Mute Home

Mute Privacy Policy

Version dated July 31, 2026. Effective upon publication at https://mymute.app (mirror: https://mymute.ru).

> This is an English translation provided for convenience. The legally binding version of this document is the Russian one, published at https://mymute.app/legal/privacy. In case of any discrepancy, the Russian version prevails.

This Privacy Policy (the "Policy") describes what data the Mute mobile application (the "App", the "Service") and its server-side services process, how that data is protected, and what rights users have. The Policy also serves as the operator's published personal data processing policy under Part 2, Art. 18.1 of Russian Federal Law No. 152-FZ "On Personal Data" ("152-FZ").

Personal data operator:
Sole proprietor (IP) Fedotova L.V.
Taxpayer ID (INN) 631107461481, OGRNIP 326632700057690
Address: office 414, bldg. 3, 70 Revolyutsionnaya St., Samara, 443023, Russia
Personal data inquiries: privacy@mymute.app
General inquiries: hello@mymute.app

By using the App you confirm that you have read this Policy. Legal bases for processing are the data subject's consent, the contract (User Agreement), and the operator's legitimate interests to the extent permitted by 152-FZ.


1. Core principle: your data lives on your device

Mute is built privacy-by-design and local-first:

  1. Your journal, trackers, and everything personal is stored only on your phone, in the App's protected storage. This includes: sleep records (yours and your baby's), feeding, pumping, nutrition and water, weight, medications, symptoms and temperature, menstrual cycle, pregnancy, emotions and notes, child data (name, date of birth), self-assessment questionnaire results (including the EPDS scale), and your conversation history with the AI companion. None of this is transmitted to or accessible by the operator's servers.
  2. Your account is anonymous. On first launch the App generates a random technical device identifier. No name, email, or phone number is required. The server stores that identifier only as an irreversible hash (SHA-256): the operator cannot link an account to a specific person. Optionally, you may link an email address to your account — it is used to sign in on the website, restore access on a new device and receive receipts; without it, every App feature keeps working as before.
  3. We do not collect: full name, address, geolocation, contacts, advertising identifiers (IDFA/GAID), address book data, or data about other apps.

The flip side of local-first: if you delete the App without exporting your data (Section 7), your local data is lost — the operator holds no copy.

2. What is processed on the server

The operator's servers (located in the Russian Federation) process a minimal technical set:

CategoryContentsRetention
AccountSHA-256 hash of the device identifier, hashes of access tokensUntil account deletion
Sign-in email (only if you linked it yourself)Email address; one-time sign-in codes stored as hashesAddress — until account deletion; codes — no longer than a day
Subscription dataProduct and purchase identifiers, subscription status and term, payment receipts from app stores and payment servicesReceipts — 4 years (accounting and tax requirements)
De-identified usage statistics (only with your consent)Technical events (e.g., "screen opened", "feature enabled") with primitive parameters; platform and App version. The identifier used in statistics changes every day and is derived so that events from different days cannot be linked to one another — including by the operator180 days
Account activity marksThe dates on which the App contacted the server (the date only, with no information about what you did). The operator needs these to know whether the Service is being used; they do not depend on statistics consent180 days
Crash reportsTechnical stack traces (pre-scrubbed of potentially personal fragments), platform, version90 days
Technical countersRequest quota counters, "likes" on content itemsQuotas — 7 days; likes — until account deletion

Statistics never include: message texts, notes, tracker entries, names, photos, or data about your body, health or wellbeing. In particular, statistics neither contain nor can contain: the results or even the fact of completing wellbeing questionnaires (including the postnatal depression scale), mood entries, medication intake or details, records about illness, pregnancy or breastfeeding, or information about your child's feeding and health.

Consent to statistics and crash reporting is requested inside the App, once you are already using it (not on first launch), via a single toggle covering both. Collection is off by default; you can switch it on or off at any time in the App settings.

The retention periods in the table above apply only to the server-side data listed there. Your journal, trackers and records of medications, feeds, sleep and cycle are stored on your device (section 1), are not bound by any of these periods and are never deleted by the operator — the operator does not have them.

IP addresses are used solely for abuse protection (rate limiting) and are not written to persistent databases. Standard web-server technical logs are kept to the extent needed for security and are regularly rotated.

3. The AI companion: what happens to your messages

The AI companion feature involves processing your message text with a language model, with layered protection:

  1. Automatic redaction of personal data before the model sees anything. The operator's server automatically finds and replaces with neutral placeholders: people's names, phone numbers, email addresses, bank card numbers, government ID numbers, messenger handles. The model receives text already stripped of these; in the reply, placeholders are restored only on your screen. If the redaction service is unavailable, the message is not sent to the model at all (fail-closed).
  2. Models receive de-identified data only. All processing of raw text (receiving the message, automatic de-identification) happens on the operator's servers in Russia. Language-model providers (whose servers may be located outside Russia — the App settings say so openly) receive only de-identified text: no names, no contact details, no account identifier, no link to your identity whatsoever. Such data does not allow anyone — the model provider included — to identify a specific person, and therefore does not constitute personal data; the operator does not perform cross-border transfers of personal data.
  3. AI hygiene: automatic de-identification removes formal identifiers but cannot redact everything you choose to write about yourself in free form. We recommend not including in the chat anything you would not want to share with the model (the model does not know who you are in any case).
  4. Tracker data reaches the chat only by your explicit choice. The companion settings contain separate toggles (profile, sleep patterns, logs, mood, notes, child data, nutrition) — all off by default.
  5. Food photo recognition. The photo is sent to the model for recognition and is not stored on the operator's servers or in logs; the original stays on your device. Do not photograph people or documents when using this feature.
  6. We do not use your messages or photos to train models.

4. Providers and processors (who receives what)

RecipientWhat is sharedPurpose
Language-model providers (incl. OpenRouter and others; servers may be outside Russia)De-identified chat text (after automatic identifier removal, with no account linkage); food photos (recognition feature, not stored)Generating the AI companion's reply
RuStore (RuStore LLC, Russia)Purchase/subscription identifiersSubscription verification and activation
YooKassa (YooMoney NBCO LLC, Russia)Payment identifiers; the payer's email for the fiscal receiptAccepting and verifying website subscription payments, sending the receipt
Unisender Go (Unisender Smart LLC, Russia)Email address and the contents of the service message (sign-in code, payment notice)Delivering service emails
Hosting providers of the operator's servers (Russia)Data listed in Section 2Infrastructure

Payment details (card numbers etc.) are handled exclusively by the payment services (RuStore, YooKassa) on their side; the operator has no access to them. The App embeds no third-party analytics or advertising SDKs.

5. Special categories of data (health)

Mute is an app about maternal well-being. Records about health, mood, cycle, pregnancy, and your child's condition are special categories of personal data (Art. 10 of 152-FZ). The operator's policy:

6. Children's data

The App's user is an adult (parent/guardian). The child is not a user of the App and has no account. Child data (name, date of birth, tracker entries) is entered by the parent acting as legal representative; it is stored only on the parent's device and is not transmitted to the operator. Children's audio content (lullabies, stories) is played under the parent's control and collects no data about the child.

7. Your rights and controls

Under Arts. 14, 20, 21 of 152-FZ you may obtain information about processing, request rectification, blocking and erasure, and withdraw consent. Most rights are exercisable directly in the App:

If you withdraw consent required for the Service to operate, use of the corresponding features ceases.

8. Data protection

The operator applies legal, organizational, and technical measures under Arts. 18.1 and 19 of 152-FZ, including: server data stored in Russia; irreversible hashing of identifiers; TLS encryption in transit; automatic redaction before any external model with fail-closed behavior; data and retention minimization (Section 2); access segregation and authenticated admin interfaces; and, by design, no journal or tracker content in server databases.

9. Notifications

The App uses local reminders only, scheduled on the device itself. Push tokens are not collected; no server-side messaging is performed. Notifications can be disabled in device or App settings.

10. Changes to this Policy

The operator may update the Policy. New versions are published at https://mymute.app with the effective date. Material changes (new data categories, new recipients) are additionally announced in the App. Continued use after changes take effect constitutes acceptance.

11. The mymute.app website: cookies and web analytics

Sections 1–10 describe the App. Processing on the website https://mymute.app (and its mirror https://mymute.ru) works differently, as follows.

The website uses Yandex.Metrica (Yandex LLC, Russia), a traffic analytics service. It sets cookies and collects de-identified information about the visit: IP address, device and browser type, referral source, pages viewed and on-page behaviour (including session recording — "Webvisor": mouse movement, scrolling, clicks).

Metrica does not load until you agree. On your first visit the website shows a banner offering "Accept" or "Decline". Until you press "Accept", the counter is not loaded and no request whatsoever is sent from the page to Yandex services. Your choice is stored in the browser's local storage (not a cookie) and applies to that browser and device only.

Consent is remembered until you withdraw it. A refusal takes effect immediately and is not time-limited — but the banner may appear again on later visits (no more often than once every few hours) to offer the choice once more. As long as you have not pressed "Accept", no data is collected, however many times the banner is shown.

What matters here:

  1. Metrica and your account are not linked. Metrica data is not matched to your account or your journal — even when you are signed in to the account area: analytics lives separately from sign-in.
  2. Which forms the website does have. An email sign-in form (we send a one-time code to the address you enter; the address and code hashes are processed as described in section 2) and a subscription area where Premium can be paid for via YooKassa (section 4; card details never reach the operator). There are no other forms: no name, phone or any other data is collected on the website.
  3. Processing takes place on servers in Russia, under the Yandex.Metrica terms. The operator has access to aggregate reports.
  4. Legal basis — your consent, given by pressing "Accept" in the banner. Declining costs you nothing: nothing on the website requires cookies, and it keeps working in full.
  5. How to change your mind. The "Cookie settings" link in the footer of any page reopens the banner — you can change the decision either way at any time. You may also clear the site data in your browser or install the Yandex.Metrica opt-out add-on.
  6. Nothing is collected without JavaScript. We deliberately do not use the no-script tracking pixel: consent cannot be obtained in such a browser, so no collection begins either.

Yandex.Metrica privacy policy: https://yandex.com/legal/confidential/

12. Contact

Questions about this Policy and personal data: privacy@mymute.app.
Operator: IP Fedotova L.V., INN 631107461481, office 414, bldg. 3, 70 Revolyutsionnaya St., Samara, 443023, Russia.