Skip to main content
is now live Try free

Privacy Policy

Last updated: September 2026

The short version. remembers the things you want off your mind: tasks, people, plans. Your data is scoped to your account, encrypted in transit and at rest, never sold, and never used to train general-purpose AI models (one narrow provider-side safety exception is described below), and shared only with providers needed to run mial. You can export or delete your account at any time.

This policy applies whenever you use or sign up for our updates.

Who this applies to

is operated by Bendwater Labs LLC ("we", "us", "our"). This policy covers getmial.com and the web app, and applies to anyone who signs up for an account or uses the app.

What we collect

Account info. Email address and a password, which our authentication provider hashes. We never see or store your password in readable form. Your subscription tier.

What you put in . Anything you add to the app: tasks, appointments, notes, people, profile details. This is your product data.

Usage. Operational metadata only: when you log in, the usage counts we need to enforce limits, your subscription tier, and aggregate page-view counts on the website. We don't run granular click-tracking or behavioral analytics, and we don't build a profile of how you use the app.

Payment info (paid plans). If you subscribe, our payment processor collects payment details. We never see or store full card numbers.

Security signals. When you sign in, or when a request is checked against our abuse and rate limits, we record your IP address, your browser's user-agent string, and a timestamp. We use these only to protect accounts, investigate abuse, and enforce limits.

What we don't collect. Advertising cookies, cross-site trackers, precise location (no GPS, no location permissions; note that the IP address we record for security is coarse location by nature), your contacts, or your calendar. Voice input is handled by your browser's own speech feature, which may send audio to the browser maker under its policy. We don't receive or store the audio.

How we use it

Who we share with

We use a small set of well-known infrastructure providers. Each is engaged to provide one specific service. We do not sell your data, and we do not authorize these providers to use data for their own purposes.

Where your data lives

When you create an account, your data is stored in our hosted cloud database so you can sign in from any device and find it there. Access is scoped to your account, and we don't access your content except to operate and secure the service, to answer a request you make, or where the law requires it.

To be precise about what that means: the web app is not end-to-end encrypted. Your content is encrypted in transit and at rest, but our service can read what it stores, which is what makes features that read your content possible. Where the product offers encrypted cross-device sync, that sync payload is end-to-end encrypted with a key derived on your device, and we cannot read it.

Data follows you across devices: sign in on a new device, your data is there.

Cookies and local storage

We use session cookies and local storage to keep you signed in. We don't use advertising, retargeting, or analytics cookies.

Information about other people

Much of what you put in is about other people: relationships, birthdays, preferences, notes about how someone is doing. You are responsible for what you choose to record about others. That information sits in your account under this policy and is never sold. It is handled exactly like the rest of your content: the providers listed above, our AI provider if you use AI features, and wherever you send it yourself when you export. A good rule: record what you would be comfortable with that person knowing you keep.

When you export

Export produces a file containing everything in your account, including anything you have recorded about other people. Once exported, the file is yours and outside our control. If you paste it into another AI tool, that tool's terms and privacy practices apply to the copy you gave it, not ours, and they can differ materially: some consumer AI tools use pasted content for model training unless you opt out. Check the destination tool's data settings before pasting sensitive context.

Your rights

These abilities are how the product works for every user, wherever you live. You can see, export, correct, and delete everything, and we will not make that difficult. does not sell personal information.

Data retention

We keep your data for as long as you have an account. When you delete your account, your data is removed as described above. Copies inside our database provider's routine backups age out on that provider's rolling backup cycle. Backups are only ever restored to recover from a serious failure, not to look anything up.

Security

Your data is encrypted in transit and at rest. Passwords are hashed by our authentication provider and we never see or store them in readable form. Access controls scope every account to its own data. No system is unbreakable, but we treat your data the way we'd want ours treated. If we become aware of a breach affecting your personal data, we'll notify you as required by law.

Children's privacy

isn't designed for anyone under 13. We don't knowingly collect data from children under 13 and will delete any account we find that violates this. Parents who think their child has signed up can email hello@getmial.com.

International transfers

's infrastructure operates in the United States. If you use the service from elsewhere, your data is stored and processed in the United States.

Changes to this policy

If we make a material change to how we handle data, we'll update this page and change the date above. Where the change is significant and we can give notice in advance, we'll email account holders before it takes effect.

Contact

Questions, requests, or complaints: hello@getmial.com.

Our Terms of Service cover your account, billing, and the rules for using .