Privacy policy
Last updated: September 14, 2026
This is a courtesy translation. The German version is binding. Read the German version.
Controller
SwiftLabs UG (haftungsbeschränkt), represented by its managing director Felix Straub, Schanzenstraße 19, 90478 Nürnberg, Germany. Commercial register: HRB 46502, Amtsgericht Nürnberg. Email: hello@miphu.com.
miphu is a product of SwiftLabs UG. Full provider details are in the legal notice.
Scope
This policy applies to the website miphu.com, to the miphu apps for iPhone, iPad and Mac, and to the services behind them (api.miphu.com, links.miphu.com).
We process data in miphu in two roles:
- As controller for this website, your account, sign-in, the related emails, the subscription and the protection of the service.
- On behalf of your company for everything your company enters in miphu: customers, contacts, enquiries, quotes, orders, invoices, expenses, personnel data and your employees' accounts. Your company is the controller for that data.
1. Visiting this website
This website sets no cookies and uses no analytics, advertising or tracking services. Fonts and images are served from our own hosting; nothing is loaded from third-party servers. Your choice of light or dark appearance is stored locally by your browser and never reaches us. Only the approval page for AI apps on api.miphu.com sets a cookie, and it is strictly necessary (section 9).
When you open the website, our host Hostinger International Ltd. (Jonavos g. 60C, 44192 Kaunas, Lithuania) processes technically necessary access data - IP address, time, page requested, user agent - in server log files as a processor under Art. 28 GDPR. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in secure and stable operation.
2. Account and sign-in
We process:
- email address and name,
- your password, stored only as a hash,
- whether and when you confirmed your email address,
- sign-in sessions (a hash of the session key, start, expiry, sign-out),
- your membership of a company with role, title, rank and departments,
- a profile photo if you or your company upload one. Only two reduced versions (128 and 512 pixels) without image metadata are stored; the uploaded file itself is not.
Employee accounts are created by the company's owner or administration. The legal basis is Art. 6(1)(b) GDPR (contract for the use of miphu).
3. Emails
To activate an account, set a new password or continue by email, we send you an email with a link. The link can be used once and is valid for at most 15 minutes, for account activation at most 24 hours. If you connect an AI app to miphu, every new connection sends you a notification with the name and address of the app, the company and the time; it contains no link. The emails contain no tracking pixels and load no images from third-party servers.
The emails are sent via the service Resend (Resend, Inc., USA) on the basis of standard contractual clauses. Your email address and the content of the message are processed for this. The legal basis is Art. 6(1)(b) GDPR.
When you write to hello@miphu.com, we process your address, your name and the content of your message to answer your request. The mailbox of this address is hosted by Apple (iCloud Mail). The legal basis is Art. 6(1)(b) GDPR where your request concerns the use of miphu, otherwise Art. 6(1)(f) GDPR.
4. Security of the service
To prevent abuse we limit the number of requests per period. For requests without sign-in, your IP address serves as the key. We do not keep access logs of the service, except for requests from connected AI apps (section 9); technical error messages of the server are held to a limited extent and continuously overwritten.
The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in secure and stable operation.
5. Subscription through the App Store
miphu is purchased as a subscription through Apple's App Store. Apple handles purchase, payment and billing under its own responsibility; Apple's terms and privacy notices apply. We do not receive your payment details.
So that we can unlock the purchased number of accounts for your company, Apple provides us with Apple-signed details of the purchase and renewals, such as product, transaction identifiers, dates and status, and we store them as Apple delivers them. At purchase the app passes a random identifier that lets us link the purchase to your account and your company. The legal basis is Art. 6(1)(b) GDPR.
6. Your company's data
What your company enters in miphu we process on behalf of your company: customers and contacts, enquiries and notes, tasks, quotes, orders, invoices and payments, expenses with uploaded receipts, personnel data and the team directory. Your company decides which data this is, what it is used for and how long it is kept. We process it only on your company's instructions.
If you are an employee, customer or contact of a company and have questions about this data, please contact that company first. We support it in responding.
7. On your device
- Your sign-in is stored in the device keychain. If you unlock the app with Face ID or Touch ID, the operating system performs the check; we do not receive biometric data.
- So that lists stay readable without a network connection, the app keeps the most recently loaded state on the device.
- So that you can find entries through system search, the app creates a search index on the device. It contains name or title and place, for enquiries also the phone number, no amounts, and is deleted when you sign out.
- Widgets show follow-ups with title, place and due date, without amounts.
- The app stores appearance settings (light, dark, accent color) per account on the device.
miphu contains no third-party analytics, advertising or tracking services.
8. Hosting and backups
The miphu services, the database including uploaded files, and the encrypted backups are operated for us by Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) as a processor under Art. 28 GDPR. Servers and backups are located in data centers in Germany.
9. Connecting AI apps
You can connect an AI app such as Claude or ChatGPT to miphu. You sign in with your own miphu account, choose the company and the areas, and approve the connection. The app can then read, on its request, data that you are allowed to see in miphu, for example customers, quotes, invoices with their payment status and open or overdue amounts, and the names, titles and ranks of your colleagues. It cannot change anything through this connection. Not available through it are personnel records, files such as PDFs and receipts, credentials, bank and payment method details, and the individual recorded payments.
For the approval, the sign-in page on api.miphu.com sets one strictly necessary cookie that links the approval to your sign-in and expires after 10 minutes. The legal basis is Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
What the app reads is received by the provider of that app, for example Anthropic or OpenAI, which processes it under its own terms and the settings of your account with that provider. This includes whether it may use this content to train its models: on some plans for individuals this is possible when the corresponding setting is turned on. miphu itself does not call a language model.
For each request we log the time, duration and outcome, user, company, app, tool and the number of records transmitted, but not search terms or content. We delete these logs after 90 days. For each connection we store who created it for which company and which app, the approved areas, when it was last used, and whether and why it was revoked; an entry is also added to your company's audit log. We keep this information for as long as the company account exists.
You can revoke your connection in miphu at any time. The owner can revoke any connection in the company and administrators can revoke employees' connections, and the owner can switch connections off for the whole company. The AI app can also end the connection from its side.
10. Recipients
- Hostinger International Ltd., Kaunas (Lithuania) - operation of this website.
- Hetzner Online GmbH, Gunzenhausen - servers, database and backups of the miphu services.
- Resend, Inc., USA - sending sign-in emails and notifications of new AI connections.
- Apple, under its own responsibility - purchase and billing of the subscription.
- Apple (iCloud Mail) - mailbox of our contact address.
- The provider of an AI app you connect to miphu yourself - the data that app reads (section 9).
We do not sell personal data. Your data is not passed on to third parties for marketing purposes.
11. Transfers to third countries
Resend, Inc. is based in the USA. We base the transfer on standard contractual clauses under Art. 46(2)(c) GDPR.
12. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21(1)). An informal email to hello@miphu.com is enough for a request. You delete your account in the app, under Settings.
You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 27, 91522 Ansbach, Germany.
13. Required information
For an account we need your email address and a name. Without them miphu cannot be used. No automated decision-making, including profiling, takes place.
14. Changes
If what miphu processes changes, we update this policy. The date at the top states the version in force.