Privacy Policy
Last updated: August 1, 2026
Mirra ("we", "us") provides AI-assisted aesthetic and wellness insights in the app and operates the getmirra.cc website. This policy explains what we collect, why we use it, where service providers may process it, and how long we keep it.
What we collect
- Waitlist email. When you join the waitlist, we collect your email and finite signup attribution (source, medium, campaign, and content) to send launch and early-access messages and understand aggregate signup performance. Cloudflare Turnstile processes browser and environment signals to distinguish bots and prevent waitlist abuse. Joining does not start a subscription. You can unsubscribe at any time.
- Account, profile, and quiz data such as your age confirmation, skin concerns, lifestyle, budget, and preferences — to personalize the experience.
- Scan photos. Three guided photos are uploaded to private storage and shared with the named AI services below to run the requested analysis or visualization. Mirra does not create a Face ID template, identify you, compare you against a face database, or use face geometry for authentication. A one-way hash may be retained to prevent duplicate billing or abuse.
- Results and generated content such as the Glow Score, appearance reads, protocol, visualization, and studio or try-on images. Generated images remain stored until you delete them or request deletion of your Mirra data so the app can show your history.
- Usage and diagnostics through services such as Mixpanel and Sentry in the app and Plausible on the website. This can include account or session identifiers, feature events, device information, and crash details.
- Subscription status through RevenueCat and Apple. We do not receive your full payment-card details.
Face data: use, sharing, storage, retention, and deletion
Mirra uses the three photos only to create the AI appearance read and any visualization or try-on you request. Before the camera opens, the app names the recipients and asks for permission. If you decline, Mirra does not upload a photo or call an AI provider.
Photos are uploaded over encrypted connections to private Supabase storage. Depending on the requested feature, Mirra may send the photos and minimum relevant quiz context to Anthropic, OpenRouter and its selected model providers, Alibaba Cloud Model Studio / Qwen, or fal.ai. Mirra does not sell face photos, disclose them to advertisers, or use them to train Mirra models.
Mirra removes its routine assessment upload copies from Supabase storage after processing. A front source photo needed for a requested visualization is normally scheduled for confirmed deletion from Mirra storage within 24 hours after upload. If a storage or processing outage prevents confirmation, retained-photo work may pause and deletion retries continue. Mirra does not report deletion until a post-delete check succeeds.
How we use and share data
We use data to provide requested features, personalize suggestions, keep the service secure, troubleshoot errors, understand product use, manage subscriptions, and send the waitlist messages described above. We do not sell personal data or accept paid placement in product rankings.
We disclose the data needed for those purposes to service providers. Current categories include Supabase for accounts, storage, and waitlist data; Anthropic; OpenRouter and the model providers it selects; Alibaba Cloud Model Studio / Qwen; and fal.ai for AI analysis, review, or generated imagery; Mixpanel, Sentry, and Plausible for analytics and diagnostics; Cloudflare Turnstile for website abuse prevention; and RevenueCat and Apple for subscriptions. Providers and models can change as the product evolves.
AI processing and regions
AI providers receive photos, relevant profile context, and feature instructions needed for the request. Processing locations vary by provider, model, and request and may include the United States and other regions. Mirra does not promise that processing occurs only in one country. Provider-side retention is separate from deletion in Mirra's Supabase storage. Mirra's OpenRouter requests require zero-data-retention routing. Anthropic states that API inputs and outputs are deleted within 30 days by default, with exceptions for zero-retention agreements, usage-policy enforcement, and law. Alibaba Cloud states that Model Studio request data is encrypted and is not used for model training, but its public materials do not promise one universal deletion period for every API request. fal.ai processes uploaded images under its API and privacy terms and may retain information for service, security, or legal purposes.
Retention
- Mirra's routine source copies are deleted from private Supabase storage after analysis; a visualization source is normally scheduled for confirmed deletion from Mirra storage within 24 hours after upload, with continued retries and an operational hold if an outage delays confirmation.
- Results and generated outputs remain available until you delete them or request deletion of your Mirra data.
- Waitlist data remains until you unsubscribe, ask us to delete it, or the waitlist is no longer needed.
- Security, billing, provider, and backup records may follow separate limited retention periods when required for operations or law.
Your rights
Use Settings → Delete my data or email privacy@getmirra.cc to request access, correction, export, or deletion. Deletion removes service data tied to the account, subject to limited backup, security, legal, and provider retention described above. You can unsubscribe from waitlist emails using the link in any message.
Age
Mirra is intended for people age 16 and older. Do not submit photos of another person or of anyone under 16. Automated age screening can be wrong; contact us if a decision needs review.
Mirra provides aesthetic and wellness insights only, not medical advice.