1. Overview & Principles
Mijatovic is an independent software project operated by Predrag Mijatović. Mijatovic is not a registered company or incorporated legal entity. Predrag Mijatović operates the independent Mijatovic project and is responsible for the processing described in this Privacy Policy. This Privacy Policy describes the categories of information processed when you access the marketing website, use the Adriaticum language workspace, manage your account, or interact with developer platform tools.
We collect and process only the information necessary to provide, secure, and maintain our services. Current contact: contact@mijatovic.io.
2. Account Registration Data
To register an account on the Mijatovic platform, you are required to provide:
- Email Address: Used as your primary account identifier for sign-in, password reset, account verification, and security notifications.
- Password: Passwords are processed through our authentication provider and are not stored by Mijatovic in plaintext.
- First Name and Last Name: Required on the registration form to identify your account within the account hub.
- Date of Birth: Collected at account creation to confirm that you are at least 18 years old. Date of birth is used for age eligibility. Users under 18 may not create or use an account. There is no parental-consent or minor account flow. This is private account data. It is not shown on public pages, blog author credits, conversation metadata, or API usage metadata.
- Legal Consent Acknowledgement: An explicit confirmation that you agree to the applicable Terms of Service and acknowledge this Privacy Policy.
- Model-improvement preference: A separate, optional choice about whether your conversations may later be used to improve Adriaticum. This preference is off by default and is not bundled into Terms or Privacy acceptance. You can create an account without opting in.
- Locale and interface preferences: Functional settings such as selected interface language and similar display preferences used to operate the product.
- Sign-in with Google or Apple: Google and Apple sign-in are not currently enabled. If those options are later configured and you choose them, Mijatovic would receive the identity information the provider supplies. Apple may provide a private relay email address, and a name may be unavailable after the first authorization.
3. Profile & Account Hub
Following registration, your account profile includes:
- Username: A unique handle configured during post-registration onboarding or through the account profile hub. Your username can be edited or cleared at your option.
- Editable Profile Details: You may update your first name, last name, date of birth, and model-improvement preference within the profile settings. Existing accounts that have no date of birth on file are shown as not provided.
Profile data is private to your account and is protected by database access controls. Mijatovic does not provide a public user directory or public profile pages.
4. Conversations & User Content
When you interact with the language workspace, we process:
- Prompts and Assistant Responses: The text prompts you submit and the natural language text generated in response, organized into user-owned conversation threads for signed-in accounts. Signed-in conversations persist in the database, including messages, titles, pin state, and attachments where those features are supported. Guest chat is ephemeral: it is available during the active session or page lifecycle only, is not stored in localStorage as history, and is not persistently saved as conversation history.
- Uploaded Attachments: Files you choose to attach to chat prompts (such as documents or images, up to 25MB). Uploaded files are stored in private storage accessible only through your authenticated account or active session.
- Search Grounding: For factual or informational requests, the product is designed to automatically use a Search grounding layer where that layer is available. There is no ordinary user Search on/off control. Search queries and retrieved context may be processed through a protected Search service and upstream search sources as necessary to provide the feature. Retrieved search material is external, untrusted information. Search can improve grounding; it does not guarantee correctness. This draft describes the intended service and does not claim that production Search is currently publicly deployed.
5. Developer Credentials
Platform tooling may allow you to generate developer API keys. This draft does not claim that a public production API is currently live. When you create a developer credential, we retain the information necessary to identify and manage that credential, such as its name and non-secret identifying information. The secret credential is shown when created and is not stored by Mijatovic in a form that can later be displayed to you. Requests made with those credentials may create operational usage records associated with your account.
6. Consent & Service Operation
Account registration requires you to agree to the Terms of Service and acknowledge this Privacy Policy. You must be at least 18 years old to create an account.
Whether conversations may later be used to improve Adriaticum is a separate account preference. It is optional, off by default, and is not bundled into Terms or Privacy acceptance. You can create an account without opting in.
No current training pipeline consumes production conversations based on this preference. Conversations are not currently automatically sent into training, and no production training export is currently running. Eligibility is captured at the time a turn is created. The user prompt and assistant response belonging to the same generation turn share that captured snapshot.
If the preference is on when a turn starts, that turn may be eligible for future model improvement. If the preference is off, that turn is not eligible. Turning the preference off later is not retroactive: earlier eligible turns remain eligible, and later off-period turns stay ineligible. Turning it on again does not make earlier off-period turns eligible. Eligibility means a turn may be considered for future model improvement; it does not mean every eligible turn will necessarily be used. A future exporter would still need to select, minimize, and prepare data. The stored preference and per-turn snapshots are kept for that future enforcement.
Approved legal documents may be updated over time and, where required, you may be asked to review or accept an updated version.
The current application does not use third-party advertising analytics, session-replay tools, or behavioral tracking scripts.
7. How Information Is Used
We process your information solely for the following operational purposes:
- Delivering Language Services: Processing your prompts through our inference systems to generate text completions and maintain your conversation history. Guest chats are processed for the active response only and are not stored as conversation rows.
- Authentication and Access Control: Verifying your identity, maintaining active sessions, and isolating user-owned data from unauthorized access.
- Platform Security & Integrity: Monitoring system health, preventing abuse, enforcing rate limits, and investigating security incidents.
- Search Grounding: Processing factual or informational requests through the protected Search service and upstream search sources where that layer is available.
The current service does not sell user personal data. The current service does not use user personal data for advertising or ad targeting. If this practice later changes, this Privacy Policy must be updated and versioned, and any required user notice or re-acceptance handled, before the changed practice applies.
9. Service Providers
We use third-party service and infrastructure providers to operate Mijatovic. Depending on the service and processing activity, a provider may process personal data on our behalf or under its own applicable terms. The following are factually present in the current project:
- Supabase: Managed authentication, Postgres database, and object storage used for accounts, conversation records, and file attachments with row-level security.
- Cloudflare: Network, DNS, edge/runtime services, security controls, and related platform services, including Search gateway infrastructure and email infrastructure where configured.
- Dedicated inference infrastructure: Private model serving used to generate Adriaticum completions. Prompts are sent to that inference service to provide Chat.
- Isolated Search service / SearXNG: A protected Search gateway may retrieve web results for factual or informational requests. SearXNG is an isolated service boundary and is not exposed directly to end users. This draft does not claim that production Search is currently publicly deployed.
- Authentication email: Transactional authentication email is delivered through the authentication provider's configured email delivery when that delivery is configured or enabled. This draft does not name a separate advertising-email vendor.
- Google or Apple: Not currently enabled as identity providers. If later configured, they would process sign-in as described above.
This draft does not claim analytics providers, advertising networks, or ad targeting partners.
10. Data Retention
We retain information for as long as necessary to provide the Services and fulfill operational requirements:
- Guest session cookies last for the current browser session only.
- Interface language preferences expire after 1 year.
- Registered account details, conversation records, and uploaded attachments are retained while your account remains active, and during any pending-deletion period until permanent deletion or restoration.
- Operational and security logs are not stored in a Mijatovic application database. Application process logs are ephemeral and follow the hosting environment. Infrastructure providers retain their own operational logs according to each provider's plan and configuration. Where a provider permits a retention limit, those logs are configured not to exceed 30 days. Some provider logs are retained for a shorter period. This draft does not claim that every provider can be configured to a custom 30-day maximum. A specific active security incident or investigation may require relevant records to be retained only as long as reasonably necessary for that incident.
11. Account Controls & Deletion
You can update your name, username, date of birth, and model-improvement preference within the profile settings.
You may delete your account from the profile settings after an explicit confirmation. Delete Account is not immediate. Confirmation records the request time and starts a 30-day pending-deletion period from that timestamp. Permanent deletion is scheduled for after that 30-day recovery period.
During the pending period, account data still exists so the account may be restored. Normal authenticated product access is blocked. API keys are revoked when deletion is requested. Data from a pending-deletion account is not selected into new model-improvement or training exports.
Before permanent deletion becomes due, you may Restore Account from Profile. Restore cancels scheduled deletion, restores normal account access, keeps existing account data, and preserves historical model-improvement eligibility snapshots. Restore does not reactivate previously revoked API keys.
After the 30-day recovery period, if the account is not restored, the account is scheduled for permanent deletion. Permanent deletion is performed by a trusted server-side process and may complete at the next scheduled finalizer run after the due time rather than at the exact due second. The system then permanently deletes user-linked account data, including the authentication account, profile, date of birth, model-improvement preference, conversations, messages, pins, account attachments, API keys, account usage records, legal acceptance records, any staff role, and other owner-linked account records. Published editorial articles on the public website remain as Mijatovic publications with the account detached from authorship. This draft does not describe hidden retention of deleted account data.
12. Technical Safeguards
We implement technical and organizational measures designed to protect your data against unauthorized access, loss, or alteration:
- All communication between your browser and our servers is encrypted in transit using Transport Layer Security (TLS/HTTPS).
- User data is partitioned at the database layer using strict row-level security policies, ensuring that authenticated users can access only their own records.
- Developer credentials and access secrets are protected through secure server-side controls and are not stored in recoverable plaintext.
13. Policy Updates
This Privacy Policy may be updated periodically to reflect changes in our services, technical architecture, or legal obligations. Updated versions will be published on this page with a revised status.
14. Inquiries
Questions about this Privacy Policy may be sent to contact@mijatovic.io. Predrag Mijatović operates the independent Mijatovic project and is responsible for the processing described in this Privacy Policy. Mijatovic is not a registered company or incorporated legal entity.