Privacy Policy
Effective 17 August 2026 · Last updated 17 August 2026
What Mixr collects, how it’s used, and who it’s shared with.
This Privacy Policy explains what personal information Mixr collects, how it's used, and who it's shared with. It's issued by Angana Buddika Galboda Liyanage, trading as ARCNOVA (ABN 12517518318) ("Mixr," "we," "us"). It should be read alongside our Terms of Service.
A scope note, not a loophole: Australia's Privacy Act 1988 exempts most small businesses (annual turnover under AUD $3 million) from the Australian Privacy Principles, unless an exception applies (e.g. trading in personal information, providing a health service, or opting in voluntarily). ARCNOVA likely starts out exempt. We're publishing this policy anyway because Google Play's Developer Program Policy requires one regardless of whether the Privacy Act itself applies to you, and because it's the right thing to do for users.
1. What we collect
Account data — email and password (Firebase Auth stores the password; we never see it in plain text), or, if you use "Continue with Google," the name and email Google shares with us.
Profile data — name, headline, and bio, as you enter them. Mixr is text-only by design (no photo uploads), so we don't collect profile photos.
Content you create — posts, comments, reactions, connection requests, direct messages, and group chats (including group names and membership).
Job board data — if you post a job: title, company, location, description, and a contact email for applications. If you apply to a job: your name, email, phone, suburb, availability, a resume/portfolio link, and a cover letter/message — see Section 3 for how this reaches the job poster.
Technical & usage data — a device push-notification token (to deliver notifications), best-effort online/last-seen presence, typing indicators in active conversations, and crash diagnostics (Firebase Crashlytics: stack traces, app version, device model, and a resettable Firebase installation identifier — no message or profile content).
Subscription data — your tier (Free/Pro/Max) and purchase/entitlement status, handled by RevenueCat and Google Play Billing. We don't receive or store your payment card details — Google Play processes those directly.
Local, on-device data — a cache of your recent direct and group messages, your hidden-posts list, and read-state markers, stored in a local database on your device (Room) so the app works offline. This isn't additional data collection — it mirrors what's already stored server-side.
We don't use any third-party analytics or advertising SDK. Nothing here is sold or used for ad targeting.
2. How we use it
- To operate the feed, connections, messaging, job board, and subscriptions.
- To send push notifications (e.g., a new direct message, a connection request, a new job application) — the notification body includes a short preview (direct messages are truncated to ~100 characters) delivered via Firebase Cloud Messaging.
- To route job applications to the job poster's listed contact email.
- To enforce tier limits, investigate abuse reports, and keep the Service secure.
- To comply with legal obligations.
We don't use your data to train AI/ML models, and we don't build advertising profiles.
3. Who we share it with
- Google / Firebase (Authentication, Firestore, Cloud Functions, Cloud
Messaging, Crashlytics) — our infrastructure provider. Firebase stores and
processes
data on Google Cloud infrastructure; Cloud Functions that route
notifications and job-application emails currently run in Google's
us-central1region (United States) regardless of where you're using the app from — see the international transfers note below. - RevenueCat and Google Play Billing — to manage and verify subscriptions.
- The job poster, if you submit a job application — your name, email, phone, suburb, availability, resume link, and cover letter are emailed directly to the contact address the poster listed. Once they receive it, the poster controls that data independently of Mixr — we don't vet posters or govern what they do with applications they receive (see the Terms of Service, Section 6).
- Our email provider, to send job-application emails — whoever sends that mail on our behalf also processes applicant data in transit.
- Other Mixr users, inherently — your posts are visible per the feed's design, your profile is visible to other signed-in users, and anyone you message or group-chat with receives what you send them.
- Law enforcement or regulators, where we're legally required to.
We don't sell personal information, and we don't share it with data brokers or advertisers.
4. Data retention
- Content (posts, comments, messages, group chats) is retained while your account is active.
- Job applications are retained on the job posting until you delete your account or, separately, until the job poster's own copy (the email we sent them) is deleted by them — outside our control.
- When you delete your account, we remove your profile and stop delivering new content to you. Messages you've already sent to other users may persist in their view, the same way a text message persists on the recipient's phone after you delete the conversation on yours.
5. Your rights
You can review and edit your profile information directly in the app, and delete your account at any time. Depending on where you're located, you may have additional rights (access, correction, erasure, portability) under applicable law — contact us at buddika@arc-nova.net to exercise them.
6. Children's privacy
Mixr's minimum age is 16 (see the Terms of Service, Section 1). We don't knowingly collect personal information from anyone younger. The minimum age is enforced at sign-up: email sign-up requires a date of birth (validated against the 16+ minimum and never stored — the account carries no birth date), and Google sign-in requires a one-time 16+ confirmation.
7. Security
Data in transit uses Firebase's default TLS encryption. Access to Firestore data is enforced through security rules scoped to what each signed-in user is actually allowed to read or write (e.g., only a group's members can read its messages) — not just hidden in the UI. No system is perfectly secure, and we can't guarantee absolute security.
8. International data transfers
Mixr's backend (Firebase/Google Cloud, including the Cloud Functions that
send notifications and job-application emails) currently runs in the
United States (us-central1), regardless of where you're located when
using the app. If you're outside the US, your information is transferred
to and processed there.
9. Changes to this policy
We may update this Privacy Policy from time to time. We'll post the updated version at /privacy and update the "Last updated" date above.
10. Contact
Questions about this policy, or requests about your data: buddika@arc-nova.net.
See also Terms of Service · Back to Mixr