MimirContributor terms
Privacy

Privacy policy

What Mimir collects, why, who else ever sees it, and how to get it back or get rid of it.

Last updated 31 July 2026·Applies to everyone with an account
The short version: we collect what an account needs and what you choose to write. We do not sell your personal data. We do use Google Analytics — it loads on every page, but stays cookieless until you accept it. You can export everything we hold, and you can delete your account — though notes you published stay, under a retired byline.

What we collect

Your account
Email address, name, username, and password. The password is held by our identity provider and hashed — nobody at Mimir can read it. This is the minimum needed for an account to exist.
Your profile
Date of birth, gender, phone number, bio, avatar, and any links you add. Everything in this group is optional except the date of birth, which exists to enforce the age minimum.
What you write
Notes, edits, comments, votes, reports and feedback, along with who made them and when. This is the graph itself — it is the product, not a by-product.
Technical data
Your IP address and basic request details, used to rate-limit abuse and keep the service up. We do not build an advertising profile from your browsing here.

Why we use it

To run your account and sign you in. To show your work in the graph and attribute it to you. To keep the place usable — rate limits, moderation, and acting on reports. To send you the emails a service has to send: verification codes, password changes, notifications you asked for.

None of that requires your permission, because none of it is optional — it is the service you signed up for. Marketing is the exception, and it gets its own section.

Marketing and advertising

Only if you opt in. The checkbox at signup is unticked, it is separate from accepting the terms, and refusing it does not affect your account in any way. You can change your mind whenever you like, in settings or from the unsubscribe link in any message.

If you do opt in, two things can happen:

  • We email you about Mimir — what is new, what we are building.
  • We may include you in an audience list at an advertising platform such as Meta or Google, so we can reach you (or people like you) with ads for Mimir. Your email or phone number is hashed before it is uploaded.
That second one is worth being precise about, because it is the part people are right to ask about. It means your details are shared with an advertising company for the purpose of showing you our ads. We do not sell your personal data to anyone, and we do not hand it over for someone else to market their own products. But "shared with a third party" is the honest description of what an audience upload is, and you should be told that before you tick the box rather than after.

Opt out and neither happens: no marketing email, and your details go into no advertising audience. If you opt out later, we remove you from the lists we have uploaded.

Who else sees it

A small number of services we depend on, each doing one job: our identity provider (accounts and passwords), our infrastructure and network provider (serving the site, blocking attacks), and our email provider (sending the messages above). They process data on our instructions and for nothing else.

Google. We use Google Analytics 4 (Google Ireland Limited) to measure how the site is used. It loads on every page — for everyone, before and regardless of any cookie choice — and on each load sends Google your IP address, the page address, your browser’s user agent, and a timestamp. Until you accept the analytics category, Google Consent Mode keeps it cookieless: no analytics cookies, and no identifier linking your page views together. Accept analytics and it sets its _ga cookies and measures normally. What it stores, and how to change your mind, are in the cookie policy.

Aside from Google Analytics there is no other tracking in the page: no session recording, no advertising pixel. Beyond the recipients above we disclose personal data only where the law requires it, or where it is genuinely necessary to protect someone from harm.

What's public

Your username, display name, avatar, bio, links, aura, and everything you publish are visible to anyone — including people who are not signed in. That is what a public knowledge graph is.

Your email address, phone number, date of birth and gender are not public and are never shown on your profile. Your exact birth date is used for the age check and your cake day; it is not displayed as a date of birth.

Your controls

All of these live in your account settings:

  • See and correct — edit your profile at any time.
  • Export — download everything we hold about you as a single JSON file.
  • Marketing — turn consent on or off in one click.
  • Delete — remove your account, as described below.

If something here is not working, or you want to object to how we are using your data, write to [email protected] and a person will read it. Depending on where you live you may also have the right to complain to your national data-protection authority.

Deleting your account

Deleting your account destroys your personal data: email, phone, name, date of birth, gender, avatar, bio and links are erased, your login is removed, and you cannot sign in again.

Your notes stay. They are reattributed to a retired account and the byline no longer points to you. This is not a loophole — it is how a shared graph has to work. Other people have edited your notes, linked to them, and built on them, and pulling them out would damage work that is not yours. It follows from the licence you granted in the contributor terms, which is irrevocable for exactly this reason.

So the decision to publish is the one that matters. Deleting your account removes you from Mimir; it does not un-publish what you wrote. If that is not what you want, delete the notes you care about before deleting the account.

How long we keep it

Account and profile data lives as long as your account does, and goes when you delete it. Anonymised notes stay in the graph indefinitely — that is the point of them. Technical logs are short-lived and used for abuse prevention. Moderation records outlive an account where they have to: a ban that vanishes the moment someone deletes their account is not a ban.

Cookies

Two cookies are essential: one keeps you signed in, one remembers your cookie choice. Because they are essential there is nothing to consent to for those. Google Analytics adds two more — _ga and _ga_<id> — but only after you accept the analytics category; until then Consent Mode holds it in a cookieless mode that sets nothing. The cookie policy lists every cookie with its purpose and lifetime.

You are asked about analytics by the banner on your first visit — a real choice, with rejecting as easy as accepting — and you can change it any time from the cookie policy, which carries the same controls.

Age

Mimir is for adults: you must be 18 or older to hold an account. We ask for your date of birth at signup to check this. We do not knowingly keep accounts for under-18s — if you believe one exists, report it or write to [email protected] and we will remove it.

Changes to this policy

When we change something that matters — a new use of your data, a new recipient — we will tell you before it takes effect, and where the change needs your agreement, we will ask for it rather than assume it. Small clarifications and typo fixes get made quietly, with the date at the top updated.

Questions about any of this go to [email protected].

What you keep when you write
This page is about your data. The contributor terms cover your writing.