1The short version
This policy describes what our system actually does today — not what a template says it should do.
- If you only watch, we need almost nothing: a phone number or an e-mail address, and your date of birth so we know you are 18.
- If you buy coins or send a gift, we hold the payment details M-Pesa gives us and a record of the gift.
- If you apply to become a host, we ask for a lot more: your name, date of birth, contact details, photos, your M-Pesa number, and a photo of your ID with a selfie holding it. That is the most sensitive thing we hold, so it is encrypted, and it is deleted as soon as a member of our team has checked it.
- Chat messages are deleted after 30 days.
- We do not sell your data, we run no advertising trackers, and we do not record live streams.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by e-mailing inuka@mireya.app.
2Who is responsible for your data
The data controller is ALF Holdings East Africa Ltd, a company registered in Kenya, based in Nairobi. It runs Miresho, also written as Mireya Live, at stream.mireya.app and miresho.co.ke.
- Company registration number: [[INVULLEN: company registration number of ALF Holdings East Africa Ltd]]
- Registered office: [[INVULLEN: full registered office address in Nairobi]]
- For anything about your data, write to inuka@mireya.app. That mailbox is read by a person on our team.
- Person responsible for data protection questions: [[INVULLEN: name and role of the person who handles data protection requests — a Data Protection Officer has not been formally appointed]]
- Separate privacy address: [[INVULLEN: decide whether to open a dedicated address such as privacy@miresho.co.ke — today every request goes to inuka@mireya.app]]
Being straight with you about our own paperwork
Two things are not finished, and we would rather say so than hide it:
- ALF Holdings East Africa Ltd is not yet registered with the Office of the Data Protection Commissioner (ODPC) as a data controller. Registration is being arranged. [[INVULLEN: ODPC registration number and date once it is granted]]
- We have not yet carried out a formal Data Protection Impact Assessment for the identity checks, even though the checks themselves are already built and running as described on this page. [[INVULLEN: date the DPIA is completed, and who carried it out]]
None of that changes your rights below. You can complain to the ODPC about us at any time, registered or not.
3What we collect and why
3.1 If you watch and chat
| What | Why | Basis | How long |
|---|---|---|---|
| Phone number or e-mail address | To log you in and to reach you about your account | Contract | While your account exists |
| Date of birth | To keep under-18s off the platform | Legal obligation | While your account exists |
| Display name (optional) | Shown in chat, with your gifts and on leaderboards | Contract | While your account exists |
| One-time login codes | To log you in without a password. We store the code as a hash, never as readable text | Contract | Deleted the night after use or expiry |
| A hashed fingerprint of your browser | To spot one device running several accounts (fraud and ban evasion) | Legitimate interest | While your account exists; deleted if you delete your account |
| Chat messages | To show the conversation and to moderate it | Contract, legitimate interest | 30 days |
| Moderation flags and reports | To keep the platform safe | Legitimate interest | See section 9 |
| Viewer counts in a room | To show how many people are watching | Legitimate interest | Temporary — kept in memory, not in a permanent record |
3.2 If you buy coins or send a gift
| What | Why | Basis | How long |
|---|---|---|---|
| The M-Pesa number that pays, the amount, and the reference Safaricom gives the payment | To take the payment, to credit your coins, and to match a payment to the right person | Contract, legal obligation (bookkeeping) | Kept with our financial records — see section 9 |
| Card payment reference (Stripe), if card payment is switched on | Same as above. We never see or store your card number | Contract | Same as above |
| Which gift, to which host, for how many coins, and when | To pay the host, to run leaderboards, and to answer questions about a gift later | Contract | Same as above |
| Your display name next to a gift | It is shown publicly in the room and on leaderboards | Contract | While the leaderboard period lasts; the gift record stays |
3.3 If you gift as a guest, without an account
You can send a gift with only your M-Pesa number. There are no anonymous gifts on Miresho: a number is required, the name you type is cosmetic, and our moderators always see the real number behind a gift. We create a minimal "guest" record with your number and that name, and a placeholder date of birth, because we do not ask a guest for one — an M-Pesa line already belongs to an adult.
If you later create a full account with the same number, that guest record becomes your account.
3.4 If you apply to become a host
This is where we collect the most. You give it in three steps: photos, identity, then the questions.
| What | Why | Basis | How long |
|---|---|---|---|
| Your host's invitation code, and the fact that the application came from that host | Miresho is invitation-only, and the host manager is paid for a talent they brought in | Contract | With the application |
| The IP address and browser you started the application from | Security, abuse prevention, and proof of where a consent came from | Legitimate interest, legal obligation (proof of consent) | With the application |
| Main photo, plus up to two extra photos | Screening on talent, and — if you consent — your public profile photo | Consent | See section 9 |
| National ID or passport photo, and a selfie holding it | To prove you are a real person and 18 or older | Legal obligation, protection of people | Deleted as soon as we have checked it — see section 4 |
| Full name, date of birth, e-mail, phone, town, country | To identify you, to contact you, and for the age check | Contract, legal obligation | See section 9 |
| Talent category and what you show or teach | This is what our team screens on | Contract | See section 9 |
| Your answers: stage name, Instagram, TikTok, follower count, languages, streaming experience, hours a week, preferred times, phone model, type of internet, the M-Pesa number you want to be paid on, and why you want to join | To judge the application and plan shifts, and to know where a payout would go | Contract | See section 9 |
| The three boxes you tick, plus the moment and the IP address | Proof that you confirmed you are 18+, agreed to the terms and this policy, agreed to your photo being shown, and accepted the house rules | Legal obligation (we must be able to show consent) | With the application |
We send you a confirmation e-mail when your application arrives. That e-mail goes out through our e-mail provider (see section 7).
If you start an application and never finish it, everything you had already uploaded — photos, ID picture and selfie — is deleted automatically. Nothing about you is kept.
3.5 If you are an approved host
| What | Why | Basis | How long |
|---|---|---|---|
| Your account, your stage name and biography, your talent category, your share percentage | To run your channel and pay you correctly | Contract | While you are a host |
| Your M-Pesa payout number, confirmed with a code sent to that number | To pay you, and to make it hard for someone else to redirect your money | Contract | While you are a host |
| Proof of your identity check: a one-way hash of your ID number, its last four digits, the KRA PIN if you gave one, who checked it, when, and their note | To prove the check happened after the document itself is deleted, and to spot one ID being used by two accounts | Legal obligation | See section 9 |
| Your streams: when they started and ended, which studio, peak viewers, coins received | To calculate your hours, your tier and your earnings | Contract | With our financial records |
| Your payouts: gross, percentage, tax withheld, what was sent, the M-Pesa reference, status | To pay you and to keep our books | Contract, legal obligation | With our financial records |
| Changes to your share percentage, and staff actions on your file | An audit trail, so any change to your money can be explained afterwards | Legitimate interest, legal obligation | See section 9 |
Some events send an alert to our operations team over Telegram — for example when a host changes their payout number, when a payout fails, or when one ID number appears on two files. Those alerts can contain your stage name and the last four digits of an ID number. They never contain a full ID number or a document.
3.6 If you are a host manager
We hold your name, your referral code, your contact details, your M-Pesa number for commission, and what you have earned per talent you brought in.
3.7 Everyone: technical data
Our servers keep normal web logs: your IP address (which reaches us through Cloudflare), the type of browser or app, and which requests were made. We use them to keep the service running, to apply rate limits and to investigate abuse. Our logging deliberately strips out login tokens, session cookies and one-time codes, and masks phone numbers and e-mail addresses where it can.
4Your ID document and selfie
This is the most sensitive information we ever hold, so it is worth a section of its own.
- Why we ask. Nobody streams on Miresho without a verified identity. It is how we keep under-18s off the platform and how we know the person on camera is the person on the account.
- How it is stored. The moment your picture reaches our server it is encrypted with AES-256-GCM. The key is on the server, not in the storage bucket. Anyone who got hold of our storage would find unreadable files — even the file type is hidden. If the encryption keys were ever missing, the upload is refused rather than stored unprotected.
- Who can open it. Only our verification team, through an admin-only route. The public media route on this site refuses anything from the ID vault. Every single time a staff member opens an ID document, that is written to an audit log with their name and the time, and the file is sent so that it is not cached anywhere.
- How long we keep it. The document and the selfie are deleted as soon as the decision is made — approved or rejected. If a file is uploaded and nobody ever reviews it, it is deleted after 90 days. If you never finish your application, it is deleted when your application session expires, three hours after you started, in the nightly clean-up.
- What stays. The proof that the check happened: a one-way hash of your ID number (we never store the number itself), its last four digits, who checked it and when. The hash lets us notice the same ID being used on two accounts, without keeping the number.
- We never take your ID away from you. We do not keep, hold or "retain" your physical document, and we will never ask for it.
5Your photos and where they appear
- Your main photo appears on your talent profile and on the public discovery grid — but only if you ticked the photo consent box, and only after a person on our team approves it.
- Before it goes live, your approved main photo is sent to an outside image service (fal.ai) that sharpens and upscales it. It improves your own photo; it does not create an AI face. If that service fails, we keep your original.
- Your extra photos are for screening. We do not publish them.
- Photos are stored in a private bucket at Cloudflare and shown through a link containing a long random key. Be aware: anyone who has that exact link can open that photo — it is not protected by a password. The link is not published anywhere for your extra photos, but this is the honest limit of how photos are protected today. Your ID document and selfie are not handled this way; they are encrypted and unreachable through any public link.
- You can withdraw your photo consent at any time by e-mailing us. We will take the photo down.
6Why we are allowed to do this
The Data Protection Act, 2019 says we must have a lawful basis for every use of your data. Ours are:
- Your consent — showing your photo on your profile and the grid, and the enhancement of that photo. You can withdraw consent at any time.
- Performing our agreement with you — your account, your coins, gifts, hosting, statements and payouts.
- A legal obligation — checking that hosts are 18 or older, withholding tax and paying it to the Kenya Revenue Authority, keeping accounting records, and answering lawful requests from authorities.
- Our legitimate interest — security, fraud prevention, moderation, spotting several accounts on one device, and keeping an audit trail. We only do this where it does not override your rights.
- Protecting people — the identity checks exist to keep minors and trafficked people off the platform.
8When your data leaves Kenya
As the table above shows, several of our providers are outside Kenya, and our servers are in Germany. That means your data crosses borders.
Under sections 48 and 49 of the Data Protection Act, we may only do that if your data stays properly protected. We rely on the data protection terms in our contracts with each provider, and we chose providers who commit to strong security. Your ID documents are encrypted before they ever reach a storage provider, so a provider outside Kenya cannot read them.
[[INVULLEN: record the transfer safeguard relied on for each provider (contract clauses, adequacy, or your consent) — to be confirmed by a Kenyan data protection lawyer]]
9How long we keep things
| What | How long |
|---|---|
| An application you started but never sent, including photos and ID pictures | Deleted automatically. The application session expires three hours after you start, and our nightly clean-up (just after midnight, Nairobi time) removes the files |
| ID document and selfie of an application you did send | Deleted as soon as our team makes the decision. If it is never reviewed, deleted after 90 days |
| Proof of the identity check (hash, last four digits, who checked, when, KRA PIN) | Kept while you are a host. [[INVULLEN: how long this proof is kept after a host leaves — set a period]] |
| Chat messages | 30 days, then deleted automatically. A message attached to an open moderation flag is kept until that flag is closed |
| One-time login codes | Deleted the night after they are used or expire |
| Applications we did not approve, and their screening photos | Not deleted automatically today. We delete them when you ask us. [[INVULLEN: set a retention period for rejected and waitlisted applications, e.g. 12 months, and have it built into the clean-up job]] |
| Financial records: purchases, gifts, payouts, ledger entries | Kept for accounting and tax. [[INVULLEN: retention period, confirm with your accountant — Kenyan tax law generally requires several years]] |
| Audit log of staff actions | Our record of who did what. [[INVULLEN: retention period]] |
| Moderation flags and reports | [[INVULLEN: retention period — these are not deleted automatically today]] |
| Server logs, including IP addresses | [[INVULLEN: log retention period — no automatic deletion is configured today]] |
| Your account after you delete it | Your personal details are removed immediately. The financial entries stay, but they are no longer connected to your name |
10How we protect your data
- ID documents and selfies are encrypted with AES-256-GCM before storage, with the key kept off the storage system.
- ID numbers are never stored as numbers — only as a one-way hash made with a secret key, plus the last four digits.
- Login codes are stored as hashes, never in readable form.
- Every connection to Miresho uses HTTPS.
- The application runs under its own restricted system account; the database and cache are only reachable from the server itself.
- Staff access to identity documents is limited to the verification team and is logged every time.
- Money can only move through a double-entry ledger with duplicate protection, so a payment or payout cannot quietly be booked twice.
- Our logs are configured to leave out tokens, cookies and one-time codes.
No system is perfectly safe. If a breach happens that puts you at risk, we will tell you and the ODPC as the law requires.
11What happens automatically
A few things on Miresho are decided by software rather than by a person:
- The chat filter blocks or flags a message before anyone sees it.
- Spending limits and speed limits refuse gifts above a daily cap or sent unusually fast.
- The device fingerprint check raises a flag when several accounts use one device.
- Payment checks refuse a guest gift if the number that paid does not match the number that ordered.
All of these can only refuse or flag. Decisions about you as a person — approving an application, verifying an identity, muting, banning, approving a payout — are made by a human being. If an automatic block affects you and you think it is wrong, e-mail us and a person will look at it.
12What we store on your phone
- Your login token, so you stay signed in.
- Your guest details, if you gifted as a guest — the number and name you used, so you do not have to type them again. Clearing your browser data removes this.
- A cached copy of the app, so pages load quickly and work on a weak connection.
We use no advertising cookies, no analytics trackers and no third-party pixels. There is nothing on Miresho that follows you to other websites.
13Your rights under the Data Protection Act, 2019
As a data subject in Kenya you have the right to:
- Be told how your data is used — that is what this page is for.
- Get a copy of the personal data we hold about you.
- Have it corrected if it is wrong, incomplete or misleading.
- Have it deleted where we no longer have a reason to keep it.
- Object to how we use it, and to ask us to pause a use while we look into your objection.
- Withdraw your consent at any time, for anything we do on the basis of consent — such as showing your photo.
- Receive your data in a portable form where that applies.
- Complain to the Office of the Data Protection Commissioner.
How to use these rights
E-mail inuka@mireya.app and tell us what you want. Please write from the e-mail address on your account, or give us the phone number on it, so we can find you. If we are not sure it is you, we may send a code to the number or address on the account before we act — we would rather check than hand your data to the wrong person.
- It is free. We will only charge if a request is repeated over and over without reason, and we will tell you first.
- We aim to reply within 30 days, and sooner where we can.
- There is no self-service "download my data" button, and no button for applicants who were never approved. We do it by hand when you ask.
- If you have an account and are logged in, you can delete it yourself in the app. Read the warning in the terms first if you still have a balance waiting to be paid.
What deletion actually does
When we delete an account, our system removes your phone number, e-mail, display name and date of birth, clears a host's stage name, biography and payout number, deletes any remaining identity data and ID files, deletes your chat messages and device records, ends your sessions and removes you from any live room. The financial entries stay, because a business must keep its books — but they no longer carry your name.
Complaining to the regulator
If you are not happy with how we handled your data or your request, you can complain to the Office of the Data Protection Commissioner (ODPC), Nairobi. Their website is odpc.go.ke, and complaints can be filed through their online complaints portal. You do not need our permission and you do not need to go through us first.
14What we do not do
- We do not sell your personal data, and we do not rent it out.
- We do not run advertising trackers or share your data with ad networks.
- We do not record live streams. There is no recording function in our system.
- We do not track your location.
- We do not read your contacts, your gallery or your messages. The only pictures we get are the ones you deliberately upload.
- We do not keep anyone's physical ID document, and we never ask for one.
15Children
Miresho is strictly for adults. We do not knowingly collect data about anyone under 18. If you believe a minor is using the platform, e-mail inuka@mireya.app immediately — we will act on it. When we find an under-18 account we close it, stop any stream, and delete the data we are not legally required to keep.
16Changes to this policy
When we change how we handle your data, we publish a new version of this page with a new version number and date at the top. For an important change we will also tell you inside the platform, and by e-mail where we have your address. If a change means we need your consent, we will ask for it before we act.
17How to reach us
ALF Holdings East Africa Ltd — Miresho (Mireya Live), Nairobi, Kenya.
- E-mail: inuka@mireya.app
- Registered office: [[INVULLEN: full registered office address in Nairobi]]
- Data protection contact: [[INVULLEN: name and role of the person handling data protection requests]]
- Regulator: Office of the Data Protection Commissioner, Nairobi — odpc.go.ke
See also our Terms of Service.