Privacy Policy

Last updated: April 2026

What we collect

  • Account data: email address, first and last name (optional), and a hashed password, managed by our third-party authentication provider.
  • Product data: the companies you add to your watchlist, groups you create, articles you save or dismiss.
  • Billing data: subscription status and variant. Payment details (card numbers) are handled by our payment processor — we never see or store them.
  • Server logs: standard request metadata (IP, user-agent, timestamps) retained for up to 30 days for abuse prevention.

How we use it

We use your data to provide the Service (tracking companies, classifying news, billing your subscription) and to communicate service-critical messages (password resets, receipts, policy changes). We do not sell or rent your data to anyone.

Third parties we rely on

To operate the Service we rely on reputable third-party providers across the following categories. Specific vendors within each category may change over time as we evolve the product; we will update this policy if the categories themselves change materially.

  • Hosting and infrastructure — cloud providers that host the application and serve it to your browser.
  • Database and authentication — managed database and identity providers that store your account and product data.
  • Payments and billing — payment processors and merchant-of-record partners that handle subscriptions, invoices, and card data. Payment details are never seen or stored by us.
  • AI and language model providers — third-party AI APIs used to classify news articles by relevance, category, and sentiment. Article titles and company descriptions are sent for classification; personal data is not. Providers may change over time.
  • News and public data sources — public news aggregators, RSS feeds, and community news sites that we query on your behalf to surface articles about companies on your watchlist.
  • Email and transactional messaging — providers used to deliver service-critical emails (password resets, receipts, policy changes).

Your rights

You can view and edit your profile, export your saved articles, and delete your account at any time from the Profile page. Account deletion cancels any active subscription and permanently removes your data within 30 days, except where retention is required by law.

If you are in the EU/UK, you have rights to access, rectify, erase, port, restrict, and object to processing of your personal data under the GDPR. To exercise them, email admin@getmira.org.

Cookies

We use strictly necessary cookies for authentication. We do not use advertising, tracking, or analytics cookies at this time.

Security

Data is stored on managed infrastructure with encryption in transit and at rest. No system is perfectly secure; if you suspect your account has been compromised, contact us immediately.

Children

Mira is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

We may update this policy. Material changes will be announced in-app or by email at least 14 days before taking effect.

Contact

Privacy questions: admin@getmira.org.