MIRR private beta

Privacy Policy

Version Beta 1.6 · Effective September 30, 2026

MIRR is a small, invitation-only private beta operated by the MIRR founder. It is not represented as an incorporated company. This policy explains the current beta’s practical data handling and known limits.

Who is responsible

The MIRR founder and privacy contact is responsible for questions about this policy and MIRR’s handling of personal information. Email support@mymirr.app. Please do not send passwords, authentication links, API keys, or journal entries unless a small excerpt is genuinely needed to explain a problem and you choose to share it.

What MIRR is

MIRR is a capture-first journaling and reflection app. Capture saves locally first. If you choose a hosted account and are signed in and online, MIRR automatically attempts to sync eligible captures to that account. Guest capture remains the non-hosted alternative. Signed-in participants can search their synced history and ask MIRR for optional source-linked reflections. MIRR proposes; you decide. MIRR is not therapy, diagnosis, crisis support, medical advice, legal advice, financial advice, or professional judgment.

Information MIRR handles

Depending on what you use, MIRR may handle:

MIRR does not ask for payment information in this beta and does not sell journal content or use it for advertising.

Where information is handled

On your device: captures save first in browser storage. Unsynced entries, drafts, return points, and some preferences can remain on a browser or device until you use MIRR’s device controls or clear site data. Signing out does not, by itself, erase browser-local data. Clearing browser storage may remove unsynced work.

In your hosted account: if you choose a hosted account, MIRR automatically attempts to sync eligible captures while you are signed in and online. Successful sync stores account-scoped entries and related records through MIRR’s hosted API and Supabase-backed services. Device clearing and hosted-account deletion are separate actions.

For optional Daily MIRR drafts: when you choose to prepare or refresh a Daily MIRR draft and the server uses OpenAI, MIRR may send the selected day’s synced capture text, source identifiers, day and time boundaries, and relevant Today or check-in question context to OpenAI. The resulting draft interpretations are saved for your review and remain proposals for you to review. Opening a day or reloading a saved draft does not itself request new generation. Local-only captures are not included in this hosted processing.

For optional Reflection: when the deployed server uses OpenAI and you request Reflection, MIRR may send selected synced captures and timestamps, the source window, relevant Today or check-in question context, an optional bounded summary of saved Help MIRR know you answers, and bounded recent correction context to OpenAI. Confirmed category labels attached to those selected synced captures may also be sent with their source posts, including labels about feelings or concerns. Pending suggestions and removed labels are excluded. A category is your organizational choice, not independent evidence of a feeling or fact; Reflection claims must be grounded in your original writing. You can remove a category before future requests; doing so does not erase earlier saved outputs. Reflection has a saved “Include accepted day summaries” setting. It starts on and is saved for the signed-in account in the current browser. While it is on and available for your account, a Reflection request uses today’s eligible synced captures and may also send up to two eligible accepted prior-day narratives. When you turn it off, Reflection uses its usual recent-entry window. You can turn the setting off before requesting another Reflection; changing it does not remove outputs already saved. Accepted narratives are historical, user-correctable summaries, not new raw evidence or verified facts. Pending local-only captures are not included in this hosted processing. AI output may be wrong or incomplete and remains a proposal.

For optional Weekly MIRR: when you request Weekly MIRR generation and the server uses OpenAI, MIRR may send a bounded selection from seven completed days: synced capture text, eligible accepted day narratives, reviewed or corrected Daily MIRR material, and separately marked provisional or unreviewed Daily MIRR material. The request also includes source identifiers, dates, and coverage or omission counts. Unreviewed material is not treated as accepted, and accepted narratives remain historical, correctable summaries. Opening the Weekly view does not itself request generation. Local-only captures are not included; the generated overview may be wrong or incomplete and remains a proposal.

For capture labels, where enabled for your account: after an ordinary submitted capture successfully syncs, MIRR may automatically request organizational label suggestions. This does not wait for you to request Reflection. When the server uses OpenAI, the request contains that capture and a small, relevant set of category, project or thread names you previously established. Suggested categories may include tentative labels for your own feelings or concerns when your words support them. It does not contain the raw text of historical captures, People reports, your reading library or Reflection summaries. Today answers, guided check-ins, typing, unfinished drafts and local-only captures do not trigger this labeling path. Suggestions remain proposals until you confirm or edit them. MIRR stores proposals, source evidence and your label decisions separately from the original text. You can inspect existing labels and remove or reject them even when new suggestions are unavailable.

For People, where enabled for your account: you explicitly choose identities and enter or correct your accounts of relationships. MIRR stores those names, optional aliases, reports, source links and your inclusion choices in your account. It does not treat a matching name or pronoun as permission to identify someone automatically. When you request Reflection, MIRR includes relevant confirmed People context by default if this feature is enabled for your account. You can turn off People context for future Reflections in Settings; that choice is saved for your account in the current browser. You can also exclude individual people from future Reflections in relationship settings. A relationship review remains a separate action. For either action, MIRR may send a bounded selection of names, your reports, linked capture text, dates and source context to OpenAI. A relationship review is temporary; People context used in an ordinary Reflection is saved with its source links. These are your reports, not independently verified facts about another person. Changing the setting does not remove outputs already saved. Corrections, exclusion, removal and supporting-source changes can hide an outdated saved interpretation. Existing People records remain available for correction, exclusion and removal when new People generation is disabled.

For closing quotes and reading observations, where enabled for your account: after a newly requested Daily MIRR or Reflection result is shown, MIRR may separately select an optional closing quote. Once this feature is enabled for your account, its quote, personal-history and automatic-book-recognition preferences initially start on unless you have saved a different choice. When the server uses OpenAI, that selection can send bounded current-day synced captures and explicit Daily MIRR corrections, candidate verified quotations, and, if personal history is enabled, relevant older captures. If automatic book recognition is enabled, a bounded set of complete current and older synced captures may also be examined for explicit statements that you read or finished a book. MIRR may save provisional title, author, reading-status and source-link observations in your editable reading library. Oversized sources may remain unexamined. Your library and preferences help choose candidates; MIRR does not send the whole library or archive on each request. Quote requests do not send People reports or the text of the generated Reflection. Reloading a saved result does not itself start a new quote-generation request. You can disable quotes, personal-history matching or automatic book recognition, and correct or remove reading observations, dismiss a day's quote or exclude a passage or work. Quotations come from reviewed sources or eligible exact words from your own captures; the feature does not automatically search the web for quotations. Relevance and reading observations can still be wrong.

For optional voice capture: if you choose the browser’s Dictate feature, the browser or its speech service may process microphone audio. MIRR does not intentionally upload or store an audio recording; only words you explicitly accept enter the normal capture path.

Service providers and processing outside Canada

MIRR uses Vultr-hosted infrastructure to run the app, Supabase for authentication and hosted account storage, OpenAI for the optional AI processing described above when the relevant feature is enabled and the server is configured to use it, and email services needed to support the beta. These providers may process or store personal information outside Canada, where it can be subject to the laws of those places.

The precise countries and provider retention or backup settings for MIRR’s current accounts have not all been independently verified. MIRR will not claim Canadian-only storage, zero provider retention, or immediate deletion from provider backups. Questions about foreign processing can be sent to the MIRR founder and privacy contact at the email above.

Why MIRR uses information

MIRR uses information only as reasonably needed to provide local capture, account access, sync, search, optional Daily MIRR, Reflection, Weekly MIRR and available organizational or reflection features described above, data controls, security, troubleshooting, support, and private-beta improvement. Optional product analytics and beta-safety review remain off unless you are separately shown the choice and explicitly allow them.

Your choices and control

Identity verification may be required before acting on an account-specific request, normally through control of the account email or a signed-in session. MIRR will not ask you to send a password or raw authentication token.

Retention and deletion limits

Browser-local information can remain on every device where MIRR was used until it is cleared there. Active hosted-account data remains while the account is in use or until an applicable control or verified support process is completed.

MIRR’s current account-closure design blocks normal hosted use and provides a 60-day recovery window before synced account data becomes eligible for permanent deletion. Account closure does not remotely erase browser-local copies. Provider backups, security records, or technical remnants may persist for a limited period under provider systems and settings; MIRR does not promise instant deletion from every backup.

Protection and limits

MIRR uses authentication, server-derived account scope, restricted server-side credentials, and other technical controls intended to keep accounts separate. No system is completely secure. MIRR does not claim certified compliance, end-to-end encryption, breach-proof storage, guaranteed availability, or guaranteed recovery.

Adults and emergencies

This private beta is for invited adults. MIRR is not monitored as an emergency or crisis service. If you are in immediate danger or need urgent help, contact local emergency services, an appropriate crisis service, or a trusted person.

Changes

MIRR is an evolving private beta and may update this policy from time to time. The version and effective date above identify the current policy, and participants should check this page periodically. Minor or operational updates may take effect when posted without individual notice. If a change materially affects how MIRR collects, uses, or discloses personal information, MIRR will use reasonable steps to present the change and obtain any notice or consent required by applicable law before the changed handling applies.

Contact

MIRR founder and privacy contact: support@mymirr.app