Privacy Policy
Last updated August 26, 2026
MiBA helps a group pick a restaurant by asking each person privately, then converging on an option that works for everyone. This policy explains what we collect, how we use it, and the controls and rights you have. We collect the minimum we need to run the service, and this page describes only things the product actually does.
Who we are
MiBA is run by two individuals, acting as joint controllers of your data under EU law (GDPR Article 26): Doron Zavelevsky, based in Portugal, and Asaf Shachaf, based in Israel. There is no company behind MiBA yet; if one is formed, this section will name it. For anything in this policy, write to privacy@miba.my, which both of us read.
Who is responsible for what
Because we are joint controllers, the law asks us to agree between ourselves who does what and to tell you the essence of it (GDPR Article 26(2)). Here it is:
- Both of us. We decide together what MiBA asks people, what it keeps, and which providers it uses. Neither of us instructs the other; that is what makes us joint controllers rather than a controller and a processor.
- Doron Zavelevsky. Runs the service and its sub-processors, keeps the record of what is collected and for how long, answers what arrives at the contact address within one month, carries out deletions and exports, and is the point of contact for the Portuguese supervisory authority (CNPD) and for notifying a personal-data breach.
- Asaf Shachaf. Decides jointly what the product asks and shows, and reads answers through the operations dashboard only to run and debug the service. Any request that reaches them personally is passed to the contact address the same day, so that every request is answered from one place.
- Both of us. Whatever the split above says, you may exercise all of your rights against either one of us. That is your right under Article 26(3) and no arrangement between us can narrow it.
What we collect
- Your answers.The choices you make in a gathering’s questionnaire: availability, preferences, and hard requirements like dietary needs. Every question is a closed choice from options MiBA offers. The questionnaire has no free-text box, so there are no typed notes to collect.
- Account data (you need an account to create a gathering or vote): your email address, the display name you choose, and the dietary needs you enter. The last two are the things you tell us once so no gathering has to ask again.
- Feedback you give us afterwards. MiBA may write to ask how a gathering went: once after the table is booked, about the decision, and once a day after the meal, about the restaurant. That is the whole of it: two emails per gathering, and never again. Every question is a closed choice and answering is entirely optional; what you pick is stored against your participation in that gathering and is treated exactly like your other answers.
- Operational records: the gatherings you create or join, an event log of what happened in each one (needed to run and debug it), a log of the emails MiBA sent so it never sends the same one twice, and metering of our own AI spend (token counts and cost, never the content).
- Anonymous usage counters.To see where people give up, MiBA counts steps: “a sign-in screen was shown”, “a questionnaire screen was answered”. A counter row stores the step name, a role (host or voter), and a timestamp. No user id, no cookie, no IP address; it can say how many, and it can never say who.
MiBA does not profile you and does not infer preferences by watching you: it keeps only what you enter yourself, and there are no advertising or analytics trackers anywhere in the product.
Who can see your answers
Your individual answers are private by default. Other participants never see them; only the outcome, plus the brief explanation of why it fits the group, is shared with the group.
To be complete: the two of us who run MiBA can read answers through an operations dashboard, and we do so only to run and debug the service (for example, to understand why a gathering produced a bad suggestion). That access is limited to the two named controllers above by a deliberate, fail-closed allowlist. Nobody else has it.
Why we may process your data (legal bases)
- Running your gathering (contract).Collecting answers, computing the group’s best option, and sending the messages that are part of a gathering: the outcome, and whether the table is booked.
- Our legitimate interests. The day-of reminder and the two feedback emails (each gathering has a switch that stops them), keeping the service secure and debugging it, and measuring the funnel with the anonymous counters described above.
- Consent: not relied on. MiBA infers nothing and tracks nothing, so there is nothing here that needs a consent banner. If that ever changes, we will ask first.
AI processing
MiBA uses an AI model (Anthropic’s Claude) for exactly one thing in a live gathering: when deterministic scoring finds no restaurant that works well enough for everyone, the model is asked to pick a strategy, such as which soft preferences to ask a few participants to reconsider. It receives a compact, structured summary: feasible times, the near-miss venues, and which preference types are blocking. Participants appear in it only as internal ids, never as names or email addresses, and since the questionnaire has no free text, no typed text of yours exists to send. We never use your data to train models, and per our agreement with Anthropic, they do not train on it either. No AI call ever runs while you are answering screens.
Emails, and how to stop them
MiBA emails you the sign-in link you asked for, the outcome of a gathering you are part of, a reminder on the day, and the two feedback questions afterwards. The “don’t send me reminders or follow-ups” switch on a gathering’s page stops the reminder and the feedback emails for that gathering. You will still be told the outcome and whether the table is booked, because that is the gathering itself rather than a message about it. There is no marketing list.
Cookies and storage on your device
MiBA sets four cookies, all first-party. None of them tracks you, and no third party reads them:
- miba_session keeps you signed in (30 days). Strictly necessary.
- miba_pt_<gathering> remembers that you are you within one gathering, so you can return to it (30 days). Strictly necessary.
- miba_next remembers, while you sign in, which page to return you to (30 minutes). Strictly necessary.
- miba_locale remembers the language you explicitly chose (1 year).
Beyond cookies, MiBA keeps one flag in your browser’s session storage (that a gathering’s opening animation was already shown to you; it is gone when the tab closes). MiBA runs no analytics script, no session recording, and no third-party JavaScript at all, which is why there is no cookie banner: everything above is either strictly necessary or a choice you made.
Service providers (sub-processors)
MiBA runs on a small set of providers, each receiving only what its job needs:
- Supabase (EU, Ireland): the database, and proving you own your email address at sign-in.
- Resend(sending from the EU): delivers MiBA’s emails.
- Vercel (US provider): hosts and serves the application.
- Anthropic (US): the AI model call described above; sees internal ids, never names or emails.
- Google Maps Platform (US): restaurant search and geocoding; receives search areas and venue queries, never your name or email.
- Overpass API (a community OpenStreetMap service): map data; receives a bounding box and no personal data at all.
- Inngest (US): schedules background jobs; receives internal ids only.
- Sentry (US provider, EU data region): server-side error monitoring; there is no Sentry script in your browser.
We don’t sell your data, to these providers or to anyone.
Where your data lives (international transfers)
Your data is stored in the European Union: the database in Ireland, and error monitoring in Sentry’s EU region. The US providers above process what reaches them under their own EU transfer safeguards (the EU-US Data Privacy Framework or standard contractual clauses). One of the two controllers works from Israel, which the European Commission recognises as providing adequate data protection, so that access needs no extra safeguards.
How long we keep things (retention)
- Your account (email, display name, dietary needs): until you delete it.
- Gatherings and answers:kept while the service runs, so a group’s page and its outcome keep working for everyone in it. When you delete your account, your answers are detached from your identity and your name is removed from them (see below).
- Anonymous counters and operational logs: kept for debugging and service history; they identify nobody, or in the case of the email log, stop identifying you when your account is deleted.
Your rights and controls
- See and change what MiBA knows. Your name and dietary needs are editable any time on your account page.
- Export your data as a JSON file from your account: your account fields, your stored preferences, and every gathering with your answers and feedback in it.
- Delete your account.Deletion is immediate: your email address, display name, dietary needs and stored preferences are erased, your sign-in record at our authentication provider is deleted, your answers are detached from your identity, and your name on past gatherings is replaced with “Former participant”.
- Everything else the GDPR gives you (access, rectification, erasure, restriction, objection, portability): write to privacy@miba.my and we will answer within a month.
- Complain. If you think we have handled your data badly, you can complain to the Portuguese supervisory authority, the CNPD (cnpd.pt). If you are in Israel, you can also turn to the Privacy Protection Authority there. We would appreciate the chance to fix it first.
Children
MiBA is not directed at children and is not meant to be used by anyone under 16. We do not knowingly collect data from children; if you believe a child has an account, write to us and we will delete it.
Changes to this policy
When this policy changes, we update the date at the top. If a change is material (new data collected, a new use, a new provider that sees personal data), we will tell you in the product before it applies to you.
See also our Terms of Service.