Misdir Privacy

Version 4 · 10 October 2026

We use your details to run your account, give you access to tutorials and help when something goes wrong. Creators see who has access to their products. They do not see who watched what, how long you spent, your reading position or your private notes.

Who is responsible

Mighty Little Steps sp. z o.o., ul. Gospodarcza 26, 20-213 Lublin, Poland, KRS 0001108348, is responsible for Misdir accounts, sign-in, security, its customer relationships and support. Contact contact@misdir.com or +48 889 006 156. Full company details are in the Terms.

The creator manages product access and their relationship with its members. Their identity, contact and any additional privacy information are linked from the product before you join. For data we host on their instructions, we are their processor under the creator section of the Terms. When Misdir's operator is also the creator, the same company fills both roles. You can contact us about either role and we will help direct your request.

What we use and why

Information Purpose and legal basis
Email, display name, account and access records Sign-in, providing the service and managing the access you request: contract, Article 6(1)(b) GDPR. Operational contact with a customer's representative: legitimate interests, Article 6(1)(f)
Your saved position and notes Resume reading or playback and keep your notes for you: contract, Article 6(1)(b). These are not individual learning reports for creators
Contributions, comments and necessary metadata Sharing at your request: contract, Article 6(1)(b). Moderation and protecting others: legitimate interests, Article 6(1)(f), or a specific legal duty, Article 6(1)(c)
Creator applications, plan and billing records Answering your application and providing your plan: contract or requested pre-contract steps, Article 6(1)(b); representative contact on Article 6(1)(f); required tax/accounting records on Article 6(1)(c)
Support, technical connection data including IP address, security logs and limited evidence Helping you: contract or legitimate interest in resolving the request. Protecting the service and defending claims: Article 6(1)(f). Handling applicable legal obligations: Article 6(1)(c)

The product's creator receives your display name, email, access status and date of joining. This lets them grant or correct access and answer your product questions. We provide that functionality as part of your requested access. A creator must have an appropriate basis for their own use; neither membership nor these Terms permits unrelated marketing.

You supply data directly; a creator may provide your email for an invitation, which identifies its source and product. We also receive reports and delivery/security information. Account data is necessary for access; contributions are optional.

We do not create named learning histories or time-spent analytics. The latest resume position is for you, not a learning timeline. Members see chosen names on shared notes and approved contributions, not emails or private notes. Technical staff may access data where necessary for security, support or legal duties.

Service providers

Cloudflare, Inc. runs our hosting, database, file/video delivery and email routing. Plus Five Five, Inc. (Resend) delivers service emails. Messages to contact@misdir.com are forwarded to our Gmail support mailbox; Google Ireland Limited supplies that service in the EEA. These providers receive the content and technical information needed for their part of the service. Necessary advisers and legally entitled authorities may also receive relevant information.

Cloudflare operates globally; Resend stores email data in the USA; Google may process mail outside the EEA. Applicable transfer safeguards include the standard contractual clauses described in the Cloudflare DPA and Resend DPA. Google's handling of support mail and its transfer mechanisms are described in its Privacy Policy and transfer information. Ask us for details or a copy of applicable safeguards. We do not promise EEA-only storage. Creator access from outside the EEA requires an applicable transfer arrangement before that access is enabled.

We do not sell lists, train AI on your materials or enrol you in newsletters. Facebook/WhatsApp links open separate services without importing conversations. Any offered payment service is identified with its privacy information before checkout; a fully discounted invitation requires no payment details.

Cookies and preferences

We use browser storage for sign-in and features you use, not advertising or audience measurement. Fonts and interface libraries are served by Misdir. Video delivery connects to Cloudflare Stream.

Item Purpose and duration
misdir_session cookie Keeps you signed in; up to 90 days, invalidated on sign-out
misdir_unlock cookie Remembers successful product-password entry while you activate access; 30 minutes
misdir.theme, misdir.coach.*, misdir.fsNotes, misdir.noteSort in local storage Remembers your theme, dismissed guidance and note-display choices; until cleared in your browser

Practice mirror. If you turn on the practice mirror, your browser shows your camera's picture next to the video on your own device. The picture is not recorded, stored or sent to Misdir or to anyone else, and the camera stops when you turn the mirror off, leave the page or hide it.

You can clear this storage in browser settings; removing sign-in cookies requires signing in again. Optional tracking will not be added without the information and choices required by law. Saving your latest position for the resume feature does not make it visible to creators.

How long we keep information

Account access, resume positions and notes last while needed for your account; operational data is removed within 30 days after closure. Creator data follows its export period. Isolated backups expire within 90 days of active deletion. Published contributions remain while shared; withdrawn copies are removed within 30 days. Inactive drafts/rejected submissions last up to 90 days after last activity, with notice before deletion.

Expired sign-in records and sessions are cleared within 24 hours; invitations within 30 days after expiry/withdrawal. Routine security logs: 30 days; failed password attempts: 24 hours. Creator applications: six months after resolution; routine support: 24 months after closure.

Limited contract/claim evidence follows the applicable limitation period, generally three or six years depending on the claim and counting rules. Tax records generally last five years after the year tax fell due, subject to statutory extensions. Specific legal requirements may justify limited longer retention, not keeping entire accounts indefinitely.

Your choices and rights

Email contact@misdir.com to request access or a copy, correction, deletion, restriction or, where applicable, portability. You may object to processing based on legitimate interests because of your particular situation; direct-marketing objections need no explanation. You can withdraw consent whenever processing relies on it. We verify identity proportionately and normally respond within one month; a lawful extension of up to two further months is explained within that first month.

You can complain to the Polish supervisory authority, UODO, or your competent EU authority. We do not make solely automated decisions with legal or similarly significant effects about you.

For consent-based online processing of a child’s data in Poland, guardian authorisation is required below 16; contractual capacity is a separate issue. Contact us where guardian involvement is needed. We explain material changes before applying them and seek new consent when required.