1. Introduction
This Privacy Policy explains how MIMS TECH, CORP. (“we”, “us” or “our”), the provider of the MIMS application and related services (the “Service”), collects, uses, protects and manages information when you use the Service.
It applies to everyone who accesses or uses the Service, including account holders and people who interact with features we make available. It covers the information handled through the application and its supporting services, and does not cover third-party products that operate under their own privacy policies.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
2. Information We Collect
We collect the following categories of information.
Account Information
Information needed to create and manage your account, which may include your name, email address, credentials, role, preferences, account settings and language.
User Content
Content you voluntarily create within the Service, such as notes, tasks, Focus/Pomodoro sessions, productivity information and other content you choose to add.
Usage Information
Information about how you interact with the Service, which may include features used, actions performed, dates and times, preferences, interactions with features, and information needed for security and to operate the Service.
Device and Technical Information
Where applicable, technical information such as browser, operating system, device, IP address and diagnostic information that helps us deliver and secure the Service. We do not collect data that the application does not actually use.
3. How We Use Information
We use the information we collect for specific, limited purposes, including to:
- provide, operate and maintain the Service;
- create, administer and secure accounts, and authenticate users;
- store your content and preserve your preferences;
- run the features you request;
- improve and personalize your experience;
- detect, diagnose and fix errors;
- prevent fraud and abuse and protect the platform and its users;
- provide support and respond to your requests;
- analyze how the product performs so we can improve it; and
- comply with applicable legal obligations.
We do not use your information for purposes that are incompatible with those described here without providing appropriate notice or obtaining your consent where required.
4. Artificial Intelligence
The Service includes Artificial Intelligence (“AI”) features. When you use an AI feature, the content you provide for that request may be processed in order to perform the specific action you asked for.
- Content processing: the AI feature processes the input you submit (for example, a note or a prompt) to generate the requested output.
- External AI providers: some AI features rely on external AI service providers that process the request on our behalf.
- Purpose: processing is limited to executing the feature you requested.
- Data used: only the data necessary to fulfill the request is processed.
- AI metrics: where applicable, we handle technical metrics related to AI usage as described in the next section.
The specific AI providers and their data-handling commitments will be confirmed and listed as part of the third-party services disclosure. We do not claim that a given provider refrains from storing information or from using data for model training unless that has been confirmed contractually.
5. AI Usage and Metrics
Where the Service records AI usage metrics, those metrics may include:
- the user associated with the request;
- the AI tool used;
- the provider and model;
- the date of the request;
- the request status;
- tokens consumed and related technical metrics; and
- associated usage/consumption.
These metrics may be used to:
- enforce quotas;
- monitor the Service;
- maintain security and support auditing;
- analyze and optimize functionality; and
- manage and control costs.
6. Third-Party Services
To provide certain features, the Service may use external service providers. These providers process information only as needed to perform their function and under appropriate obligations.
The categories of providers we may rely on include:
- infrastructure and hosting;
- database and storage;
- authentication;
- AI providers;
- communications (for example, transactional email); and
- external integrations you choose to connect.
The providers currently used by the Service are:
- Amazon Web Services (AWS) — cloud infrastructure, application hosting and database storage (United States).
- Resend — delivery of transactional email, such as the notification and confirmation messages generated by the contact form (United States).
This list is kept up to date, and we do not list providers that are not actually used by the Service. Additional providers will be added here before they begin processing your information.
7. Zoom Integration
The Service offers an optional integration with Zoom that depends on your explicit authorization. You are not required to connect Zoom to use the Service.
- You voluntarily connect your Zoom account to enable the integration.
- Zoom may provide the information necessary to operate the integration once you connect.
- The application uses the permissions you authorize to provide meeting-related features.
- Meetings may be created from the platform when you request it.
- Your use of Zoom is also subject to Zoom’s own policies, including its Zoom Privacy Statement.
If you choose to connect Zoom, the integration requests only the authorizations required to provide the meeting-related features you use, and those OAuth scopes always match the ones the application declares in the Zoom Marketplace. You can disconnect the integration at any time and revoke its access from your Zoom account settings. For step-by-step instructions on adding, using and removing the Zoom app, see our Zoom Integration Guide.
9. Data Retention
We retain information for as long as it is necessary to:
- provide the Service;
- fulfill the purposes described in this Policy;
- comply with legal obligations;
- resolve disputes;
- prevent fraud; and
- protect the platform.
Unless a longer period is required by law, we apply the following retention periods:
- Contact-form submissions: up to 24 months from your last interaction, after which they are deleted or anonymized.
- Server and security logs: up to 12 months.
- Backups: rotated on a 30–90 day cycle.
When information is no longer needed for the purposes above, we delete or anonymize it. These periods are reviewed periodically and may be extended where required to comply with a legal obligation or to resolve a dispute.
10. Data Security
We implement reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss and destruction.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not disclose internal infrastructure details that could compromise the security of the Service.
11. Data Encryption
We use protective mechanisms to help safeguard information in transit and at rest:
- In transit: all traffic to and from the Service is encrypted over HTTPS (TLS 1.2 or higher).
- At rest: stored data is encrypted using industry-standard AES-256, managed through our cloud provider’s key-management service.
- Access: access to production systems and data is restricted to authorized personnel and protected by strong authentication.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to keep these measures aligned with what the Service actually implements.
12. User Rights
Depending on your location and applicable law, you may have rights over your personal information, which may include the right to:
- access your information;
- correct or update inaccurate information;
- request deletion of your information;
- obtain information about how your data is processed; and
- withdraw consent where processing is based on consent.
To exercise these rights, contact us at privacy@mimstechcorp.com. We may need to verify your identity before acting on a request, and some rights may be subject to legal limitations.
13. Account Deletion
You may request deletion of your account by contacting us at privacy@mimstechcorp.com.
- What can be deleted: account information and user content associated with your account.
- What may be retained: information we are required to keep for legal, security or fraud-prevention reasons, or that remains in routine backups for a limited period.
- Your content: content you created may be removed or anonymized as part of the deletion process.
- Processing time: deletion requests may take a reasonable period to process. We do not promise immediate or absolute deletion from all backups.
15. Children's Privacy
The Service is not intended for children below the minimum age permitted under applicable law (18). We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, please contact us at privacy@mimstechcorp.com so we can take appropriate action.
16. International Data Transfers
Our infrastructure and providers may process information in countries other than the one where you are located. Where this happens, your information may be transferred internationally and we apply the safeguards required by applicable law to protect it.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top of this page, and we will notify you of material changes where appropriate. Your continued use of the Service after an update means you accept the revised Policy.
18. Contact
If you have questions about this Privacy Policy or how your information is handled, contact us:
- Company: MIMS TECH, CORP.
- Privacy Email: privacy@mimstechcorp.com
- Address: 8180 NW 36th Street, Suite 420, Doral, FL 33166, United States
See also our Terms of Use.