Mipore
View Mipo-Cat
English

Policy archive / 2026-08-27

Privacy Policy

How Mipore handles personal data across the website, desktop app, customer services, and connected Mipo hardware.

Last updated: August 27, 2026 · Policy version: 2026-08-27

Privacy requests and contact

Mipore processes personal data for this website and its customer services. For privacy requests, email ainfiniapp@gmail.com with the subject “Privacy Request”. We may ask for information needed to verify that a request concerns your account before disclosing, correcting, exporting, or deleting data.

Personal data we collect

We collect account and authentication data such as email address, password hash, email-verification activity, session information, and security/rate-limit records. For an order, we collect name, email, phone number if provided, shipping address, ordered products, shipping calculation, order status, payment-provider order and transaction identifiers, and support correspondence.

When you request an availability notification for an unavailable or not-yet-released product while signed in, we store your verified account email, the exact product and SKU, storefront language, request status, and notification history. The request takes no payment, does not hold inventory, and can be cancelled from the relevant product page.

For order support, we collect the information you submit, such as product details, destination, and messages. We also process limited technical information used to secure and operate the site, including request metadata, security events, country code derived by Cloudflare, and hashed analytics identifiers when you choose analytics cookies. We do not intentionally collect card numbers or full payment credentials.

Why we use data

We use personal data to create and secure accounts; record product and SKU demand; send a requested launch or restock notice; price, accept, process, and fulfill orders; calculate shipping and taxes; communicate about orders, delays, support, returns, and security; prevent fraud and abuse; comply with legal, tax, accounting, and recordkeeping duties; and measure site usage only where analytics consent has been given. Depending on the context, processing is necessary to perform a contract, comply with law, pursue legitimate interests in secure store operation, or is based on consent where consent is required.

Mipore desktop app and Mipo hardware

Mipore is designed to store conversation history, personal-memory choices, agents, schedules, voice setups, robot bindings, and application settings in local application data on your computer. This history remains local unless you share or export a session, configure session auto-sharing, or send relevant content to a selected model or extension.

You choose the AI provider account, API credentials, or compatible endpoint used for a conversation. When you use a hosted model, the current request and the context needed to answer it are sent to that provider. Context can include earlier messages, attached file content, tool results, and system instructions. The provider processes it under its own terms, retention rules, and privacy policy.

During normal conversations, Mipo-Cat exchanges the active audio, reply, display state, and device commands needed for that interaction. During setup, it stores the Wi-Fi and pairing configuration needed to reconnect to the bound Mipore computer. It does not receive provider credentials, complete conversation history, local file paths, or tool secrets. Optional online voices, information tools, plugins, Skills, MCP connections, and other external services may receive the input needed to perform the function you enable.

Packaged Mipore builds check the Mipore update service and may send strictly limited incident metadata when a serious application failure occurs. Update checks include version, platform, architecture, update channel, and a random update-session identifier. Incident reports exclude conversations, prompts, files and paths, account or model details, credentials, Wi-Fi information, audio, and raw crash dumps.

Local application data is separate from website account, order, payment, delivery, and support data. If you intentionally send app logs, screenshots, exported conversations, or other local content to support, we process the material you choose to provide for that support request.

Service providers and disclosures

We disclose only the data needed for the service to Cloudflare for hosting, security, database, storage, and Access controls; PayPal for payment processing; Resend for transactional email; carriers, customs brokers, and fulfillment partners for delivery; and professional advisers or authorities when legally required. We do not sell personal information or share it for cross-context behavioral advertising.

The optional FAQ assistant is restricted from receiving customer addresses, payment details, order data, or administrator data. It cannot make refunds, change orders, or access other customers’ information.

International processing

Because we operate and ship internationally and use global infrastructure providers, personal data may be processed in countries outside your home country, including China and locations where our service providers operate. We limit transfers to what is necessary for the relevant service and use contractual, technical, organizational, or other safeguards required by applicable law when they apply.

Cookies, local storage, and analytics

Essential cookies and similar storage support sign-in, cart continuity, security, language preferences, PayPal checkout, and Cloudflare bot protection. They are necessary for requested site functions. Analytics uses a locally generated visitor identifier and session identifier that are hashed before storage on our server; it records no email address, IP address, full referrer URL, or browser fingerprint. Analytics remains off until you choose “Accept analytics” in the consent banner, and you can change that choice through “Cookie preferences” in the footer.

We do not use advertising, retargeting, or social-media tracking cookies. Declining analytics does not prevent you from browsing, signing in, or checking out, although essential storage remains necessary for those functions.

Retention and security

Expired OTPs, sessions, anonymous carts, and rate-limit records are removed by scheduled cleanup. Availability-notification requests remain until they are cancelled, notified, or the account is anonymized so we can send the requested notice and measure demand. Account anonymization cancels the request and replaces its email with a non-deliverable anonymized value.

Analytics events are retained for up to 13 months. Raw PayPal webhooks are minimized after 30 days. After a terminal order has remained unchanged for 24 months, separate PayPal payer and provider-shipping snapshots are minimized, as are delivery snapshots for orders that never became completed financial transactions. An active payment or dispute hold pauses that cleanup.

The delivery-address snapshot attached to a completed paid transaction is not changed by that 24-month cleanup because it remains necessary for transaction, tax, fulfillment, fraud, and legal-claims evidence. It stays protected with the payment ledger for applicable statutory and claims periods, including seven-year recordkeeping where required.

FAQ-assistant conversations are deleted after 30 days for guests and 90 days for signed-in users. We use access controls, encryption-capable managed services, audit logs, rate limits, and data minimization, but no internet transmission can be guaranteed completely secure.

Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data, withdraw consent for optional analytics, and complain to a competent data-protection authority. You may also request a copy of account data or request account anonymization after a fresh email verification. We may retain information needed for completed transactions, fraud prevention, legal claims, tax, accounting, and other lawful obligations after an account is anonymized.

Children and policy changes

The site is not directed to children under 14, and we do not knowingly collect their personal data. We may update this policy when our practices or legal requirements change. Material changes apply prospectively and are posted with a revised date and version; we will provide additional notice where required by law.