Last updated 6 October 2026
Privacy policy
Minarva exists to protect your account and your work. We collect only what that takes, keep it in the EU, and never sell it.
Who we are
Minarva (“we”) runs the Minarva website and app. For the personal data described here we are the data controller. Contact us at privacy@minarva.app.
What we collect, and why
Your account
Your email address, to sign you in with a one-time link (we have no passwords to lose), and the workspaces you belong to and your role in each.
Connected Instagram accounts
When you connect an account through Instagram’s own sign-in, we receive read-only access: the account’s ID, username and type, and its posts for backups. The access token is encrypted before it’s stored. We never see or store your Instagram password, and we can’t post, message or change anything.
Backups
Your posts are copied to storage you choose and own (Google Drive or Dropbox). With Drive we can only see the files we created; with Dropbox, only our app folder. We keep a list of what was saved (file names, sizes and dates) so nothing is saved twice, not the files themselves.
Monitoring and alerts
Health checks on connected accounts (every 30 minutes on Business and Agency plans, every hour otherwise) and the alerts they raise, with your answers to them. If you add a phone number for urgent texts, we keep it to send them.
Forwarded security emails
If you forward Instagram’s security emails to your Minarva address, we check each one is genuinely from Meta and keep its type, subject, sender domain and time. We never store the body of the email.
Cases and letters
What happened to an account, the dates, the steps you’re working and your notes, and the letters you prepare. You choose whether a case’s outcome counts, anonymously, in public statistics.
Lifeboat pages
If you publish a Lifeboat page, your followers can leave their email address. We confirm each address before it’s added (double opt-in), and you can export the list. We act as your processor for those contacts.
The “Is this really Meta?” checker
The text you paste is checked in memory and never stored or logged.
Payments
Paddle is the merchant of record and handles your card details; we never see them. We keep your plan, its status and renewal date.
Security records
Sign-ins and sensitive changes (who did what, when, from which IP address) go into an audit log, to keep accounts safe and investigate misuse.
Legal bases
- Contract: to provide the service you signed up for (backups, monitoring, alerts, cases, Lifeboat pages).
- Legitimate interests: to keep the service secure, prevent abuse and improve it with aggregated, non-identifying measurements.
- Consent: for optional things like text alerts and sharing a case outcome in public statistics. You can withdraw it at any time.
- Legal obligation: for tax and accounting records of payments.
Who we share it with
Only the providers that run parts of the service for us, under contracts that require them to protect it:
- Our hosting and database provider, in the EU.
- Postmark, to send emails; Twilio, to send text messages.
- Paddle, for payments.
- Meta (Instagram), Google and Dropbox, only to do what you connect them for.
We don’t sell personal data, show ads, or share it for anyone else’s marketing.
Where it’s kept
In one EU region. Where a provider processes data outside the EU, we rely on the European Commission’s standard contractual clauses or an adequacy decision.
How long we keep it
- Your account and workspaces: until you delete them. A deleted workspace disappears at once and is erased for good after 7 days.
- Forwarded security email records: 180 days. Backup run logs: 180 days. Account health checks: 90 days.
- Unconfirmed Lifeboat sign-ups: 30 days.
- Billing events: 400 days, and payment records as long as tax law requires.
- The security audit log is kept to protect accounts; it holds actions, not content.
Your rights
You can see and download everything we hold about you from Your account in the app, and delete your account there too. You also have the right to correct your data, object to or restrict how we use it, and complain to your data protection authority. To use any of these rights, or if something here is unclear, write to privacy@minarva.app. We reply within one month.
Security
Access tokens and storage credentials are encrypted at rest. Sign-in links and tokens are single-use and stored only as hashes. Every request is checked against your role in the workspace. We’ll never ask you for a password or a login code.
Children
Minarva is for people aged 16 and over.
Changes
If we change this policy in a way that matters, we’ll email account owners before it takes effect.