Privacy Policy
Last updated: 25 July 2026 · Effective version
1. The data controller
The controller is the operator of Mirrify (mirrify.app): [Name / company, seat, tax number]. Contact: [privacy@mirrify.app]. Detailed identifying data is in the Imprint.
2. What data we process
- Account data: email address, display name, password (stored encrypted at the authentication provider).
- Content (user-provided) data: journal and reflection entries, mood data, goals, habits, financial notes, voice notes, and everything else you enter. This may include special data (e.g. about health or beliefs) if you enter such.
- Technical data: basic data needed for operation (e.g. session id) and technical logs for debugging.
3. Purposes and legal bases
- Providing the service (account, storage and sync) — basis: performance of a contract (GDPR Art. 6(1)(b)).
- Storing and displaying content, including any special data — basis: your explicit consent (GDPR Art. 9(2)(a)), which you may withdraw anytime.
- Running the AI mentor — basis: performance of a contract and your consent (see section 4).
- Security, abuse prevention, debugging — basis: legitimate interest (GDPR Art. 6(1)(f)).
- Billing and legal obligations — basis: legal obligation (GDPR Art. 6(1)(c)).
4. AI processing
When you use an AI feature (e.g. AI mentor, weekly/monthly analysis), part of the content needed for the feature (e.g. the conversation or relevant entries) is transferred for processing to Anthropic PBC (USA) as the AI provider, acting as a processor on our instructions.
- We do not sell your data and do not use it to train AI models; under our terms, Anthropic does not train on content sent via the API.
- The AI mentor is not medical, psychological or therapeutic advice (see Terms).
- AI features are optional; if you don't use them, your content is not sent to the AI provider.
5. Processors
- Database, authentication
- Supabase Inc. — data stored in the EU region (Ireland)
- Hosting / CDN
- Vercel Inc. (USA)
- AI processing
- Anthropic PBC (USA)
- Payment
- Stripe Payments Europe, Ltd. — processes card and payment data (EU / Ireland; with Stripe, Inc., USA, as sub-processor)
6. Transfers outside the EU
Some processors (Vercel, Anthropic, Stripe) operate in the USA. Such transfers take place with appropriate GDPR safeguards (typically the European Commission's Standard Contractual Clauses / SCCs, or the provider's data-processing agreement). [Verify and record the specific safeguards in the contracts with each provider.]
7. Retention
Your account and its data are stored while the account exists. On account deletion we delete your data (except data required by law, e.g. billing data, kept until the end of the statutory retention period). You can export your data anytime and permanently delete your account from the app.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure ("to be forgotten"), restriction of processing, data portability, objection, and to withdraw consent anytime (which does not affect the lawfulness of processing before withdrawal). Send requests to the contact email above; we respond without undue delay, within 1 month.
9. Data security
Your data is stored in isolation: row-level security (RLS) ensures no other user can access your entries. Data transfer is over an encrypted (HTTPS) channel. We apply reasonable technical and organisational measures.
10. Cookies and local storage
The app uses your browser's local storage (localStorage / IndexedDB) for operation — e.g. the login session and offline functionality. These are strictly necessary. See the Cookie Policy.
11. Changes to this notice
We may update this notice from time to time. We inform you of material changes in the Service or by email; the current version is on this page.
12. Contact and complaints
For privacy questions write to [privacy@mirrify.app].
If you believe our processing is unlawful, you may complain to the supervisory authority. In Hungary: National Authority for Data Protection and Freedom of Information (NAIH) — 1055 Budapest, Falk Miksa u. 9-11., naih.hu. You may also contact your local EU data-protection authority.