Privacy Policy
Minitu Privacy Policy
Last updated: 2026-09-13
Minitu is a social app for adults to meet real people, make global friends, and share experiences through conversation. This policy explains the data Minitu currently collects, how it is used, who helps process it, how long it is kept, and how users can exercise privacy rights.
Controller, Contact, And Jurisdiction
The data controller for Minitu is Mauricio Joaquín Izaguirre Moreno, an individual operating from Mexico. Privacy questions, data-rights requests, and account deletion requests should be sent to privacy@minitu.app. Safety and moderation concerns may be sent to support@minitu.app.
The address for privacy and legal notices is Abeto 452, Lomas de San Genaro, General Escobedo, Nuevo León 66061, México.
Minitu currently uses Mexico as its primary operating jurisdiction. Store availability may vary by platform and country. Before expanding to additional territories, Minitu will reassess applicable privacy rights, representation requirements, vendor transfers, and local disclosures. This policy will also be updated if the controller identity, legal entity, or primary operating jurisdiction changes.
Information Minitu Currently Collects
- Account data: name, email address, password hash and salt, account ID, session tokens, email verification status, password reset records, and legal consent timestamps.
- Age and eligibility data: age, date of birth, minimum-age confirmation, country, language settings, and onboarding choices.
- Profile data: public name, country or city-style profile location, gender, sexual orientation, availability, profile photos, gallery photos, interests, bio, about-me text, looking-for text, boundaries, social intent, conversation preferences, visibility, message privacy, safety mode, appearance settings, and chat counters.
- User content: chat text, photo-message URLs, voice-message URLs and duration, message translations, archived user content, saved vocabulary, correction entries, relationship notes, and friend request messages.
- Safety and moderation data: reports, report reasons, blocked profiles, muted profiles, hidden profiles, reported photos, reported messages, reported posts or comments, moderation status, timestamps, reporter IDs, and admin review actions.
- Device and notification data: Expo push tokens, web push subscriptions when used, device name, platform, language, notification permission status, and notification delivery metadata needed to send social updates.
- Media upload data: profile photos, gallery photos, chat photos, and voice-message files uploaded through the app or stored through a vendor.
- Optional profile verification data: a short video selfie streamed to AWS Rekognition, a reference frame returned by AWS, approved profile photos used for comparison, consent version and timestamp, verification status, decision source, and internal liveness or face-match confidence metadata.
- Potentially sensitive data: optional profile fields and free text may reveal gender, sexual orientation, identity, social preferences, boundaries, or other sensitive personal information. Optional profile verification may involve biometric identifiers or biometric information.
- Subscription and purchase data: the internal Minitu account identifier; Apple App Store and RevenueCat customer identifiers; product and entitlement identifiers; plan and billing period; purchase, renewal, expiration, cancellation, refund, billing-issue, and restore status; transaction or receipt information; storefront, currency, price, and limited synchronization or event metadata.
- Operational data: timestamps, IP-derived request and security metadata, API activity needed for app state, direct-message safety counters, database status, feature-use counters, provider response metadata, and records needed to keep the service reliable and secure.
- Support data: messages users send to support or privacy contact channels, including email or optional WhatsApp support; this may include a phone number, WhatsApp profile information, messages, attachments voluntarily sent, and message metadata.
If a user chooses location autofill, the device temporarily accesses its current coordinates and uses reverse geocoding to suggest a city and country. Minitu receives the resulting city and country but does not intentionally store the latitude or longitude. Users can enter the city and country manually instead. Minitu does not currently collect address-book contacts, full payment-card details, health data, fitness data, advertising identifiers for cross-app tracking, or browsing history.
Sensitive Information And User Choice
Gender, sexual orientation, identity-related free text, social preferences, and biometric verification data may be sensitive under applicable law. Profile fields include "Prefer not to say," and biometric verification is optional. Minitu processes sensitive information only for the profile, discovery, safety, or verification purpose explained when it is provided and requests express electronic consent where required. Users can remove optional profile information, decline verification, withdraw consent for future processing, or request deletion. Withdrawing consent does not affect processing that was lawful before withdrawal.
How Minitu Uses Information
- To create accounts, authenticate users, verify email addresses, reset passwords, and restore saved sessions.
- To provide social profiles, global discovery context, chats, friend requests, saved vocabulary, corrections, and notifications.
- To personalize profile discovery, language preferences, message visibility, safety settings, and social recommendations.
- To upload, host, display, and moderate photos, chat photos, and voice messages.
- When a user opts in, to check that a live person is present, compare an AWS reference frame with approved profile photos, reduce impersonation, and issue or deny a profile verification badge.
- To translate supported chat messages when a user taps Translate and a translation path is available.
- To operate report, hide, block, mute, photo-report, message-report, account export, and account deletion tools.
- To display subscription products, complete and restore eligible purchases, verify entitlements, provide paid features, reconcile renewals, cancellations and refunds, prevent purchase fraud, provide subscription support, and understand subscription performance.
- To investigate abuse, enforce community rules, protect users, prevent spam or scams, comply with law, and satisfy App Store or Google Play policy obligations.
- To troubleshoot bugs, monitor reliability, and operate the service safely.
Legal Bases Where Required
- Contract: account creation, authentication, profiles, discovery, messages, optional subscriptions, support, export, and deletion requested by the user.
- Consent: optional permissions, sensitive profile fields where required, external translation requested by the user, push notifications, and optional biometric profile verification.
- Legitimate interests: preventing fraud and abuse, securing the service, enforcing rules, moderating content, diagnosing failures, and improving reliability, balanced against user rights.
- Legal obligations and protection of people: responding to valid legal process, addressing child-safety or credible-harm reports, and establishing or defending legal claims.
Where a legal basis is not used in a user's jurisdiction, Minitu relies on the consent, contractual necessity, or other authorization required by applicable law. Minitu does not use sensitive profile or biometric information for advertising.
Synthetic Practice Profiles
Explore may contain clearly labeled synthetic practice profiles that help a user learn the discovery and gallery controls. These fictional profiles use AI-generated portraits and invented names, locations, biographies, interests, activity indicators, compatibility, and conversation prompts. They are not real members and do not represent an actual person's account, location, availability, or interest in the user. Interactions with them may be stored in the user's own discovery and safety state so the interface can function and reset.
Some clearly labeled practice profiles provide a limited, predetermined language exercise. They are not real members, do not conduct an open-ended autonomous conversation, and cannot form a real-world relationship.
Vendors And Subprocessors
Minitu uses third-party vendors to run the service. These vendors process data only as needed for hosting, database storage, email delivery, push notifications, media hosting, photo safety checks, optional translation, Apple subscription billing, subscription administration, and user-initiated support through WhatsApp. The current public vendor list is available at Minitu Vendor and Subprocessor List.
- Render and PostgreSQL for backend hosting, database storage, and operational infrastructure.
- Expo Push Notifications, Apple Push Notification service (APNs), and Firebase Cloud Messaging where applicable for push notification delivery.
- Cloudflare R2 for private photo and voice storage and short-lived media delivery when configured.
- Cloudinary for photo and voice hosting, including legacy media, when cloud upload is configured.
- AWS Rekognition for automated profile-photo safety checks and optional Face Liveness profile verification when configured.
- Google Cloud Vision for profile-photo SafeSearch review when configured.
- Google Cloud Natural Language for profile-text moderation when configured.
- Resend for email verification, password reset, and service email delivery when configured.
- Apple App Store for purchase confirmation, billing, subscription management, refunds, and storefront-localized prices.
- RevenueCat for subscription product retrieval, entitlement verification, purchase restoration, lifecycle synchronization, fraud prevention, customer support, and subscription analytics.
- Google Cloud Translation, including its configured Translation LLM model, for requested translations. LibreTranslate or OpenAI may be used only as configured fallback providers. Selected message or profile text and language information may be sent to the selected provider.
When Information Is Disclosed
- Other users receive profile information and user content according to the user's visibility, messaging, and social choices.
- Service providers receive only the categories needed to provide hosting, media, email, push, moderation, translation, verification, subscription, payment, analytics, or support services.
- Competent authorities or other parties may receive information when required by valid legal process, to report suspected child exploitation or credible threats, to protect rights and safety, or to establish or defend legal claims.
- A successor may receive information during a merger, financing, acquisition, reorganization, or sale of assets, subject to confidentiality, required notice, and applicable privacy rights.
Minitu does not sell personal data to data brokers and does not share personal data for cross-context behavioral advertising.
International Processing And Transfers
Minitu is operated from Mexico, and its providers may process information in Mexico, the United States, and other countries where they or their infrastructure operate. Those countries may have different privacy laws. Minitu limits transfers to providers needed to operate the service and uses the contractual, consent, and other safeguards required by applicable law.
By accepting this policy and using features that require these providers, users acknowledge the transfers described here. When applicable law requires separate express consent, including for sensitive or biometric data, Minitu requests that consent before starting the feature. Minitu does not sell personal data to data brokers or share it for cross-app advertising tracking.
Optional Live Profile Verification — Face Data
Feature status: Profile verification is optional. A user can use Minitu without completing it; declining means only that the profile will not receive a verification badge.
1. Face data Minitu collects
- A short video selfie streamed directly from the iOS device camera to Amazon Web Services, Inc. (AWS) Rekognition Face Liveness.
- The liveness result and single reference frame returned by AWS.
- The user's approved profile photos, which are sent to AWS CompareFaces with the reference frame.
- Consent version and timestamp, verification status, decision source, and internal liveness or face-match confidence metadata.
2. Purpose and use
Minitu uses this data only to confirm that a live person is present, compare that person with the approved profile photos, reduce impersonation, decide whether to issue a verification badge, prevent verification fraud, and permit human review when an automatic result is uncertain. Minitu does not use face data for advertising, tracking, user profiling, or identification against a database, and does not create a searchable face collection. A verification badge is not proof of legal identity, government ID, or a background check.
3. Sharing and storage
AWS Rekognition is the only third party that performs liveness detection, face comparison, or other biometric analysis for this feature, acting as Minitu's service provider. Minitu does not sell the data, share it with other users, or disclose it to advertising partners. AWS processes the live video, reference frame, and approved profile photos to provide Face Liveness and CompareFaces. Minitu requests zero AWS audit images and configures no S3 output location. If human review is required, Minitu stores only the returned reference frame in access-controlled private managed PostgreSQL storage hosted through Render; the short video is never stored by Minitu. Cloudflare R2 stores approved profile photos as ordinary profile media. Render, managed PostgreSQL, and Cloudflare R2 do not perform liveness detection, face matching, or biometric analysis. No other provider receives the short video selfie or reference frame for face analysis.
4. Retention and deletion
- Short video: Minitu never stores it. AWS states that data associated with the Face Liveness session becomes unavailable when the session expires, three minutes after the session ID is issued.
- Reference frame: deleted immediately after a clear automatic approval or rejection. If the result is uncertain, it is kept privately only until human review is approved, rejected, or cancelled, and never longer than 30 days after submission. It is also deleted sooner when profile photos change in a way that invalidates the review or when the account is deleted.
- Approved profile photos: retained as normal profile content until the user replaces or deletes them or deletes the account; they are not copied into a face collection.
- Verification records: consent, status, decision source, and limited confidence metadata may remain with the account only as reasonably needed for safety, audit, fraud prevention, legal obligations, and support.
On July 19, 2026, Minitu attached an AWS Organizations AI-services content-use opt-out policy for Amazon Rekognition to the organization root. AWS states that the opt-out prevents opted-out content from being used to improve AWS AI services and deletes historical copies kept only for that purpose.
5. Consent, controls, and requests
Minitu displays a separate consent checkbox before creating the AWS session. A user may decline verification, cancel a pending human review in the app, withdraw consent for future processing, request deletion at privacy@minitu.app, or delete the account in the app. Minitu deletes face data it controls. AWS session data becomes unavailable after the three-minute session expires, and Minitu configures no audit-image or S3 copy. Face Liveness and face comparison are probabilistic and may be wrong; users may request human review or appeal a result at support@minitu.app.
Photos, Voice, Messages, And External Translation
Photos, chat photos, and voice messages are user content. New media may be stored privately in Cloudflare R2 and delivered through short-lived signed URLs when R2 is configured. Cloudinary may host profile, gallery, chat, or voice media, including legacy assets, when configured. A local backend storage path may be used only in allowed non-production or fallback environments. Messages are visible to conversation participants and may be reviewed by moderation if reported.
Profile photos may be checked for safety before they appear publicly. When configured, Minitu may send uploaded image data to AWS Rekognition and Google Cloud Vision to help detect nudity, sexual content, weapons, drugs, violence, hate symbols, unclear or missing faces, or possible underage users. Profile introductions may be checked by local rules or Google Cloud Natural Language for abusive or unsafe text. Content that needs human review may be held from public display until a moderator approves or rejects it.
Minitu can translate supported chat messages on demand and may translate supported profile text for the viewer. Translation is not intended to
translate all chat history in bulk. The primary configured path is Google Cloud Translation, using its configured NMT or Translation LLM model.
Fallback paths may include LibreTranslate, local phrasebook-style translations, or OpenAI depending on the backend environment. When an
external provider is used, the selected message or profile text, source language, and target language may be sent to that provider. Minitu
stores the resulting translation fields for a translated message, including translation,
translationLanguage, translationSource, and translatedAt, so the translated text can remain visible
when the chat is reopened. The original message remains available through View Original. Translations may be incomplete or inaccurate.
Translation providers are listed at vendors.html.
Automated Processing And Human Review
Minitu uses profile information, stated preferences, safety state, activity, and compatibility signals to rank discovery profiles. Automated photo and text checks may approve, reject, or hold content, and optional biometric checks may approve, reject, or refer verification for human review. These systems are probabilistic and can be wrong. They are not used to determine credit, employment, housing, insurance, or access to essential services. Users can report an error, appeal moderation, cancel pending verification, or request human review at support@minitu.app. Where applicable law grants a right to object to a decision based solely on automated processing that significantly affects the user, requests may be sent to privacy@minitu.app.
Data Retention
| Category | Retention |
|---|---|
| Account, profile, and consent records | Kept while the account exists. Removed from active systems when the account is deleted, except limited records described below. |
| Messages, message translation fields, archived user content, vocabulary, corrections, friend requests, and relationship notes | Kept while the account exists and the feature requires them. Removed from active app surfaces during account deletion. |
| Photos and voice files | Kept while used by the account or message. Account deletion removes active app references and schedules physical deletion of owned local, R2, and Cloudinary media. While cleanup is unresolved, a restricted job retains the references needed to retry and verify completion; those references are then removed or minimized, subject to limited audit, safety, and legal retention. |
| Biometric profile verification | AWS Face Liveness session data becomes unavailable after the three-minute session expires. Minitu does not store the video selfie. The private reference frame is deleted after an automatic decision, completed human review, cancellation, or account deletion, and never later than 30 days after submission. Consent, status, decision source, and internal confidence metadata may remain while the account exists or as reasonably needed for safety, audit, fraud prevention, legal obligations, and support. |
| Safety and moderation records | Kept as long as reasonably needed to investigate reports, prevent abuse, enforce rules, comply with law, or protect users. Current account deletion removes many user-linked reports from active records, but Minitu may retain limited safety records where required. |
| Push tokens and sessions | Kept while notifications or sessions are active. Removed when users log out, disable notifications where supported, or delete the account. |
| Email verification and password reset records | Kept until used, expired, replaced, or cleared after successful verification/reset. |
| Subscription and purchase records | Minitu keeps a verified subscription summary and limited synchronization or event records while needed to provide access, restore purchases, resolve billing issues, prevent fraud, analyze subscription performance, and meet legal obligations. Account deletion removes the active account summary and starts the configured RevenueCat customer-deletion follow-up; Apple purchase records and Apple billing are controlled separately by Apple. Limited transaction, audit, tax, fraud-prevention, dispute, or backup records may remain where required by law or reasonably necessary for those purposes. |
| Account deletion log | While cleanup is unresolved, Minitu may keep a restricted job containing an internal account reference, status history, and the media or provider references needed to retry and verify completion. After cleanup, Minitu may retain a limited deletion receipt, minimized or hashed references, and limited audit, safety, fraud-prevention, dispute, tax, or legal records where required or reasonably necessary. |
| Support requests | Kept as long as needed to answer the request, maintain records of privacy/safety decisions, and comply with legal obligations. |
Your Rights And Choices
- Access: request a copy of your account data or use the in-app Export data control in Profile > Settings > Privacy & account. The public Privacy Choices page summarizes all available controls.
- Correction: update profile information in the app or contact privacy@minitu.app for help correcting account data.
- Export/portability: use Export data in the app or request a copy by email.
- Deletion: delete your account in the app from Profile > Settings > Privacy & account or use the public account deletion page. Deleting a Minitu account does not cancel an Apple subscription.
- Objection/restriction: contact privacy@minitu.app if you want to object to or restrict certain processing where applicable law gives that right.
- Consent withdrawal: cancel a pending profile verification in-app, contact privacy@minitu.app regarding an approved verification or biometric record, and turn off optional permissions such as photos, camera, microphone, or notifications in device settings. Some features may not work without the permission they require.
- Complaint: users in locations with privacy regulators may have the right to complain to their local data protection authority.
To exercise access, rectification, cancellation, or opposition rights in Mexico, email privacy@minitu.app with the account email, name, a means to receive notices, the right requested, a clear description of the data involved, and any information that helps locate it. Minitu may request reasonable proof of identity or representation and supporting documents, but users should not send unnecessary identity documents before Minitu explains a secure verification method. Minitu will communicate its determination within 20 days and, if granted, make it effective within the following 15 days, subject to lawful extensions or exceptions. A user who is dissatisfied with the response may pursue the protection procedure available before Mexico's Secretaría Anticorrupción y Buen Gobierno under applicable law.
Users can limit use or disclosure through profile visibility, message privacy, safety settings, notification permissions, optional-feature consent controls, and requests sent to privacy@minitu.app.
Users in the EEA, United Kingdom, or Switzerland may also have rights to data portability, restriction, objection, withdrawal of consent, and complaint to a supervisory authority. Depending on applicable United States state law and statutory thresholds, users may have rights to know, access, correct, delete, or obtain a portable copy of personal data and to appeal certain request decisions. Minitu does not discriminate against users for exercising privacy rights. Authorized-agent requests will be verified as required by applicable law.
Security And Incident Notices
Minitu uses administrative, technical, and organizational safeguards appropriate to the nature of the service, including password hashing, session controls, restricted moderation access, provider credentials kept outside the mobile app, private media delivery where configured, and deletion workflows. No system is completely secure. If a security incident is reasonably likely to significantly affect user rights, Minitu will notify affected users and authorities as required by applicable law.
Children
Minitu is not directed to anyone under 18 and does not knowingly permit minors to create accounts. If Minitu learns that an account belongs to a minor, it may restrict or delete the account and associated data. Reports concerning a minor or suspected child exploitation should be sent promptly to support@minitu.app. Minitu may preserve and report relevant evidence when required or permitted by law.
Account Deletion
Users can delete their account in the app from Profile > Settings > Privacy & account by typing DELETE and confirming. The deletion flow removes the account, session tokens, profile data, conversations, posts, comments, relationship records, and social links from active app surfaces. Details are available at Minitu Account Deletion.
The deletion flow removes active account data, revokes sessions, schedules cleanup of owned files from local storage, Cloudflare R2 and Cloudinary, and starts configured RevenueCat customer-data deletion follow-up. Provider phases are tracked separately and may remain pending and retryable until completion can be verified. Apple retains purchase records under its own legal and service obligations, and deleting Minitu does not cancel Apple billing.
Changes To This Policy
Minitu may update this policy when its features, providers, legal obligations, or data practices change. The updated date appears at the top. Material changes will be communicated through the app or another reasonable channel, and renewed consent will be requested when required.
Safety And Limitations
Moderation, deletion workflows, account export, and automated abuse detection continue to evolve. Do not use Minitu for emergencies, sensitive personal data, financial data, identity documents, or high-risk communications. If you are in immediate danger, contact local emergency services.
Contact
Privacy questions and rights requests: privacy@minitu.app. Safety and moderation concerns: support@minitu.app. General support: support@minitu.app.