LogoMiyora// net
Hub Games
Legal

Privacy policy

Privacy policyTerms of serviceCookie policyCommunity guidelinesContact
Updated 2026-07-25

This page explains what account and session data Miyora collects, why it collects it, and what control you have over it. Miyora is currently in beta — this policy will keep evolving alongside the product.

// 01 What this covers

This policy covers data handled by the Miyora web application and its backend API. It does not cover third-party sites you reach through outbound links, or the games whose account data you choose to connect.

// 02 Information we collect

Account details you provide (email, username, avatar), profile information from Google or Discord if you sign in that way, authentication and session cookies, session metadata such as IP address, browser, and device type shown on your Sessions page, and — only if you enable it — a TOTP secret and one-time backup codes for two-factor authentication. If you link a game account (for example a Honkai Star Rail UID), we store the identifiers needed to fetch that account's public game data.

// 03 How we use it

We use this data to keep you signed in, secure your sessions, show you the devices signed in to your account, run two-factor authentication if you turn it on, and display the public game data for accounts you link. Miyora does not use your data for advertising and does not sell it to anyone.

// 04 Cookies and local storage

Authentication runs entirely on HttpOnly, Secure cookies that this application cannot read directly. The full list of cookies and what each one does lives on the Cookie Policy page.

// 05 How long we keep it

Access cookies last about 15 minutes and refresh cookies about 7 days, both rotating automatically while you stay active. Session records disappear once they expire or you end them. Account data is kept for as long as your account exists; TOTP secrets and backup codes are deleted immediately when you disable two-factor authentication.

// 06 Signing in with Google or Discord

If you choose Google or Discord sign-in, Miyora only receives the profile fields that provider grants — typically your email, display name, and avatar. That provider's own privacy policy also applies to your use of their sign-in service.

// 07 Your controls

From your account you can review every active session and end any of them individually, sign out everywhere at once, and enable or disable two-factor authentication. Miyora does not yet have a self-service account deletion button — email us and we will close your account.

// 08 How we protect it

Every mutating request requires a CSRF token, authentication cookies are HttpOnly and Secure, and two-factor secrets and backup codes are never shown again after setup. We do not store raw passwords.

// 09 Changes to this policy

As Miyora moves out of beta this policy will be updated to match. Meaningful changes will be reflected on this page.

// 10 Questions

For anything about this policy or your data, reach out through the Contact page.

Home
miyora.net beta

Game tools, built one at a time and shipped when they work.

Support us on Ko-fi
HubProfileSecurity
Privacy policyTerms of serviceCookie policyCommunity guidelinesContactcontact@miyora.net
© 2026 Miyora. All rights reserved.