Trusted Device
Important actions build on a trusted device and its current security state.
SECURITY & PRIVACY
MiiA does not treat “AI can do this” as “AI is allowed to do this.” Security and privacy boundaries come before assistance and automation.
DESIGN PRINCIPLES
These principles describe MiiA’s product and architecture direction without relying on absolute or unverifiable security claims.
Important actions build on a trusted device and its current security state.
When re-authentication is required, iOS or Android owns the native security presentation.
Specific conversations can have an additional privacy and re-authentication boundary.
When authorization is unclear, access and sharing scope do not expand.
Request only the permissions actually needed for the task at hand.
Trust comes from relationships the user explicitly establishes or verifies, not AI inference alone.
Sensitive content should remain appropriately redacted in notification and preview contexts.
AI assistance follows existing relationship, sharing and authorization boundaries.
Personal memory is designed around user control, confirmation and manageability.
AI PERMISSION BOUNDARY
Permission and authentication are prerequisites MiiA must respect, not conclusions AI is allowed to invent.
Trust grants coordination; AI never manufactures authority.

USER CONTROL
MiiA security experiences should be clear and restrained so users understand when authentication is required, when content is protected and where the sharing boundary sits.
When authentication or permission is needed, show an understandable next step instead of internal diagnostics.
MiiA does not create fake Face ID, Touch ID or Android BiometricPrompt experiences.
Trust is not built with absolute security language that lacks validated evidence.
SECURITY REPORTING
The official security reporting method will be published after a real, tested MiiA contact channel is ready to receive reports. No unverified channel is presented as active.