Mia

Legal

Privacy Policy

Last updated: June 6, 2026

Who Operates Mia

Mia is operated by Orichalque SAS, 26 rue Bosquet, Paris, France. For privacy or support requests, contact us at hey@loopmia.com.

What Mia Does

Mia helps users schedule meetings from email conversations. When a user connects Google, Mia reads free/busy and event details on the calendars the user selects, uses them to work out which times are open, and creates, updates, or cancels the calendar invitation after a meeting time is confirmed, rescheduled, or cancelled.

Google Calendar Access

When you connect Google, Mia requests three Calendar scopes and reads only the calendars you select in the dashboard:

  • calendar.freebusy: reads free and busy time ranges to find open slots, without reading event content.
  • calendar.calendarlist.readonly: lists your calendars so you can choose which ones Mia uses.
  • calendar.events: reads event details (such as title, time, and status) on the selected calendars to interpret your real availability, and creates, updates, or cancels the meeting invitation when you book, reschedule, or cancel.

Mia does not request Gmail access or full account access.

Data We Process

Depending on how you use Mia, we may process:

  • Account information such as name, email address, provider account ID, and timezone.
  • OAuth tokens needed to access connected Google accounts.
  • Email metadata, snippets, and thread content from messages sent to Mia through Postmark inbound webhooks.
  • Calendar data on the calendars the user selects: free/busy, event details such as title, time, and status used to interpret availability, and the events Mia creates, updates, or cancels.
  • Editable scheduling preferences supplied by the user.
  • Billing, subscription, managed-contact usage, AI usage metadata, and audit information.

Email Data

Mia receives email content only when Mia is included on a thread and Postmark forwards that inbound message to the application. Email content may be processed to understand the scheduling request or draft a reply. Mia temporarily stores cleaned text from scheduling messages and Mia's public replies so later emails can refer to earlier choices. Attachments and email HTML are not retained.

AI Processing

Mia uses OpenAI to understand meeting context and draft email replies. Relevant thread text may be sent to OpenAI for this purpose. Mia is configured not to log raw email bodies.

How We Share, Transfer, Or Disclose Google User Data

We do not sell Google user data, use Google user data for advertising, transfer Google user data to data brokers, or use Google user data to train generalized AI models. We share, transfer, or disclose Google user data only as needed to provide, secure, support, or improve the user-facing scheduling assistant features requested by the connected user.

  • Service providers process Google user data for Mia, including hosting, database storage, email delivery, billing, background jobs, security, analytics, and AI processing. These providers are authorized to process the data only as needed to provide their services to Mia.
  • Google receives Google user data through the Google APIs when Mia authenticates the connected account, checks Calendar availability, and creates calendar events requested through the service.
  • OpenAI may receive relevant email snippets, thread text, scheduling preferences, and availability context so Mia can understand scheduling requests and draft replies.
  • Email recipients and calendar invitees may receive scheduling replies, proposed time slots, booking links, and calendar invitations that Mia sends or creates as part of a scheduling thread.
  • We may disclose data when required by law, to protect Mia and users from security threats or abuse, or as part of a merger, acquisition, or sale of assets after obtaining any consent required by applicable law and Google policy.

Service Providers

Mia relies on infrastructure and service providers including Vercel, Supabase, Postmark, Stripe, Inngest, OpenAI, Google, and Cloudflare. These providers process data only as needed to operate Mia.

Security

OAuth tokens are encrypted before storage. Access to data is limited to the server-side systems required to operate Mia. No internet service can be guaranteed perfectly secure, but Mia is designed to minimize retained email content.

Google API Limited Use

Mia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve Mia's scheduling assistant features that are visible to and requested by the user. Humans do not read Google user data except where you give explicit consent, such as a support request you start, where it is necessary for security or to investigate abuse, or where required to comply with applicable law.

Retention And Deletion

We retain account, preference, booking, billing, and audit data for as long as needed to provide Mia and meet legal or operational obligations. Stored scheduling-message text is deleted after the booked meeting ends, immediately when a thread is canceled, or after 30 days without activity when no meeting is booked. You may request deletion of your account data by contacting hey@loopmia.com.

Contact

For privacy questions or deletion requests, contact Orichalque SAS at hey@loopmia.com.