Milila — Privacy Policy

Last updated: 27 July 2026

Milila is a place where people make something for someone they love. That means we hold things that matter — photographs, letters, the name of a person and the reason they are important to you. This page explains exactly what we hold, why, for how long, and what you can make us do about it.

Milila includes Gifts, Events and MEIE. Gifts let people make meaningful things for other people. Events help people preserve and revisit meaningful shared experiences. MEIE is Milila's emotional AI companion: a space for reflection, encouragement and the everyday human experiences that matter.

It is written to be read. Where a law requires a particular phrase, we use it and then say what it means.


1. Who we are

Milila is operated by Bonaventure Oke in Nigeria. In data protection law we are the data controller for the information described here.

You can reach us about anything on this page at privacy@milila.app. We answer privacy requests within 30 days, and usually much sooner.


2. The two kinds of people on Milila

This matters, because most services only have one.

A creator signs up, makes a gift and sends it. They have an account with us.

A recipient receives a link. They never sign up, never give us their email, and often do not know Milila exists until a gift arrives. We hold information about them — their first name, perhaps a photograph of them, certainly something written about them — that a creator gave us.

If you are a recipient and you want to know what we hold about you, or want it removed, write to privacy@milila.app. You do not need an account and you do not need the creator's permission. We will find the gift and act on it.


3. What we collect

When you create an account. Your email address, and a password we never see in readable form. If you sign in with Google, we receive your email address, name and profile picture from Google, and nothing else — we never see your Google password.

When you build a gift. Everything you put into it. That includes the letter you write, captions, the reasons you list, the recipient's first name, the occasion, the relationship, any theme choices, and any photographs, images or audio you upload. If you set a code on a gift, we store a one-way cryptographic hash of it and never the code itself — which is why nobody, including us, can tell you what it was.

When you use the site. Basic technical information that any website receives: IP address, browser and device type, and timestamps. We also record a small number of product events — that a builder was opened, that a step was completed, that a gift was published — so we can tell whether the product works. These events are counts and timings. They do not contain the contents of your gift.

When you use MEIE. MEIE is Milila's emotional AI companion. It uses the words and other information you choose to share in a conversation to respond to you. It is designed for emotional connection, life, relationships, meaningful moments, memories, reflection, encouragement and helping people stay grounded. It is not a generic AI assistant, maths solver, productivity assistant or "ask anything" chatbot.

When you pay. Payment is handled by a third-party payment provider. Card details are entered on their systems and never reach ours. We receive a record that a payment succeeded and what it was for.

What we do not collect. We do not buy data about you from anyone. We do not run advertising, we do not host advertising trackers, and we do not sell, rent or share your information with anyone for marketing. There is no version of Milila where your letter becomes an advertising signal.


4. Why we hold it, and on what legal basis

We hold your account details to give you an account — that is the contract between us.

We hold your gift content because storing and displaying it is the product. Without it there is nothing to send.

We hold basic technical logs and product events because we have a legitimate interest in the service working, in it not being abused, and in knowing where people get stuck. We keep this to the minimum that answers those questions.

We use information you choose to share with MEIE to provide its responses as part of the service.

We hold payment records because tax and accounting law requires us to.

Where a gift contains information about a recipient, the legal basis is our legitimate interest in operating a personal gifting service — balanced against that person's rights, which is why section 2 gives any recipient a direct route to us that does not go through the creator.

Sensitive information. Photographs and letters can reveal things the law treats as special — health, beliefs, relationships, who someone loves. We do not ask for any of it and we do not analyse it. If you choose to put it in a gift, you are doing so knowingly, and we hold it only to show it to the person you sent it to.


5. Your responsibility when the content is about someone else

When you upload a photograph of another person, or write about them, you are handing us information about someone who has not spoken to us.

By publishing a gift you confirm that you have that person's permission, or that you are their parent or guardian, or that the relationship makes it plainly reasonable — a photograph of your own wedding, your own child, your own friend. You also confirm that any audio you upload is yours to use.

If someone tells us that content about them was published without their agreement, we will take it down while we look into it.


6. Who else touches your information

We use a small number of well-known providers to run the service. Each one sees only what it needs to.

ProviderWhat it doesWhat it sees
SupabaseDatabase, file storage, sign-inAccount details, gift content, uploaded media
NetlifyServes the websiteTechnical request logs
CloudflareDomain and network routingTechnical request logs
BrevoSends account emailsYour email address and the message
GoogleOptional sign-inYour email, name and profile picture, if you use it
Payment providerTakes paymentYour payment details, on their systems

These providers act on our instructions and are bound by contract to protect what they hold. Some of them operate servers outside Nigeria and outside the European Economic Area. Where information moves across a border, it is protected by the standard contractual safeguards those providers maintain.

We will also disclose information where a law or a valid court order requires it. If that ever happens and we are permitted to tell you, we will.


7. How long we keep things

A published gift stays until you delete it or close your account. That is deliberate — a keepsake that disappears on a schedule is not a keepsake.

An unpublished gift's media is deleted from storage when you unpublish, not merely hidden.

A draft you never publish is kept while your account is active.

An account that is never confirmed is removed, along with its drafts, after 30 days of no activity. If that account ever published a gift, it is kept — because a published gift belongs to the person who received it as much as to the person who made it.

When you delete your account, we delete your profile, your drafts, your gifts and every file you uploaded. This is not a flag in a database; the rows and the files are removed. It cannot be undone.

Technical logs are kept for a short period for security and troubleshooting, and then discarded. Payment records are kept for as long as tax law requires.


8. Cookies and what we store on your device

We do not use advertising or tracking cookies. We store three things on your device, all of them functional:

A sign-in token, so you are not asked to log in on every visit. A local copy of your draft, so a dropped connection does not cost you your work. And, if you open a locked gift, a key for that one gift, so you are not asked for the code every time you come back to it — that key works for that gift alone and expires after a long period of the gift not being opened.

Clearing your browser storage removes all three.


9. Keeping it safe

Access to gift data is enforced at the database level, not just in the app, so a bug in the interface cannot expose someone else's gift. Codes on locked gifts are stored as one-way hashes with a per-gift salt. Everything travels over an encrypted connection. Files you upload are stored under unguessable names.

No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your information in a way that puts you at risk, we will tell you and the relevant regulator without undue delay, and we will tell you what actually happened rather than what sounds best.

Milila is in beta. Please keep your own copies of photographs that matter to you. Do not let Milila be the only place a memory exists.


10. Children

You must be 18 or older to create a Milila account.

Gifts are often about children — a birthday, a first day of school, a photograph of a family. That is expected and allowed, on the understanding that the person uploading is the child's parent or guardian, or has their permission. We do not knowingly let anyone under 18 hold an account, and if we learn that one exists we will close it and delete what it holds.


11. What you can require of us

You can ask us to show you everything we hold about you. You can ask us to correct it. You can ask us to delete it. You can ask us to give it to you in a portable form. You can object to us holding it, or ask us to restrict what we do with it. Where we rely on your consent for something, you can withdraw it at any time.

Write to privacy@milila.app. We do not charge for this and we will not make it difficult.

If you think we have handled your information badly, you can complain to us first — we would rather hear it — and you can also complain to a regulator. In Nigeria that is the Nigeria Data Protection Commission. In the EU or UK it is your national data protection authority.


12. Changes to this page

If we change how we handle your information, we will update this page and change the date at the top. If the change is significant, we will email you about it rather than hoping you notice.


Questions, requests, or something that looks wrong: privacy@milila.app