Privacy
What Mneva holds, and where it actually goes.
This page describes the real system as it is built today, not a system we intend to build. Where something is unfinished, incomplete, or handled by a person rather than a button, it says so in the same place it would otherwise be easy to imply otherwise.
Last updated: 26 August 2026.
1. Who is responsible for your data
Mneva is built and run by Pedro Carlos Camilleri, a sole trader established in Malta, trading as Mneva. He is the data controller for everything described on this page.
There is no company behind Mneva. The controller is one named individual, personally and directly responsible — not a corporate entity, not a holding structure, and not a subsidiary of anything else. The Imprint states the current trader-identification status; new paid checkout stays closed until the full trading address and VAT status are published. Mneva's published monthly price is the Mneva Founding Circle, EUR 9 (€9) per month, cancellable at any time. A separate intended EUR 59 (€59) first-year offer is capped at 100 places but is not on sale: its renewal contract and matching recurring checkout are not yet verified. Both exit paths are on the Billing page. The full trading address and VAT status are the remaining owner-supplied fields on the Imprint page.
Contact for anything on this page, including every request described in section 9: pedro@mneva.ai. There is no separate data protection officer; Mneva is not large enough to be required to appoint one, and mail to that address reaches the controller directly.
2. Mneva is in early access
Mneva is in early access. Google sign-in is offered when the hosted runtime is ready; unavailable access stays visibly unavailable. Features appear, change, and are withdrawn. Some things this policy describes are handled by a person reading an email rather than by an automated control, and where that is true it is named explicitly rather than implied away.
3. What Mneva collects
If you only look at the public site
Nothing on the public landing page listens, records, connects an account, or runs an agent. It loads no third-party script, no analytics, no advertising pixel, and no external font. Cloudflare, who serve the site, process your IP address and request metadata as part of delivering and protecting it — see section 5.
If you use the demo
The demo chat is a small fixed script, not a live model. It starts blank, saves nothing, and uses no personal data. Your choice of "demo" is remembered in your browser for the length of the tab session only.
Separately from that scripted demo, the app's opening conversation for visitors who have not signed in can be answered by a live model: when that feature is switched on, the first few messages you type before signing in are sent to OpenAI to generate each reply. Mneva does not save that transcript to an account or its own conversation store unless you choose to sign in, and its Responses request disables provider application-state storage. OpenAI may still retain prompts, replies, and related metadata in safety and abuse-monitoring logs for up to 30 days by default (or longer where legally or operationally required), under OpenAI's published data controls.
If you sign in with Google
- Your Google account identity — the email address, the display name, and the Google account identifier (the "sub"). This is used to identify your account and for nothing else. Signing in with Google connects no Gmail, no Drive, no Calendar, and no other account; each of those would require a separate, explicit approval.
- The text you type in chat, up to 4,000 characters per message, together with recent turns of the same conversation so a reply can follow what came before.
- A text or data file you deliberately attach, including its file name and the text content sent with that turn. Mneva currently accepts plain text, Markdown, JSON and CSV files; choosing a local avatar image or video does not upload the raw media.
- Anything you explicitly save — the notes, captures and records you ask Mneva to keep, and the profile details you choose to give it.
- Support messages you send from the "Support and your data" page inside the app, including any contact detail you choose to put in them.
- Operational records needed to run the account: when your session was minted and when it expires, which permissions you granted, and receipts for actions such as a deletion run.
Mneva does not build an advertising profile, does not sell data, does not share it with advertisers, and does not use your content to train any model, ours or anyone else's.
4. Where a signed-in conversation is actually processed
Read this one carefully — it is the most unusual thing about Mneva.
By default, when you are signed in and send a chat message, Mneva relays it to a computer that Pedro Carlos Camilleri owns and operates personally, where a local language model runs. Along with the text of your message, the relay carries your email address, your display name, your account identifier, and your session credential.
The connection is encrypted in transit and the machine is not open to the public. But it is a private machine in one person's control, not a hardened data centre with a compliance team, and you should weigh that honestly before typing something you would not want a named individual to be able to read.
The optional live-web exception. The signed chat has an account-scoped switch labelled “Use live web sources for current questions”. It is off by default. If you turn it on and your account is enabled for this beta feature, Mneva may send only the exact message you are sending now to OpenRouter for a searched, cited answer. It does not send your conversation history, saved profile, email address, account identifier, or session credential in that provider request. Messages detected locally as containing health details, credentials, financial or identity identifiers, or common personal contact details are kept on the local path instead. You can turn the switch off again at any time.
OpenRouter routes that message to a model provider and, for live questions, a web-search provider. Mneva asks OpenRouter to deny data collection and to use only a zero-data-retention endpoint for every such model call; if no qualifying endpoint is available, the remote call fails and chat falls back locally. OpenRouter and its providers still process the message and operational metadata under their own terms and settings. This is therefore an external disclosure you choose, not a claim that no third party receives the message.
What that gets you. Ordinary signed chat stays on the owner-operated model path by default. When you deliberately enable live web, current answers can use fresh sources and show source references without sending the rest of your conversation or profile.
What it costs you. When that machine is offline, chat may not work. It also means a copy of your conversation exists outside the hosting platform, and Pedro can technically access that copy. If live web is on, the current eligible message also leaves that machine for the external processing described above. Section 9 is honest about what "delete" currently covers.
One route is deliberately narrower: the newer paired-conversation surface strips your identity headers before relaying and sends only a one-way digest of your account identifier. The main chat route described above does not.
5. Who else processes your data
| Who | What for | When |
|---|---|---|
| Cloudflare | Hosting, the network edge, and the stored records for your account. Cloudflare therefore processes your IP address, request metadata, and the data described in section 3. | Always, for every visit. |
| Sign-in only. Google tells Mneva who is signing in. Mneva does not read your Google mail, files, or calendar. | Only if you choose to sign in. | |
| Your browser or device's speech-recognition provider | If you deliberately start browser speech, that browser or device service may process microphone audio to return text. Mneva does not retain the raw recording. Browser speech is disabled in the Google Play edition until its processor and store disclosure can be verified for that distribution. | Only after you start an available browser-speech feature and grant microphone permission; never in the Google Play edition. |
| The owner's own machine | Running the language model for signed-in chat, as described in section 4. Not a third-party company — one named person's hardware. | Every signed-in chat message; its local model is the default answer path. |
| OpenRouter and its routed model and web-search providers | A bounded, searched answer to a current question. The provider request contains only the current message and a system instruction, not chat history, profile, email, account identity, or session credential. Mneva requests zero data retention and denies provider data collection. | Only when you switch on live web for your account, the account is enabled for the beta, the message passes the local sensitivity gate, and the question needs current information. |
| OpenAI | Two paths exist in the deployed code. Spoken replies, when the voice feature is switched on, send the text of the reply to OpenAI to be turned into audio. And if the owner's own machine is ever not configured as the chat path, the chat fallback is an OpenAI model. | Only when those settings are on. We cannot claim OpenAI is unreachable, so it is disclosed. |
| Stripe | Taking payment, if you buy something. Stripe handles the card details; Mneva never sees or stores them. | Only if you pay. |
Some of these providers are outside the EU/EEA. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses and each provider's own published transfer terms. If a new processor is added, this page is updated and the date at the top changes.
6. Why Mneva is allowed to hold it
- To give you the thing you asked for (GDPR Article 6(1)(b), performance of a contract) — your account identity, your conversations, and the notes and records you save. Without these there is no product.
- Because you said yes (Article 6(1)(a), consent) — anything optional: connecting an outside account, turning on voice, sharing your location, uploading an avatar sample, or turning on live web for current questions. Every one of these stays off until you approve it individually, and you can withdraw that consent at any time.
- To keep the service running and safe (Article 6(1)(f), legitimate interests) — rate limiting, abuse prevention, and diagnosing faults.
- Because the law requires it (Article 6(1)(c)) — payment and tax records, where you have paid.
One of those four is not enough on its own for part of what Mneva does, and the next section says which part and why.
7. The sensitive part, and the one thing Mneva asks you to agree to
Most privacy policies would not put this section in. It is here because leaving it out would be the kind of quiet omission the rest of this page exists to avoid.
Mneva is built to notice how you are. If you write that you are exhausted, or frightened, or grieving, Mneva changes how it answers — it stops being clever and becomes gentle, and it will not push. There is a wellbeing area inside the app for exactly this. That is the product working as intended, and it is the reason people find it worth having.
It also means Mneva does something the law treats with particular care. Information about your health or your state of mind is special category data under Article 9 of the GDPR, and that is true whether you state it outright or a system works it out from what you wrote. Mneva works it out. So Article 9 applies, and the honest thing is to say so on the page rather than to argue that you volunteered it.
Article 9 permits this on one realistic basis for a product like this: your explicit consent (Article 9(2)(a)). So Mneva asks for it, once, as its own separate question when you first create your signed space — not folded into the terms, not a pre-ticked box, and not something you have to hunt for. You are told what it covers before you agree, and the answer is recorded with the moment you gave it.
You can take it back at any time, by email to pedro@mneva.ai or from the "Support and your data" page inside the app. Withdrawing does not make what happened before unlawful, and it does not delete anything on its own — ask for erasure as well if that is what you want, and section 9 describes what erasure really reaches today.
What Mneva does not do with it. It is never sold, never shared with advertisers, never used to train any model, and never used to build an advertising profile. It is not used to make an automated decision that has a legal effect on you or anything similarly significant — there is no scoring, no eligibility check, no automated judgement about you in the sense Article 22 means. Mneva changes its tone; it does not decide your life.
Before you sign in. The opening conversation on the public site works without an account. Nothing from it is written to an account or kept by Mneva unless you choose to carry it in when you sign in, and the notice next to that first message says where those words go before you send them. If you would rather Mneva never handled anything of this kind, the honest answer is that this is not the right product for you, and that is a fair thing to decide here rather than three months in.
8. How long it is kept
These are the retention windows actually configured in the running system, not aspirations:
| What | Kept for |
|---|---|
| Notes, captures and records you save, and the profile picture Mneva builds of you from them | 400 days from when they are written |
| Chat history held at the network edge | 30 days |
| Your signed-in session | 24 hours, then you sign in again |
| Permissions you granted, and connector preferences | 365 days |
| Access tokens for any outside account you connected | 90 days, encrypted |
| Support messages you send | Until the matter is closed and no longer needed |
| Payment and tax records | As long as Maltese tax law requires |
The 400-day figure is the real one and is stated here because it is longer than most people assume. It exists because notes and records are meant to be the user's own long-lived material, not conversational scratch.
9. Your rights — and what honestly works today
Under the GDPR you have the right to:
- ask what is held about you, and get a copy of it (access and portability);
- have anything wrong corrected (rectification);
- ask for your data to be erased (erasure);
- ask that processing be restricted, or object to it;
- withdraw any consent you gave, at any time, without it affecting what was lawful before;
- complain to a supervisory authority.
How to exercise any of them: email pedro@mneva.ai, or use the form on the "Support and your data" page inside the app. During early access these are handled directly by Pedro, usually within a few days, and always within the one month the GDPR allows. Nothing automated, nothing overstated.
The honest limits on erasure right now.
Mneva will not tell you it has forgotten you when it has not, so here is the real position:
- The automated delete route erases your records from the hosting platform's store. It does not reach the copy of your conversation on the owner's own machine described in section 4 — no automated route to that store exists yet. Erasing that side is done by hand, by Pedro, on request.
- Encrypted access tokens for outside accounts you connected are deliberately kept rather than deleted, because destroying them would strand a live grant at the provider with no way left to revoke it. Ask, and they are revoked at the provider and then removed.
- A self-service delete control is reachable in the hosted web app, under “You”. It shows you the real counts of what it is about to destroy before it destroys anything, asks you to type a confirmation, and returns a receipt of what was removed. It erases what Mneva holds for you on this hosted side. It does not touch the copy on the owner's machine that runs signed-in chat, and it does not revoke a connected account at the provider — the email route above does both. If it cannot finish, it tells you so rather than reporting success.
- There is still no self-service export control. The email route above is the real route for export, and it is the one the product points at.
So: ask by email and your data is erased, including the copy on the owner's machine. Do not read a completion message from any in-product control as proof that every copy is gone.
If you are not satisfied, you can complain to the Maltese supervisory authority, the Information and Data Protection Commissioner (IDPC), at idpc.org.mt, or to the authority in your own EU country.
10. Cookies and what your browser keeps
Mneva sets no advertising cookies, no analytics cookies, and no third-party cookies, so there is no consent banner to click through. What exists is this:
Cookies
-
mneva_preview_unlock— set only if you unlock a password-protected internal page. It is strictly necessary for that, holds no personal data, is HttpOnly and same-site, and lasts 30 days. -
mneva_first_say— your first landing-page message, carried to the chat in a same-site cookie for at most 60 seconds and deleted when the disclosed handoff opens.
Kept in this browser until you clear it (localStorage)
mnevaHostedSession— your signed session, which includes your email address and display name;mnevaConversationIdandmnevaPairedConversationHandle— which conversation you are in;mnevaLocalPermissions— the permissions you have granted;mnevaLocationProof— your exact latitude and longitude, and only if you ever allowed location;mnevaPresenceStats,mnevaPresenceXp— presence and progress counters;mnevaTheme,mnevaVoiceEnabled,mnevaDictationEnabled,mnevaDictationLanguage,mnevaGuideStep,mnevaGuideCloudHidden,mnevaBridgeUrl— preferences and tutorial progress.
Kept only until you close the tab (sessionStorage)
mnevaEntryChoiceV1— whether you chose the demo or sign-in;mnevaHostedOAuthState— a one-time value that binds a sign-in attempt to this browser, so a sign-in cannot be forged from elsewhere;mnevaFirstConversationCarryV1— up to the 12 most recent turns in an opening conversation, whether answered by the live opener or the labelled script (your prompts and Mneva's replies), so a reload in the same tab can continue it; Mneva clears this when you choose the empty scripted demo, choose “Let it go,” or carry the conversation into your signed-in space;mnevaPendingSignedTurnV1— a message that was waiting to be sent when a signed session expired, together with the signed user identifier and the time it was held; it is removed when Mneva attempts to restore it after you sign in again, or when you sign out;mnevaMindIntroSeen— whether an introduction has already been shown.
Clearing site data for this site removes all of it. Signing out removes the session entry immediately.
11. Security, and who Mneva is for
Traffic is encrypted in transit. Your session is cryptographically signed and expires after 24 hours. Records are scoped to your account identifier, so one account's records cannot be read from another. Access tokens for connected accounts are stored encrypted. None of this makes any system perfect, and section 4 tells you exactly where the conversation runs so you can judge for yourself.
Mneva adapts to the person in front of it rather than excluding categories of person. It should make sense to a teenager and to someone in their eighties, and the way it speaks changes accordingly.
The one place the law draws a line is consent. In Malta, where Mneva is established, a person can consent to an online service like this one for themselves from the age of 13. That is the age set by S.L. 586.11 under the Data Protection Act (Cap. 586) — the Processing of Child's Personal Data in Relation to the Offer of Information Society Services Regulations — and it is lower than the GDPR's default of 16 because Malta took the floor Article 8 allows. So from 13 you hold your own account. This page previously set that line at 16, which was neither the rule that actually applies here nor what Mneva intends.
Below 13, an account is held by a parent or guardian who consents on the child's behalf and can see, export and erase what is kept. That custodian arrangement is not yet a button — today it is set up by writing to pedro@mneva.ai, and Mneva says so plainly rather than implying a control exists. Until it is set up, Mneva is not for a child under 13 to use alone.
Paying is different from using. You must be 18 to enter the subscription contract, because that is the age of contractual capacity, not because Mneva is unsuitable before it.
If you believe a child is using an account without a custodian, write to pedro@mneva.ai and it is handled the same day it is read.
12. Changes to this policy
If this policy changes in a way that matters, the date at the top changes with it and signed-in users are told inside the app. Mneva is in active development, so expect this page to move as the product does — including, we hope, to record that the erasure limitation in section 9 has been closed.