Privacy Policy

Last Updated: July 13, 2026

DRIMSSY SRL ("we," "us," or "our") operates the mi mi Friend mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

mi mi Friend is a child-friendly companion app. The companion responds using a curated library of pre-written, pre-recorded content. The App does not use artificial intelligence, does not use the microphone, and does not accept free-form text or voice input.

By downloading, installing, or using mi mi Friend, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the App.


1. Who We Are

DRIMSSY SRL
CUI 52129815
Registered in: Romania, European Union
Address: Jud. Brașov, Sat Hărman, Comuna Hărman, Strada Livezii, Nr. 22, 507085, Romania
Contact Email: std@drimssy.com
Data Protection Officer: std@drimssy.com

For the purposes of the EU General Data Protection Regulation ("GDPR"), we are the data controller responsible for your personal data.


2. Information We Collect

2.1 Information You Provide Directly

Data TypePurposeLegal Basis (GDPR)
Email addressAccount creation, activation, verification, and communicationPerformance of contract
Activation codeLinking a physical mi mi product to your account (entered manually)Performance of contract
Age rangeSelf-reported age group (e.g. "6-12", "12-16", "16+") used to determine age-appropriate features and consent requirements. We do NOT collect date of birth or exact age — only a broad, non-identifying age rangeLegitimate interest (child safety)
mi mi companion nameNaming your mi mi companion. The name is chosen from a preset list — it is not free-form text and is not the child's real namePerformance of contract
Support request contentResponding to support requests. You may optionally attach one screenshot you choose to sendPerformance of contract
Parental consent detailsFor users under 16: parent email and a consent record (timestamp, IP address, device/user-agent, agreed clauses, policy version)Legal obligation / child safety

2.2 Information Collected Automatically

Data TypePurposeLegal Basis (GDPR)
Device identifier (Android ID / iOS IDFV)Account identification and device linkingLegitimate interest
Push notification token (FCM token) and device metadata (platform, app version, language, timezone)Delivering push notifications in the correct language and platformConsent / legitimate interest
Game scores and activity dataTracking progress, leveling, and engagementPerformance of contract
mi mi Arena data (best replay per game, in-game wallet of coins/gems, owned and equipped cosmetics, friend code, leaderboard entries, daily prize-wheel results)Providing the Arena games, shop, leaderboards and friend featuresPerformance of contract
Anonymous gameplay telemetryBucketed event counters (e.g. game started/finished, multiplayer latency). No identifiers are attached. Automatically deleted after 90 daysLegitimate interest (reliability)
mi mi Academy learning progressLesson completion, numeric quiz scores (0-100%), and spaced-repetition data to adapt difficulty. No free-text answers — button selections onlyPerformance of contract
Care activity timestamps (feed, toilet dates)Core gameplay functionalityPerformance of contract
Crash reports (only if you opt in)Diagnosing and fixing technical issuesConsent / legitimate interest
Subscription statusManaging access to premium featuresPerformance of contract

2.3 Information We Do NOT Collect


3. How We Use Your Information

  1. Provide and maintain the App — create your account, activate mi mi companions, and deliver core features
  2. Power the companion — mi mi responds using a library of pre-written, pre-recorded questions and answers (no AI, no microphone, no free-form input)
  3. Provide educational content — deliver mi mi Academy pre-written lessons and quizzes, track progress, and adapt difficulty
  4. Provide mi mi Arena — single-player and multiplayer games, leaderboards, an in-game shop, and friend features; in multiplayer we share gameplay state with other players in the same session (see Section 5.3)
  5. Manage subscriptions — process and verify in-app purchases and subscription status
  6. Track progress — record game and Arena scores, energy, activity completions, leveling, and learning progress
  7. Deliver push notifications you have enabled
  8. Communicate with you — send verification codes, important updates, and respond to support requests
  9. Ensure security and fair play — detect and prevent fraud, abuse, cheating, and unauthorized access through rate limiting, authentication, and anti-cheat validation

4. Third-Party Service Providers

We share data with the following third-party service providers who process data on our behalf:

4.1 Firebase / Google (United States)

Purpose: Crashlytics (anonymous crash reporting, opt-in) and Firebase Cloud Messaging (push notifications)

Data shared: Crash logs, device type, OS version, app version (only if crash reporting is enabled); FCM push token and device metadata (platform, app version, language, timezone) for notifications. No personal content. Firebase Analytics and Performance Monitoring are fully disabled.

Privacy Policy: firebase.google.com/support/privacy

Safeguards: EU-US Data Privacy Framework; Standard Contractual Clauses

Note: Crash reporting is disabled by default. A parent may opt in via Settings. When enabled, only anonymous crash reports are collected — no user content or personal identifiers.

4.2 RevenueCat (United States)

Purpose: In-app purchase and subscription management

Data shared: Anonymous app user identifier, purchase transaction data, subscription status. No payment card data.

Privacy Policy: revenuecat.com/privacy

Safeguards: Standard Contractual Clauses

4.3 Amazon Web Services — AWS (United States)

Purpose: Storing and delivering media via S3 and CloudFront (companion audio, images, Academy and Arena assets, and support screenshots)

Data shared: Media files and the assets needed to run the App. Image metadata (including EXIF/GPS) is stripped before storage.

Privacy Policy: aws.amazon.com/privacy

Safeguards: United States region; Standard Contractual Clauses; encryption in transit

4.4 MongoDB Atlas (United States)

Purpose: Cloud database hosting

Data shared: All account and app data stored in encrypted databases

Privacy Policy: mongodb.com/legal/privacy-policy

Safeguards: Standard Contractual Clauses; encryption at rest and in transit

4.5 Resend (United States)

Purpose: Transactional email delivery (verification codes, parental consent links, support notifications)

Data shared: Email address and message content. Open and click tracking are disabled.

Privacy Policy: resend.com/legal/privacy-policy

Safeguards: Standard Contractual Clauses

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.


5. How mi mi Works (No AI)

5.1 Companion Responses

mi mi replies using a curated library of pre-written text and pre-recorded audio. The child taps a question, and the App plays a matching pre-recorded answer. There is no artificial intelligence, no microphone, no free-form text input, and no conversation is sent to any third-party AI service. All companion content is authored and reviewed by our team in advance.

5.2 mi mi Academy (Educational Lessons)

5.3 mi mi Arena (Games, Multiplayer and Social Features)

mi mi Arena includes 3D games (some with real-time multiplayer), a library of mini-games, public leaderboards, an in-game cosmetics shop, a daily prize wheel, and shareable friend codes. Please read this section carefully:

5.4 Anonymous Telemetry

We collect anonymous, bucketed event counters for games and multiplayer (for example, game started/finished, multiplayer latency). No user identifier is attached, and these events are automatically deleted after 90 days. They are used only to keep the App reliable.

5.5 Character States

We do not perform emotion recognition or psychological profiling of any user, including children. Any "mood" values displayed in the App are scripted character states. These values are never used for advertising or profiling.


6. Data Storage and Security

6.1 Where We Store Data

6.2 Security Measures

6.3 Data Retention

Data TypeRetention Period
Account data (email, device ID)Until account deletion
Game, Arena, and learning progressUntil account deletion
Anonymous gameplay telemetryAutomatically deleted after 90 days
Push notification tokensUntil logout or token refresh
Support ticketsUp to 12 months after resolution
Crash reports (if enabled)Up to 90 days
Authentication tokens30 days (auto-renewed)
Parental consent recordsRetained as required for legal compliance

7. Children's Privacy (All Ages)

mi mi Friend is designed for users of all ages, including young children. We take children's privacy extremely seriously and apply protections consistent with the U.S. Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR, Article 8), and the UK Age Appropriate Design Code (AADC), where applicable.

7.1 The Same Safe Experience for Everyone

There is no AI chat, no microphone, no voice recording, and no free-form messaging for any user, of any age. mi mi responds only with pre-recorded content, and companion names are chosen from preset lists. Content filtering is built into the curated content itself.

7.2 Age Classification and Consent

During registration, users (or their parent or guardian) select a broad age range (1-6, 6-12, 12-16, or 16+). We do not collect date of birth or exact age. Users under 16 require verifiable parental consent. For these accounts we collect the parent or guardian's email address, which serves as the account's identity and consent contact — we do not collect the child's own email address. The parent confirms consent via a secure link sent to that email before the account is fully activated. Users 16 and older may self-consent using their own email address. We keep a consent record (timestamp, IP address, user-agent, agreed clauses, and policy version) for legal compliance.

7.2.1 Age Truthfulness

The age gate presents the options in a neutral, non-leading manner. By proceeding, the user (or their parent or legal guardian) warrants the truthfulness of the age range provided. If we receive credible information that an account's stated age range is inaccurate, we will reclassify the account into the appropriate age tier and request parental consent before any further processing inconsistent with the corrected classification.

7.3 Data We Collect from Children

We apply strict data minimization for child users. The data collected is limited to:

Data TypeCollected?Purpose
Age range (e.g. "6-12")YesAge-appropriate features and consent (not personally identifiable)
Activation codeYesLinking the physical mi mi product to the account
Device identifierYesAccount linking and internal operations (no cross-app tracking)
mi mi companion name (preset)YesNaming the companion (not the child's real name)
Game, Arena, and learning progressYesGameplay and educational progress tracking
Push notification tokenYes (with permission)Delivering notifications
Free-form text or chatNoNot collected from any user
Voice recordingsNoMicrophone is never used
Precise geolocationNoNever collected
Photos or media filesNoNot collected (except a screenshot a user chooses to attach to support)
Analytics / advertising identifiersNoAnalytics disabled; no advertising IDs

7.4 What We Do NOT Do with Children's Data

7.5 Other Players and Multiplayer (Child Safety)

mi mi Arena includes multiplayer games and public leaderboards. Parents should be aware that:

7.6 Parental Rights and Controls

Parents and legal guardians can exercise the following rights at any time, in-app or by contacting std@drimssy.com:

We respond to all parental requests within 30 days. Deletion erases personal data and unlinks your devices; the activation code that pairs a physical mi mi is reset so the toy can be re-registered later. Deletion is performed without undue delay, residual copies in encrypted backups expire on a rolling basis (within 30 days), and consent records are retained only where legally required.

7.7 Third-Party Data Processing for Children

7.8 School and Educational Use

If mi mi Friend is used in an educational setting, the school may provide consent on behalf of parents for the collection of children's data solely for educational purposes, in accordance with COPPA's school consent exception. Schools must notify parents and provide them the opportunity to review this Privacy Policy.


8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of all personal data we hold about you (also available via in-app export)
RectificationRequest correction of inaccurate or incomplete data
Erasure ("Right to be Forgotten")Request deletion of your personal data (also available via in-app account deletion)
RestrictionRequest that we limit how we process your data
Data PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests
Withdraw ConsentWithdraw consent at any time where processing is based on consent
Lodge a ComplaintFile a complaint with your local Data Protection Authority

To exercise any of these rights, contact us at std@drimssy.com. We will respond within 30 days of receiving your request.


9. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area, including the United States (where some of our third-party providers operate).

When we transfer data outside the EEA, we ensure appropriate safeguards are in place:


10. In-App Purchases and Subscriptions

mi mi Friend may offer optional premium subscriptions. Where a subscription is offered, all payments are processed exclusively through the Apple App Store or Google Play Store. We do not collect, process, or store any payment card information. Subscription management and billing are handled entirely by the respective app store. RevenueCat acts as our intermediary to verify subscription status; only an anonymous transaction identifier and subscription status are shared with us.

In-game currency (coins, gems) and items have no real-world monetary value and cannot be purchased with, or exchanged for, real money.


11. Device Permissions

mi mi Friend may request the following device permissions:

PermissionPurposeRequired?
NotificationsDelivering reminders and updatesOptional
Photo LibraryAttaching a single screenshot to a support request (only when you choose to)Optional
Motion sensors (Android)Gameplay physics in Arena gamesOptional
InternetCore app functionalityRequired

You can manage these permissions at any time through your device settings. Denying optional permissions will only disable the related feature — the App will continue to function. The App does not request microphone access and does not request advertising/tracking permission.


12. Cookies and Tracking Technologies

The mi mi Friend mobile app does not use cookies. In addition:


13. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  1. Notify the relevant Data Protection Authority within 72 hours of becoming aware of the breach
  2. Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  3. Document the breach, its effects, and the remedial actions taken

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do:


15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.


16. Legal Basis Summary (GDPR Article 6)

Processing ActivityLegal Basis
Account creation and managementArt. 6(1)(b) — Performance of contract
Delivering companion and Academy contentArt. 6(1)(b) — Performance of contract
mi mi Arena and multiplayer gameplayArt. 6(1)(b) — Performance of contract
Anonymous gameplay telemetryArt. 6(1)(f) — Legitimate interest (reliability)
Crash reporting (opt-in)Art. 6(1)(a) — Consent
Subscription managementArt. 6(1)(b) — Performance of contract
Device identificationArt. 6(1)(f) — Legitimate interest
Push notificationsArt. 6(1)(a) — Consent
Transactional emailsArt. 6(1)(b) — Performance of contract
Support requestsArt. 6(1)(b) — Performance of contract
Security, anti-cheat, and fraud preventionArt. 6(1)(f) — Legitimate interest
Parental consent for under-16 accountsArt. 6(1)(c) — Legal obligation; Art. 8 GDPR
Age range classificationArt. 6(1)(f) — Legitimate interest (child safety)