Privacy Policy
Last updated: 12 August 2026. Short version: we collect the minimum needed to let you talk to the people around you, we never sell your data, and you can delete your account at any time.
1. Who we are
Migo.chat ("Migo", "we", "us") operates this website and application and is the data controller for the personal data described in this policy. For any privacy question or request, contact us at contact@migo.chat.
2. What data we collect
Account data: your email address, display name, avatar, and your date of birth or age, which is used once to confirm you are 18 or older.
Profile data: your status (available, busy, do not disturb, away) and any custom status text you write.
Content you create: messages in group rooms and direct chats, reactions, events you create or join, groups you join, chat themes you choose.
Social data: friend requests and friendships, buddy groups, blocks, notifications, and profile visits (who viewed your profile).
Technical data: authentication session identifiers, connection/presence state, and basic security logs produced by our hosting provider (including IP address and timestamps).
We do not collect precise GPS location. Groups are tied to fixed public places, not to your device.
3. What other people can see
Other members can see your display name, avatar, status and anything you post in rooms, events or direct chats. Your email address and your age or date of birth are never shown to other members. Your profile visitor list is visible only to you.
4. Why we use your data and our legal basis (GDPR Art. 6)
To provide the service — creating your account, delivering messages, showing groups and events. Legal basis: performance of a contract.
To keep the platform safe — moderation, blocking, preventing abuse, spam and fraud. Legal basis: legitimate interests, and compliance with legal obligations.
To verify you are 18+ — Legal basis: legitimate interests and legal obligation for an adults-only service.
To communicate with you — sending login codes and service messages. Legal basis: performance of a contract.
5. Cookies and local storage
We use only what is strictly necessary to run the service: an authentication session token and small local-storage entries that remember your sign-in preferences. We do not use advertising cookies, third-party trackers or profiling. Because these cookies are strictly necessary, no consent banner is required under the ePrivacy Directive.
6. Who we share data with
We do not sell your personal data and we do not share it for advertising. We use a small number of processors who handle data strictly on our instructions:
Supabase — database, authentication, realtime messaging and transactional auth emails (hosting infrastructure).
Netlify — website hosting and delivery.
We may also disclose data where legally required, or where necessary to protect the rights and safety of our users.
7. International transfers
Some of our processors may store or process data outside the European Economic Area. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR.
8. How long we keep data
Account and profile data is kept while your account exists. Messages, events and social data are kept while the account and the related group or conversation exist. When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must keep limited records longer for security, abuse-prevention or legal reasons.
9. Your rights under the GDPR
If you are in the EU/EEA or the UK, you have the right to access your data, to correct it, to erase it, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right not to be subject to automated decision-making — we do not carry out any.
Exercise any of these rights by writing to contact@migo.chat. We respond within one month. You can also lodge a complaint with your local data protection authority.
10. Security
Data is stored with our hosting provider and protected by row-level security rules so members can only read what they are allowed to read. Traffic is encrypted in transit with TLS and passwords are stored hashed. No online service can guarantee absolute security, but we take reasonable technical and organisational measures and will notify you and the relevant authority of a qualifying personal data breach as required by law.
11. Children
Migo is for adults only. You must be 18 or older to create an account. If we learn that a minor has created an account, we delete it.
12. Changes to this policy
We may update this policy. If a change is significant we will let you know inside the app or by email before it takes effect. The date at the top always shows the current version.