Mute Privacy Policy
Version dated July 21, 2026. Effective upon publication at https://mymute.app (mirror: https://mymute.ru).
> This is an English translation provided for convenience. The legally binding version of this document is the Russian one, published at https://mymute.app/legal/privacy. In case of any discrepancy, the Russian version prevails.
This Privacy Policy (the "Policy") describes what data the Mute mobile application (the "App", the "Service") and its server-side services process, how that data is protected, and what rights users have. The Policy also serves as the operator's published personal data processing policy under Part 2, Art. 18.1 of Russian Federal Law No. 152-FZ "On Personal Data" ("152-FZ").
Personal data operator:
Sole proprietor (IP) Fedotova L.V.
Taxpayer ID (INN) 631107461481, OGRNIP 326632700057690
Address: office 414, bldg. 3, 70 Revolyutsionnaya St., Samara, 443023, Russia
Personal data inquiries: privacy@mymute.app
General inquiries: hello@mymute.app
By using the App you confirm that you have read this Policy. Legal bases for processing are the data subject's consent, the contract (User Agreement), and the operator's legitimate interests to the extent permitted by 152-FZ.
1. Core principle: your data lives on your device
Mute is built privacy-by-design and local-first:
- Your journal, trackers, and everything personal is stored only on your phone, in the App's protected storage. This includes: sleep records (yours and your baby's), feeding, pumping, nutrition and water, weight, medications, symptoms and temperature, menstrual cycle, pregnancy, emotions and notes, child data (name, date of birth), self-assessment questionnaire results (including the EPDS scale), and your conversation history with the AI companion. None of this is transmitted to or accessible by the operator's servers.
- Your account is anonymous. On first launch the App generates a random technical device identifier. No name, email, or phone number is required. The server stores that identifier only as an irreversible hash (SHA-256): the operator cannot link an account to a specific person.
- We do not collect: full name, address, geolocation, contacts, advertising identifiers (IDFA/GAID), address book data, or data about other apps.
The flip side of local-first: if you delete the App without exporting your data (Section 7), your local data is lost — the operator holds no copy.
2. What is processed on the server
The operator's servers (located in the Russian Federation) process a minimal technical set:
| Category | Contents | Retention |
|---|---|---|
| Account | SHA-256 hash of the device identifier, hash of the access token | Until account deletion |
| Subscription data | Product and purchase identifiers, subscription status and term, payment receipts from app stores and payment services | Receipts — 4 years (accounting and tax requirements) |
| De-identified usage statistics | Technical events (e.g., "screen opened", "feature enabled") with primitive parameters; hashed device identifier; platform and App version | 180 days |
| Crash reports | Technical stack traces (pre-scrubbed of potentially personal fragments), platform, version | 90 days |
| Technical counters | Request quota counters, "likes" on content items | Quotas — 7 days; likes — until account deletion |
Statistics never include: message texts, notes, tracker entries, names, or data about your body or child. Statistics and crash reporting can be switched off in the App settings (separate toggles).
IP addresses are used solely for abuse protection (rate limiting) and are not written to persistent databases. Standard web-server technical logs are kept to the extent needed for security and are regularly rotated.
3. The AI companion: what happens to your messages
The AI companion feature involves processing your message text with a language model, with layered protection:
- Automatic redaction of personal data before the model sees anything. The operator's server automatically finds and replaces with neutral placeholders: people's names, phone numbers, email addresses, bank card numbers, government ID numbers, messenger handles. The model receives text already stripped of these; in the reply, placeholders are restored only on your screen. If the redaction service is unavailable, the message is not sent to the model at all (fail-closed).
- Models receive de-identified data only. All processing of raw text (receiving the message, automatic de-identification) happens on the operator's servers in Russia. Language-model providers (whose servers may be located outside Russia — the App settings say so openly) receive only de-identified text: no names, no contact details, no account identifier, no link to your identity whatsoever. Such data does not allow anyone — the model provider included — to identify a specific person, and therefore does not constitute personal data; the operator does not perform cross-border transfers of personal data.
- AI hygiene: automatic de-identification removes formal identifiers but cannot redact everything you choose to write about yourself in free form. We recommend not including in the chat anything you would not want to share with the model (the model does not know who you are in any case).
- Tracker data reaches the chat only by your explicit choice. The companion settings contain separate toggles (profile, sleep patterns, logs, mood, notes, child data, nutrition) — all off by default.
- Food photo recognition. The photo is sent to the model for recognition and is not stored on the operator's servers or in logs; the original stays on your device. Do not photograph people or documents when using this feature.
- We do not use your messages or photos to train models.
4. Providers and processors (who receives what)
| Recipient | What is shared | Purpose |
|---|---|---|
| Language-model providers (incl. OpenRouter and others; servers may be outside Russia) | De-identified chat text (after automatic identifier removal, with no account linkage); food photos (recognition feature, not stored) | Generating the AI companion's reply |
| RuStore (RuStore LLC, Russia) | Purchase/subscription identifiers | Subscription verification and activation |
| YooKassa (YooMoney NBCO LLC, Russia) | Payment identifiers | Verifying website subscription payments |
| Hosting providers of the operator's servers (Russia) | Data listed in Section 2 | Infrastructure |
Payment details (card numbers etc.) are handled exclusively by the payment services (RuStore, YooKassa) on their side; the operator has no access to them. The App embeds no third-party analytics or advertising SDKs.
5. Special categories of data (health)
Mute is an app about maternal well-being. Records about health, mood, cycle, pregnancy, and your child's condition are special categories of personal data (Art. 10 of 152-FZ). The operator's policy:
- such records are stored only on your device and are not transmitted to the operator's servers;
- they reach the AI chat only if you write about them yourself or enable the corresponding toggle (all toggles off by default); anything leaving the device does so exclusively in de-identified form, with no way to link it to you (Section 3);
- the Apple Health integration (iOS) works strictly on per-category permissions you grant; Health data never reaches the servers or the statistics;
- your EPDS score is computed on the device, is sent nowhere, and is not a diagnosis.
6. Children's data
The App's user is an adult (parent/guardian). The child is not a user of the App and has no account. Child data (name, date of birth, tracker entries) is entered by the parent acting as legal representative; it is stored only on the parent's device and is not transmitted to the operator. Children's audio content (lullabies, stories) is played under the parent's control and collects no data about the child.
7. Your rights and controls
Under Arts. 14, 20, 21 of 152-FZ you may obtain information about processing, request rectification, blocking and erasure, and withdraw consent. Most rights are exercisable directly in the App:
- Account deletion — in the App settings ("Delete account"). This deletes the account, subscription links, statistics, crash reports, and likes tied to the device. Payment receipts are anonymized (unlinked from the account) and retained for the remainder of their statutory term as financial records.
- Local data is deleted together with the App, and via the App's own controls.
- Data export — the "Data transfer" feature: a full dump of your records to a file with optional strong encryption (only you know the passphrase).
- Disabling statistics and crash reports — in settings.
- Consent withdrawal / requests — email privacy@mymute.app. Response within 10 business days. Include the technical identifier from the App settings — otherwise the operator physically cannot locate your data, since no identifying information is stored.
If you withdraw consent required for the Service to operate, use of the corresponding features ceases.
8. Data protection
The operator applies legal, organizational, and technical measures under Arts. 18.1 and 19 of 152-FZ, including: server data stored in Russia; irreversible hashing of identifiers; TLS encryption in transit; automatic redaction before any external model with fail-closed behavior; data and retention minimization (Section 2); access segregation and authenticated admin interfaces; and, by design, no journal or tracker content in server databases.
9. Notifications
The App uses local reminders only, scheduled on the device itself. Push tokens are not collected; no server-side messaging is performed. Notifications can be disabled in device or App settings.
10. Changes to this Policy
The operator may update the Policy. New versions are published at https://mymute.app with the effective date. Material changes (new data categories, new recipients) are additionally announced in the App. Continued use after changes take effect constitutes acceptance.
11. The mymute.app website: cookies and web analytics
Sections 1–10 describe the App. Processing on the website https://mymute.app (and its mirror https://mymute.ru) works differently, as follows.
The website uses Yandex.Metrica (Yandex LLC, Russia), a traffic analytics service. It sets cookies and collects de-identified information about the visit: IP address, device and browser type, referral source, pages viewed and on-page behaviour (including session recording — "Webvisor": mouse movement, scrolling, clicks).
Metrica does not load until you agree. On your first visit the website shows a banner offering "Accept" or "Decline". Until you press "Accept", the counter is not loaded and no request whatsoever is sent from the page to Yandex services. Your choice is stored in the browser's local storage (not a cookie) and applies to that browser and device only.
Consent is remembered until you withdraw it. A refusal takes effect immediately and is not time-limited — but the banner may appear again on later visits (no more often than once every few hours) to offer the choice once more. As long as you have not pressed "Accept", no data is collected, however many times the banner is shown.
What matters here:
- The website and the App are not linked. Metrica data is not matched to your App account or your journal: you are not signed in on the website, and the App account is anonymous (section 1).
- There are no forms on the website. We collect no name, email, phone or any other data you would enter yourself. You can only reach us by email, which is ordinary correspondence rather than a website form.
- Processing takes place on servers in Russia, under the Yandex.Metrica terms. The operator has access to aggregate reports.
- Legal basis — your consent, given by pressing "Accept" in the banner. Declining costs you nothing: nothing on the website requires cookies, and it keeps working in full.
- How to change your mind. The "Cookie settings" link in the footer of any page reopens the banner — you can change the decision either way at any time. You may also clear the site data in your browser or install the Yandex.Metrica opt-out add-on.
- Nothing is collected without JavaScript. We deliberately do not use the no-script tracking pixel: consent cannot be obtained in such a browser, so no collection begins either.
Yandex.Metrica privacy policy: https://yandex.com/legal/confidential/
12. Contact
Questions about this Policy and personal data: privacy@mymute.app.
Operator: IP Fedotova L.V., INN 631107461481, office 414, bldg. 3, 70 Revolyutsionnaya St., Samara, 443023, Russia.