Legal
Privacy Policy
This policy describes exactly what information MIRA collects, why, and how it is handled.
Last updated: September 5, 2026
1. Overview
MIRA is a tarot reading and personal-reflection app. This policy covers the MIRA mobile app and the backend service at api.miraoracle.app. It describes only the data MIRA actually collects and processes — we do not claim to collect anything the app or service does not, in fact, collect.
2. Information We Collect
2.1 Account & Authentication
- Email address — if you sign in with email, we collect the address you enter to send you a one-time verification code (OTP).
- Apple Sign-In data — if you use Sign in with Apple, we receive the identifier, and optionally the name and email, that Apple shares based on your choices at Apple's consent screen.
- Guest identifier — if you use the app without creating an account, we generate a random identifier stored only on your device to let the app function; this identifier is not linked to an email or real name.
- Verification codes — one-time 6-digit codes are generated per sign-in attempt. We store only a cryptographic hash of the code, never the code itself, and it automatically expires shortly after being issued.
- Session tokens — after sign-in, an access token and refresh token are issued to keep you signed in. These are stored securely on your device (iOS Keychain / Android Keystore); the server stores only a hash of your refresh token, never the raw value.
2.2 Reading Content
To provide Daily Reading, Feelings Reading, and premium spreads, we process:
- The card(s) drawn and the AI-generated interpretation text for each reading.
- For Feelings Reading and premium spreads: the relationship context you select (e.g., "Ex," "Situationship," "Crush," "No Contact") and the intention you select (e.g., seeking clarity, reconnection, closure).
- An optional name or initials — you may optionally type the name or initials of a person your reading concerns. This is free text you control; you can leave it blank. If entered, it is sent to our servers to personalize your reading and is stored as part of your reading history. Please avoid entering sensitive information about yourself or others beyond a first name or initials.
- Your reading history and any readings you mark as favorites, so you can revisit them in your journal.
2.3 Preferences & Usage
- Notification preferences and your device's time zone, used to time your daily reminder correctly.
- Reading streak counters (current/longest streak, last reading date) to power in-app streak features.
2.4 Push Notifications
- If you enable notifications, we store an Expo push token, your device platform (iOS/Android), and an installation identifier so we can deliver your daily reminder.
- Push messages we send contain only a generic reminder title and body (e.g., "Your daily reading is ready") — they never include reading content, names, or other personal details.
- Delivery is handled through Expo's push notification infrastructure, which necessarily receives the push token to route the message to your device.
2.5 Subscriptions & Purchases
- MIRA offers optional premium subscriptions billed through the Apple App Store or Google Play. We never see or store your payment card details — billing is handled entirely by Apple or Google.
- Purchase and entitlement status is synced through RevenueCat, our subscription management provider. RevenueCat identifies your subscription using an internal MIRA account identifier only — we do not send your email, name, or other personal information to RevenueCat.
- Our servers store subscription metadata such as plan, status, renewal dates, store (Apple/Google), and the store transaction identifier, so the app can reflect your current entitlement.
2.6 Diagnostics
- Our servers keep standard operational request logs (endpoint called, response status, timing) to operate and secure the service. These logs do not include reading content, email addresses, verification codes, or authentication tokens.
- IP addresses are used only transiently, in memory, to apply rate limits that protect against abuse of the sign-in system. They are not written to our database or retained.
2.7 What We Do Not Collect
- We do not use any analytics, advertising, or crash-reporting SDKs (such as Sentry, Firebase Analytics, Mixpanel, or similar) in the MIRA app or backend.
- We do not access your camera, contacts, microphone, or precise location.
- We do not use advertising identifiers (IDFA/GAID) or device fingerprinting.
- We do not sell your personal information, and we never will.
3. How We Use Your Information
- To create and secure your account, and to sign you in via email OTP or Sign in with Apple.
- To generate and personalize your tarot readings, including substituting a name you provide into your reading's interpretation text.
- To maintain your reading journal, favorites, and streaks.
- To send you daily reminder notifications, if enabled.
- To manage your premium subscription and reflect your entitlement in the app.
- To operate, secure, and troubleshoot the service, including preventing abuse of authentication endpoints.
4. Service Providers We Use
We share the minimum data necessary with the following providers to operate MIRA:
- Apple — Sign in with Apple, and App Store purchase processing (for iOS users).
- Google — Google Play purchase processing (for Android users).
- RevenueCat — subscription and entitlement management, identified only by an internal account ID.
- Expo — push notification delivery infrastructure.
- Our email delivery provider — used solely to send one-time sign-in verification codes to the email address you provide.
- Hetzner — our infrastructure hosting provider, where our servers and database run.
We do not permit these providers to use your data for their own advertising purposes, and we do not sell or rent your information to any third party.
5. Data Storage & Retention
- Your account data, reading history, and preferences are retained for as long as your account is active.
- Verification codes expire automatically shortly after being issued and are stored only as irreversible hashes.
- Session/refresh tokens are stored as hashes server-side and are invalidated when you sign out or delete your account.
6. Account Deletion
You can permanently delete your account at any time from Settings → Account → Delete Account. When you do:
- Your account, reading history, favorites, device/push tokens, and session tokens are permanently deleted from our active database.
- Locally on your device, your session, cached reading context, and account identifiers are cleared.
- A small number of records that are not linked back to your identity after deletion — such as an already-expired verification-code hash tied only to an email address, or an anonymous payment-processing event ledger used to prevent duplicate billing events — may persist briefly but do not identify you as an individual once your account is removed.
7. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can:
- Delete your account and associated data directly in the app at any time.
- Contact us at support@miraoracle.app to request access to, correction of, or deletion of your data, or with any other privacy question.
8. Security
We apply reasonable technical safeguards, including: hashing verification codes and refresh tokens rather than storing them in plain text, encrypting traffic to our servers in transit, and storing session tokens in your device's secure hardware-backed storage (Keychain on iOS, Keystore on Android). No method of transmission or storage is perfectly secure, but we work to protect your information appropriately for the type of data MIRA handles.
9. International Data Processing
Our servers are hosted with Hetzner. Depending on where you use MIRA, your information may be processed in a different country than where you live, including by service providers such as Apple, Google, RevenueCat, and Expo, which operate internationally. We take steps to ensure any such providers offer an appropriate level of protection for your data.
10. Children's Privacy
A minimum age requirement for MIRA has not yet been finalized by the product owner. This section will state MIRA's minimum age of use and, if applicable, our approach to children's data once that decision is made. MIRA is not currently designed or marketed for use by children.
11. Changes to This Policy
We may update this policy as MIRA evolves. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app.
12. Contact Us
Questions about this policy or your data can be sent to support@miraoracle.app.