Privacy

Effective date: September 2, 2026
Last updated: September 2, 2026

Mira ("Mira," "we," "us") is an iOS migraine journal that helps adults describe patterns in their own attacks, context, treatments, and optional health summaries. This policy explains what we collect, why, where it lives, who processes it, and the controls you have.

The short version:

  • Core journaling works without an account. Guest records stay on that device.
  • We collect only what you choose to record and what the service needs to work.
  • Apple Health access is optional and read-only. Mira never writes to Apple Health.
  • We never sell your data, share it with advertisers, or include third-party advertising trackers.
  • You can export your data and delete your account yourself in Settings.

1. Who we are

Mira is operated by Gowtham T G, an independent developer operating as a sole proprietor with no separate company entity. Contact: hello.getmira@gmail.com. This policy covers the Mira iOS app and mira.openzentra.com, including the website launch-update form.

2. Information we collect

2.1 Information you give us

  • Account information. If you create an account, we use your email and password for sign-in and essential service messages. Sign in with Apple may provide your email or an Apple private relay address.
  • Profile information. Your optional display name, migraine history, aura history, approximate frequency, and the factors or symptoms you choose to track.
  • Migraine journal. Attack dates and duration, severity, pain, aura, symptoms, suspected context, treatments, response, and optional notes. Free-text notes may contain anything you enter; avoid including another person's information.
  • Daily context. Optional check-ins such as sleep quality, stress, hydration, meals, caffeine, alcohol, and cycle context when relevant.
  • Launch-update email. If you join the website list, we use the address only for Mira launch updates and delete it on request.

2.2 Apple Health information

If and only if you grant permission, Mira reads daily summaries for sleep duration, step count, heart-rate variability, resting heart rate, and active energy.

  • Access is read-only; Mira never writes to Apple Health.
  • Raw HealthKit samples are normalized on your device into daily summaries before account sync.
  • Missing values are expected and are not filled from another source.
  • You can revoke access in iOS Settings. Mira continues working without it.
  • Health information is never used for advertising, marketing, or data-broker purposes.

2.3 Information collected automatically

  • Subscription status. Apple and RevenueCat provide entitlement state and transaction identifiers. Mira never receives payment-card details.
  • Notification token. If you enable notifications, Expo provides a token used only for reminders you request.
  • Technical diagnostics. App/device version and redacted crash or service-failure diagnostics may be processed by Sentry. Mira disables personal information, request data, breadcrumbs, journal content, and Health values in diagnostic events.

2.4 What we deliberately do not collect

No advertising identifiers, precise location, contacts, photos, microphone recordings, cross-app tracking, third-party ads, or data purchased from brokers.

3. How we use information

  • Operate the local journal, optional account backup, and multi-device synchronization.
  • Compute deterministic 28-day and 90-day observations from your own records.
  • Create factual Doctor Report PDFs on your device.
  • Deliver reminders you enable and confirm Premium access.
  • Protect accounts, investigate failures, and comply with valid legal obligations.

We do not use your information to advertise, sell or rent data, train language models, diagnose, or recommend treatment.

4. AI narration

Mira's own server code computes pattern statistics first. A configured language provider—Anthropic, Groq, or OpenRouter—may then phrase verified, identifier-free aggregates in plain language. Exactly one provider handles a given narration attempt. We do not send your email, account identifier, free-text notes, or raw HealthKit samples. Narration passes through a server-side filter that blocks diagnostic, causal, and prescriptive claims. If narration is unavailable, Mira uses deterministic template language.

5. Where data lives and who processes it

Account data is stored in a Supabase-hosted PostgreSQL database in the United States, protected in transit and at rest. Row-level security restricts records by account. A local encrypted journal copy supports offline use.

  • Apple: Sign in with Apple, HealthKit, App Store billing.
  • Supabase: authentication, database, synchronization, and server functions.
  • RevenueCat: subscription entitlement state.
  • Expo: optional notification delivery.
  • Sentry: redacted operational diagnostics.
  • Anthropic, Groq, or OpenRouter: identifier-free aggregate narration when configured.

Providers process data only to supply their service to Mira. We do not authorize them to advertise to you or sell your data.

6. Retention and deletion

  • Guest records remain on that device until you delete them, clear the app, or claim them into an account.
  • Account records remain while the account is active so synchronization works.
  • Deleting an account starts a 30-day recovery period. After that period, account data is automatically and permanently purged.
  • Launch-list addresses remain until launch updates finish or you request removal.
  • Backups and legally required transaction records may persist for a limited period before normal deletion cycles complete.

7. Your controls

Settings provides data export, Apple Health controls, notification preferences, display-name editing, account deletion, and deletion cancellation during the recovery period. Subscription cancellation is managed by Apple. You may also request access, correction, deletion, or launch-list removal at hello.getmira@gmail.com.

8. Security and limits

Mira uses encrypted transport, device secure storage, local journal encryption, scoped database policies, and server-only administrative credentials. No system is perfectly secure; keep your device and account credentials protected and export records you need as an independent copy.

9. Adults only

Mira is intended for adults aged 18 or older and is not directed to children. Contact us if you believe a child provided account information.

10. Changes and contact

Material policy changes will be posted here and, where appropriate, communicated in the app or by email. Questions or privacy requests: hello.getmira@gmail.com.