Last Updated: August 14, 2026
DRIMSSY SRL ("we," "us," or "our") operates the mi mi Friend mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
mi mi Friend is a child-friendly companion app. The companion responds using a curated library of pre-written, pre-recorded content. The companion uses no artificial intelligence, the App never uses the microphone, and it accepts no free-form text or voice input. One optional game feature — the photo-to-3D toy workshop described in Section 5.6 — sends a photograph the child takes with the in-game camera to an image-to-3D generation service so it can be turned into a 3D toy. That photograph is never stored; only the 3D toy it produces is kept.
By downloading, installing, or using mi mi Friend, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the App.
DRIMSSY SRL
CUI 52129815
Registered in: Romania, European Union
Address: Jud. Brașov, Sat Hărman, Comuna Hărman, Strada Livezii, Nr. 22, 507085, Romania
Contact Email: std@drimssy.com
Data Protection Officer: std@drimssy.com
For the purposes of the EU General Data Protection Regulation ("GDPR"), we are the data controller responsible for your personal data.
| Data Type | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Email address | Account creation, activation, verification, and communication | Performance of contract |
| Activation code | Linking a physical mi mi product to your account (entered manually) | Performance of contract |
| Age range | Self-reported age group (e.g. "6-12", "12-16", "16+") used to determine age-appropriate features and consent requirements. We do NOT collect date of birth or exact age — only a broad, non-identifying age range | Legitimate interest (child safety) |
| mi mi companion name | Naming your mi mi companion. The name is chosen from a preset list — it is not free-form text and is not the child's real name | Performance of contract |
| Support request content | Responding to support requests. You may optionally attach one screenshot you choose to send | Performance of contract |
| Photograph taken with the in-game camera | Only in the photo-to-3D toy workshop (Section 5.6): a photo of an object the child chooses to photograph, used solely to generate a 3D toy from it. The photograph is never stored — it is discarded as soon as the 3D model has been generated | Performance of contract |
| Parental consent details | For users under 16: parent email and a consent record (timestamp, IP address, device/user-agent, agreed clauses, policy version) | Legal obligation / child safety |
| Data Type | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Device identifier (Android ID / iOS IDFV) | Account identification and device linking | Legitimate interest |
| Push notification token (FCM token) and device metadata (platform, app version, language, timezone) | Delivering push notifications in the correct language and platform | Consent / legitimate interest |
| Game scores and activity data | Tracking progress, leveling, and engagement | Performance of contract |
| mi mi Arena data (best replay per game, in-game wallet of coins/gems, owned and equipped cosmetics, friend code, leaderboard entries, daily prize-wheel results) | Providing the Arena games, shop, leaderboards and friend features | Performance of contract |
| Anonymous gameplay telemetry | Bucketed event counters (e.g. game started/finished, multiplayer latency). No identifiers are attached. Automatically deleted after 90 days | Legitimate interest (reliability) |
| mi mi Academy learning progress | Lesson completion, numeric quiz scores (0-100%), and spaced-repetition data to adapt difficulty. No free-text answers — button selections only | Performance of contract |
| Care activity timestamps (feed, toilet dates) | Core gameplay functionality | Performance of contract |
| Generated 3D toys — the 3D model file produced in the photo-to-3D workshop, its thumbnail image, and a record linking them to the child's mi mi companion | Keeping the 3D toy in the child's collection so it can be used in the game. Kept until the account is deleted (Section 5.6) | Performance of contract |
| Photo-to-3D progress records (job or film-roll identifier, status, timings). They contain no photograph | Showing generation progress and enforcing the daily and hourly limits. Automatically deleted after 24 hours | Performance of contract |
| Product analytics (first-party) — which screens are opened, how long each screen is open, a daily record that the account was active, and a short-lived "in app now" record (current screen, platform, app version) | Understanding which parts of the App are used, where they need improvement, and whether the service is healthy. Collected by our own server only — never sent to an analytics provider, never used for advertising, and never used to make automated decisions about a user | Legitimate interest (product improvement and reliability) |
| Diagnostic error logs (first-party) — error message, technical stack trace, the screen it occurred on, platform, OS and app version, and the account email address | Detecting and fixing crashes and bugs in the live App. Always active, stored on our own server, and deleted automatically after 30 days | Legitimate interest (reliability and security) |
| Crash reports (Firebase Crashlytics — third party, only if you opt in) | Diagnosing native crashes. Disabled by default; a parent may enable it in Settings | Consent |
| Demo session record | When the App is tried without an activation code we store one record per demo session: a random session identifier, an irreversible keyed hash used only to count unique visitors, and the country the session came from. The IP address is used only at that moment to derive the country and the hash and is not stored. Deleted automatically after 90 days | Legitimate interest (measuring interest, abuse prevention) |
| IP address (transient) | Used at the moment of each request for rate limiting and abuse prevention, and for demo sessions to derive the country and the visitor hash described above. IP addresses are not stored in our analytics or session records. The only place an IP is retained is inside a parental consent record, as evidence of consent (see Section 7.2) | Legitimate interest (security) / Legal obligation (consent records) |
| Subscription status | Managing access to premium features | Performance of contract |
We share data with the following third-party service providers who process data on our behalf:
Purpose: Crashlytics (anonymous crash reporting, opt-in) and Firebase Cloud Messaging (push notifications)
Data shared: Crash logs, device type, OS version, app version (only if crash reporting is enabled); FCM push token and device metadata (platform, app version, language, timezone) for notifications. No personal content. Firebase Analytics and Performance Monitoring are fully disabled.
Privacy Policy: firebase.google.com/support/privacy
Safeguards: EU-US Data Privacy Framework; Standard Contractual Clauses
Note: Crash reporting is disabled by default. A parent may opt in via Settings. When enabled, only anonymous crash reports are collected — no user content or personal identifiers.
Purpose: In-app purchase and subscription management
Data shared: Anonymous app user identifier, purchase transaction data, subscription status. No payment card data.
Privacy Policy: revenuecat.com/privacy
Safeguards: Standard Contractual Clauses
Purpose: Storing and delivering media via S3 and CloudFront (companion audio, images, Academy and Arena assets, and support screenshots)
Data shared: Media files and the assets needed to run the App. Image metadata (including EXIF/GPS) is stripped before storage.
Privacy Policy: aws.amazon.com/privacy
Safeguards: United States region; Standard Contractual Clauses; encryption in transit
Purpose: Cloud database hosting
Data shared: All account and app data stored in encrypted databases
Privacy Policy: mongodb.com/legal/privacy-policy
Safeguards: Standard Contractual Clauses; encryption at rest and in transit
Purpose: Transactional email delivery (verification codes, parental consent links, support notifications)
Data shared: Email address and message content. Open and click tracking are disabled.
Privacy Policy: resend.com/legal/privacy-policy
Safeguards: Standard Contractual Clauses
Purpose: Running the image-to-3D generation model that turns a photograph into a 3D toy in the photo-to-3D workshop (Section 5.6). Modal provides the GPU compute; the model runs on our behalf and under our instructions.
Data shared: The photograph only. No name, no email address, and no account or device identifier is sent with it. The image is transmitted solely to generate the 3D model. We do not store the photograph at any point, and we do not keep a copy after the model has been generated.
Privacy Policy: modal.com/legal/privacy
Safeguards: Standard Contractual Clauses; Data Processing Agreement; encrypted transport to an authenticated private endpoint
Note: this is the only place in mi mi where a generative model is used. It is used on images only — never on speech, never on text, and never for the companion's replies.
Purpose: Object storage for the results of the photo-to-3D workshop (Section 5.6)
Data shared: The generated 3D model file and its thumbnail image. No photograph, no name, and no email address. The stored files carry no account identifier, and the App reaches them only through short-lived signed links that are generated per request and never stored.
Privacy Policy: cloudflare.com/privacypolicy
Safeguards: Standard Contractual Clauses; Data Processing Agreement; encryption in transit
Purpose: Cloud hosting of our application server. The server described throughout this Policy runs on Render's infrastructure in its European Union region (Frankfurt, Germany)
Data shared: As the host of our server, Render's infrastructure processes the data described in Section 2 while our server handles it. The databases themselves are stored with MongoDB Atlas (Section 4.4) and files with AWS (Section 4.3)
Privacy Policy: render.com/privacy
Safeguards: Data Processing Addendum supplementing Render's Terms of Service; EU Standard Contractual Clauses; EU hosting region (Frankfurt)
We do not use any third-party analytics, attribution, or measurement provider. The product analytics described in Sections 2.2 and 5.4 is collected and stored by our own server only.
The country shown for a demo session is resolved locally on our own server using an offline country database. No IP address and no device information is sent to any geolocation service.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
mi mi replies using a curated library of pre-written text and pre-recorded audio. The child taps a question, and the App plays a matching pre-recorded answer. The companion contains no artificial intelligence, uses no microphone, accepts no free-form text input, and no conversation is ever sent to any third-party AI service. All companion content is authored and reviewed by our team in advance.
The only generative model anywhere in mi mi is the image-to-3D model used in the photo-to-3D toy workshop (Section 5.6). It works on a photograph and produces a 3D shape. It never takes part in what mi mi says, and it never receives speech or text.
mi mi Arena includes 3D games (some with real-time multiplayer), a library of mini-games, public leaderboards, an in-game cosmetics shop, a daily prize wheel, and shareable friend codes. Please read this section carefully:
We use two kinds of measurement. Both are first-party: collected by our own server, never shared with an analytics provider, never used for advertising or cross-app tracking, and never used for automated decision-making or profiling of a user.
Under GDPR Article 21 you may object to this processing at any time. The App has a built-in switch: Settings → Data & Privacy → Usage analytics. Turning it off stops collection on the device immediately and deletes the analytics records already collected for that account. You can also write to std@drimssy.com (see Section 8). Deleting an account also deletes its analytics and diagnostic records.
We do not perform emotion recognition or psychological profiling of any user, including children. Any "mood" values displayed in the App are scripted character states. These values are never used for advertising or profiling.
Inside one of the mi mi Arena games a child can point the in-game camera at a real object — a toy, a drawing, an everyday thing — and turn that photograph into a 3D toy that appears in their own mi mi world. The feature is intended for objects, not people. It is switched off by default and is currently available only to a small closed beta group; where it is enabled, generation is capped (5 per day and 6 attempts per hour per companion).
We use a child's photograph for one purpose only: producing the 3D toy the child asked for. It is not used for advertising, not used to profile anyone, and not analysed for any other reason.
We keep personal data only for as long as is reasonably necessary for the purpose it was collected for, and we do not retain personal data indefinitely. This applies with particular strictness to children's data. Each retention period below is enforced automatically by our systems — when it ends, the data is deleted without any manual step. When an account is deleted, its data is erased as described in Section 7.6, including its analytics and diagnostic records.
| Data Type | Retention Period |
|---|---|
| Account data (email, device ID) | Until account deletion |
| Game, Arena, and learning progress | Until account deletion |
| Photographs taken in the photo-to-3D workshop | Never stored. Used only to generate the 3D toy, then discarded |
| Generated 3D toys (model file, thumbnail, and the record linking them to the companion) | Until account deletion — deletion erases the record, which is the only pointer to the stored file |
| Photo-to-3D progress records (job and film-roll status; no photograph) | Automatically deleted after 24 hours |
| Anonymous gameplay telemetry | Automatically deleted after 90 days |
| Product analytics (screens opened, time per screen, daily-active records) | Automatically deleted after 13 months |
| Live "in app now" record | Deleted within minutes of closing the App |
| Diagnostic error logs (message, stack trace, account email) | Automatically deleted after 30 days |
| Demo session records (country and hashed visitor value; no IP stored) | Automatically deleted after 90 days |
| Push notification tokens | Until logout or token refresh |
| Support tickets | Up to 12 months after resolution |
| Crash reports (Crashlytics, only if enabled) | Up to 90 days |
| Authentication tokens | 30 days (auto-renewed) |
| Parental consent records | Retained as required for legal compliance |
mi mi Friend is designed for users of all ages, including young children. We take children's privacy extremely seriously and apply protections consistent with the U.S. Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR, Article 8), and the UK Age Appropriate Design Code (AADC), where applicable.
There is no AI chat, no microphone, no voice recording, and no free-form messaging for any user, of any age. mi mi responds only with pre-recorded content, and companion names are chosen from preset lists. Content filtering is built into the curated content itself.
The one place a model generates something is the photo-to-3D toy workshop (Section 5.6), which turns a photograph of an object into a 3D shape. It never speaks to the child, never receives speech or text, and its results are reviewed before they can be seen by anyone other than the child who made them.
During registration, users (or their parent or guardian) select a broad age range (1-6, 6-12, 12-16, or 16+). We do not collect date of birth or exact age. Users under 16 require verifiable parental consent. For these accounts we collect the parent or guardian's email address, which serves as the account's identity and consent contact — we do not collect the child's own email address. The parent confirms consent via a secure link sent to that email before the account is fully activated. Users 16 and older may self-consent using their own email address. We keep a consent record (timestamp, IP address, user-agent, agreed clauses, and policy version) for legal compliance.
The age gate presents the options in a neutral, non-leading manner. By proceeding, the user (or their parent or legal guardian) warrants the truthfulness of the age range provided. If we receive credible information that an account's stated age range is inaccurate, we will reclassify the account into the appropriate age tier and request parental consent before any further processing inconsistent with the corrected classification.
We apply strict data minimization for child users. The data collected is limited to:
| Data Type | Collected? | Purpose |
|---|---|---|
| Age range (e.g. "6-12") | Yes | Age-appropriate features and consent (not personally identifiable) |
| Activation code | Yes | Linking the physical mi mi product to the account |
| Device identifier | Yes | Account linking and internal operations (no cross-app tracking) |
| mi mi companion name (preset) | Yes | Naming the companion (not the child's real name) |
| Game, Arena, and learning progress | Yes | Gameplay and educational progress tracking |
| Push notification token | Yes (with permission) | Delivering notifications |
| Free-form text or chat | No | Not collected from any user |
| Voice recordings | No | Microphone is never used |
| Precise geolocation | No | Never collected. Photographs carry no GPS tags and the App has no location permission |
| Photo library / camera roll | No | The App never browses or reads the photo library (the only exception is a screenshot a user chooses to attach to a support request) |
| Photograph taken in the photo-to-3D workshop | Used, never stored | Sent to our generation provider only to produce the 3D toy, then discarded. Not written to any file, database or storage bucket, and no identifier is sent with it (Section 5.6) |
| 3D toys generated from a photo | Yes | The generated model file and thumbnail are kept so the child keeps the toy. Never shown to other players. Erased with the account |
| Third-party analytics / advertising identifiers | No | No analytics SDK, no advertising IDs, no cross-app tracking |
| First-party product analytics | Yes | Screens opened and time spent per screen, kept on our own server and used only to operate, maintain and improve the App — COPPA "support for internal operations". Never used for advertising or to profile a child |
| Diagnostic error logs | Yes | Error message and stack trace when the App breaks, kept for 30 days so we can fix it |
mi mi Arena includes multiplayer games and public leaderboards. Parents should be aware that:
Parents and legal guardians can exercise the following rights at any time, in-app or by contacting std@drimssy.com:
We respond to all parental requests within 30 days. Deletion erases personal data and unlinks your devices; the activation code that pairs a physical mi mi is reset so the toy can be re-registered later. Deletion is performed without undue delay, residual copies in encrypted backups expire on a rolling basis (within 30 days), and consent records are retained only where legally required.
If mi mi Friend is used in an educational setting, the school may provide consent on behalf of parents for the collection of children's data solely for educational purposes, in accordance with COPPA's school consent exception. Schools must notify parents and provide them the opportunity to review this Privacy Policy.
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of all personal data we hold about you (also available via in-app export) |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure ("Right to be Forgotten") | Request deletion of your personal data (also available via in-app account deletion) |
| Restriction | Request that we limit how we process your data |
| Data Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests |
| Withdraw Consent | Withdraw consent at any time where processing is based on consent |
| Lodge a Complaint | File a complaint with your local Data Protection Authority |
To exercise any of these rights, contact us at std@drimssy.com. We will respond within 30 days of receiving your request.
Your personal data may be transferred to and processed in countries outside the European Economic Area, including the United States (where some of our third-party providers operate).
Two of these transfers concern the photo-to-3D workshop (Section 5.6) and are worth stating plainly: a photograph taken in the workshop is transmitted to Modal (United States) for the sole purpose of generating a 3D model from it, and the generated model and thumbnail are stored with Cloudflare R2 (United States). The photograph is not stored in either place by us, and nothing identifying the child is transferred with it.
When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
mi mi Friend may offer optional premium subscriptions. Where a subscription is offered, all payments are processed exclusively through the Apple App Store or Google Play Store. We do not collect, process, or store any payment card information. Subscription management and billing are handled entirely by the respective app store. RevenueCat acts as our intermediary to verify subscription status; only an anonymous transaction identifier and subscription status are shared with us.
In-game currency (coins, gems) and items have no real-world monetary value and cannot be purchased with, or exchanged for, real money.
mi mi Friend may request the following device permissions:
| Permission | Purpose | Required? |
|---|---|---|
| Notifications | Delivering reminders and updates | Optional |
| Camera | Two explicit actions only: scanning the activation QR code on a mi mi box, and taking a photo of an object in the photo-to-3D workshop (Section 5.6). The camera is never used in the background, and photos taken in the workshop are not stored | Optional |
| Photo Library | Attaching a single screenshot to a support request (only when you choose to). The App never browses your photo library on its own | Optional |
| Motion sensors (Android) | Gameplay physics in Arena games | Optional |
| Internet | Core app functionality | Required |
You can manage these permissions at any time through your device settings. Denying optional permissions will only disable the related feature — the App will continue to function; declining or later withdrawing camera access simply means QR scanning and the photo-to-3D workshop are unavailable. The App does not request microphone access, does not request location access, and does not request advertising/tracking permission.
The mi mi Friend mobile app does not use cookies. In addition:
This section covers our website (including the QR landing page a mi mi box leads to), which is separate from the App:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
We may update this Privacy Policy from time to time. When we do:
August 14, 2026 update: we added the photo-to-3D toy workshop (Section 5.6) — what the in-game camera is used for, that the photograph is never stored, that only the generated 3D toy is kept, and that generated toys are never shown to other players. We named the two processors it relies on, Modal and Cloudflare R2, both in the United States (Sections 4.6, 4.7 and 9), listed the new data and its retention (Sections 2.1, 2.2, 6.1, 6.3 and 7.3), added the camera permission (Section 11), and rescoped the "no artificial intelligence" statement so it says precisely what remains true: the companion uses no AI, there is still no microphone and no free-form input, and the only generative model in mi mi works on photographs in the workshop (Sections 5.1 and 7.1). We also named Render (Section 4.8) — the cloud provider that has always hosted our application server in the European Union (Frankfurt). Naming it adds no new data flow; it makes the existing hosting explicit.
July 26, 2026 update: we described our first-party product analytics and diagnostic error logs in full (Sections 2.2, 3, 5.4 and 12), added their retention periods (Section 6.3), confirmed that no third-party analytics or geolocation provider is used (Section 4.8), and stopped storing IP addresses for demo sessions.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Art. 6(1)(b) — Performance of contract |
| Delivering companion and Academy content | Art. 6(1)(b) — Performance of contract |
| mi mi Arena and multiplayer gameplay | Art. 6(1)(b) — Performance of contract |
| Photo-to-3D toy generation and storage of the generated toy | Art. 6(1)(b) — Performance of contract |
| Anonymous gameplay telemetry | Art. 6(1)(f) — Legitimate interest (reliability) |
| First-party product analytics (screens opened, time per screen, daily active) | Art. 6(1)(f) — Legitimate interest (product improvement) |
| Diagnostic error logging | Art. 6(1)(f) — Legitimate interest (reliability and security) |
| Demo session measurement (country and hashed visitor value) | Art. 6(1)(f) — Legitimate interest (measuring interest, abuse prevention) |
| Crash reporting via Crashlytics (opt-in) | Art. 6(1)(a) — Consent |
| Subscription management | Art. 6(1)(b) — Performance of contract |
| Device identification | Art. 6(1)(f) — Legitimate interest |
| Push notifications | Art. 6(1)(a) — Consent |
| Transactional emails | Art. 6(1)(b) — Performance of contract |
| Support requests | Art. 6(1)(b) — Performance of contract |
| Security, anti-cheat, and fraud prevention | Art. 6(1)(f) — Legitimate interest |
| Parental consent for under-16 accounts | Art. 6(1)(c) — Legal obligation; Art. 8 GDPR |
| Age range classification | Art. 6(1)(f) — Legitimate interest (child safety) |