Data protection
Privacy policy for Mingle
This is an English translation for your convenience. If the English and Swedish versions differ, the Swedish version applies.
Mingle is built to minimise exposure of real photos, exact location and sensitive profile choices. The member controls consent, photo visibility, private contact, export and deletion.
Data controller
The full legal company name, corporate ID number, postal address and a named data protection contact will be published before the pilot opens widely. Until then, questions can be sent to info@minglemingle.se or through Mingle's support form.
1. Data we process
| Category | Examples | Why |
|---|---|---|
| Account | Email, authentication ID, times of consent | Create and secure the account |
| Website statistics | Page views and interactions on the website via Google Analytics and the Meta pixel (cookies and anonymised device data), for example button taps, which sections are viewed, which fields in the waitlist form are filled in and whether the link is shared – never what you type in the fields — only if you have said yes in the consent box. The Meta pixel is used to measure the reach and results of Mingle’s ads on Facebook and Instagram (Meta Platforms Ireland). You can change your choice via "Cookies" in the footer. Legal basis: consent. | Understand how the website is used and improve it |
| Waitlist | Email, city, intention and a mandatory age range. After signing up, you can choose to add your first name and gender | Manage the waitlist and plan balanced pilot cohorts |
| Profile | Name, age, bio, prompts, photos, voice prompt, intention, notification choices | Show your profile and make contact possible |
| Context | Communities you have joined or follow, saved areas and your visibility choices for them (all switched off by default) | Context-based discovery and local activation |
| Sensitive choices | Who you want to meet, which may reveal sexual orientation. Mingle does not ask about ethnicity. | Voluntary personalisation after explicit consent |
| Location | Rounded position and approximate distance | Local suggestions and meetings; exact position is not stored |
| Rooms and presence | Rooms you have joined, your role (member or host), interest in meet-ups in the rooms, invitations to private rooms (who invited whom and whether the invitation was answered), Bring a friend links (whose link it is, to which open room and who first came in through it), temporary presence (who is in a room right now) who you have been in the same room as at the same time in the last 14 days (room and time, no location) and who you have chosen "would like to meet again" with | Show who is in the rooms, gather the rooms around meet-ups, show Meet again and people from your rooms, and let those of you who both want to meet again see when the other person is in an open room |
| Communication | Messages in the rooms' conversations, whispers, chat, photos, reactions | Social rooms and private contact |
| Voice in the rooms | Your audio in a voice call is streamed directly to the people in the call and is never recorded. We store when you joined the voice call, the host's actions (mute, remove) and requests for someone to leave the open voice call, with who they concerned. | Voice calls in the rooms and safety (host controls, requests to leave, reports) |
| Safety | Blocks, reports (and whether the reported person was showing a photo when the report came in, for statistics without names), verification status, reviews | Moderation, fraud protection and security |
| Product outcomes | Rooms, consents, photo choices, meet-up suggestions, activity and meeting outcomes. If you have chosen "Not yet", the days you have used Mingle are stored on your phone, so that the reminder about photos comes at most twice | Measure meaningful contact, not screen time |
| Technical | Push token and limited operational and security logs | Notifications, troubleshooting and abuse protection |
The waitlist and Netlify Forms
Data in the mingle-waitlist form is received and stored via Netlify Forms. The age range is mandatory and is used together with city and intention for cohort planning ahead of the pilot. If you live outside Sweden, you give your country instead of a city, from a fixed list; it is used only to count interest per country. Between 5 and 8 October 2026, after signing up, you could choose to add your first name and gender in the mingle-waitlist-mer form (stored via Netlify Forms, linked by a random reference number, not by email). We no longer ask for this; the few answers that came in are deleted on request via support. The waitlist does not collect your exact date of birth and does not create an app account in Supabase. The first time an address signs up, we send a confirmation email to it via our email provider Resend. The address is passed to Resend only for that email. At the same time, the founder receives a short notification about city, intention and age, without your address.
The support chat (Crisp)
On the support page you can choose to chat with us. The chat is provided by Crisp (Crisp IM SAS, France), which processes the data on our behalf. What you write, your email address if you leave it, and technical data Crisp needs to relay the chat (for example IP address and browser) are processed to handle your request. Nothing is loaded from Crisp and no cookie is set until you press the button to open the chat yourself. After that, Crisp stores a cookie to keep the conversation together. Chats are kept only as long as the request requires.
2. Legal bases
- Contract: account, profile, social rooms, matching, chat, activities and meet-up suggestions.
- Explicit consent: sensitive profile data and choices that may reveal orientation, as well as voluntary location sharing.
- Legitimate interest: security, reporting, blocking, fraud and abuse protection, and privacy-minimised product measurement.
- Legal obligation: handling lawful requests from authorities and documenting data protection measures.
3. Your choices
- Real profile photos are shown either to all members (“Show my photo”) or to no one (“Not yet”). In Chemistry before photo, the photos are shown to the other person only once you have both said yes.
- Private messages can be limited or switched off.
- Explicit consent for sensitive profile choices can be withdrawn in Settings. The values concerned are then cleared without the account having to be deleted.
- Location sharing is voluntary and can be stopped.
- You are only visible in a room while you are there: others then see your name and your profile photo in the room and on the room card in the lobby, as well as your first prompt answer. The photo is shown only to those your photo settings allow; everyone else sees a tinted silhouette. Entering a room never makes your photos visible to more people. Someone you have been in the same room as can see this under Meet again for 14 days (which room and roughly when) — never if either of you has blocked the other, and a block deletes the record immediately. "Would like to meet again" is visible to the other person only once you have both chosen it — a one-sided mark is never shown and is deleted after 30 days. Private rooms, their conversations and who is in them are visible only to the room's members. You get a reminder about this the first time you step into a room.
- Voice in the rooms is always an active choice: you join the voice call yourself and your microphone is off until you switch it on. A room's open voice call opens when at least three people are in the room; two people in the call can ask someone to leave, and that person then cannot join the voice call in that room for 24 hours. During a planned voice meet-up with a host, the host can mute or remove participants. You can always report someone. No one records — neither Mingle nor other members via the app.
- The account can be paused, exported and deleted.
4. Retention periods
| Data | Normal retention period |
|---|---|
| Account and active profile | As long as the account exists |
| Verification selfie | Deleted immediately after the decision |
| Completed verification review | 365 days |
| Messages in the rooms, whispers, crossings and finished Chemistry before photo | 30 days |
| Presence in rooms | Deleted within a few minutes of you leaving the room |
| Room membership | Until you leave the room or delete your account |
| Voice in the rooms (who joined, host actions, requests for someone to leave) | 30 days. The audio itself is never stored. |
| Invitations to private rooms | 30 days after they were answered or expired (an unanswered invitation is valid for 7 days) |
| Bring a friend links | 30 days after someone came in through the link or it expired (a link is valid for 7 days) |
| Profile visits and impressions | 90 days |
| Finished meet-up suggestions, older RSVPs and meeting feedback | 180 days |
| User-linked product outcomes | 180 days |
| Anonymous daily aggregates | 25 months |
| Reports | 24 months, unless longer retention is required |
| Moderation cases, actions and the staff log | 24 months after the case was closed or the action ended; an action that is still in force is kept for as long as it applies |
| Backup copy of photos and voice clips (Scaleway) | Follows the original: anything you remove, or that is deleted with your account, disappears from the copy within one hour |
5. Recipients and providers
Data is shown to other members according to your settings. Technical providers include Supabase for authentication, database and storage (Ireland), Scaleway for backups of profile photos, avatar images, chat photos and voice clips (Paris region, France; verification selfies are never copied), Google Cloud Vision for automatic checks of uploaded photos, Cloudflare Turnstile for protection against automated sign-ups and login attempts, LiveKit for relaying the audio in voice sessions (without recording), Resend for emails about your account (confirmation and password reset) and the confirmation when you sign up for the waitlist, Crisp for the support chat (France) when you open it yourself, Expo, Apple and Google for push and distribution and — after your consent — Google Analytics for website statistics and the Meta pixel (Meta Platforms Ireland) for ad measurement on the website. Some providers, their support and their subprocessors may process data outside the EU/EEA. In that case, an applicable adequacy decision, standard contractual clauses and supplementary safeguards are used where required. Data processing agreements, region, transfer safeguards and actual log/backup retention will be verified before the wide pilot.
6. Security
Mingle uses Row-Level Security, private storage areas, time-limited signed links, server-side contact and intention rules, rate limits, duplicate protection, blocking and reporting. Exact location is not shown or stored.
7. Your rights
You can request access, rectification, data portability, restriction, objection or erasure. Data export and account deletion are available in the app. A deletion request can also be sent via the public account deletion page. You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
8. Children
Mingle is only for people aged 18 or over. Accounts suspected of belonging to minors may be restricted or suspended.
9. Changes
Material changes to the processing or the policy are announced in the app. New sensitive purposes require a new, specific consent where the law requires it.