Privacy policy
Last updated 15 June 2026.
Who runs Mingl
Mingl is operated by Alex Lukic, an individual based in Melbourne, Australia. There is no registered company behind Mingl at this time. References to “we”, “us”, or “Mingl” in this policy mean Alex Lukic operating the Mingl service.
You can contact us about anything privacy-related at raveshaw@gmail.com.
Our approach
Mingl is small enough that the federal Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) do not strictly apply to us yet, but we choose to follow them voluntarily. We collect as little as we need, only use it for the purposes you can see in the app, and don’t sell or rent it to anyone.
What we collect, and why
The personal information we collect falls into five buckets:
1. Event-attendee profile
When you scan an event QR code and fill in the join form, we collect: a first name, an optional last name, optional pronouns, a photo (selfie), a short descriptor of what you do, what you’d like to talk about (“intent”), optional other interests, an optional contact text (e.g. handle or number), an optional LinkedIn URL, an optional response to a host’s question, and an optional follow-up email address. We use this to render your profile to other attendees of the same event and to power our AI matching for that event.
2. Account information
If you create a Mingl account (currently via Google sign-in only), we receive your name and email address from Google. We use these to authenticate you, attach your attendee profiles to a persistent identity, and send you service-related emails.
3. Networking activity
If you send connection requests, accept introductions, or exchange messages, we store who connected with whom, who introduced whom, and the contents of any messages you send. We use this to make the networking features work and to retain enough of a record to investigate abuse if it’s reported.
4. Technical metadata
Like most websites we receive IP addresses, browser user-agent strings, and timestamps via our hosting providers, and we keep server logs of requests for debugging and security. We don’t use analytics, advertising trackers, or fingerprinting cookies.
5. Web-derived professional info (only if you give a LinkedIn URL)
If you provide a LinkedIn URL on your profile, Mingl looks up publicly available professional information about you from the open web (using the URL, or your name and role, as the search) and stores a short summary (“brief”) on your record. We use it only to make your matches and conversation starters more specific. We use the URL purely as an identity anchor and never sign in to or read LinkedIn itself. If you don’t provide a LinkedIn URL, we skip this entirely, so it is effectively opt-in.
How we use it
We use your information to:
- Show your profile card to other attendees at the same event, so people you meet can find you and connect. This is part of how a Mingl event works. We keep your profile only as long as described in “How long we keep it” below (for a guest, the lifetime of that event).
- Generate AI matches and short conversation starters between attendees. To do this we send your profile fields to Google (see “Third parties” below).
- If you provide a LinkedIn URL, look up publicly available professional information about you from the open web to make your matches and conversation starters more specific. We use the URL only as an identity anchor and never sign in to or access LinkedIn itself.
- If you choose “Save to Drive” on an event file, send that file to your own Google Drive with your permission. We can only touch files we create for you, we keep no ongoing access to your Drive, and we never store your Google credentials.
- Send transactional emails about your matches, connections, and referral activity, and respond to anything you ask us about.
- Operate the connection, referral, and messaging features you interact with.
- Investigate problems, abuse, and security incidents if any arise.
We do not use your information to send marketing emails, advertise to you, or build a profile of you across other websites.
Third parties
We rely on a small set of providers to run Mingl. Each handles your personal information only to provide their service to us:
- Supabase (Supabase, Inc., US-headquartered) hosts our database and authentication. The database for Mingl is provisioned in Sydney/Melbourne, Australia. Supabase may process your data via its US operations for support and infrastructure reasons.
- Vercel (Vercel Inc., US-headquartered) hosts the application. Our serverless functions are pinned to the Sydney region, but Vercel may process logs and metadata in other regions.
- Google (Google LLC, US-headquartered) provides the Gemini AI we use to generate match reasons and conversation starters. We send your profile fields (first and last name, pronouns, descriptor, intent, optional interests, optional contact text, optional LinkedIn URL, optional question response), any web-derived professional summary we hold for you, and other attendees’ equivalent fields in the same event. Google’s API terms govern that processing.
- Third-party search and AI providers. To gather the web-derived professional info described above, we send a search containing your LinkedIn URL (or your name and role) to third-party search and AI services. They receive only that query; we never send them your other profile fields. We use the URL only as an identity anchor and never access LinkedIn itself.
- Resend (Resend, Inc., US-headquartered) delivers our transactional emails. Our sending region is Tokyo, Japan.
Other than sharing attendee email addresses with the relevant event host (see “Event hosts” below), we don’t share your information with anyone beyond the providers listed above, and we don’t sell it.
Event hosts
When you join an event, the organiser of that event receives your email address: your account email if you have a Mingl account, or the follow-up email you give on the join form, plus the email you provide if you ask for an event’s materials. Hosts use this to follow up with the people who attended their event. We never add you to a marketing or mailing list, and we never sell your details.
Hosts only ever see aggregate figures about networking at their event, such as how many connections were made or how many files were downloaded. They never see who connected with or messaged whom, or the contents of any messages.
Cross-border disclosure
Because the providers above are US-headquartered, some of your personal information will be stored or processed outside Australia. The primary database for Mingl is hosted in Sydney/Melbourne, but US-based support, debugging, and infrastructure may involve overseas access. By using Mingl you consent to this cross-border disclosure.
How long we keep it
- Your attendee profiles and selfies persist for the lifetime of the event they belong to; when an event is deleted, its attendee selfies are removed. If you have a Mingl account, your profiles and selfies stay linked to it until you delete your account or ask us to remove them. Selfies are served via long, unguessable links so they load without a sign-in.
- Any web-derived professional summary we hold for you is kept with your profile on the same basis (event lifetime for a guest, or until account deletion for an account holder), and is refreshed if you change your LinkedIn URL.
- Save-to-Drive records (which event file you saved and the resulting Drive link, used to avoid re-uploading duplicates and to apply fair-use limits) are kept for 90 days and then purged.
- Pending connect requests, declined connections, pending and resolved referral requests, messages, and holding-table invites for unclaimed users are retained for at least 30 days from creation and then purged by an automated nightly job. This window exists so we can investigate disputes or abuse if reported.
- Accepted connections persist until either party removes them. When removed, they enter the 30-day hold bucket and are then purged.
- Audit logs of connection / message activity are retained for at least 30 days and then purged.
- Email delivery logs (which emails were sent to which address) are retained while needed for diagnostics.
Cookies
Mingl uses only first-party cookies needed for the app to work. We don’t use advertising, analytics, or tracking cookies. The cookies we set include:
- Supabase authentication cookies that keep you signed in.
- Per-event “edit token” and attendee-id cookies that let you return to an event you joined anonymously without re-doing the form.
Anonymity
You can join an event without creating a Mingl account. In that case we store the profile you fill in for that event, the cookie that lets you return to it, and (only if you provide a LinkedIn URL) the web-derived professional summary described above. You can choose to create an account later if you want to keep a persistent identity across events.
Security
We rely on industry-standard measures provided by our hosting and database providers: HTTPS in transit, encryption at rest for the Supabase-managed database, role-based access controls, and row-level security policies in the database. We don’t hold any independent security certifications (e.g. ISO 27001, SOC 2) and don’t represent ourselves as having undergone formal audit. If you spot a security issue please email us at the address below.
Your rights
You can:
- Access a copy of the personal information we hold about you by emailing us.
- Correct your profile information directly via the app, or by emailing us if a field is locked.
- Delete your Mingl account and associated data by emailing us. We may retain certain records for the 30-day investigation window described above before final deletion.
- Complain to us first. If you’re not satisfied with how we handle it, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Children
Mingl is not designed for people under 16. If we become aware that we’ve collected personal information from someone under 16 without verifiable parental consent, we’ll delete it.
Updates
We may update this policy as the product evolves. The “Last updated” date at the top of the page reflects the most recent material change. If a change materially reduces your rights or expands how we use your information, we’ll try to give you a heads-up via email if we have one for you.
Contact
Any questions, requests, or complaints about privacy: raveshaw@gmail.com. We’ll respond within a reasonable time.
