Legal
Privacy Policy
Last updated ·
1. Who is responsible
The operator of Mirra is the controller of the personal data described here, for the service at onemirra.com. For anything in this policy, write to privacy@onemirra.com — that address reaches the person responsible and is the fastest way to exercise any right you have over your data.
2. What we collect
Only what the service needs to work:
- Your entries — the dream you write, your answers to the follow-up questions, the emotion and intensity you assign to each scene, any optional note about what is going on in your waking life, the readings generated for you, and your “that's me / not quite me” calibration.
- Account details — if you register: your email address and a salted PBKDF2-SHA256 hash of your password. We never store your password itself and cannot recover it.
- Session — a signed, HTTP-only cookie (mirra_sid) that identifies your browser session so your entries stay yours.
- Purchase records — if you buy a plan: the plan, its status, the current period end, and identifiers issued by our payment provider. We never receive or store your card number.
- Technical data — the country code your request arrives with, used only to choose which AI provider serves your region, plus ordinary server logs.
3. Why we process it, and on what basis
We do not profile you for advertising, and we do not make automated decisions that have a legal or similarly significant effect on you.
- To provide the service you asked for — writing and storing your readings, keeping your journal, tracking patterns across it. Basis: performance of a contract.
- To keep the service secure and prevent abuse. Basis: legitimate interests.
- To take payment, invoice you and meet tax and accounting obligations. Basis: contract and legal obligation.
- To answer your support messages. Basis: legitimate interests.
4. Cookies
Mirra sets one cookie: mirra_sid, an HTTP-only, signed session identifier that lasts up to one year. It is strictly necessary to keep your entries attached to you and to keep you signed in.
We use no analytics, advertising, or third-party tracking cookies, and no tracking pixels. Because the only cookie is strictly necessary, there is no consent banner to click through.
5. Who else processes your data
We use a small number of processors, each for one job:
- Cloudflare — hosting, and the database (Cloudflare D1) where your entries and readings are stored.
- An AI provider — the text of your entry, your answers and your emotion labels are sent so a reading can be generated. We currently use DeepSeek, and depending on your region may use OpenAI, Anthropic or OpenRouter. Content is sent for generation only; we do not permit it to be used to train their models.
- Creem — our merchant of record, which processes payments, issues receipts and handles tax. It receives your email address and an account identifier. It does not receive your entries.
6. International transfers
Mirra runs on a global edge network and our processors operate in several countries, so your data may be processed outside the country where you live, including outside the EEA and the UK. Where that happens we rely on the transfer mechanisms our processors make available, such as standard contractual clauses.
7. How long we keep it
Your entries and readings are kept until you delete them or ask us to close your account — a journal is only useful if it lasts. Anonymous sessions with no account are removed after 12 months of inactivity. Records we must keep for tax and accounting are retained for the period the law requires, typically 7 years, and are limited to the transaction, not your entries.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent where we rely on it.
Write to privacy@onemirra.com and we will respond within 30 days. We will not charge you, and we will not treat you differently for asking. If you are in the EEA or the UK you also have the right to complain to your local data protection authority.
9. What we never do
- We do not sell or rent your personal data, and we never have.
- We do not share your entries with advertisers or data brokers.
- We do not make your entries public. Mirra has no social feed, no sharing to other users, and no public profiles.
- We do not use your entries to train our own or third-party AI models.
10. Security
Traffic is encrypted in transit with TLS. Passwords are stored only as salted PBKDF2-SHA256 hashes (100,000 iterations). Session cookies are HTTP-only and signed with HMAC-SHA256 so they cannot be forged. Access to production data is limited to what is needed to operate the service.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
11. Children
Mirra is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@onemirra.com and we will delete it.
12. Changes
If we change this policy we will update the date above, and for material changes we will make the change clear before it takes effect.
13. Contact
Privacy questions and rights requests: privacy@onemirra.com. Anything else: support@onemirra.com.
Still unclear?
Write to support@onemirra.com. A person reads it, and we answer within 2 business days.