Privacy Policy

Svenska | English | Norsk

Last updated: 20 July 2026

1. Who is responsible for your personal data?

Art A, a Swedish sole trader based in Lund, Sweden (”MyMiracle”, ”we”, ”us”), is the controller for the processing described in this policy.

For privacy questions or to exercise your rights, contact info@mittmirakel.com.

2. What data do we process?

The data depends on how you use the service:

  • Account and contact data: name, email address, phone number, user ID, sign-in and account status, and information you provide to support.
  • Family, children and other people: names, relationships, roles, dates of birth, pregnancy and birth details, milestones, notes and other information you choose to add. This may include sensitive data such as health information.
  • Your content: diary text, photos, videos, audio, documents, captions, reactions, comments, book content, product previews and other content you create or upload.
  • Sharing and access: family groups, invitations, member roles, recipients, blocking and reporting information, and activity needed to manage access.
  • Device features: location, contacts, calendar, camera, photo library, microphone and speech recognition are processed only when you use a feature that needs them and grant the relevant iOS permission. Local face and image analysis is performed on the device using Apple Vision.
  • Purchases and delivery: Apple subscription status and purchase history, and the name, address, contact details, order data, product files and delivery information needed for physical products. MyMiracle does not process full payment-card details.
  • Technology and security: IP address, timestamps, short-lived authentication tokens, device and app information, and technical logs required for operation, troubleshooting, fraud prevention and security.

MyMiracle does not use this data for advertising or tracking across other companies’ apps and websites.

3. Why do we process data and on what legal basis?

  • Provide the app and account: to create and manage accounts, store and sync content, and provide family, sharing, book and other features. The legal basis is performance of our contract with you.
  • Purchases and delivery: to manage subscriptions, previews, orders, payment status, production, delivery, complaints and customer service. The basis is performance of a contract and, for accounting records, compliance with legal obligations.
  • Information you actively choose to store: the service is designed for private family memories and may contain sensitive data. Where processing is not necessary for the core service, it is based on your explicit and voluntary choice to use the feature. You can remove content and withdraw device permissions at any time.
  • Security and abuse prevention: to authenticate requests, limit unauthorised traffic, prevent fraud, investigate reports and protect users, children, the service and our rights. The basis is our legitimate interest in providing a safe service, with particular weight given to children’s protection.
  • Legal compliance and claims: for accounting, authority requests and legal claims. The basis is a legal obligation or legitimate interest, depending on the situation.

We do not sell personal data or use it for automated decisions that have legal or similarly significant effects.

4. Children’s personal data

The service is intended for adult users. Information about children is added and managed by a guardian or another adult who has the right to do so. Only add and share information when this is consistent with the child’s best interests, taking account of the child’s age, maturity and views.

You are responsible for having the right to add and share information about children and other people in your content. Contact us if you believe a child’s data is being processed without authorisation.

5. Who receives the data?

  • Google Firebase and Google Cloud: authentication, databases, file storage, server functions and technical operation.
  • Apple: App Store distribution, device permissions, push notifications, purchases and subscriptions.
  • Gelato and other named production and logistics partners: when you request a quote, preview, production or delivery of a physical product.
  • Online store, hosting and payment provider: WordPress/WooCommerce, hosting providers and the payment provider shown at checkout.
  • Professional advisers and authorities: when required by law or necessary to establish, exercise or defend legal claims.

People you invite receive access according to their group role and permissions. Processors may act only under contract and our instructions. A recipient that independently decides why and how data is processed is a separate controller.

6. Transfers outside the EU/EEA

Some providers are international and processing or support access may take place outside the EU/EEA. Where a country lacks an adequacy decision, we use a lawful transfer mechanism such as the European Commission’s Standard Contractual Clauses and additional safeguards where required. Contact us for information about a specific transfer.

7. How long do we keep data?

  • Account data and user content are normally kept while the account exists and removed from active systems when you delete the account or content, unless retention is required for another reason below.
  • Temporary rendering, preview and order files are retained only as long as needed to perform and secure the task.
  • Orders, transactions and accounting records are retained as required by accounting, tax and consumer law.
  • Security, reporting and dispute data are retained as long as necessary to investigate an incident, protect the service or handle a legal claim.
  • Deleted data may remain temporarily in backups until overwritten under the provider’s normal backup cycle and is then used only for recovery and security.

When a retention period ends, data is deleted or anonymised.

8. Security

We use authentication, access rules, encrypted transport, restricted server functions, access controls, rate and size limits, and separation of users’ files. No service can guarantee absolute security. Protect your password, invitations and devices, and contact us immediately if you suspect unauthorised access.

9. Your rights

Depending on the circumstances, the GDPR may give you the right to access, correct or erase your data; restrict or object to processing; receive data you provided in a commonly used machine-readable format; and withdraw consent without affecting earlier lawful processing.

You can delete your account and cloud data in the app’s account settings. For other requests, contact info@mittmirakel.com. We may need to verify your identity and will respond within the period required by law.

You may complain to the Swedish Authority for Privacy Protection (IMY), www.imy.se, or the data protection authority where you live or work.

10. Website, online store and cookies

Mittmirakel.com uses necessary cookies and similar storage for the website, cart, checkout, account sign-in, security and user choices. Necessary cookies are used to perform a contract or for our legitimate interest in providing a secure, functional service. Non-essential analytics or marketing cookies will not be activated without information and consent where the law requires it.

When you shop online, WooCommerce, the hosting provider, the payment provider shown at checkout, and Gelato or another named production partner process the information needed for checkout, payment, production and delivery.

11. Contact

For support, privacy questions and GDPR requests, email info@mittmirakel.com or visit https://mittmirakel.com/contact-en/.

12. Changes

We may update this policy when the service, providers or law changes. The date above shows the latest revision. Material changes will be communicated clearly in the app or through an appropriate contact channel when required by law.