Minitu
Terms Guidelines Safety Vendors Support Delete account

Privacy Policy

Minitu Privacy Policy

Last updated: 2026-07-19

Minitu is a social app for adults to meet real people, make global friends, and share experiences through conversation. This policy explains the data Minitu currently collects, how it is used, who helps process it, how long it is kept, and how users can exercise privacy rights.

Controller, Contact, And Jurisdiction

The data controller is Minitu. Privacy questions, data-rights requests, and account deletion requests should be sent to privacy@minitu.app. Safety concerns may also be sent to safety@minitu.app.

Minitu currently uses Mexico as its primary operating jurisdiction, while also honoring privacy rights required by applicable laws in the locations where users access the service. If Minitu forms a separate legal entity or changes its operating jurisdiction, this section must be updated before App Store submission.

Information Minitu Currently Collects

  • Account data: name, email address, password hash and salt, account ID, session tokens, email verification status, password reset records, and legal consent timestamps.
  • Age and eligibility data: age, date of birth, minimum-age confirmation, country, language settings, and onboarding choices.
  • Profile data: public name, country or city-style profile location, gender, availability, profile photos, gallery photos, interests, bio, about-me text, looking-for text, boundaries, social intent, conversation preferences, visibility, message privacy, safety mode, appearance settings, and chat counters.
  • User content: chat text, photo-message URLs, voice-message URLs and duration, message translations, archived user content, saved vocabulary, correction entries, relationship notes, and friend request messages.
  • Safety and moderation data: reports, report reasons, blocked profiles, muted profiles, hidden profiles, reported photos, reported messages, reported posts or comments, moderation status, timestamps, reporter IDs, and admin review actions.
  • Device and notification data: Expo push tokens, web push subscriptions when used, device name, platform, language, notification permission status, and notification delivery metadata needed to send social updates.
  • Media upload data: profile photos, gallery photos, chat photos, and voice-message files uploaded through the app or stored through a vendor.
  • Optional profile verification data: a short video selfie streamed to AWS Rekognition, a reference frame returned by AWS, approved profile photos used for comparison, consent version and timestamp, verification status, decision source, and internal liveness or face-match confidence metadata.
  • Operational data: timestamps, API activity needed for app state, direct-message safety counters, database status, and records needed to keep the service reliable and secure.
  • Support data: messages users send to support, privacy, or safety contact channels.

Minitu does not currently collect precise GPS location, address book contacts, payment card data, purchase history, health data, fitness data, advertising identifiers for tracking, or browsing history.

How Minitu Uses Information

  • To create accounts, authenticate users, verify email addresses, reset passwords, and restore saved sessions.
  • To provide social profiles, global discovery context, chats, friend requests, saved vocabulary, corrections, and notifications.
  • To personalize profile discovery, language preferences, message visibility, safety settings, and social recommendations.
  • To upload, host, display, and moderate photos, chat photos, and voice messages.
  • When a user opts in, to check that a live person is present, compare an AWS reference frame with approved profile photos, reduce impersonation, and issue or deny a profile verification badge.
  • To translate supported chat messages when a user taps Translate and a translation path is available.
  • To operate report, hide, block, mute, photo-report, message-report, account export, and account deletion tools.
  • To investigate abuse, enforce community rules, protect users, prevent spam or scams, comply with law, and satisfy App Store or Google Play policy obligations.
  • To troubleshoot bugs, monitor reliability, and operate the service safely.

Vendors And Subprocessors

Minitu uses third-party vendors to run the service. These vendors process data only as needed for hosting, database storage, email delivery, push notifications, media hosting, photo safety checks, and optional translation support. The current public vendor list is available at Minitu Vendor and Subprocessor List.

  • Render and PostgreSQL for backend hosting, database storage, and operational infrastructure.
  • Expo Push Notifications, Apple Push Notification service (APNs), and Firebase Cloud Messaging where applicable for push notification delivery.
  • Cloudinary for profile photo and gallery photo hosting when cloud upload is configured.
  • AWS Rekognition for automated profile photo safety checks and optional Face Liveness profile verification when configured.
  • Resend for email verification, password reset, and service email delivery when configured.
  • Google Cloud Translation for manual chat translation when configured. LibreTranslate or OpenAI may be used only as fallback translation providers if their environment variables are configured. If enabled, selected chat message text may be sent to the configured provider when the user requests translation.

Optional Biometric Profile Verification

Profile verification is optional. If a user chooses it, Minitu uses Amazon Web Services, Inc. (AWS) as a service provider for Amazon Rekognition Face Liveness and CompareFaces. The iPhone camera streams a short video selfie to AWS to check whether a live person is present. AWS returns a liveness result and a reference frame. Minitu then sends that reference frame and the user's approved profile photos to AWS for face comparison. This processing may involve biometric identifiers or biometric information under applicable law.

By selecting the verification consent checkbox and starting the check, the user consents on behalf of Minitu and AWS, as Minitu's service provider, to collecting, transmitting, processing, using, and temporarily storing the video selfie, reference frame, and approved profile photos for profile verification, fraud prevention, and human review of uncertain results. Minitu does not use this data for advertising, does not create a searchable face collection, and does not use the verification badge as proof of a legal identity or government ID.

Minitu does not store the short video selfie. Minitu requests zero AWS audit images and does not configure an S3 output location. AWS states that Face Liveness session data becomes unavailable when the session expires, three minutes after the session ID is issued. Minitu deletes the returned reference frame immediately after a clear automatic approval or rejection. If the result is uncertain or a comparison cannot be completed, Minitu may keep the reference frame in private storage for human review and deletes it after approval, rejection, cancellation, or account deletion. Verification status, consent records, decision source, and internal confidence metadata may remain with the account for safety, audit, fraud prevention, and user support.

AWS Rekognition documentation states that AWS may store and use image or video inputs to maintain or improve its services unless an applicable account-level AI services opt-out policy is enabled. On July 19, 2026, Minitu enabled an AWS Organizations opt-out policy for Amazon Rekognition and attached it to the organization's root. AWS states that opting out deletes historical copies stored only for service improvement; content needed to provide the service is not deleted by that setting. Users may request deletion through privacy@minitu.app; Minitu will delete data it controls and instruct AWS to delete biometric data stored on Minitu's behalf when required by applicable law.

Face Liveness and face comparison are probabilistic and may be wrong. Clear results may be decided automatically; uncertain results may be reviewed by the Minitu moderation team. A pending review can be cancelled in the app. Users may decline verification, contact privacy@minitu.app to withdraw consent or request deletion of verification records, or delete their account. Declining or withdrawing verification means the profile will not display the verification badge.

Photos, Voice, Messages, And External Translation

Photos, chat photos, and voice messages are user content. Profile and gallery photos may be uploaded to Cloudinary when Cloudinary settings are configured. Voice messages are uploaded to Minitu backend storage. Messages are visible to conversation participants and may be reviewed by moderation if reported.

Profile photos may be checked for safety before they appear publicly. When AWS Rekognition is configured, Minitu may send uploaded profile photo image data to AWS Rekognition to help detect nudity, unsafe content, unclear faces, or possible underage users. Photos that need human review may be held from public display until a moderator approves or rejects them.

Minitu can translate supported chat messages manually, on demand, when a user taps Translate. Translation is not intended to translate all chats in bulk. The current production translation path is Google Cloud Translation when configured. Fallback paths may include LibreTranslate, local phrasebook-style translations, or OpenAI depending on the backend environment. When an external provider is used, the selected message text, source language, and target language may be sent to that provider to return a translation. Minitu stores the resulting translation fields for that message, including translation, translationLanguage, translationSource, and translatedAt, so the translated text can remain visible when the chat is reopened. The original message remains available through View Original. Translations may be incomplete or inaccurate. Translation providers are listed at vendors.html.

Data Retention

Category Retention
Account, profile, and consent records Kept while the account exists. Removed from active systems when the account is deleted, except limited records described below.
Messages, message translation fields, archived user content, vocabulary, corrections, friend requests, and relationship notes Kept while the account exists and the feature requires them. Removed from active app surfaces during account deletion.
Photos and voice files Kept while used by the account or message. Account deletion removes active app references and attempts to physically delete owned local uploads plus Cloudinary assets when a safe public_id can be derived or was stored during upload. Failed or pending media deletion attempts are logged with hashed media references for review or retry.
Biometric profile verification AWS Face Liveness session data becomes unavailable after the three-minute session expires. Minitu does not store the video selfie. The private reference frame is deleted after an automatic decision, completed human review, cancellation, or account deletion. Consent, status, decision source, and internal confidence metadata may remain while the account exists or as reasonably needed for safety, audit, fraud prevention, legal obligations, and support.
Safety and moderation records Kept as long as reasonably needed to investigate reports, prevent abuse, enforce rules, comply with law, or protect users. Current account deletion removes many user-linked reports from active records, but Minitu may retain limited safety records where required.
Push tokens and sessions Kept while notifications or sessions are active. Removed when users log out, disable notifications where supported, or delete the account.
Email verification and password reset records Kept until used, expired, replaced, or cleared after successful verification/reset.
Account deletion log After account deletion, Minitu keeps a limited deletion record containing deletion time, a hashed account reference, optional reason, and a minimal media deletion audit for security, audit, abuse-prevention, and legal purposes.
Support requests Kept as long as needed to answer the request, maintain records of privacy/safety decisions, and comply with legal obligations.

Your Rights And Choices

  • Access: request a copy of your account data or use the in-app Export data control in Profile > Settings > Privacy & account.
  • Correction: update profile information in the app or contact privacy@minitu.app for help correcting account data.
  • Export/portability: use Export data in the app or request a copy by email.
  • Deletion: delete your account in the app from Profile > Settings > Privacy & account or use the public account deletion page.
  • Objection/restriction: contact privacy@minitu.app if you want to object to or restrict certain processing where applicable law gives that right.
  • Consent withdrawal: cancel a pending profile verification in-app, contact privacy@minitu.app regarding an approved verification or biometric record, and turn off optional permissions such as photos, camera, microphone, or notifications in device settings. Some features may not work without the permission they require.
  • Complaint: users in locations with privacy regulators may have the right to complain to their local data protection authority.

Account Deletion

Users can delete their account in the app from Profile > Settings > Privacy & account by typing DELETE and confirming. The deletion flow removes the account, session tokens, profile data, conversations, posts, comments, relationship records, and social links from active app surfaces. Details are available at Minitu Account Deletion.

The deletion flow also attempts to delete owned files from local upload storage and Cloudinary. If Cloudinary credentials are unavailable, a legacy URL cannot be mapped safely, or a vendor deletion call fails, Minitu records a minimal hashed audit entry so the item can be reviewed or retried without keeping unnecessary media details.

Safety And Limitations

Moderation, deletion workflows, account export, and automated abuse detection continue to evolve. Do not use Minitu for emergencies, sensitive personal data, financial data, identity documents, or high-risk communications. If you are in immediate danger, contact local emergency services.

Contact

Privacy questions and rights requests: privacy@minitu.app. Safety concerns: safety@minitu.app. General support: support@minitu.app.