Privacy policy
Not reviewed by a lawyer. Not legal advice. It describes what MimOS and its infrastructure actually do, checked on 8 September 2026 — not what we would like them to do. The first version of this document declared two things we would rather not do — loading typefaces from Google and logging the IP of every download. Rather than justify them, we removed them.
Last updated: 8 September 2026.
The short version
The operating system collects nothing. MimOS has no telemetry, creates no accounts, sends no usage or crash reports, and does not contact any server of ours on its own. This is not a promise: the MimOS Centre has no network capability at all, and the accounts the installer creates are local and never leave your computer.
Our servers do see things, as any server delivering a file does. This policy exists to say exactly what, for how long, and why.
We never sell data, do no profiling or advertising, and share nothing with third parties beyond what hosting the service on their infrastructure technically entails.
Data controller
David Fontanet Bujaldón and Jan Arrillaga Ferrer, jointly, under the team name XI14. Contact: support@mimoslinux.org. See the Legal notice.
When you visit mimoslinux.org
The site is static and uses no cookies, session identifiers, analytics, advertising or trackers. It embeds no videos, maps, social buttons or other third-party content. External links contact their destination only when you choose to open them.
The appearance button stores one preference in the browser’s local storage: the
theme key, with value light or dark. It is written only when you choose a
theme, remains until you clear the site’s data, and is never sent to MimOS or a
third party. The cookies and storage policy explains how to
inspect or remove it.
There is no analytics, including optional analytics. The conditional Umami loader has been removed so a deployment variable cannot enable measurement before this policy is updated and consent is obtained if required.
Typefaces are served from this site, not Google. Cloudflare hosts and delivers the website and processes the IP address and connection data needed to serve and protect it.
When you download a MimOS image
Downloads are served from iso.mimoslinux.org, a server we operate. Its
access log records no address at all: not the source IP, not the client IP,
not the port. They are discarded before anything is written.
What does remain, for 30 days, is which file was requested, when, and with
what tool — the user agent, which separates a browser from curl when
diagnosing a broken download. None of that identifies anyone.
Legal basis: legitimate interest (GDPR article 6(1)(f)) in keeping the service available and being able to diagnose faults.
Until 3 August 2026 the IP address of every download was recorded. It stopped that day.
When you update MimOS
An installed MimOS system does not talk to us, but it does talk to the
repositories it downloads software from, like any Linux distribution. When you
run pacman -Syu:
- MimOS updates are requested from GitHub Pages, which will see your machine’s IP address as any web server would;
- everything else is requested from the official Arch Linux mirrors chosen by your system’s configuration.
We receive no notification of those updates and keep no record of which machines exist or what version they run. Whatever GitHub or the Arch mirrors log on their own is governed by their policies.
And there is one request you do not make yourself. MimOS checks for updates once an hour, on its own, on every installation, so it can tell you with a tray icon. That check asks the MimOS channel, the Arch mirrors and the AUR, so those servers see your machine’s IP address at that interval even if you do nothing.
What that check does not do, and this is measured: it changes nothing on your system, it never asks for administrator rights — it works against a private copy of the databases — and it reports nothing to us. If you would rather it did not happen, remove it in System Settings → Autostart, by turning off “Actualizar MimOS”.
In a full capture of the network traffic of a freshly installed MimOS, everything that left the machine was this, the connectivity check Arch ships, and time synchronisation. Nothing else.
What we do not do
- No telemetry, active, passive or opt-in.
- No installation identifiers are generated.
- No automatic crash reporting. A manual diagnostic-bundle mechanism is planned; it does not exist yet, and when it does it will show exactly what it contains and send nothing without your approval.
- No accounts, registration or sign-in.
- No advertising or trackers.
Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to support@mimoslinux.org.
In practice we hold nothing that identifies you. The download server’s logs contain no addresses, so there is no way to connect a line to you — for us or for anyone else.
You may also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (https://www.aepd.es), or to the supervisory authority in your own country.
International transfers
Cloudflare and GitHub are United States companies and may process data outside the European Economic Area, relying on the mechanisms the GDPR provides. Google is no longer involved: the transfer the typefaces caused was removed on 3 August 2026.
Changes
If this policy changes, the date at the top changes with it. Changes that affect what is collected will be made before anything new is collected, not after.