts only. You must choose and separately confirm any send, publish, or role-growth action; AI never acts on your behalf.
6. Retention and deletion
We keep information while your account is active and as needed to provide the service. After deletion, online copies are removed or de-identified; encrypted disaster-recovery backups expire through their regular rotation.
An approximate 5 km Nearby presence area is retained for no more than 24 hours. Opting in again refreshes that period; leaving visibility or deleting the account removes it earlier.
First-party evidence snapshots created from reports are retained for 90 days by default. Law, an active appeal, or a serious safety risk may require longer restricted retention. Codes and short-lived security tokens are retained only as long as verification and abuse prevention require.
Support tickets are retained for up to 12 months after resolution for follow-up, audit, and repeat-abuse prevention. Legal duties or an unresolved safety matter may require longer restricted retention.
7. How we protect information
- Birth records, provider keys, and push tokens use AES-256-GCM application-layer encryption.
- Exact birth data, location, and private messages are excluded from ordinary operations analytics; privileged access is minimized and audited.
- Our first-party IM separates authorization, persistence, and real-time delivery; every conversation requires server-side relationship authorization.
- We use rate limits, device revocation, reporting, evidence hashes, and dependency security scanning.
8. Your choices and rights
- Access and correct account, role, and public profile information.
- Withdraw nearby visibility, notifications, or permissions without affecting earlier lawful processing.
- Delete birth details, AWAI content, conversation relationships, or the entire account.
- Export portable information and request an explanation of material account actions.
- Appeal account or content actions; the Safety Center remains available to restricted accounts.
- Exercise access, correction, deletion, restriction, objection, or complaint rights available under local law.
9. Updates and contact
We will update this policy when data uses, product scope, or applicable law materially changes. Material changes will be communicated in the app or by registered email before they take effect.
Submit privacy, data, or safety requests through the website Support Center without signing in and receive a ticket number. The app also retains a Settings → Help & Safety Center entry. Do not post identity documents, exact addresses, or other highly sensitive data in public AWAI content.