← Back to Milvia

Privacy

Reviewed at beta launch

What Milvia stores, what it deliberately does not store, and how your information is shared during the beta.

What we store

Your email address and password (handled by our authentication provider — we never see your password), your profile, the posts, comments, messages and reactions you create, the communities you join, your reports and blocks, and the feedback you send.

We store the outcome of each OPSEC review — the risk level, a numeric score, the pattern categories that matched, the version of the screening used and a one-way fingerprint (a SHA-256 hash) of the text — so we can improve the screening. We never store the text itself, the phrases that matched, or the text of anything that was refused.

What we deliberately do not collect

Unit, command, duty station, assignment, clearance level, deployment or travel dates, precise location, or rank and paygrade. These fields do not exist in Milvia, so they cannot leak.

We do not build maps of where members are. Areas are broad and self-declared.

Who can see what

Your profile is visible to signed-in members only, and only while you have discoverability turned on. You can turn it off in your profile privacy settings.

Private messages are visible only to the people in that conversation. Blocked members cannot see or interact with you.

Your Footprint Check analyses only your own content. It is never runnable against another member, and the result is private to you.

Getting a copy of your data

Account settings has a Download my data button. The file is built in your browser the moment you tap it — nothing is stored on our side and nothing is emailed. It contains your profile and settings, your communities, your posts, comments and the messages you sent, your connections and the blocks you made, reports and review requests you filed, your moving, journey, screening and notification records, your plan, and the status history of any deletion request.

It deliberately leaves out other members' messages and profiles, internal moderation notes, who reviewed a verification, and anything we do not actually collect.

Deleting your account

Requesting deletion from Account settings logs the request with a target date 30 days out. That date is an operational target we work towards — it is not a guaranteed grace period and nothing is removed automatically when it passes. You keep access until the team starts work, so you can download your data or change your mind up to that point.

When the team carries it out, your profile, settings, communities, saves, reactions, connections, notifications, moving and journey records, feedback, plan and review requests are removed. Your posts remain as empty placeholders with your name removed, so replies other members wrote under them are not destroyed. Your comments and the messages you sent are emptied and detached from you, so conversations other people took part in still make sense to them. Reports you filed stay as moderation history with your name and free text removed.

Your sign-in account is removed separately by a person. The request is only marked complete once our database has itself checked that the sign-in account no longer exists — it cannot be marked complete by anyone simply saying so.

This describes how Milvia behaves. It is not a legal compliance statement.

Your choices

You can edit or delete your posts and comments, block members, download your data, and request account deletion from Account settings.