Skip to content
Mirror
Terms Sign in

Privacy Policy

Last updated July 28, 2026

This Privacy Policy explains how Mirror collects, uses, stores, and shares information when you use the Mirror website, web application, and mobile applications (the “Service”).

Information we collect

Depending on how you use Mirror, we may collect:

  • a randomly generated account or installation identifier and the credentials needed to keep that installation connected;
  • your email address when you choose to verify an account for purchases, account recovery, export, or deletion;
  • conversation messages and related session timestamps and status;
  • subscription and purchase information, such as product, plan, status, transaction identifiers, and billing-provider customer identifiers;
  • limited content-free operational information, such as request identifiers, error categories, model usage, and performance data.

How we use information

We use information to:

  • provide and preserve your reflection sessions;
  • generate and supervise conversational responses;
  • verify access, purchases, and subscriptions;
  • deliver requested account-verification messages;
  • protect the Service and diagnose reliability problems;
  • respond to export, deletion, support, and legal requests.

Conversation privacy

Conversation content is encrypted before it is stored in Mirror’s database. Mirror does not put conversation text in billing systems, analytics events, or application logs. A bounded portion of the current conversation is sent to our model provider to generate and supervise a response. Mirror does not create or save an AI-generated summary of your inner state.

Service providers

We use service providers to operate Mirror. They may process information only as needed to provide their services:

  • Anthropic for conversational generation and supervision;
  • Render for application hosting and managed database services;
  • Stripe for web checkout and billing management;
  • Apple, Google, and RevenueCat for native purchases and entitlement verification;
  • Resend for requested email-verification messages;
  • PostHog for optional content-free product analytics.

Retention

Mirror is configured to delete encrypted conversation bodies and cached responses 30 days after the last session activity. Limited lifecycle metadata may remain so retention cannot create another free session. Billing and operational records may be kept as needed for access, reconciliation, fraud prevention, accounting, and legal obligations. Deleting your account removes the account data held by Mirror, subject to provider availability and records we must retain by law.

Your choices

The Service provides controls to export your account information and delete your account. You may also manage or cancel a subscription through the billing provider that processed it. Deleting a browser’s local storage or removing the app may remove that installation’s credentials but does not by itself delete server-side account data.

Security

We use technical and organizational safeguards designed to protect information, including encrypted transport, encrypted conversation storage, scoped credentials, and access controls. No system is completely secure, and we cannot guarantee absolute security.

Children

Mirror is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it.

Changes

We may update this policy as the Service changes. We will post the updated policy here and change the “Last updated” date.

Contact

For privacy questions or requests, email support@mirrorxyz.com.