Privacy Policy
Last updated: August 31, 2026
Last updated: 31 August 2026
Marianito is a small, private app for capturing shared aperitif moments with the people you're actually with. This policy explains exactly what we collect, why, and what control you have. It is written to be read, not to be survived.
The short version: we collect the minimum needed to run the app. We do not sell your data, we do not advertise, we do not track you across other apps or websites, and we never reveal your location to other users — the app tells them "nearby" and nothing more. Some features do send your position to mapping providers to work at all, and the section on location says exactly which and when.
Marianito is operated by Niche Studio LLC, a Wyoming limited liability company doing business as Megamind Labs ("we", "us", "our"), of 30 N Gould St, Ste R, Sheridan, WY 82801, USA. We are the data controller for the information described here. On the App Store the app is distributed through the individual Apple Developer account of Cameron Gordon, which is why that is the seller name Apple shows.
Contact: hello@megamindlabs.ai.
What we collect
Your account
Email address — used only to sign you in. Marianito has no passwords; we email you a one-time code instead.
Display name, username, and profile photo — the things you enter so friends recognise you. Optional beyond a name and username.
Your email address is deliberately unreadable by the app: the database grants exclude that column, so no other user can retrieve it, and your own address comes from your sign-in session rather than from your profile.
What you create
Photos and captions you post to a moment.
Comments and photos you add to someone else's moment.
A place on a moment — a name you type (e.g. "Plaza Nueva"), and, if you choose to pin it, its coordinates. Both are things you choose to add; neither is read from your device unless you tap "Use current location".
Who was at the table — the people you tag, including "guests" (names you add manually for people without the app).
Your connections
Who your friends are, which moments you shared, and anyone you have blocked.
Reports you submit about a problem or a person, including who filed them.
Your location — only if you turn it on See the dedicated section below. It is off until you switch it on.
Crash reports — only in some builds If the build you are running was compiled with crash reporting enabled, a crash sends Sentry a technical report: the error, the device model, and the OS version. It carries no account identifier, no screenshots, no session recording, and no record of the requests the app made. If the build has crash reporting switched off, nothing is sent and errors stay on your device.
What we do not collect
No contacts or address book.
No advertising identifiers, no cross-app or cross-site tracking.
No analytics, and no profiling of your behaviour. There is no analytics library in the app at all.
No payment information. Marianito is free.
How we use it
Only to make the app work: to sign you in, to show your journal, to let the people at a table co-author a moment, to show who is nearby, to honour your privacy settings, to keep the app safe (below), and to act on reports. That's the whole list.
We do not use your content to train machine-learning models, and we do not sell or rent data to anyone.
Keeping the app safe
Text you post — captions, place names, comments, display names, and the names you give guests — is automatically checked against a list of prohibited terms before it is saved. Content that matches is refused: it is not posted and it is not stored. Nothing about that check is kept, and no human sees the text because of it.
Photographs are not automatically screened. If you see something that shouldn't be there, report it from the moment or comment itself. We review reports and act within 72 hours. What you write in a report is sent to us straight away through the alerting services listed under "Who else touches your data", so that a person sees it quickly. It is never shown to the person you reported, and reporting someone in good faith never counts against you.
You can block any user at any time; they disappear from your lists and searches.
Your location
Location is off until you turn it on, in Settings → Location consent, and the app is fully usable with it off.
What happens with it on
The app reads your position only while it is open on screen. There is no background tracking, and it does not read your position more than once every couple of minutes.
Your last position is stored so we can work out which friends are near you. It is replaced each time it updates, not accumulated into a history, and it is ignored after 45 minutes.
Your coordinates are never shown or sent to other users. The comparison happens on our server, and other people only ever learn "this person is nearby" — never where you are, never how far away, never in which direction. This is enforced in the database: the query that answers "who is nearby" returns a list of user identifiers and is structurally incapable of returning a coordinate. The search radius is fixed by us and cannot be widened by anyone's app.
Turning Location consent off deletes your stored position immediately, in the database itself rather than as something the app remembers to do.
Who can see you're nearby is your choice — everyone near you, or friends only. It changes only what other people can discover; your own "Nearby" view works the same either way. The choice is enforced on our server, not in the app, so it holds even for a modified client.
Where your location does leave us
Two features can't work without asking someone else, and both send data to companies we do not control. This is the one place your position goes beyond us, and it happens only in these situations:
Searching for a place. When you type a place name on a moment or on the map, the text you type is sent to a mapping provider — Google Places, Komoot's Photon, or OpenStreetMap's Nominatim, depending on what is available. If you have Location consent on, your approximate position is sent with it, so that searching "café" finds cafés near you instead of famous ones. With consent off, the search text is still sent, but no position goes with it.
"Use current location". Tapping that turns your coordinates into a place name. On a phone this is usually done by the device itself, with nothing leaving it. When it can't be — on the web, or if the device can't answer — your exact coordinates are sent to OpenStreetMap's Nominatim to be named.
The map screen. Map imagery is served by CARTO. Loading the map tells CARTO your IP address and which part of the world you are looking at, the same as any online map.
These providers receive that data as independent companies under their own privacy policies, not as processors working to our instructions. We send them the minimum the feature needs, we do not send them your name, your email, your account identifier, or anything you have posted, and none of it is linked to your account on their side.
If you would rather none of this happened: leave Location consent off, type place names rather than searching for them (a typed name is stored as text, with no lookup), and don't open the map.
Your privacy controls
Inside the app under Settings you can:
Blocking, for being found at all. Your profile — your name, your username and your photo — can be found in search by anyone else using Marianito, the way it works on most social apps. There is no switch for this. If you don't want a particular person to find you, block them: blocking hides you from them and them from you, and it is enforced in the database rather than by the app.
Use my location — the one location switch. Off means we don't read your position at all, nobody sees you as nearby, and the position we had stored is deleted.
Share my location with — while location is on, choose whether it is everyone near you or friends only who can see that you're nearby. Neither option shows anyone where you are.
Blocked accounts — block someone and they vanish from your lists and searches.
Report a problem — flag a person or content to us.
Location is off by default, and onboarding asks for it with the switch starting off. We don't pre-tick consent. Saying yes to it does two things at once — we read your position, and people can see you're nearby — and the screen that asks says so in those words rather than burying the second half. Who "people" means is the next question, and it arrives with neither answer selected.
Deleting your account
You can delete your account at any time from Settings → Delete my account. This is immediate and permanent. It removes your profile, photos, journal, stored location, friendships, settings, and any guests you created. Moments you started are removed for everyone who was at those tables; moments where you were only tagged remain for the others, without you.
If you'd rather we did it for you, email hello@megamindlabs.ai.
Who else touches your data
We use a small number of outside services. The first group process data on our behalf, under their own security obligations:
Supabase — hosts our database, file storage, and sign-in system. Data is held in their EU region.
Brevo — sends the sign-in code emails, and therefore handles your email address. It also delivers our safety-report alerts, which contain the text of the report.
Slack — receives those same safety-report alerts, so that a person sees them quickly. The alert contains the text of the report. It does not contain your email address, your username, or the username of anyone reported.
Sentry — receives crash reports, in builds that have crash reporting switched on. No account identifier is attached.
Apple — distributes the app, and during the beta runs TestFlight.
The second group are independent companies that receive data when you use a particular feature, as described under "Your location":
Google (Places), Komoot (Photon), or OpenStreetMap (Nominatim) — place searches, and reverse geocoding for "Use current location".
CARTO — map imagery.
We do not share your personal data with anyone else, except where we are legally required to, or where it's needed to investigate a safety report.
Some of these providers are outside the UK/EU, including in the United States. Where that applies we rely on the transfer mechanisms in their own terms, typically the EU Standard Contractual Clauses.
How long we keep it
Your content is kept until you delete it or delete your account. Your stored location is only ever your latest position, is unused after 45 minutes, and is deleted the moment you withdraw consent. Reports are kept while a safety issue is open and for a reasonable period afterwards, because a report has to outlive the content it is about. Backups may persist for a short period after deletion before being overwritten.
Your rights
Depending on where you live (including under UK/EU GDPR, and under US state privacy laws such as California's), you may have the right to access, correct, export, or delete your personal data, to object to processing, and not to be discriminated against for exercising those rights. You can do most of this yourself in the app — edit your profile in Settings, and delete everything with Delete my account.
For anything else, email hello@megamindlabs.ai and we'll respond within 30 days.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.
Our lawful basis for processing is performance of a contract (running the account you asked for) and, for location, your explicit consent — which you can withdraw at any time in Settings. If you are in the UK or EU you may also complain to your local data protection authority.
Age
You must be 18 or older to use Marianito — or the legal drinking age where you live, if that is higher. This is the same cutoff as our Terms of Use; the two documents are meant to agree, so if one changes, change the other.
Marianito is built around aperitif culture and is intended for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe someone under 18 has created an account, email hello@megamindlabs.ai and we'll remove it.
Security
Data is encrypted in transit. Access to your data is enforced at the database level, per user — the rules are written so one account cannot read another's private data, including location. Photos are stored privately and served through short-lived links, so a photo cannot be read by anyone who wasn't at that table, and cannot be reached at all without an account. No system is perfectly secure, but we keep the amount of data we hold deliberately small.
Beta software
Marianito is currently in beta. Things may break, and data may occasionally be reset while we're building. Please don't treat it as your only copy of a photo you care about.
Changes
If we change this policy we'll update the date at the top, and tell you in the app if the change is significant.
Niche Studio LLC (dba Megamind Labs) 30 N Gould St, Ste R Sheridan, WY 82801, USA
Questions? hello@megamindlabs.ai
