Privacy Policy
Data Retention & Deletion Policy
Last Updated - Mar 30 2026.
Miko is an advanced consumer robotics innovation lab passionate about bringing the best of technology to young learners everywhere. This Privacy Policy (“Privacy Policy”) is designed to help you understand how we collect, use and share your personal information, and to assist you in exercising the privacy rights available to you.
The below mentioned Privacy Policy is for Miko Products, applicable on Miko 3 and Miko Mini.
SCOPE
This Privacy Policy applies to personal information collected and processed by us when you access and use our websites, services, software, apps, the Miko Robot (“Miko Robot” or “Products”) and other products (collectively, “Miko Services” or “Services”) For information about data practices relating to children's use of Miko devices, see Section VIII - Children's Information below.
I. PERSONAL INFORMATION WE COLLECT
The categories of personal information we collect depend on whether you are:
- A visitor of the www.miko.ai website (“Site Visitor”)
- An individual who purchases one of our Products (“Customer”)
- A parent, guardian or other representative who registers a Miko Robot (“Authorized User”)
- The user of a Miko Robot, who is either the Authorized User or the Authorized User’s child or an individual who interacts with our Products in a store (“Primary User”)
Information You Provide to Us
-
Account Creation
When you purchase from us or create a Customer account, we may collect your contact number, email address, shipping address and credit card details. If you are an Authorized User and create a profile for your child to use the Miko Robot, you have the option of providing additional details such as your child’s name, photograph, date of birth, and likes and dislikes. Account creation on Miko App is a parent or adult-directed activity. Miko uses appropr ate age screening mechanisms and/or collects verifiable parental consent prior to the collection of any personal information.
-
Your voice commands to Miko
The Miko Robot’s Primary User will also provide information to us through their voice commands and queries to the Miko Robot. This information includes the Primary User’s age (used to provide an age-appropriate experience), preferences, and demographic information. This information may be asked for by the Miko Robot directly or inferred by the Primary User’s interactions with the Miko Robot. Please be aware that it is possible that some background audio, including the voices of other nearby persons, may be captured when a user is speaking to the Miko Robot. Audio recordings of your voice interactions with the Miko robot may be transmitted to us to be converted into machine readable text so that the Miko Robot can respond to your commands. We may also use this data to improve our voice recognition software. Voice training used to detect accents and improve wake-word recognition runs entirely on the Miko device. The resulting model is stored locally on the device and is not transmitted to Miko servers. The audio files are deleted immediately post transcription, and are not shared with any third parties or retained by Miko.
-
Your Communications with Us
We collect personal information from you such as email address, phone number, or mailing address when you request information about our Services, request customer or technical support, apply for a job, or otherwise communicate with us.
-
Surveys
We collect personal information from you such as email address, phone number, or mailing address when you request information about our Services, request customer or technical support, apply for a job, or otherwise communicate with us.
-
Social Media Content
We may offer forums, blogs, or social media pages. Any content you provide on these channels will be considered “public” and is not subject to privacy protections.
-
Registration for Sweepstakes or Contests
We may run sweepstakes and contests. Contact information you provide may be used to reach you about the sweepstakes or contest and for other promotional, marketing and business purposes, if permitted by law. In some jurisdictions, we are required to publicly share information of winners.
-
Information from individuals who may interact with Miko
Miko Robot is primarily intended for purely personal, household use. You can restrict Miko
Robot’s use of the camera by applying the camera cover and/or by disabling camera access in
the mobile app.In addition, the Miko Robot continually listens for its trigger words, “Hello,
Miko,” that will enable listening mode, and will continually record audio for a ten-second
window after a Primary User stops talking.You (not Miko) are responsible for ensuring that you
comply with any applicable laws when you use Miko Robot. Depending on your use of Miko
Robot, you may need to notify individuals that may interact with Miko Robot that their faces or
voices may be detected and obtain any consent required by law.
Information Collected Automatically or From Others
-
Your surroundings
The Miko Robot will collect information about the environment in which it is deployed. For example, the Miko Robot collects information about its movement throughout the environment to create a location ‘map’ of the space accessible to the Miko Robot. The spatial map is a digital representation of the Miko Robot’s domain and may not include recognizable images from the location environment.
-
Automatic Data Collection.
We may collect certain information automatically when you use the Services. This information
may include your Internet protocol (IP) address, user settings, MAC address, cookie identifiers,
mobile carrier, mobile advertising and other unique identifiers, details about your browser,
operating system or device, approximate location information, Internet service provider, pages
that you visit before, during and after using the Services, information about the links you click,
and other information about how you use the Services. Information we collect may be
associated with accounts and other devices.
In addition, we may automatically collect data regarding your use of our Services, such as the types of content you interact with and the frequency and duration of your activities.
Cookies, Pixel Tags/Web Beacons, Analytics Information, and Interest-Based Advertising technologies.
We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. Technologies are essentially small data files placed on your computer, tablet, mobile phone, or other devices that allow us and our partners to record certain pieces of information whenever you visit or interact with our Services.
- Cookies.
Cookies are small text files placed in Site Visitors’ computer browsers to store their preferences. Most browsers allow you to block and delete cookies. However, if you do that, the Services may not work properly.
- Pixel Tags/Web Beacons
A pixel tag (also known as a web beacon) is a piece of code embedded in the Services that collects information about Site Visitors’ engagement on that web page. The use of a pixel allows us to record, for example, that a Site Visitor has visited a particular web page or clicked on a particular advertisement.
- Analytics
We may also use Google Analytics and other service providers to collect information regarding Site visitor behavior and Site Visitor demographics on our Services. For more information about Google Analytics, please visit : www.google.com/policies/privacy/partners/. You can opt out of Google’s collection and processing of data generated by your use of the Services by going to: http://tools.google.com/dlpage/gaoptout.
Biometric information
We will not collect biometric data that uniquely identifies you without your explicit prior
consent. As a user of Miko Robot, you agree that we may collect the relevant User’s face, voice
and emotional states in order to help the User securely log into our services and give you a
better experience with our Products. A User’s biometric data is used only to identify the User,
and to securely allow the User to access our Products. It is not used for advertising, unrelated
model training, or sharing with business partners in absence of a separate, explicit parental
opt‑in. Biometric data we collect is accessible only by us and not by partner companies unless
you have given your consent for the same. We do not sell, lease, trade, or otherwise profit from
biometric data; provided, however, that we and our partner companies may be paid for a User’s
use of the Services that utilize such biometric data. We will store biometric data using industry
standard security for sensitive data, for no more than three years from the last used date you
accessed our product, after which we will destroy the data. You may delete your biometric data
from our systems at any time through our mobile app or by contacting us as described in
“Contact Us” below.Information from Other Sources. We may obtain information about you
from other sources, including through third-party services and organizations to supplement
information provided by you. For example, if you access our Services through a third-party
application, such as an app store, a third-party login service, or a social networking site, we may
collect information about you from that third-party application that you have made public via
your privacy settings. Information we collect through these services may include your name,
your user identification number, your user name, location, gender, birth date, email, profile
picture, and your contacts stored in that service. This supplemental information allows us to
verify information that you have provided to us and to enhance our ability to provide you with
information about our business, products, and Services.
II. HOW WE USE YOUR INFORMATION
We use your information for a variety of business purposes, including to:
- Fulfill our contract with you and provide you with our Services, such as:
- Managing your information and accounts;
- Providing access to certain areas, functionalities, and features of our Services;
- Communicating with you about your account, activities on our Services and policy changes;
- Undertaking activities to verify or maintain the quality or safety of a service or device;
- Processing your financial information and other payment methods for products or Services purchased;
- Providing advertising, analytics and marketing services;
- Providing Services on behalf of our customers, such as maintaining or servicing accounts, providing customer service, and verifying customer information;
- Processing applications and transactions; and
- Allowing you to register for events.
- Analyze and improve our Services pursuant to our legitimate interest, such as:
- Detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
- Measuring interest and engagement in our Services and short-term, transient use, such as contextual customization of ads;
- Undertaking research for technological development and demonstration;
- Researching and developing products, services, marketing or security procedures to improve their performance, resilience, reliability or efficiency;
- Improving, upgrading or enhancing our Services;
- Developing new products and services;
- Ensuring internal quality control;
- Debugging to identify and repair errors that impair existing intended functionality;
- Enforcing our terms and policies; andComplying with our legal obligations, protecting your vital interest, or as may be required for the public good.
- Provide you with additional content and services, such as:
- Furnishing you with customized materials about offers, products, and Services that may be of interest, including new content or services;
- Auditing relating to interactions, transactions and other compliance activities; and
- Other purposes you consent to, are notified of, or are disclosed when you provide personal information.
Automated profiling
We may use technologies considered automated decision making or profiling. We will not make
automated decisions about you that would significantly affect you, unless such a decision is
necessary as part of a contract we have with you, we have your consent, or we are permitted by
law to use such technology. You may escalate any concerns you have by contacting us
below.Use De-identified and Aggregated Information. We may use personal information and
other data about you to create de-identified and aggregated information, such as de-identified
demographic information, de-identified location information, information about the computer
or device from which you access our Services, or other analyses we create.Share Content with
Friends or Colleagues. Our Services may offer various tools and functionalities to allow you to
share Miko content with others. For example, we may allow you to provide information about
your friends through our referral services.Our referral services may allow you to forward or
share certain content with a friend or colleague, such as an email inviting your friend to use our
Services.How We Use Automatic Collection Technologies. We, as well as third parties that
provide content, advertising, or other functionality on the Services, may use cookies, pixel tags,
local storage, and other technologies to automatically collect information through the Services.
Our uses of these Technologies fall into the following general categories:
- Operationally Necessary. This includes Technologies that allow you access to our Services, applications, and tools that are required to identify irregular site behavior, prevent fraudulent activity and improve security or that allow you to make use of our functionality;
- Performance Related. We may use Technologies to assess the performance of our Services, including as part of our analytic practices to help us understand how our visitors use the Services;
- Functionality Related. We may use Technologies that allow us to offer you enhanced functionality when accessing or using our Services. This may include identifying you when you sign into our Services or keeping track of your specified preferences, interests, or past items viewed;
- Advertising or Targeting Related. We may use first party or third-party Technologies to deliver content, including ads relevant to your interests, on our Services or on third-party sites.
- Cross-Device Tracking. Your browsing activity may be tracked across different websites and different devices or apps. For example, we may attempt to match your browsing activity on your mobile device with your browsing activity on your laptop. To do this our technology partners may share data, such as your browsing patterns, geo-location and device identifiers, and will match the information of the browser and devices that appear to be used by the same person.
Notice Regarding Third-Party Websites, Social Media Platforms and Software Development Kits.
The Services may contain links to other websites, and other websites may reference or link to
our website or other Services. These other websites are not controlled by us. We encourage our
users to read the privacy policies of each website and application with which they interact. We
do not endorse, screen or approve and are not responsible for the privacy practices or content
of such other websites or applications. Visiting these other websites or applications is at your
own risk. Our Services may include publicly accessible blogs, forums, social media pages, and
private messaging features. By using such Services, you assume the risk that the personal
information provided by you may be viewed and used by third parties for any number of
purposes. In addition, social media buttons that might include widgets such as the “share this”
button or other interactive mini-programs may be on our site. These features may collect your
IP address, which page you are visiting on our site, and may set a cookie to enable the feature to
function properly. These social media features are either hosted by a third party or hosted
directly on our site. Your interactions with these features apart from your visit to our site are
governed by the privacy policy of the company providing it. We may use third-party Application
Program Interfaces (“APIs”) and software development kits (“SDKs”) as part of the functionality
of our Services. APIs and SDKs may allow third parties including analytics and advertising
partners to collect your personal information (in aggregate format only) for various purposes
including to provide analytics services and content that is more relevant to you. For more
information about our use of APIs and SDKs, please contact us as set forth below.
III. DISCLOSING YOUR INFORMATION TO THIRD PARTIES
We will only share your personal information with the following categories of third parties. We have not sold consumers’ personal information in the preceding 12 months.
- Third-Party Developers
We may offer games developed by third parties. We vet all third-party developers before we allow them to make content for our Services. We may share any anonymous user data with these third-party developers to allow them to provide and improve their content.
- Service Providers.
We may share any personal information we collect about you with our third-party service providers. The categories of service providers (processors) to whom we entrust personal information include, but are not limited to: IT and related services (such as providers of speech-to-text technologies); information services; payment processors; customer service providers; and vendors to support the provision of the Services.
- Business Partners
We may provide personal, non-biometric, information to business partners with whom we jointly offer Products or Services. In such cases, our business partner’s name will appear along with ours. In some cases, you can use the Miko Robot to use the services or content of our business partners to log into your account with that business partner, in which case you consent to their privacy policy and are providing your data to them directly.
- Affiliates
We may share personal information with our affiliated companies.
- Advertising Partners
On our website, we may allow third-party advertising partners to set Technologies and other tracking tools to collect information regarding your activities and your device (e.g., your IP address, mobile identifiers, page(s) visited, location, time of day). We may also combine and share such information and other information (such as demographic information and past purchase history) with third party advertising partners. These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit third party websites within their networks. This practice is commonly referred to as “interest-based advertising” or “online behavioral advertising.” We may allow access to other data collected by the Services to share information that may be useful, relevant, valuable or otherwise of interest to you. If you prefer not to share your personal, non-biometric, information with third party advertising partners, you may follow the instructions below.
- Disclosures to Protect Us or Others
We may access, preserve, and disclose any information we store associated with you to external parties if we, in good faith, believe doing so is required or appropriate to: comply with law enforcement or national security requests and legal process, such as a court order or subpoena; protect your, our or others’ rights, property, or safety; enforce our policies or contracts; collect amounts owed to us; or assist with an investigation or prosecution of suspected or actual illegal activity.
- Disclosure in the Event of Merger, Sale, or Other Asset Transfers
If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction, as permitted by law and/or contract.
- International Data Transfers
Where applicable, we will protect information through other legally valid methods, including international data transfer agreements.
You agree that all information processed by us may be transferred, processed, and stored
anywhere in the world, including but not limited to, the United States or other countries, which
may have data protection laws that are different from the laws where you live. We have taken
appropriate safeguards to require that your personal information will remain protected and
require our third-party service providers and partners to have appropriate safeguards as well.
Further details can be provided upon request.
V. YOUR CHOICES
General
You have certain choices about your personal information. Where you have consented to the processing of your personal information, you may withdraw that consent at any time and prevent further processing by contacting us as described below. Even if you opt out, we may still collect and use non-personal information regarding your activities on our Services and for other legal purposes as described above.
Email and Telephone Communications
If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails. Note that you will continue to receive transaction-related emails regarding products or Services you have requested. We may also send you certain non- promotional communications regarding us and our Services, and you will not be able to opt out of those communications (e.g., communications regarding the Services or updates to our Terms or this Privacy Policy).
You may reply STOP to opt out at any time from SMS and WhatsApp messages.
Mobile Devices
We may send you push notifications through our mobile application. You may at any time opt-out from receiving these types of communications by changing the settings on your mobile device. We may also collect location-based information if you use our mobile applications. You may opt-out of this collection by changing the settings on your mobile device.
“Do Not Track.”
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
Cookies and Interest-Based Advertising
You may stop or restrict the placement of Technologies on your device or remove them by adjusting your preferences as your browser or device permits. The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in self-regulatory programs. You can access these and learn more about targeted advertising and consumer choice and privacy, at
www.networkadvertising.org/managing/opt_out.asp,
http://www.youronlinechoices.eu/,
https://youradchoices.ca/choices/,
and www.aboutads.info/choices/.
To separately make choices for mobile apps on a mobile device, you can download DAA’s AppChoices application from your device’s app store. Alternatively, for some devices you may use your device’s platform controls in your settings to exercise your choice.
Please note you must separately opt out in each browser and on each device. Advertisements on third party websites that contain the AdChoices link may have been directed to you based on information collected by advertising partners over time and across websites. These advertisements provide a mechanism to opt out of the advertising partners’ use of this information for interest-based advertising purposes.
Your Privacy Rights
In accordance with applicable law, you may have the right to:
- Access personal data about you consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic Personal Data transferred to another party.
- Request correction of your personal information where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal information, or we may refer you to the controller of your personal information who is able to make the correction.
- Request deletion of your personal information, subject to certain exceptions prescribed by law.
- Request restriction of or object to processing of your personal information, including the right to opt in or opt out of the sale of your personal Data to third parties, if applicable, where such requests are permitted by law.
If you would like to exercise any of these rights, please log into your account via the mobile app (to delete your information), or contact us as set forth below. We will process such requests in accordance with applicable laws. To protect your privacy, we will take steps to verify your identity before fulfilling your request.
V. DATA RETENTION AND DELETION
We collect and use children’s personal information only with verified parental consent. We
retain it only as long as reasonably necessary to provide the Services and for legitimate business
needs such as maintaining accounts and settings, delivering requested features, supporting
customers, preventing fraud and abuse, and complying with applicable laws. Our data retention
and deletion policy can be found here
VI. SECURITY OF YOUR INFORMATION
We maintain a written information security program designed to protect children’s personal
information. The program is appropriate to the sensitivity of the information we collect and our
size, complexity, and operations. It includes designated personnel responsible for the program,
at least annual risk assessments, administrative, technical, and physical safeguards to address
identified risks, regular testing and monitoring, and at least annual evaluation and updates. No
system is 100% secure, and we cannot guarantee absolute security. If we learn of a security
incident involving personal information, we will provide notice as required by applicable law.
The written information security program can be found here.
VII. CHILDREN’S INFORMATION
We require verifiable parental consent before collecting information from or about you and
children under 13.
Parents or legal guardians ("Parents") must provide their verified consent for the collection, use,
or disclosure of their child’s personal data. Miko will not collect, use, or disclose any personal
data from a child if their parent or guardian does not provide such consent. Miko will store and
recognize your child’s unique face and voice data, demographic information and individual
preferences, and use it to personalize your child’s experience, provide an age-appropriate
experience, and otherwise pursuant to this privacy policy. Children cannot communicate with
Other Users, such as by initiating video calls, without their parent or guardians’ consent.You
may delete your child’s information from the Miko Robot at any time using the mobile app. If
you learn that your child has provided us with personal information without your consent, you
may contact us as set forth below. If we learn that we have collected any personal information
in violation of applicable law, we will promptly take steps to delete such information, unless we
have a legal obligation to keep it, and terminate the child’s account.We do not employ any advertising trackers, ( such as pixel tags etc.) on Miko Robot for targeting or retargeting children
for any marketing.
Our privacy practices for children
Aside from potentially collecting a parent's contact information, we do not collect any personal information from children before collecting verifiable parental consent from their parent. The parents' contact information is used only to seek parental consent as required. Under the Children’s Online Privacy Protection Act, you can review your child’s information by contacting us at support@miko.ai. You may also request that we no longer collect information from your child or have your child’s information deleted. To do so, contact us at support@miko.ai
You may delete your child’s information from the Miko Robot at any time using the mobile app
If you learn that your child has provided us with personal information without your consent, you may contact us as set forth below. If we learn that we have collected any personal information in violation of applicable law, we will promptly take steps to delete such information, unless we have a legal obligation to keep it, and terminate the child’s account.
Children's Information
We collect only the personal information from children that is reasonably necessary to enable participation in Miko services and only after obtaining verifiable parental consent, as required under the Children’s Online Privacy Protection Act (COPPA).
The categories of personal information we collect from children, and how we use it, are described below:
Name:Used to personalize the child’s experience, including enabling the Miko device to address the child by name during interactions.
Gender (Optional):Used to personalize interactions and address the child using appropriate
pronouns. Providing gender information is optional.
Date of Birth (DOB):Used to determine the child’s age and provide age-appropriate content,
features, and recommendations.
Child Interests:Used to personalize content recommendations, stories, learning modules, and
interactive experiences.
Voice Recordings:Voice recordings are processed to: Enable voice-based interaction with the
Miko device, Train and recognize wake word functionality, and Process and respond to user commands. Children’s voice recordings are not stored permanently. They are deleted after processing and transcription.
Photos:Child photos may be used for personalized experiences, such as generating personalized
stories or interactive content.
Videos:Children may record videos using the camera on the Miko device. These videos are
stored locally on the device and are not transmitted to Miko servers or shared with any third
parties.
Location Data (Including IP Address)
We collect IP address and general location data to:
- Deliver geographically appropriate content
- Comply with content licensing restrictions
- Ensure platform security and fraud prevention
- Ensure platform security and fraud prevention
We do not collect precise geolocation data (such as GPS coordinates) from children unless explicitly disclosed and consented to by a parent.
App and Device Identifiers
We collect persistent identifiers such as device IDs, app identifiers, and similar technical identifiers to:
- Maintain account authentication
- Support security and fraud prevention
- Enable device functionality
- Enable device functionality
- Diagnose technical issues and errors/li>
These identifiers are used for internal operations and are not used for behavioral advertising.
Push Notification Tokens: If a parent enables push notifications on the companion mobile app or Miko device, we collect push tokens to send service-related communications, updates, and alerts.
How we use children’s information
Unless permitted by law, we use children’s information after getting verified parental consent. Parents or legal guardians ("Parents") must provide their verified consent for the collection, use, or disclosure of their child’s personal data. Miko will not collect, use, or disclose any personal data from a child if their parent or guardian does not provide such consent, except in limited circumstances — i.e., if we are only using the information one time to respond to a direct request, or if we are using information obtained from a child to get parental consent. We also use children’s information as described in any request for parental consent.Miko will store and recognize your child’s unique face and voice data, demographic information and individual preferences, and use it to personalize your child’s experience, provide an age-appropriate experience, and otherwise pursuant to this privacy policy.
Personal Identifiers.
Miko does not use children’s personal information, including persistent identifiers linked to a child profile, for interest‑based or targeted advertising on any property, and does not permit advertising networks to build profiles on child users. Any advertising or analytics cookies on the public website or companion app are either: (a) limited to adults / parents only; or (b) not linked to a child’s profile, and are used solely for support for internal operations unless a separate adult consent is obtained.”
We may share children’s information
We will share children’s information if required by law. We do not currently have any platforms designed to let kids make their personal information publicly available.
Use and Disclosure of your Information
Consistent with the section “We collect information from and about you and children under 13,” we collect certain categories and specific pieces of information about individuals that are considered "personal information" in California. As detailed, we may collect this personal information from you and other third parties. We collect, share, and disclose personal information for the purposes described in this Privacy Policy.
VIII. OTHER PROVISIONS
SUPERVISORY AUTHORITY
If you are located in the European Economic Area or the UK, you have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law.
CHANGES TO OUR PRIVACY POLICY
We may revise this Privacy Policy from time to time in our sole discretion. If there are any material changes to this Privacy Policy, we will notify you as required by applicable law. You understand and agree that you will be deemed to have accepted the updated Privacy Policy if you continue to use the Services after the new Privacy Policy takes effect.
IX. CONTACT US
If you have any questions about our privacy practices or this Privacy Policy, or if you wish to submit a request to exercise your rights as detailed in this Privacy Policy, please contact us at:
Miko
RN Chidakashi Technologies Pvt. Ltd. Flat No. 4, Plot No. 82, Stambhtirth Rafi Ahmed Kidwai Marg
Wadala (West), Mumbai - 400031 legal@miko.ai
Phone No. : +1 415 854 5954
Rakuten Advertising may collect personal information when you interact with our digital property, including IP addresses, digital identifiers, information about your web browsing and app usage and how you interact with our properties and ads for a variety of purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes.
X. Miko Chess
To view Privacy Policy for Miko Chess, click here
XI. Language
This Privacy Policy may be made available in multiple languages. We aim to provide translations to help users better understand our practices. In the event of any inconsistency or conflict between a translated version and the English version, the English version shall prevail.
XII. Other
Miko Device and Services Vulnerability Reporting and Bug Bounty Program, click here
You can find the UK PSTI statement of compliance document here
Data Retention and Deletion Policy
Policy Statement
Miko is committed to the principle of data minimization. We retain Personal Information collected from children only for as long as is reasonably necessary to fulfill the specific purpose(s) for which it was collected. Note that personal information collected online from a child will not be retained indefinitely if the purpose for collection has ended.
1. Data Retention Schedule
The following schedule defines the retention periods for specific categories of Children's Data held by Miko.
| Data Category | Purpose(s) of Collection | Business Need for Retention | Retention Period / Deletion Trigger |
|---|---|---|---|
| Account Credentials (Parent Email, Parent Phone, Account Country, Account Language) collected from Parent | To create and maintain the Parent’s account and allow access to and manage Mikos. Also, To provide notice, obtain consent, and communicate regarding the account. | Authentication and account access, Legal compliance (i.e. proof of consent) and service notifications. | Retained while the account is Active. Deleted 24 months after the account becomes Inactive (see definition below). Deleted immediately if the parent requests for account deletion. |
| Consent Verification Records | To demonstrate valid parental consent was obtained. | Legal defense and regulatory audit trail. | and regulatory audit trail. Retained for 8 years after the account is closed to demonstrate historical compliance. |
| Child Profile (Nickname, Date of Birth, Gender, Interests, Child Photo) collected from Parent with verifiable parental consent | To create a profile the child to curate game-plays and interactions which are age-relevant and personalised to foster learning and play. | For continued use of age-relevant and personalised experience. | Same as Account Credentials. |
| Gameplay/Activity Data (Progress, rewards, levels, scores, theme, usage) | To maintain the child's progress and experience in the game/app. To create progress and usage reports for parents. | Continuity of user experience and Providing accurate child’s progress report to Parent. | Same as Account Credentials. |
| User-Generated Content (UGC) (Photos, and videos intentionally taken by the user, Text/image/video/audio created during specific gameplay) | To enable features such as photo & video capture, and allow creative gameplays. | Maintaining user-created content that the child or parent chooses to create, save and access later. | Retained until it is deleted by user (via delete function) or Account deletion (by request or inactivity) In addition, only-on- device UGC (like photos/videos in the camera app) are also deleted when the user unlinks the device. |
| Interaction Data: Voice & Image (Voice commands/microphone audio snippets, and camera inputs used to interpret user requests) | To understand and respond to user requests, enable voice interaction with Miko, support interactive learning experiences (e.g., object recognition). | To understand and respond to user requests, enable voice interaction with Miko, support interactive learning experiences (e.g., object recognition). | Ephemeral. Voice inputs, and image data are processed in real time and deleted once the request has been fulfilled. |
| Interaction Data: Transcripts and Responses (Transcripts of Child Inputs and text of Miko responses) | To understand and respond to user requests, enable voice interaction with Miko, support interactive learning experiences and ensure safety (content moderation). | Continuity of user experience, Providing accurate child’s progress report to Parent. | Transcripts and Responses are saved without Personal Data. Deleted along with account deletion (as defined in Account credentials) |
| Interaction Data: Prompts for AI models (prompts used for various models) | To support the feature (answer questions, generate images) and ensure safety (content moderation). | Maintaining conversation flow during the active session or generating assets needed in gameplay. And for Detecting and blocking abuse or CSAM. Note: 1. Child’s Personal data is not used for any AI model training. 2. Voice (Wakeword) training and Face training on Miko is processed and stored entirely on-device; associated data never leaves the device and therefore is not stored on servers. |
Ephemeral. Not retained Beyond processing of specific requests. |
| Technical Logs & Analytics (IP addresses, Device IDs, crash reports, usage logs) | Security monitoring, debugging, and internal operations. Note: This information does not contain Child’s personal data. | Maintaining security, integrity, and optimizing performance. | Same as Account Credentials. |
| Customer Support Records (Emails, chat logs, tickets) | To resolve user issues and improve service quality. | Quality assurance, dispute resolution, and analyzing recurring bugs. | Retained for 24 months from the date of ticket closure, then securely deleted. |
| Transaction or Subscription data | To enable in-app purchases, subscriptions, resolve paymen issues, and provide continuity in account access/progress. | Maintaining records for payment issues or disputes, regulatory compliance, and continuity of user experience. | We use a data decoupling approach. The financial record (which belongs to the parent) is separated from the usage data (which belongs to the child). Transaction ID, parent’s email/billing address, price, and timestamp may be retained for regulatory compliance. The child’s specific activity logs, persistent identifiers (not needed for billing), or other in- app data are deleted in accordance with the rest of this retention policy. |
2. Definition of "Inactive Account"
An account is considered "Inactive" if there has been no login or meaningful interaction with the account for a continuous period of 24 months.
Notification Process:
30 days prior to the expiration of the inactivity period, Miko will notify the user (through an email to the verified Parent Email Address on file where possible). This notification will alert the user that the account and all associated Children's Data will be permanently deleted, in accordance with this retention policy, unless an opt-in action is performed.
3. Deletion Procedures
When a retention period expires, or a valid deletion request is received, Miko employs the following measures to ensure secure deletion:
3.1 Active Systems
Data in active databases and file systems is permanently deleted using secure methods (e.g., cryptographic erasure or database overwriting) that render the data unrecoverable. In specific cases, we may adopt an anonymization approach where there is a business need to retain deidentified data, stripping all direct and indirect identifiers so the data can no longer be linked to a specific child.
We acknowledge that deleted data may remain in backup archives for a short period due to the nature of our backup rotation schedule.
- Data in backups is put beyond use (not accessible for ordinary business operations).
- Backups are encrypted and subject to strict access controls.
- Data in backups will be overwritten in accordance with our backup rotation schedule (e.g., every 90 days), ensuring final deletion.
3.3 Third-Party Signaling
Upon deletion of Children's Data from our systems, Miko actively signals our third-party service providers (e.g., analytics providers) via API or manual request to delete the associated data from their systems, in accordance with our Third-Party Data Security Agreements.
4. Parental Deletion Requests
At any time, a verified parent may request the deletion of their child's personal information by contacting support@miko.ai
- Response Time: Miko will delete the information within 45 days of receiving a verified request.
- Revocation of Consent: Consent revocation is treated as an Account deletion request.