Privacy Policy
Last updated: July 13, 2026
1. What we collect
- Account: email address, authentication identity (via Clerk), plan and billing state (via Stripe — card details never touch Mirra’s servers).
- Configuration: the authors you follow, delivery settings, timezone, your Telegram identity when you connect it, and how you arrived (referral/UTM), stored at signup.
- Analytics: product events and session replays of product usage (form inputs are masked and never recorded) via PostHog; page views via Google Analytics; opens/clicks on brief emails via Resend.
We do not sell personal data. Briefs are derived from the public X posts of the authors you follow, not from your personal data.
2. Email
Transactional email (receipts, account state) cannot be opted out of while you hold an account. Brief emails are sent only where enabled and carry one-click unsubscribe. Marketing email honors a separate suppression list; one click unsubscribes permanently. Unsubscribing stops email; it does not delete your data (§4).
3. Processors
Clerk (auth), Stripe (payments), Supabase (database), Railway (hosting), Resend (email), PostHog and Google Analytics (analytics), LLM providers (brief generation over public posts only), Telegram (delivery). Each receives only what its function needs.
4. Your data
Email support@mirra.to to access, correct, or erase your data. Erasure removes your account and all personal records within 30 days; two things survive: your email on the unsubscribe suppression list (the legal basis for not emailing you again) and financial records retained at Stripe as required by law. Briefs older than 12 months and raw fetched posts are deleted on rolling windows.
5. Contact
support@mirra.to