Service Provider
MiiA is provided by:
NETCOMTESCO CO., LTD. 網通益購科技有限公司 Taiwan Unified Business Number: 53106072 Place of Establishment: Taiwan Service Brand: MiiA Official Domain: miia-ai.com
For general service, privacy, and data-related matters:
For information security incidents or security-related matters:
MiiA’s initial supported service market is Taiwan. The official website may be accessible from other countries or regions, but such accessibility does not mean that MiiA services are officially offered in every jurisdiction.
Age Eligibility
The initial public release of MiiA V1 is intended for users who are:
18 years of age or older.
MiiA V1 is not directed primarily to children or minors.
If MiiA later opens services to minors, appropriate product, safety, parental or guardian, privacy, and legal mechanisms will be established before such services are formally offered.
Our Core Data-Processing Principles
MiiA processes personal data according to the following principles:
- Function Necessity — Data should be processed only where reasonably necessary to provide a requested feature or maintain service security.
- Purpose Limitation — Data should not be repurposed for unrelated or incompatible purposes without an appropriate legal basis or authorization.
- Data Minimization — MiiA seeks to avoid collecting data unrelated to the applicable service purpose.
- User Control — Appropriate controls should be available for Personal Memory, permissions, relationships, calendars, and other important user data.
- Security First — Identity, permissions, and high-risk actions are subject to security controls proportionate to their risk.
- AI Does Not Equal Human Authority — AI inference must not independently create a human trust relationship, permission, payment authorization, legal commitment, or other human intent.
Data We May Process
Depending on the MiiA features you actually use, we may process the categories described below.
4.1 Account and Basic Identity Data
This may include:
- phone number and information necessary for channel verification;
- display name and basic account information;
- account identifiers;
- Trusted Device status;
- credential identifiers, public keys, and related security data necessary for Passkey/WebAuthn;
- account security states and authentication records.
OTP is primarily used as a channel-confirmation mechanism or as part of a verification process. Possession of an OTP alone does not necessarily provide the highest level of identity authority within MiiA.
Friends, Trust Relationships, and Group Data
To provide MiiA’s closed friend and Trusted Group features, we may process:
- invitation and acceptance states;
- friend relationship states;
- Stable Pair Keys or other necessary relationship identifiers;
- Trusted Group membership;
- Owner, Admin, and Member roles;
- group permissions and necessary change records.
MiiA V1 does not use a public stranger directory, nearby-person discovery system, or public social-following model as its default relationship architecture.
AI does not independently create friendship, Trusted Group membership, Owner/Admin authority, or other human trust relationships merely because it infers that two people may be close.
Messages and Attachments
To provide Messenger functionality, MiiA may process:
- messages that you send or receive;
- necessary message identifiers and time information;
- delivery, synchronization, delivered/read, or related state;
- conversation and group identifiers;
- photos and approved document types that you actively upload or send;
- metadata necessary to provide attachment functionality and perform security checks.
The existence of private messages within MiiA does not grant MiiA unrestricted rights to use those messages for unrelated commercial purposes or general AI model training.
Security inspection of attachments should be limited to purposes reasonably necessary to protect the service, users, and systems.
Voice and Video Calls
MiiA V1 supports trusted one-to-one voice and video calls.
To establish, maintain, and protect calls, we may process necessary:
- call session information;
- signaling data;
- connection or relay information;
- quality and diagnostic metadata;
- security and abuse-prevention information.
Call Media Content
MiiA V1 does not provide retention of voice or video call media as a normal product feature.
Voice and video media may pass through necessary network, relay, or communications infrastructure to enable real-time communication, but MiiA does not use that fact to create stored call recordings or video files for later playback.
Necessary signaling, security, and quality metadata should be governed separately from actual call media content.
Calendar, Reminders, and Voice-to-Action
If you use these features, MiiA may process:
- calendar events you create or authorize;
- reminders;
- tasks;
- time information and related context;
- data necessary to perform a Voice-to-Action that you have confirmed.
AI recognition of a spoken or written instruction does not mean that every high-authority action has automatically been authorized.
Actions requiring confirmation or additional security must continue to follow the product’s applicable confirmation or security boundaries.
AI Secretary and MiiA X
MiiA AI functionality may process inputs, context, and outputs necessary for features that you request.
AI context should generally originate from:
- content you directly provide to MiiA;
- content you actively select and ask MiiA to process;
- continuous-assistance context within an appropriately authorized scope;
- confirmed Personal Memory available for the requested purpose;
- other lawful context necessary to provide the function you requested.
The availability of AI does not mean that MiiA automatically reads or may freely use all private chats, attachments, calendars, or other private data.
Personal Memory
MiiA Personal Memory is governed around user confirmation.
The intended process is:
Memory Candidate → User Confirmation → Save
MiiA may identify information that could be useful in future assistance, but an AI inference should not automatically become permanent or authoritative Personal Memory.
For saved Personal Memory, MiiA should provide appropriate user controls, depending on the applicable feature, including:
- viewing;
- correction;
- deletion;
- revocation;
- management of visibility or usage scope.
Personal Memory that has been deleted or revoked by the user should no longer be used as normal AI context.
AI in Trusted Groups
Within a Trusted Group, MiiA AI interactions follow a:
Requester-Private by Default
principle.
A private AI request made by an individual group member does not automatically become visible to all members merely because it occurred within a group environment.
Where sharing functionality is available, sharing should occur through an explicit sharing process, shared candidate, shared state, or another approved mechanism rather than through independent AI judgment.
AI Model Training
MiiA’s default policy is that:
Private messages, call content, attachments, Personal Memory, calendar data, contact data, and private content submitted through Support or Security channels are not default sources for general model training.
If MiiA later offers a voluntary data-contribution or model-improvement program, separate information and governance should be provided, including:
- purpose of use;
- categories of data;
- participation eligibility;
- whether de-identification or other protective measures are used;
- consent and withdrawal mechanisms;
- other necessary governance conditions.
Consent for Personal Memory and consent for model training are separate matters.
Device and Security Data
To maintain service functionality, security, and compatibility, we may process:
- device type;
- operating-system version;
- application version;
- push notification tokens;
- authentication events;
- Security Hold or other security states;
- IP address, network, or necessary connection information;
- crash, error, security-event, and necessary diagnostic data.
Production diagnostics should not ordinarily include the following as general diagnostic log content:
- private message bodies;
- complete attachment contents;
- Personal Memory;
- voice or video call media.
Biometrics
Where MiiA uses Face ID, fingerprints, or other platform biometric capabilities, authentication is generally performed by the device operating system or another trusted platform.
MiiA does not use an architecture in which it obtains or stores raw Face ID, fingerprint, or similar biometric templates as its own authentication database.
MiiA receives only the necessary authentication or security result provided by the applicable platform rather than creating its own raw biometric repository.
Points, Subscriptions, and Payments
MiiA’s product strategy includes Free, Plus, Pro, Points, and related capabilities.
However, publication of the website does not mean that every paid plan is already available for purchase.
Paid functionality will be offered only after the applicable billing, App Store, Google Play, or other payment and release requirements have been completed.
As a product principle, MiiA:
- does not store complete payment-card numbers or CVV itself;
- does not impose automatic overage charges without clear user authorization;
- should clearly disclose pricing, billing cycle, renewal, cancellation, and other material terms when subscriptions are actually offered.
Actual payment processors, refund rules, taxes, trials, cancellation rules, and regional requirements must reflect the payment mechanisms, platform rules, and legal requirements in effect when the relevant paid service is launched.
Support and Security Communications
If you voluntarily contact us through:
or
we may process information that you choose to provide, such as:
- your email address;
- email content;
- problem description;
- attachments;
- case-handling and reply records;
- information necessary to investigate a security matter.
Please do not send the following by email:
- passwords;
- recovery secrets;
- OTP codes;
- Passkey private keys;
- full payment-card information;
- unnecessary sensitive information.
The ability to send an email from an address does not, by itself, prove that the sender is authorized to control an account, delete data, or perform another high-risk action.
For sensitive privacy, deletion, account, or security requests, MiiA may require additional identity verification.
Data We Do Not Normally Collect or Retain
Unless separately introduced through an appropriate product, legal, and user-authorization process, MiiA V1 does not use the following as ordinary service data:
- raw Face ID, fingerprint, or other biometric templates;
- stored voice/video call recordings for later playback;
- complete device contact books permanently uploaded without necessary authorization;
- continuous precise-location tracking;
- heart rate, blood oxygen, blood pressure, or other Health/Wearable physiological data;
- complete credit-card numbers or CVV;
- cross-site advertising tracking profiles;
- device data unrelated to MiiA functionality, security, or legal obligations.
If MiiA Care, wearable, or health-related capabilities are introduced in the future, they will require separate product, security, privacy, and legal review before launch.
Third-Party Service Providers
MiiA may use approved third parties to provide website hosting, cloud, AI, communications, authentication, notification, support, security, payment, or other infrastructure.
MiiA uses an Approved Processor Register governance model.
A third party should be treated as a formal Production Processor only when it:
- actually enters Production;
- has a defined purpose;
- processes data within a necessary scope;
- has completed applicable security, contractual, and privacy review.
Testing, validation, candidate, or future providers do not automatically become MiiA Production Processors.
Data Location and Cross-Border Processing
MiiA’s initial supported market is Taiwan, but approved cloud or third-party services may involve processing outside Taiwan.
MiiA does not make an unsupported promise that all data is stored exclusively in Taiwan where Production architecture cannot prove that claim.
Where cross-border processing occurs, MiiA’s principles are that it should:
- be necessary for providing the service;
- involve only necessary data;
- use approved Processors;
- apply appropriate safeguards required by applicable law and contractual arrangements;
- trigger appropriate privacy and legal review when material Provider or processing-region changes occur.
Data Retention
MiiA uses a:
Data-Class-Based / Minimum-Necessary Retention
approach.
Different categories of data should not automatically share the same retention period merely because they exist within the same service.
Retention should be determined according to factors such as:
- the period necessary to provide the applicable function;
- account, message, group, or relationship lifecycle;
- user deletion or revocation;
- security and incident-investigation needs;
- legal, accounting, consumer-dispute, or other statutory obligations;
- actual backup and deletion capabilities of Production Providers.
In particular:
- Voice/Video call media: 0-retention product principle;
- Personal Memory: should remain subject to user deletion and revocation controls;
- expired or revoked push tokens: should be removed according to system lifecycle;
- attachments should not become permanently orphaned data without a legitimate purpose;
- Legal Holds should be limited to necessary data and necessary duration.
MiiA does not make fixed deletion-time commitments that have not yet been proven by Production architecture.
Account and Data Deletion
MiiA will provide appropriate mechanisms for account and data deletion.
As a general principle:
- users should first use available in-App account or data-management functionality;
- if they cannot access the App, they may contact support@miia-ai.com for assistance;
- sensitive deletion requests may require additional identity verification;
- Active Production data, backups, security/audit records, and Processor copies may have different lawful lifecycles;
- certain necessary data may be retained for a limited purpose where required by a security incident, dispute, legal obligation, or lawful hold.
MiiA will not assume that a person is entitled to delete another person’s account or data merely because that person can send an email from a particular address.
Your Rights Regarding Personal Data
Subject to applicable law and the circumstances of the request, you may have rights to request:
- inquiry or access;
- a copy;
- supplementation or correction;
- cessation of collection;
- cessation of processing or use;
- deletion.
Certain requests may be subject to lawful limitations necessary for security, fraud prevention, disputes, legal retention obligations, or protection of the rights of others.
General data requests may be submitted to:
Where MiiA provides a more direct and secure in-App data-management or deletion mechanism, we may recommend that you use that process first.
Sensitive requests may require identity verification.
Consequences of Not Providing Data
You may choose not to provide data that is not necessary.
However, where specific data is required to provide a requested feature — such as account verification, communication recipients, message content, calendar data, or necessary security information — failure to provide that data may make the relevant feature unavailable or prevent it from functioning properly.
MiiA should not require data unrelated to a function as an unreasonable condition for access to an otherwise necessary service.
Information Security
MiiA applies technical and organizational controls appropriate to the relevant data and feature risk, which may include, depending on the implemented architecture:
- Trusted Device;
- Passkey/WebAuthn;
- platform authentication;
- step-up verification;
- role and permission controls;
- Security Hold;
- least-privilege principles;
- privileged-action and security-event auditing;
- appropriate encryption, transport security, or other safeguards.
No networked service can guarantee the complete absence of all security risks.
If you discover a security issue that may affect MiiA or its users, please contact:
Limitations of AI
MiiA AI may assist with organizing, understanding, summarizing, reminding, recommending, and carrying out appropriately authorized functions. However, AI outputs may be incomplete, incorrect, or affected by insufficient context.
In particular, where an issue concerns:
- identity;
- permissions;
- finance;
- law;
- medicine;
- security;
- other significant rights or interests,
an AI inference must not automatically be treated as a legally effective human intention, authority, or professional determination.
MiiA is designed to assist the real user, not to create human decisions without authorization.
Updates to This Policy
This Policy may be updated due to:
- product changes;
- Production Provider changes;
- legal or regulatory requirements;
- security architecture changes;
- expansion of MiiA into new supported markets.
Each formal version should have a clear:
- Version;
- Effective Date.
For material changes that may significantly affect user rights or data-processing practices, MiiA will provide appropriate notice according to applicable law and the nature of the change.
MiiA should retain a reasonable history of prior versions to support traceability.
Contact Us
If you have questions about this Privacy Policy, personal data, account information, or other privacy-related matters, please contact:
NETCOMTESCO CO., LTD. 網通益購科技有限公司 Taiwan Unified Business Number: 53106072 Brand: MiiA
General, Support, Privacy, and Data Requests:
Security Matters:
