Privacy Policy

Last updated July 29, 2026

This privacy notice explains how Milnerva LLC ("Milnerva," "we," "us," or "our") collects, uses, stores, and discloses information when you use our website, web application, mobile application, and related services (collectively, the "Services").

Milnerva is a privately owned company. We are not affiliated with, sponsored by, or endorsed by the United States Government, the Department of Defense, the United States Army, or any other government entity.

The Services are not designed to receive classified information, controlled unclassified information, protected health information, or other information subject to special government, regulatory, or contractual handling requirements. Do not submit that information to the Services.

1. Information we collect

Information you provide

Depending on the features you use, we may collect:

  • Account and profile information, such as your name, email address, password credential, duty title, account preferences, connected sign-in provider, and records showing when you accepted our terms and privacy policy. Passwords are stored in hashed form rather than as readable text.
  • User content, such as awards, evaluations, counselings, memoranda, saved addresses, publications, conversations, prompts, feedback, and other information you enter, upload, generate, or save through the Services.
  • Communications, such as messages you send through contact forms or to our support address.
  • Subscription and transaction information, such as your plan, subscription status, transaction identifiers, and billing contact details. Stripe collects and processes payment card details. Milnerva does not store complete payment card numbers.
  • Notification information, such as a mobile push notification token when you choose to enable notifications.

Authentication and security information

When you register, sign in, refresh or end a session, or otherwise use an authenticated feature, we collect and generate records used to operate and protect your account. These records may include:

  • IP address;
  • browser or application user-agent information;
  • device name and client type, such as web or mobile;
  • session identifier, creation time, last-used time, idle and absolute expiration times, and revocation time and reason;
  • sign-in, refresh, sign-out, rate-limit, token-replay, and other security events; and
  • information identifying an authorized administrator when the administrator uses a time-limited impersonation session to provide support or administer the Services.

Authentication access and refresh tokens are stored server-side as cryptographic digests. Some security logs use a one-way keyed digest of an email address instead of logging the address itself. Session details may be shown to you so that you can review and revoke sessions associated with your account.

Information collected automatically

When you use the Services, our systems may automatically collect technical and usage information such as your IP address, browser and device characteristics, operating system, referring URL, pages or features used, request and error logs, approximate location inferred from IP address, and dates and times of access.

If you consent to analytics cookies on the web application, Heap may collect interactions, events, session details, device and browser information, IP address, and usage patterns. Heap is not loaded through our application unless analytics consent is enabled.

Information from third parties

We may receive information from:

  • Google, when you choose Google sign-in, such as a provider account identifier, verified email address, name, and profile image;
  • Stripe, such as subscription, payment status, customer, invoice, and transaction information; and
  • application stores and mobile infrastructure providers, such as information needed to distribute, update, and operate the mobile application and deliver notifications.

2. How we use information

We use information to:

  • create, authenticate, and administer accounts;
  • provide, personalize, maintain, and improve the Services;
  • save, retrieve, generate, format, and export the content you ask us to process;
  • operate subscriptions, billing, and customer support;
  • send transactional, account, security, support, and policy communications;
  • detect abuse, enforce rate limits, prevent fraud, investigate security events, revoke compromised sessions, and protect users and the Services;
  • understand feature usage and improve performance when analytics consent applies; and
  • comply with law, enforce our agreements, and establish, exercise, or defend legal claims.

3. Artificial intelligence features

The Services use artificial intelligence to help draft, edit, search, summarize, and organize content. When you use an AI feature, the information needed to fulfill your request may be sent to OpenAI, including your prompt, relevant saved content, conversation context, and tool results. AI-generated output may be inaccurate and should be reviewed before use.

Do not enter classified, controlled, health, financial, authentication, or other sensitive personal information into an AI feature. Only provide personal information about another person when you have the authority and a valid reason to do so.

4. Cookies and similar technologies

We use cookies and similar technologies that are necessary for sign-in, security, preferences, and core application functions. With your consent, we also use Heap for product analytics. You can decline or change optional analytics consent through the cookie controls we provide. Blocking necessary cookies may prevent parts of the Services from working.

We use Google reCAPTCHA on certain public forms and authentication pages to help distinguish legitimate activity from automated abuse. Google may receive technical information through reCAPTCHA under its own privacy policy and terms.

Some browsers offer a Do Not Track setting, but there is no consistently adopted standard for interpreting it. We therefore do not currently respond to Do Not Track signals. Optional Heap analytics remain controlled by the consent choice described above.

5. When we disclose information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We may disclose information in the following circumstances:

  • Service providers. We use providers to host and operate the Services, store files, send email, process AI requests, analyze consented usage, process payments, verify sign-ins and reCAPTCHA results, distribute and update the mobile application, and deliver push notifications. These providers include Amazon Web Services, OpenAI, Stripe, Google, Heap, Expo, Apple, and Google Play, depending on the feature you use.
  • Legal and safety reasons. We may disclose information when we reasonably believe it is required by law, legal process, or a valid government request, or is necessary to protect the rights, safety, property, and security of Milnerva, our users, or others.
  • Business transfers. We may disclose information in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate protections.
  • With your direction. We may disclose information when you ask us to or consent to the disclosure.

Third-party services process information under their own terms and privacy notices. You can review the notices for OpenAI, Amazon Web Services, Stripe, Google, Heap, and Expo.

6. Data retention

We retain information for as long as reasonably necessary to provide the Services, maintain your account, fulfill the purposes described in this notice, comply with legal and accounting requirements, resolve disputes, and enforce our agreements. Retention periods vary based on the type of information and why we use it.

Authentication sessions have idle and absolute expiration limits, but related session and security records may remain after a session expires or is revoked when needed for account history, security, abuse prevention, auditing, or legal compliance. We may retain de-identified or aggregated information that can no longer reasonably identify you.

7. Data security

We use administrative, technical, and organizational safeguards designed to protect personal information. These measures include short-lived access credentials, hashed server-side token storage, session expiration and revocation, rate limiting, security event logging, and controls for administrative access. No transmission or storage system is completely secure, so we cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your credentials, reviewing your active sessions, signing out of devices you no longer use, and notifying us if you suspect unauthorized access.

8. International data transfers

Milnerva is based in the United States, and the Services and our providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live. Where required, we use appropriate safeguards for international transfers.

9. Your rights and choices

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; to object to or restrict certain processing; or to withdraw consent. You may also have the right to appeal a decision about a privacy request or complain to a data protection authority.

You can update certain account information and manage active sessions in the Services. You can control optional analytics cookies through our consent controls and mobile notifications through your device settings. To make another privacy request, email support@milnerva.com. We may need to verify your identity before completing a request. Some information may be exempt from a request or retained where permitted by law.

10. United States state privacy disclosures

In the preceding 12 months, we may have collected the categories of personal information described above, including identifiers; customer-record information; commercial and subscription information; internet or electronic network activity; approximate location inferred from IP address; professional or employment-related information you include in the Services; and inferences used to operate, secure, or improve the Services.

We collect and disclose these categories for the business purposes described in Sections 2 and 5. We do not sell personal information or share it for cross-context behavioral advertising. Subject to applicable law, residents of certain states may exercise the rights described in Section 9 without unlawful discrimination.

11. Children

The Services are intended for people who are at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, contact support@milnerva.com so that we can investigate and take appropriate action.

12. Changes to this notice

We may update this notice as our Services and practices change. The "Last updated" date shows when this version became effective. If a change is material, we may provide additional notice through the Services or by email where appropriate.

13. Contact us

For questions, concerns, or privacy requests, contact support@milnerva.com or write to:

Milnerva LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States