SILVR
Privacy Policy
Version: 2026-07-25
Last updated: 25 July 2026
This version replaces all previous versions of this Policy.
1. Who is responsible for your data
The data controller is:
Silviu Timaru Solutions, a sole proprietorship registered in Poland (CEIDG)
Registered address: ul. Władysława Pytlasińskiego 16/13, 00-777 Warsaw, Poland
NIP: 5213913023
Contact for all privacy matters: info@mivton.com
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy enquiries go to the address above.
2. What we collect and why
2.1 Your email address
What: the email address you enter to verify yourself.
Why: to confirm you control the address, to give you access to posting and rooms, and to record your age and terms confirmation.
Legal basis: performance of a contract (Article 6(1)(b) GDPR) — you cannot use these features without it.
2.2 Your display name
What: the name you choose, shown to other users.
Why: so other people can see who they are listening or talking with.
Legal basis: performance of a contract.
2.3 Your age and terms confirmation
What: a record that you confirmed you are 18 or older and accepted a specific version of our Terms and this Policy, with the date and time, your email address, and the type of room.
Why: to operate an adults-only service and to be able to demonstrate that we did so. This is a compliance record.
Legal basis: legal obligation and legitimate interests (Article 6(1)(c) and 6(1)(f)) — our interest in running a lawful adults-only service and protecting minors.
2.4 Wall messages
What: the message you post, your display name, and the country detected from your connection.
Why: to display your message publicly on the wall.
Legal basis: performance of a contract. Your message is public — anyone visiting the site can read it.
2.5 Room chat
What: messages you send in the shared room or in a private room for two.
Why: to deliver them to the other people in the room.
How we handle it: room chat is held in memory only for as long as needed to deliver it. We do not store room chat in a database and we do not keep a record of it. Once the message is delivered it is gone from our systems.
Legal basis: performance of a contract.
2.6 Reports
What: when you report someone, we record the type of room, its identifier, the time, and your verified identity. We do not capture the conversation.
Why: to investigate and act on breaches of our Terms and to protect users.
Legal basis: legitimate interests — user safety and platform integrity.
2.7 Usage and listening analytics
What: pages viewed, whether you pressed play, how long audio played, invites created and opened, and a daily-rotating hashed identifier derived from your connection. We do not store your raw IP address alongside this data. The hash changes every day, so it cannot be used to follow you over time.
Why: to understand whether the product works — how many people arrive, how many invite someone, how many invitations are opened.
Legal basis: legitimate interests — we need to know whether the service functions, and we have deliberately designed this to be as privacy-preserving as we can make it while still being useful.
2.8 Waitlist
What: an email address you give us to be notified about Mivton.
Why: to send you occasional updates about the service.
Legal basis: consent. You can withdraw it at any time by contacting us or using the unsubscribe link.
2.9 Technical data
What: standard server logs generated when you connect, including IP address, browser type, and timestamps.
Why: security, abuse prevention, and diagnosing faults.
Legal basis: legitimate interests.
3. What we do not do
- We do not sell your data. Ever.
- We do not show advertising and we do not share your data with advertisers.
- We do not build advertising profiles about you.
- We do not read or store private room conversations.
- We do not use third-party tracking or analytics services. Our analytics are our own, and they run on our own servers.
4. Cookies and local storage
We use the minimum necessary:
- a session cookie that keeps you signed in after you verify your email (approximately 30 days);
- local storage in your browser to remember your member number and whether we have already shown you a prompt, so we do not show it repeatedly.
These are strictly necessary for the service to work as you have asked it to. We do not use advertising or tracking cookies.
5. Who we share data with
We use a small number of service providers ("processors") who handle data on our instructions and only for the purposes below:
| Provider | What they do | Where |
|---|---|---|
| Railway | Hosts the application and database | United States / EU |
| Resend | Sends verification and notification emails | United States |
| Hostinger | Domain services | EU |
| Anthropic | Real-time translation of chat messages, where enabled | United States |
| Mixcloud | Provides the embedded music player | United Kingdom |
On translation: where translation is enabled, the message text is sent to Anthropic's API to be translated and returned. It is processed for that purpose only and is not used to train models.
On Mixcloud: the player is embedded from Mixcloud, which may set its own cookies and receive your IP address when it loads. That processing is governed by Mixcloud's own privacy policy.
We may also disclose data where we are legally required to do so, or where it is necessary to investigate a serious breach of our Terms or to protect someone from harm — in particular, where content involving a minor is reported to us.
6. Transfers outside the EEA
Some providers listed above are in the United States. Where data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision. You can ask us for details.
7. How long we keep things
| Data | Retention |
|---|---|
| Email address and account | While your account is active, and 12 months after last use, then deleted |
| Age and terms consent record | 3 years after your account is closed — this is our compliance evidence |
| Wall messages | Until you or we remove them |
| Room chat | Not retained — held in memory only during delivery |
| Reports | 2 years, or longer where an investigation or legal obligation requires it |
| Analytics (hashed) | 24 months |
| Waitlist email | Until you unsubscribe |
| Server logs | 90 days |
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you;
- Rectification — correct data that is wrong;
- Erasure — ask us to delete your data ("the right to be forgotten");
- Restriction — ask us to stop processing while a dispute is resolved;
- Portability — receive your data in a machine-readable format;
- Object — object to processing based on legitimate interests, including on grounds relating to your particular situation;
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting what happened before.
To exercise any of these, email info@mivton.com. We will respond within one month.
One limit worth being honest about: we may need to keep your age and terms consent record even after deleting the rest of your account, because it is the evidence that we operated an adults-only service lawfully. We will keep only what is necessary for that purpose and nothing more.
Complaints. If you are unhappy with how we handle your data, you can complain to the Polish supervisory authority:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
You may also complain to the supervisory authority in the EU country where you live.
9. Children
Mivton is not for anyone under 18. We do not knowingly collect data from anyone under 18.
If we learn that a user is under 18, we will terminate their access and delete their data without delay.
If you are a parent or guardian and believe your child has used Mivton, contact us at info@mivton.com and we will act immediately.
10. Security
We protect your data with encrypted connections (HTTPS), email-based verification rather than passwords, hashed identifiers instead of raw IP addresses in our analytics, restricted administrative access, and regular backups.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.
11. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects.
12. Changes to this Policy
We may update this Policy. Each version carries a version date at the top.
If we make a material change, the next time you enter a room you will be asked to read and accept the new version before continuing. Your acceptance of each version is recorded.
13. Contact
info@mivton.com
Silviu Timaru Solutions, ul. Władysława Pytlasińskiego 16/13, 00-777 Warsaw, Poland
Addendum — 2026-07-25: Studio Camera
This addendum adds to the Policy above; it does not change the version dated at the top.
The host may sometimes broadcast a one-way video feed of the studio (the "studio camera") into a room, so that listeners can watch while they listen. Watching is always optional and off by default — the audio experience is identical whether or not you watch.
When the host broadcasts video and you choose to watch it, your display name is shown to the broadcaster as someone currently watching, and we log that a view took place. Watching is always your choice; the video is one-way, from the studio to you — we never access your camera.
We record your one-time acceptance of this addendum (against the addendum date above) so we do not have to ask again. We keep a minimal count of views to understand how many people chose to watch a session; we do not record or store the video itself, which is deleted moments after it is shown.