Privacy Policy
Last updated July 28, 2026
This Privacy Policy explains how Mirror collects, uses, stores, and shares information when you use the Mirror website, web application, and mobile applications (the “Service”).
Information we collect
Depending on how you use Mirror, we may collect:
- a randomly generated account or installation identifier and the credentials needed to keep that installation connected;
- your email address when you choose to verify an account for purchases, account recovery, export, or deletion;
- conversation messages and related session timestamps and status;
- subscription and purchase information, such as product, plan, status, transaction identifiers, and billing-provider customer identifiers;
- limited content-free operational information, such as request identifiers, error categories, model usage, and performance data.
How we use information
We use information to:
- provide and preserve your reflection sessions;
- generate and supervise conversational responses;
- verify access, purchases, and subscriptions;
- deliver requested account-verification messages;
- protect the Service and diagnose reliability problems;
- respond to export, deletion, support, and legal requests.
Conversation privacy
Conversation content is encrypted before it is stored in Mirror’s database. Mirror does not put conversation text in billing systems, analytics events, or application logs. A bounded portion of the current conversation is sent to our model provider to generate and supervise a response. Mirror does not create or save an AI-generated summary of your inner state.
Service providers
We use service providers to operate Mirror. They may process information only as needed to provide their services:
- Anthropic for conversational generation and supervision;
- Render for application hosting and managed database services;
- Stripe for web checkout and billing management;
- Apple, Google, and RevenueCat for native purchases and entitlement verification;
- Resend for requested email-verification messages;
- PostHog for optional content-free product analytics.
Retention
Mirror is configured to delete encrypted conversation bodies and cached responses 30 days after the last session activity. Limited lifecycle metadata may remain so retention cannot create another free session. Billing and operational records may be kept as needed for access, reconciliation, fraud prevention, accounting, and legal obligations. Deleting your account removes the account data held by Mirror, subject to provider availability and records we must retain by law.
Your choices
The Service provides controls to export your account information and delete your account. You may also manage or cancel a subscription through the billing provider that processed it. Deleting a browser’s local storage or removing the app may remove that installation’s credentials but does not by itself delete server-side account data.
Security
We use technical and organizational safeguards designed to protect information, including encrypted transport, encrypted conversation storage, scoped credentials, and access controls. No system is completely secure, and we cannot guarantee absolute security.
Children
Mirror is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it.
Changes
We may update this policy as the Service changes. We will post the updated policy here and change the “Last updated” date.
Contact
For privacy questions or requests, email support@mirrorxyz.com.