Privacy Policy
Last updated: April 2026
Mycelium is built on a simple principle: your data belongs to you. We collect as little as possible, store nothing we don't need, and will never sell, share, or monetize your information. This document explains exactly what we do - and don't do - with your data.
1. What we collect
To provide the service, we store the following data, each on the legal basis noted:
- Email address - used for authentication and account recovery only. Legal basis: performance of the contract with you.
- Username - chosen by you, displayed to other users. Legal basis: performance of the contract with you.
- Password - stored as a salted hash. We cannot read it. Legal basis: performance of the contract with you.
- Messages and files - stored to deliver the messaging and drive features. Legal basis: performance of the contract with you.
- Device tokens - used solely to deliver push notifications if you opt in. Legal basis: your consent, which you can withdraw at any time by disabling notifications.
- Reports and moderation records - if you report content or another account, or if action is taken on your account (warning, timeout, ban, suspension), we keep a record of the report or action, its reason, and who handled it. Legal basis: our legitimate interest in keeping the platform safe and enforcing our Terms of Service.
We do not collect your real name, phone number, location, or any behavioral analytics, and we keep no IP address logs of our own (see section 7 for the network provider that routes our traffic).
2. What we don't do
- We do not run ads, ever.
- We do not sell or share your data with third parties for their own use.
- We do not track you across the web.
- We do not use third-party analytics (no Google Analytics, no tracking pixels).
- We do not read your private messages.
3. Cookies & sessions
Mycelium uses a single session cookie (jwt) to keep you authenticated.
This cookie contains a signed token that identifies your session - it holds no personal information and is never shared with third parties.
No tracking cookies are used.
4. Data retention
Your data is kept for as long as your account is active. When you delete your account, your profile, messages, and files are permanently deleted from our servers. Backups are purged within 30 days.
5. Security
All data is transmitted over HTTPS and hosted in Europe. Passwords are hashed using bcrypt before storage. Mycelium is open source - you can audit the full codebase on GitLab.
6. Your rights
Under the GDPR, you have the right to:
- Access all data we hold about you.
- Correct any inaccurate information.
- Delete your account and all associated data at any time.
- Export your data in a portable format (data portability).
- Object to processing based on our legitimate interest (e.g. moderation records), or ask us to restrict it.
To exercise any of these rights, contact us at the address below.
You also have the right to lodge a complaint with your national data protection authority. In Belgium, this is the Autorité de protection des données (APD/GBA).
7. Service providers
We keep external services to a strict minimum. Two providers are involved in running Mycelium:
- OVH (OVHcloud, France) - our email provider, used solely to deliver account emails such as sign-in, verification and account-recovery messages. Your email address and the content of those messages pass through OVH's mail servers for that purpose only.
- Gcore (Gcore, Luxembourg) - an EU-based content-delivery and security network that sits in front of our servers to protect the service and speed it up. Because all traffic is routed through it, Gcore processes technical connection data - including your IP address - to deliver requests and block abuse. It acts on our behalf and does not use this data for its own purposes.
Both OVH and Gcore act as data processors on our behalf, and both are EU-based companies subject to EU data-protection law. Your data is stored exclusively on our own servers in the EU - in Nantes (France) and Brussels (Belgium). We deliberately choose EU-based providers to keep your data under European jurisdiction; while we cannot guarantee that traffic never transits a non-EU edge node, keeping your data in Europe and as safe as possible.
8. Contact
Questions about this policy or your data? Reach us at contact@carbonlab.dev or open an issue on our GitLab repository.