1. Scope and processing roles
This Policy applies to mimix-ai.xyz, registration, the unified account, contributor and company areas, support and projects offered through MIMIX AI.
The controller applicable to your relationship will be identified in registration, contracting or project documents. Providers processing data under our instructions act as processors; clients or partners defining their own purposes may act as independent controllers, which will be disclosed in the relevant context.
2. Data we may process
Account data: name, email, language, protected credentials, verification status and preferences. Company and team data: company identity, invitations, memberships, roles, current project and split versions applying to future commercial work.
Activity data: eligibility answers, project participation, submitted, approved, pending or rejected hours or seconds, quality, history, credits and audit records. Technical and security data: IP address transformed into a pseudonymous identifier, signed device cookie, installation identifier, browser agent, platform, screen dimensions, access logs and anti-fraud events.
Financial data: payout method, Pix key or public cryptocurrency wallet address, provider references, display labels, amounts and credit or payment history. MIMIX stores the Pix key or wallet address in encrypted form to execute payments and displays it in masked form in ordinary screens. We do not request bank passwords or wallet private keys.
3. Videos sent directly to Minute Data
For projects currently integrated with Minute Data, operated by Baker Data LLC, participants record and submit material directly through the external application. MIMIX AI does not receive, store, access or view those videos and does not act as an intermediary in file transmission.
MIMIX processes operational registration data and outcomes needed for participation and payments, such as duration, quality, approval, rejection, credits and history. Operational and financial intermediation does not give MIMIX access to audiovisual content.
Video operations, including storage, use, licensing, sharing and deletion, take place within Minute Data's service and are subject to that provider's documents and applicable law. Consult Minute's terms and privacy policy before recording. This Policy describes processing carried out by MIMIX and does not replace the external service's documents.
Profile photos, messages and attachments submitted directly to MIMIX features, as well as communications in the Minute inbox provided within the account, are processed by MIMIX to offer those features. They are distinct from task videos submitted to Minute Data.
4. How we obtain data
We receive data directly from you during registration, account use, support, payout setup and projects; from company owners when they send invitations or manage team membership; from operational providers confirming registration, activity and outcomes; and automatically from the device for functionality, security and fraud prevention.
Do not use a project to record third parties, private places or protected information without the authorization required by the brief and applicable law.
5. Purposes and legal bases
We process data to create and secure your account; verify eligibility; connect people, companies and projects; reconcile participation outcomes reported by the provider; calculate credits; process payments; provide support; meet legal duties; prevent fraud; maintain audit and security; and operate, measure and improve the platform.
Legal bases may include contract performance and pre-contract steps, legal or regulatory duties, legal claims, legitimate interests subject to necessity and impact review, fraud prevention and, where applicable, consent. Project notices will state relevant conditions, especially for sensitive data or capture content.
6. Sharing
We may share only necessary data with infrastructure, hosting, database, security, communications, support and payment providers; operational collection and review tools; project clients or partners within the disclosed purpose; advisers under confidentiality; and authorities where a legal basis or duty applies.
Company owners access only operational data needed to manage their own team. They do not receive a member's payout credentials, other companies' data or information beyond their role permissions.
In the Minute Data integration, MIMIX's sharing covers operational and financial data; it does not include video files, which MIMIX neither receives nor accesses.
7. International transfers
Some providers or participants in the processing chain may operate outside Brazil. When an international transfer is subject to the LGPD, we will use a valid mechanism and compatible safeguards, limit the transfer to what is necessary and provide transparency under ANPD rules.
8. Retention and deletion
We retain data for the disclosed purposes and then for periods required by legal, tax, accounting, fraud-prevention, audit or legal-claim needs. Registration security events are generally retained for up to 180 days; financial, approval and audit histories may require longer periods.
At the end of the applicable period, data is deleted, anonymized or isolated according to purpose and law. Deletion requests do not immediately erase information we must keep for legal duties or legitimate legal protection.
These criteria concern data held by MIMIX, not videos submitted to Minute Data. Consult the provider's documents and channels about video retention. Closing a MIMIX account does not automatically delete the Minute account or recordings.
9. Your rights
Under the LGPD, you may request confirmation of processing, access, correction, anonymization, blocking or deletion where applicable, portability under regulation, sharing information, objection, review of solely automated decisions and withdrawal of consent.
We may request information to verify your identity and protect the account. If a request cannot be fully fulfilled, we will provide the applicable reason. You may also petition Brazil's National Data Protection Authority.
Requests about videos sent directly to Minute Data may be directed to contact@useminute.app, the contact published by the provider. MIMIX may help direct a request but does not delete external files it cannot access or guarantee their removal. This does not remove its obligation to respond to rights requests concerning data processed by MIMIX or other obligations imposed on it by law.
10. Automated decisions and security
Technical signals may support risk and fraud investigations, but they are not used alone to make automatic identity decisions. Where a solely automated decision has significant effects, you may request information and review under applicable law.
We use technical and administrative safeguards proportionate to risk, including access controls, encryption, separation of duties, audit logs and secret protection. No system is invulnerable; relevant incidents will be assessed and reported to data subjects and the ANPD when required.
11. Cookies and local storage
We use cookies and local storage needed for sessions, security, language, registration continuity, invitations and referral attribution. These features maintain the experience and help prevent abuse. If optional analytics or advertising tools are added, the required notices and controls will be presented before use.
12. Changes and contact
We may update this Policy for legal, security or product changes. Material changes will be highlighted and the current version will remain available on this page.
To exercise rights or ask questions, use the official support channels shown on the website and in your account. Privacy requests received through those channels will be directed to the person responsible for responding to data subjects.