Privacy Policy

Last updated: 26 June 2026 · Effective date: 26 June 2026

Mycelium is self-hosted software you run on your own device. The most important fact about your privacy is structural: your data stays on your machine, and we never receive it. We have no copy of your vault and no ability to read it.

This policy therefore covers two separate things: (A) what the Mycelium application does with your data on your own device, and (B) the limited data the mycelium.id website and our optional online services collect — which is the only data we (the operator) actually handle.

The operator of the website and optional services is Altus Centauri OÜ (registry code 17371918), registered in Estonia ("Curious Life", "we", "us").

1. The Short Version

A. The Mycelium Application (on your device)

A.1 What it holds — all locally

When you use Mycelium, the following are created and stored only on your own device. None of it is transmitted to us:

DataWhat it isWhere it lives
Messages & conversationsText you write or importYour device (encrypted)
Documents & notesNotes, reflections, living documentsYour device (encrypted)
FilesImages, PDFs, audio, etc.Your device (encrypted)
EmbeddingsLocal Nomic v1.5 vectors (768-dim search, 256-dim clustering)Your device — generated by an on-device model
Topology / MindscapeClusters and structure computed from your contentYour device

Embeddings and clustering are computed by a model that runs locally on your machine — your content is not sent anywhere to be embedded.

A.2 What the app sends us: nothing

The application contains no telemetry, no analytics, no crash reporting, and no phone-home. It does not report your usage, contents, or metadata to us or anyone else.

B. Data That Leaves Your Device — Only When You Choose

Some optional features send specific data off your device. Each is opt-in and under your control:

B.1 Cloud AI models (bring-your-own-key)

By default, Mycelium can use local AI models, so nothing leaves your device. If you choose to connect your own API key to a third-party cloud model (e.g. Anthropic, OpenAI, OpenRouter), then for each such request the prompt and context you send travel directly from your device to that provider, authenticated with your key. That exchange is governed by the provider's own privacy policy. We are not in the loop — we never see your key, your prompts, or the responses.

B.2 Remote access relay

If you enable remote access to your own instance, your connection may pass through a relay we operate. The relay is a TLS-passthrough pipe: it forwards encrypted traffic it cannot decrypt or read. We do not terminate your encryption or inspect the contents.

Setting up managed remote access sends our provisioning service only your chosen handle and a public key (to register your address) — never your vault data, contents, or recovery key. This happens only when you explicitly set it up; it is off by default.

B.3 Publishing

If you choose to publish a document, that specific document is served publicly at your chosen handle. Only the content you explicitly publish is made public; nothing else is exposed.

B.4 Connections & shared spaces (roadmap)

Future federation features will let you share specific content with people you choose. They will be opt-in, and this policy will be updated before they launch.

C. The mycelium.id Website & Services

The website and our optional services are where we actually collect a limited amount of personal data:

C.1 Google Analytics & cookies

Our marketing pages use Google Analytics 4 (measurement ID G-P1SYTSNGGM) to understand site usage. GA4 sets cookies and assigns a per-device identifier, and shares data with Google (e.g. IP address, device/browser, pages viewed, approximate location). We use it for traffic measurement only — never advertising.

We ask first. Analytics is not strictly necessary, so we request your consent before it loads. Google Analytics runs only after you accept analytics cookies in our consent banner, and not at all if you decline. You can change or withdraw your choice at any time via the "Cookie settings" link in the footer, and you may additionally install the Google Analytics opt-out add-on. Google's handling is governed by Google's Privacy Policy.

Cookies we set: only Google Analytics cookies (e.g. _ga and _ga_<id>), placed after consent, to distinguish visitors and sessions. We use no advertising or cross-site tracking cookies. To remember your consent choice, the website stores a single value in your browser's local storage — strictly necessary, first-party, stored without consent, and never transmitted to us.

C.2 Waitlist / early-access form

If you submit your email to our waitlist or early-access form, we store that email to contact you about availability and updates. The form submits to our portal endpoint (at mya.is); the email is stored in our database (Supabase), and a notification and a confirmation email are sent via our email-delivery provider (Resend). Legal basis: your consent, given when you submit the form. Every email we send includes an unsubscribe option, and you can ask us to delete your address at any time (business@curiouslife.is).

C.3 Public profile & published pages

If a user publishes a profile or document, the website serves that public content at the user's handle. This displays only what that user chose to make public.

C.4 Hosting & downloads

The website and software downloads are served via Cloudflare and GitHub Releases. Like any web host, these process standard request logs (e.g. IP address, user agent) transiently to deliver content and protect against abuse.

C.5 Paid handle & payment

If you subscribe to a Mycelium handle (EUR 1/month — see our Terms §6), we process the data needed to provide and bill it: your chosen handle, a public key (to provision your relay address), your subscription status, and a billing email. Payment is handled by Stripe: Stripe processes and stores your card details — we never receive or store them, only a Stripe customer reference and whether your subscription is active. Lawful basis: performance of our contract with you (Art. 6(1)(b)). We retain subscription and billing records for the life of the subscription and for as long as accounting and tax law require.

C.6 Donations

If you choose to support development financially (e.g. via Patreon), that transaction is handled by the payment platform under their terms. We receive only what that platform shares with creators (such as your supporter name and tier) — never your full payment details.

C.7 What we do NOT do

2. Encryption & Security

At rest: the sensitive data in your vault is encrypted on your device with AES-256-GCM, using a wrapped data-encryption-key envelope keyed to your recovery key. Your recovery key exists only on your machine and never leaves it.

In transit: connections to optional services use TLS; the remote-access relay is TLS-passthrough (encrypted end to end through it).

We hold no vault data, so a breach of our systems cannot expose your conversations, notes, or files.

Your responsibility: the security of your device, OS account, credentials, and recovery key. If you lose your recovery key and backups, your data cannot be recovered — by us or anyone.

3. Legal Bases (GDPR)

For the limited personal data we process (Section C):

ProcessingLegal basis
Website analytics (Google Analytics)Consent (Art. 6(1)(a)) — loaded only after you accept analytics cookies
Waitlist email (to contact you)Consent (Art. 6(1)(a))
Serving the website & downloads (request logs)Legitimate interest (Art. 6(1)(f))
Paid handle subscription & paymentPerformance of contract (Art. 6(1)(b)) + legal obligation for billing records (Art. 6(1)(c))
Donations (supporter info)Performance of contract / legitimate interest (Art. 6(1)(b)/(f))

Your vault data is not processed by us under any basis, because we never receive it.

4. Data Retention

DataRetention
Your vault (on your device)Entirely under your control — kept until you delete it
Waitlist emailUntil you unsubscribe or request deletion, and in any case no longer than 24 months after your last interaction
Google AnalyticsUser- and event-level data retained for 14 months, then automatically deleted (GA4 setting)
Web request logsShort-term, per host (Cloudflare/GitHub) policy
Handle subscription & billing recordsFor the life of the subscription, then as long as accounting/tax law requires (typically up to 7 years)

5. Sub-processors

For the website and optional services only (never for your vault):

Cloud AI providers you connect with your own key are your chosen processors, not ours.

6. Your Rights (GDPR)

For the personal data we hold (Section C), you have the right to access, rectify, delete, export, restrict, and object to processing, and to withdraw consent. Contact business@curiouslife.is; we respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

Your vault data is already in your hands on your own device — you can export or delete it yourself at any time, and we could not act on it even if asked, because we don't have it.

7. Data Transfers

As an Estonian (EU) company, the data we process is protected under GDPR. Where a sub-processor transfers data outside the EU/EEA — primarily Google (Google Analytics, Google LLC, USA) — the transfer relies on the EU–US Data Privacy Framework (Google is DPF-certified) and on Standard Contractual Clauses as a fallback (GDPR Chapter V). Cloudflare, GitHub, Supabase, and Resend similarly rely on Standard Contractual Clauses or adequacy mechanisms (and, where applicable, EU/EEA-region hosting) for any transfers.

8. Security Incidents

Because we hold no vault data, a breach of our systems cannot expose it. If a security incident affects personal data we do process (Section C), we will notify affected users without undue delay and, where required, within 72 hours of becoming aware, describing the incident, the data affected, and the measures taken.

9. Children

Mycelium is not intended for anyone under 18, and we do not knowingly collect data from minors.

10. Changes

We may update this policy. Material changes will be posted on the website with reasonable notice.

Data Flow

YOUR DEVICE  ── everything lives here, sensitive data encrypted (AES-256-GCM) ──
  |
  |  vault, notes, files, embeddings, mindscape
  |  computed + stored locally · keys only you hold
  |  the app sends us NOTHING (no telemetry)
  |
  |  Optional, only when YOU choose:
  |-- Cloud AI (your key) ─────► provider you pick (their terms)   [off by default]
  |-- Remote-access relay ─────► TLS-passthrough pipe (can't read it)
  |-- Publish a document ──────► public at your handle (only what you publish)
  |
mycelium.id WEBSITE  (the only data we collect)
  |-- Google Analytics 4 (cookies + device id, only after you consent)
  |-- Waitlist form (your email → stored in Supabase, if you submit it)
  |-- Paid handle €1/mo (optional): handle + public key + subscription status;
  |     card payment handled by Stripe — we never see your card
  +-- Downloads + standard request logs (Cloudflare / GitHub)

Contact & Supervisory Authority

Data Controller: Altus Centauri OÜ (registry code 17371918), Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
business@curiouslife.is

Supervisory Authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — aki.ee