Last Updated: June 25, 2026

Privacy Policy

Miningful, also referred to as the Platform, we, us, or our, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our website, services, applications, and tools, in accordance with the GDPR and applicable Greek data protection laws.

1. Data Controller

For GDPR purposes, the Data Controller is APEIRON SOFTWARE O.E., Thessaloniki, Greece. Privacy requests may be sent to support@miningful.bio. VAT: EL803281060. GEMI: 193713204000. Registered address: Straitsa 2, 57001 Thessaloniki, Greece. Miningful has not appointed a Data Protection Officer because we do not currently consider such appointment mandatory under the GDPR.

2. Legal Basis for Processing

We process personal data only where we have a valid legal basis under the GDPR. Account and registration data is processed to create, authenticate, secure, and maintain your account under contract and legitimate interests for security.

Page content, public profile data, uploaded media, billing metadata, AI prompts, usage logs, visitor analytics, support communications, and marketing communications are processed according to the purposes, legal bases, recipients, and retention periods described in this policy.

3. Data We Collect and How We Collect It

From Creators, we collect registration and profile data such as email address, username, hashed password, display name, bio, and avatar; page content and custom elements; uploaded media; billing and payment metadata handled through Stripe; and interaction logs for AI credit and usage management.

From visitors of published pages, we may collect hashed IP signatures, user agent information, referrers, link interactions, and Google Analytics signals if the Creator configured Google Analytics and the visitor consented.

4. How We Share Your Data

We share data with service providers as needed to provide the Services, including AI generation providers such as Anthropic, Google Gemini, and OpenRouter; Brevo for transactional email; Stripe for payment processing; Cloudflare for domain, SSL, KV, CDN, and R2 storage; and MongoDB Atlas for database hosting.

5. International Data Transfers

To deliver the Services, some third-party infrastructure may be located outside the EEA, primarily in the United States. Where personal data is transferred outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses or rely on recipient certification under the EU-U.S. Data Privacy Framework where applicable.

6. Required and Optional Data

Some personal data is required to use the Services, such as email, username, and password for account creation, and billing-related information for paid subscriptions. Optional profile, page, media, integration, and customization data can be omitted, but some features may not be available or may not function as intended.

7. Cookies and Local Storage

For logged-in Creators, we use a session or JWT token to keep you securely logged into your dashboard.

For visitors of published pages, our tracking script displays a consent banner before analytics tracking takes place. Visitors can accept or reject analytics tracking. The mf_analytics_consent and mf_vid localStorage values are used only as described in this policy, and Google Analytics loads only after consent where configured by the Creator.

8. Data Retention

Account data is retained while your account is active. If you request account deletion, profile, pages, and metadata are permanently deleted or anonymized within 30 days. Individual visitor analytics logs are retained for a maximum of 12 months before deletion or aggregation. AI prompts are retained for a maximum of 30 days for debugging unless longer retention is legally necessary.

9. Creator-Controlled Integrations and Third-Party Links

Creators may add third-party links, embeds, widgets, and integrations. Third-party services may collect or process personal data under their own policies. For visitor data collected directly on published pages through our Services, the Creator acts as Data Controller and Miningful acts as Data Processor. Creators are responsible for providing any privacy notices or consents required for their own end-users.

10. Your Rights Under the GDPR

You may have the right to access, rectify, erase, restrict, port, object to processing, and withdraw consent where processing is based on consent. To exercise your rights, email support@miningful.bio. We will respond within 30 days. You may also contact the Hellenic Data Protection Authority at www.dpa.gr.

11. Security of Your Data

We implement appropriate technical and organizational measures including HTTPS encryption, bcrypt password hashing, and salted hashing of visitor IP addresses. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the Last Updated date.