Privacy Policy
Mycelium is self-hosted software you run on your own device. The most important fact about your privacy is structural: your data stays on your machine, and we never receive it. We have no copy of your vault and no ability to read it.
This policy therefore covers two separate things: (A) what the Mycelium application does with your data on your own device, and (B) the limited data the mycelium.id website and our optional online services collect — which is the only data we (the operator) actually handle.
The operator of the website and optional services is Altus Centauri OÜ (registry code 17371918), registered in Estonia ("Curious Life", "we", "us").
1. The Short Version
- Your data lives on your device — your conversations, notes, files, and the search index never leave your machine unless you explicitly send them somewhere.
- We never receive it. We have no server holding your vault, no copy, and no way to access or decrypt it.
- It's encrypted at rest on your device — sensitive data is encrypted with AES-256-GCM (a wrapped-key envelope), with keys only you hold.
- We don't sell, rent, profile, or train on your data — we can't, because it never reaches us.
- Anything that leaves your device is your explicit choice — connecting your own cloud-AI key, enabling remote access, or publishing a document (Section B).
- The website uses Google Analytics (only if you accept analytics cookies) and an optional waitlist form; if you buy a handle (EUR 1/mo) we handle your subscription details and Stripe handles payment — that is the only personal data we directly collect (Section C).
- We are an Estonian company subject to GDPR and the Estonian Personal Data Protection Act.
A. The Mycelium Application (on your device)
A.1 What it holds — all locally
When you use Mycelium, the following are created and stored only on your own device. None of it is transmitted to us:
| Data | What it is | Where it lives |
|---|---|---|
| Messages & conversations | Text you write or import | Your device (encrypted) |
| Documents & notes | Notes, reflections, living documents | Your device (encrypted) |
| Files | Images, PDFs, audio, etc. | Your device (encrypted) |
| Embeddings | Local Nomic v1.5 vectors (768-dim search, 256-dim clustering) | Your device — generated by an on-device model |
| Topology / Mindscape | Clusters and structure computed from your content | Your device |
Embeddings and clustering are computed by a model that runs locally on your machine — your content is not sent anywhere to be embedded.
A.2 What the app sends us: nothing
The application contains no telemetry, no analytics, no crash reporting, and no phone-home. It does not report your usage, contents, or metadata to us or anyone else.
B. Data That Leaves Your Device — Only When You Choose
Some optional features send specific data off your device. Each is opt-in and under your control:
B.1 Cloud AI models (bring-your-own-key)
By default, Mycelium can use local AI models, so nothing leaves your device. If you choose to connect your own API key to a third-party cloud model (e.g. Anthropic, OpenAI, OpenRouter), then for each such request the prompt and context you send travel directly from your device to that provider, authenticated with your key. That exchange is governed by the provider's own privacy policy. We are not in the loop — we never see your key, your prompts, or the responses.
B.2 Remote access relay
If you enable remote access to your own instance, your connection may pass through a relay we operate. The relay is a TLS-passthrough pipe: it forwards encrypted traffic it cannot decrypt or read. We do not terminate your encryption or inspect the contents.
Setting up managed remote access sends our provisioning service only your chosen handle and a public key (to register your address) — never your vault data, contents, or recovery key. This happens only when you explicitly set it up; it is off by default.
B.3 Publishing
If you choose to publish a document, that specific document is served publicly at your chosen handle. Only the content you explicitly publish is made public; nothing else is exposed.
B.4 Connections & shared spaces (roadmap)
Future federation features will let you share specific content with people you choose. They will be opt-in, and this policy will be updated before they launch.
C. The mycelium.id Website & Services
The website and our optional services are where we actually collect a limited amount of personal data:
C.1 Google Analytics & cookies
Our marketing pages use Google Analytics 4 (measurement ID G-P1SYTSNGGM) to understand site usage. GA4 sets cookies and assigns a per-device identifier, and shares data with Google (e.g. IP address, device/browser, pages viewed, approximate location). We use it for traffic measurement only — never advertising.
We ask first. Analytics is not strictly necessary, so we request your consent before it loads. Google Analytics runs only after you accept analytics cookies in our consent banner, and not at all if you decline. You can change or withdraw your choice at any time via the "Cookie settings" link in the footer, and you may additionally install the Google Analytics opt-out add-on. Google's handling is governed by Google's Privacy Policy.
Cookies we set: only Google Analytics cookies (e.g. _ga and _ga_<id>), placed after consent, to distinguish visitors and sessions. We use no advertising or cross-site tracking cookies. To remember your consent choice, the website stores a single value in your browser's local storage — strictly necessary, first-party, stored without consent, and never transmitted to us.
C.2 Waitlist / early-access form
If you submit your email to our waitlist or early-access form, we store that email to contact you about availability and updates. The form submits to our portal endpoint (at mya.is); the email is stored in our database (Supabase), and a notification and a confirmation email are sent via our email-delivery provider (Resend). Legal basis: your consent, given when you submit the form. Every email we send includes an unsubscribe option, and you can ask us to delete your address at any time (business@curiouslife.is).
C.3 Public profile & published pages
If a user publishes a profile or document, the website serves that public content at the user's handle. This displays only what that user chose to make public.
C.4 Hosting & downloads
The website and software downloads are served via Cloudflare and GitHub Releases. Like any web host, these process standard request logs (e.g. IP address, user agent) transiently to deliver content and protect against abuse.
C.5 Paid handle & payment
If you subscribe to a Mycelium handle (EUR 1/month — see our Terms §6), we process the data needed to provide and bill it: your chosen handle, a public key (to provision your relay address), your subscription status, and a billing email. Payment is handled by Stripe: Stripe processes and stores your card details — we never receive or store them, only a Stripe customer reference and whether your subscription is active. Lawful basis: performance of our contract with you (Art. 6(1)(b)). We retain subscription and billing records for the life of the subscription and for as long as accounting and tax law require.
C.6 Donations
If you choose to support development financially (e.g. via Patreon), that transaction is handled by the payment platform under their terms. We receive only what that platform shares with creators (such as your supporter name and tier) — never your full payment details.
C.7 What we do NOT do
- No advertising or ad-targeting profiles
- No selling or renting of personal data
- No using your vault content for anything (we don't have it)
- No cross-site tracking beyond the analytics described above
2. Encryption & Security
At rest: the sensitive data in your vault is encrypted on your device with AES-256-GCM, using a wrapped data-encryption-key envelope keyed to your recovery key. Your recovery key exists only on your machine and never leaves it.
In transit: connections to optional services use TLS; the remote-access relay is TLS-passthrough (encrypted end to end through it).
We hold no vault data, so a breach of our systems cannot expose your conversations, notes, or files.
Your responsibility: the security of your device, OS account, credentials, and recovery key. If you lose your recovery key and backups, your data cannot be recovered — by us or anyone.
3. Legal Bases (GDPR)
For the limited personal data we process (Section C):
| Processing | Legal basis |
|---|---|
| Website analytics (Google Analytics) | Consent (Art. 6(1)(a)) — loaded only after you accept analytics cookies |
| Waitlist email (to contact you) | Consent (Art. 6(1)(a)) |
| Serving the website & downloads (request logs) | Legitimate interest (Art. 6(1)(f)) |
| Paid handle subscription & payment | Performance of contract (Art. 6(1)(b)) + legal obligation for billing records (Art. 6(1)(c)) |
| Donations (supporter info) | Performance of contract / legitimate interest (Art. 6(1)(b)/(f)) |
Your vault data is not processed by us under any basis, because we never receive it.
4. Data Retention
| Data | Retention |
|---|---|
| Your vault (on your device) | Entirely under your control — kept until you delete it |
| Waitlist email | Until you unsubscribe or request deletion, and in any case no longer than 24 months after your last interaction |
| Google Analytics | User- and event-level data retained for 14 months, then automatically deleted (GA4 setting) |
| Web request logs | Short-term, per host (Cloudflare/GitHub) policy |
| Handle subscription & billing records | For the life of the subscription, then as long as accounting/tax law requires (typically up to 7 years) |
5. Sub-processors
For the website and optional services only (never for your vault):
- Cloudflare — website hosting and relay edge. Privacy policy
- Supabase — storage of waitlist / early-access emails. Privacy policy
- Resend — delivery of waitlist / early-access emails. Privacy policy
- Google — Analytics on the marketing site. Privacy policy
- Stripe (if you buy a handle) — payment processing for handle subscriptions. Privacy policy
- GitHub — software release downloads. Privacy statement
- Patreon (if you donate) — voluntary financial support. Privacy policy
Cloud AI providers you connect with your own key are your chosen processors, not ours.
6. Your Rights (GDPR)
For the personal data we hold (Section C), you have the right to access, rectify, delete, export, restrict, and object to processing, and to withdraw consent. Contact business@curiouslife.is; we respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
Your vault data is already in your hands on your own device — you can export or delete it yourself at any time, and we could not act on it even if asked, because we don't have it.
7. Data Transfers
As an Estonian (EU) company, the data we process is protected under GDPR. Where a sub-processor transfers data outside the EU/EEA — primarily Google (Google Analytics, Google LLC, USA) — the transfer relies on the EU–US Data Privacy Framework (Google is DPF-certified) and on Standard Contractual Clauses as a fallback (GDPR Chapter V). Cloudflare, GitHub, Supabase, and Resend similarly rely on Standard Contractual Clauses or adequacy mechanisms (and, where applicable, EU/EEA-region hosting) for any transfers.
8. Security Incidents
Because we hold no vault data, a breach of our systems cannot expose it. If a security incident affects personal data we do process (Section C), we will notify affected users without undue delay and, where required, within 72 hours of becoming aware, describing the incident, the data affected, and the measures taken.
9. Children
Mycelium is not intended for anyone under 18, and we do not knowingly collect data from minors.
10. Changes
We may update this policy. Material changes will be posted on the website with reasonable notice.
Data Flow
YOUR DEVICE ── everything lives here, sensitive data encrypted (AES-256-GCM) ── | | vault, notes, files, embeddings, mindscape | computed + stored locally · keys only you hold | the app sends us NOTHING (no telemetry) | | Optional, only when YOU choose: |-- Cloud AI (your key) ─────► provider you pick (their terms) [off by default] |-- Remote-access relay ─────► TLS-passthrough pipe (can't read it) |-- Publish a document ──────► public at your handle (only what you publish) | mycelium.id WEBSITE (the only data we collect) |-- Google Analytics 4 (cookies + device id, only after you consent) |-- Waitlist form (your email → stored in Supabase, if you submit it) |-- Paid handle €1/mo (optional): handle + public key + subscription status; | card payment handled by Stripe — we never see your card +-- Downloads + standard request logs (Cloudflare / GitHub)
Contact & Supervisory Authority
Data Controller: Altus Centauri OÜ (registry code 17371918), Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
business@curiouslife.is
Supervisory Authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — aki.ee