Privacy Policy
This Privacy Policy explains how the company that operates Midium (the "Operator", "we", "us", "our") collects, uses, and protects information about you when you use the Midium website at midium.live, the Midium mobile application, and any related services (together, the "Service"). We are the data controller for the personal data described in this policy. You can contact us at privacy@midium.live.
1. The information we collect
a. On the website (midium.live)
The website itself is intentionally low-data. When you visit, we collect:
- A salted SHA-256 hash of your IP address, used solely to evidence your consent to legal documents and to defend against fraud. We do not store raw IP addresses on the website.
- A SHA-256 hash of your User-Agent string, used for the same purposes.
- A two-letter country code derived at the network edge from your IP, used for geographic compliance and to determine whether the Service is available in your country. The country code is never linked back to your identity.
- Your cookie and consent choices, stored in browser cookies on your own device.
- Aggregate analytics events through Plausible Analytics, which is cookie-less and does not collect personal identifiers, fingerprints, or cross-site tracking data.
We do not collect names, email addresses, telephone numbers, or account information through the website.
b. In the mobile application
Through the application we collect: account data that you provide (display name, email when you sign in by email magic link or via OAuth, authentication tokens issued by Apple, Google, or Midas Exchange); profile data that you choose to provide (avatar, country, preferred language, notification preferences); game data generated as you play (predictions made, cards seen, sessions played, XP earned, streaks, achievements, mini-league memberships, leaderboard positions); subscription and purchase data received from the Apple App Store and Google Play Store, sufficient to verify and grant access to the room you have subscribed to (card numbers and other payment instrument details are processed by the relevant app store, not by us); device data such as device model, operating system version, application version, language, time zone, advertising identifier where you have not opted out at OS level, and a push-notification token where you have granted notification permission; diagnostic data including crash reports, performance metrics, and error logs; and any communications that you exchange with our support, abuse, privacy, or legal teams.
c. From Midas Exchange
Where you link your Midium account to Midas Exchange, we receive a stable user identifier and limited account-status data (for example, whether KYC is complete and what trading tier you are in) from Midas Exchange. We do not receive your trading positions, order book activity, balances, or banking information.
2. How we use your information
We use the information we collect to: operate the Service, including matching cards, scoring predictions, ranking leaderboards, running campaigns, and crediting promotional benefits; create and maintain your account and authenticate you across sessions; provide customer support and respond to your enquiries; prevent and detect fraud, abuse, multi-accounting, automation, money-laundering, sanctions evasion, and security incidents; comply with legal and regulatory obligations, including tax, anti-money-laundering, and lawful disclosure requests; protect, exercise, or defend legal claims; understand how the Service is used and improve it; and communicate operationally with you about the Service.
3. Legal bases (where required)
Where applicable law (including the EU and UK GDPR, the UAE PDPL, the Saudi Arabia PDPL, and the Turkish KVKK) requires us to identify a legal basis for processing, we rely on: performance of a contract for processing necessary to deliver the Service to you (your account, your gameplay, your subscriptions); legitimate interests for fraud prevention, network and information security, abuse detection, service analytics, and product improvement, balanced against your rights and freedoms; consent, freely given, for non-essential analytics, optional marketing communications, and the placement of non-essential cookies, which you may withdraw at any time; legal obligation for record-keeping, tax, sanctions compliance, anti-money-laundering, and responses to lawful requests; and vital interests in rare circumstances where we must protect the life or physical safety of a person.
4. How we share your information
We do not sell your personal data and we do not share your personal data for cross-context behavioural advertising. We share information only as follows:
- With service providers that process information on our behalf, including cloud hosting (Microsoft Azure), email delivery, customer support tooling, push-notification delivery, analytics, and crash reporting. Each is bound by contractual confidentiality and data-protection obligations and may use your data only on our instructions.
- With Midas Exchange for the purpose of crediting promotional benefits, verifying identity, and reconciling rewards. Midas Exchange is a separate controller for the personal data it processes.
- With Apple and Google in the limited scope necessary to deliver and verify in-app subscriptions and to send push notifications.
- With law-enforcement, courts, regulators, or other competent authorities where we are required to do so by valid legal process or where disclosure is necessary to protect the Service, our rights, or the rights and safety of users or the public.
- In connection with a corporate transaction such as a merger, acquisition, restructuring, or sale of assets, in which case we will require any successor to honour this Privacy Policy or notify you and offer a meaningful choice.
5. International transfers
Your data may be transferred to, stored in, or processed in countries other than your country of residence, including the European Union, the United Kingdom, and the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or another jurisdiction whose law restricts transfers, we use European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may request a copy of the relevant safeguards at privacy@midium.live.
6. Retention
We retain personal data only for as long as is necessary for the purposes for which we collected it: legal-consent records (age confirmation, cookie consent, terms acceptance) for seven years; account data for the life of your account and for up to 24 months after closure for legal-claim defence and fraud prevention, except where a longer period is required by law (tax records: 10 years); game data linked to your account for the life of your account, with aggregated and anonymised game data retained indefinitely; analytics events in aggregated form indefinitely with raw events deleted after 12 months; crash and diagnostic logs for 12 months; and support correspondence for 24 months from last contact. After the applicable retention period we delete the data or irreversibly anonymise it.
7. Your rights
Subject to applicable law, you have the right to: request access to the personal data we hold about you and a copy of it; request correction of inaccurate or incomplete data; request erasure of your personal data; request restriction of, or object to, certain processing; request portability of personal data you provided to us; withdraw any consent you have given (without affecting prior lawful processing); and lodge a complaint with the data-protection authority of your country of residence or place of work.
You can exercise these rights through the form at /legal/privacy/request or by writing to privacy@midium.live. We will respond within 30 days. We may need to verify your identity before acting on a request. There is no charge for a request unless it is manifestly unfounded or excessive.
8. Cookies and similar technologies
We use a small number of strictly necessary cookies on the website to remember your age confirmation, language, theme, and consent choices. Analytics is provided by Plausible, which is cookie-less. We do not use advertising cookies and we do not place third-party trackers. Full details are in our Cookie Policy at /legal/cookies.
9. Security
We protect personal data using administrative, technical, and physical safeguards designed to be appropriate to the risk, including encryption in transit and at rest, network segmentation, access controls, multi-factor authentication for staff with access to production data, code review, vulnerability scanning, and incident-response procedures. No system is impervious. If we become aware of a personal-data breach that is likely to result in a high risk to your rights and freedoms we will notify you and the relevant supervisory authority without undue delay and as required by law.
10. Children
The Service is not directed to children under 18 (or 21 where a higher local minimum applies). We do not knowingly collect personal data from a child. If you believe we hold personal data of a person under the applicable minimum age, please contact privacy@midium.live and we will delete the data and close any associated account. We do not target advertising to children and we never knowingly process the personal data of a child for advertising purposes.
11. Automated decisions
We use automated systems to detect fraud, abuse, multi-accounting, and security incidents, and to score the integrity of leaderboard activity. These systems may result in restrictions on your account. You have the right to obtain human review of any decision that significantly affects you, to express your point of view, and to contest the decision, by writing to privacy@midium.live.
12. Changes
We may update this policy from time to time. Material changes will be notified through the Service at least 30 days in advance. The current version is always available at /legal/privacy. Each prior version is preserved at /legal/privacy/v[version].
13. How to contact us
Email: privacy@midium.live. Postal address: the registered office of the Operator, available on request. If you reside in the European Economic Area, the United Kingdom, or another jurisdiction with a designated data-protection authority, you may also lodge a complaint with that authority. We would, however, appreciate the chance to address your concern first.