PRIVACY FIRST
Privacy Notice
This Notice explains how MyMetik handles personal data for one private Owner Account and its independent social Identities.
Version and controller
Version: privacy-2026-08-31.1
Effective: 31 August 2026
The controller is A-MICO, a sole proprietorship at Giacomettistrasse 20, 3006 Bern, Switzerland (UID CHE-298.481.983; commercial-register number CH-550.1.116.705-7).
Privacy and account requests: [email protected].
Safety and support: [email protected].
General enquiries: [email protected].
MyMetik's Identity model
An Owner Account is the private login that controls one or more independent Identities. Social actions belong to the selected Identity. MyMetik does not publicly disclose the Owner Account identifier or the list of sibling Identities. An Identity's visibility, audience, group, message, Story, event and entitlement settings determine who may see data.
Data we process
- Owner Account details, including email, private display name, verification status and versioned consent records.
- Security data, including password hashes, sessions, CSRF credentials, IP address, user agent, login attempts and audit records.
- Identity data, including handle, display name, biography, visibility, interests, profile image, banner and theme.
- Posts, comments, reactions, friendships, blocks, messages, groups, events, Stories, shares and their selected audiences.
- Uploaded photos, videos, files and related technical metadata.
- Approximate area and distance preferences when Radar is used; precise location is not shown to other users.
- Safety data, including reports, hides, moderation cases, decisions, appeals, age-eligibility state and restricted-content preferences.
- Support, privacy-request, email-delivery, notification and service-operation records.
- Reviewed legacy recovery data only when a legacy claim is separately enabled and approved.
Why we process data
- To create and administer Owner Accounts and provide the Identity, social, media, messaging, discovery and safety features requested by users.
- To authenticate users, secure the service, prevent abuse, enforce visibility and investigate incidents.
- To deliver account, support, moderation and operational communications.
- To comply with legal obligations and respond to valid rights, safety and legal requests.
- To operate optional preferences only when the user chooses them and, where required, gives consent that can be withdrawn.
Depending on the processing, the basis is performance of the user agreement, compliance with law, A-MICO's legitimate interests in security and service integrity, or consent where required. MyMetik does not sell personal data and does not use MyMetik data for behavioural advertising.
Visibility and recipients
Data is shared with other users according to the selected Identity and audience controls. Internal or external sharing cannot widen the source content's authorized audience. Data may also be disclosed when legally required, to protect people or the service, or as part of a properly governed business reorganisation.
Current service providers are:
- GoDaddy / Airo for public application hosting, VPS hosting, DNS/TLS and encrypted off-site backup functions.
- Microsoft 365 / Microsoft Graph for transactional, account, support and operational email.
PostgreSQL, Redis and MinIO are self-hosted on the MyMetik VPS. LiveKit Cloud processes real-time audio, video and connection metadata for invitation-only Solo Live; MyMetik does not enable provider recording or replay in the initial release. Google or Facebook receives data only if its social-login option is enabled and the user chooses it. Event, payment/KYC and stronger age-verification providers remain disabled until separately reviewed and disclosed.
International transfers
Data may be processed in Switzerland, the EEA, the United States and other countries in which an approved provider or subprocessor operates. Transfers use an applicable adequacy decision or recognized contractual safeguards, including adapted Standard Contractual Clauses where required. Current provider and safeguard information is available from [email protected].
Retention
- Active account and Identity data is retained while needed to provide the service.
- An account may be reviewed after 24 months without login; where contact remains possible, at least 30 days' notice is given before inactivity deletion.
- User-deleted content and account data is removed or anonymised from ordinary active systems within 30 days, subject to legal holds and records that must be retained.
- Sessions use the configured 60-minute idle and 168-hour absolute limits; revoked-session security metadata may remain for up to 90 days.
- Expired verification, reset and invitation credential material is purged within 30 days.
- Support and privacy cases are retained for 3 years after closure.
- Moderation reports, decisions and appeals are retained for 2 years after closure.
- Ordinary security and audit logs are retained for 12 months; material incident evidence may be retained for 3 years after closure.
- Versioned consent evidence is retained for the account lifetime plus 5 years, unless an active dispute requires longer.
- Encrypted operational backups use a rolling maximum of 35 days.
- Stories leave the active carousel after 24 hours but remain longer if the user selects Archive or Highlights.
A narrowly scoped legal hold, fraud or security investigation, active dispute or mandatory recordkeeping duty may delay deletion. Paid and KYC retention remains inapplicable while those services are disabled. MyMetik does not retain a recording of initial-release Solo Live media; versioned host consent, broadcast-rights evidence, control events, moderation records and security metadata follow the applicable periods above.
Your choices and rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection or portability and may withdraw consent. MyMetik provides protected account deletion, data export and privacy-request controls. We may verify identity before disclosing or changing private data.
Send requests to [email protected]. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or another authority competent for you.
Automated safety actions and human review
Reports and other safety signals may temporarily restrict or quarantine content pending review. They do not convert content into paid content. Eligible decisions can be reviewed by a human moderator, who may restore, retain, reclassify, restrict or remove the content.
Age, cookies and security
The minimum account age is 16 and there is no under-16 parental-consent flow. Explicitly restricted features require a separate 18+ decision. Ordinary music and music communities never require age verification merely because of their genre.
MyMetik uses a Secure, HttpOnly, SameSite session cookie for authentication, CSRF protection and active-Identity continuity. Optional advertising and cross-site tracking cookies are not enabled. Passwords are hashed with Argon2id, media is held in private object storage, traffic uses HTTPS, and audit and backup controls protect service continuity.
Changes
Material changes receive a new immutable version and, where required, advance notice or renewed acceptance. The accepted document version is stored with the Owner Account's consent evidence.