Privacy Policy
MIRA Labs OÜ ("MIRA," "we," "us") respects your privacy. This policy explains what data we collect, how we use it, and the rights you have over it.
Company
MIRA Labs OÜ
Registry code: 17407993
Kanarbiku tee 15/3, Rae vald, Estonia, European Union
1. Who this policy is for
MIRA is sold business-to-business. Companies purchase seats for their employees; there is no public sign-up — you can only create a MIRA account if a company administrator invites you. Because of that, this policy describes two different relationships at once.
You, as an employee
Your employer decides to give you access, and — for the data your employer can see about you — your employer is generally the party responsible under data protection law. MIRA acts on your employer's instructions for that data.
Your employer, as our customer
For the account, billing, and administrative information your employer gives us directly, MIRA is the party responsible.
We explain below exactly where that line falls for each type of data.
2. Our role: processor vs. controller
Under the EU General Data Protection Regulation (GDPR):
- ProcessorMIRA acts as a data processor for data about individual employees — roster entries, session data, device data, and similar records generated by using the product — which we process solely on the instructions of, and under a Data Processing Agreement (DPA) with, the company that employs you (the "Controller").
- ControllerMIRA acts as a data controller for data about the company relationship itself: admin account credentials, company/organization details, billing contacts, and support communications with us.
If you're an employee and want to exercise a data protection right (access, correction, deletion, etc.), your employer is generally the right first point of contact, since they control your account and instruct us on your data. We're also glad to help directly — see Your rights.
3. Data we collect
Everything below is grounded in what the current product actually does, not a general description of what a product like this "might" do. This policy covers every MIRA client: the iOS, Android, macOS, and Windows apps, the admin dashboard, and the MIRA Focus Chrome/Edge browser extension.
3.1 Company & admin account data (MIRA as controller)
- Admin email address and password (handled by Firebase Authentication; we never see or store your raw password — only Firebase does, in hashed form).
- Company/organization name, contact email, and any custom department names your admin sets up.
- Billing contact details and a Stripe customer ID. Card numbers are handled entirely by Stripe — our own systems never touch them. Depending on how your company checks out, Stripe may also collect billing email and shipping address for hardware orders.
3.2 Employee roster data (MIRA as processor, on your employer's instructions)
- For each invited employee, your employer's admin dashboard can see: email address, role, invitation/activation status and timestamps, your department, a yes/no flag for whether you've granted calendar-write access for Company Focus Blocks (see 3.6), and the platform and device name of every device you've ever connected (a last-seen date is shown only for devices you've marked as company devices). Built only from sessions you've marked Work (see 3.4): your most recent Work session timestamp. Sessions you mark Personal are never visible to any admin, individually or in aggregate, regardless of which device they happened on. Admins never see the underlying calendar access tokens — those are stored in a part of our database that is not exposed to any client, including the admin dashboard.
- Admins can export this roster list (the same fields above) as a CSV.
3.3 Device data
Each device signed into your account registers: a device display name (e.g., your phone or computer's name — this comes from your OS and can be personal), platform, a randomly generated install ID we create ourselves (not your device's Apple/Google advertising ID), and a push-notification token used only to keep your focus-session state in sync across your own devices.
3.4 Session data
When you start a focus session (by tapping your NFC card, pressing the MIRA Button, or using the app directly), we record the start/end time, the mode (fixed / toggle / cycles), duration settings, and whether you marked that session Work or Personal. We do not record what you did during a session — only that a session happened and when. You choose Work or Personal per session, in the app's Timer Settings, before it starts — see section 6 for what that choice controls.
3.5 App and website blocking lists
- iOS/macOS: which apps or categories you've chosen to block. This goes through Apple's Family Controls framework, which deliberately gives us only opaque, anonymous tokens for your selections — we cannot see which actual apps you've blocked, and neither can anyone else. This is stored only on your device.
- All platforms — website block lists: stored only on your device, never sent to our servers.
- Android: foreground-app tracking and screen-time totals used to enforce blocking are stored locally on the device only.
- MIRA Focus (browser extension): your website blocklist is stored locally in the browser (
chrome.storage.local) and enforced with Chrome'sdeclarativeNetRequestAPI — it is never sent to our servers. The extension uses thetabspermission only to detect the active tab's domain against your local blocklist, andalarms/notificationsonly to poll your focus-session status and show session start/end alerts.
3.6 Calendar data
- Personal calendar connections (Apple Calendar, or your personal Google/Microsoft calendar, including via the MIRA Focus browser extension) are read-only and processed entirely on your device, so the app can auto-start focus sessions around your existing schedule. In the browser extension, Google Calendar access uses Chrome's built-in Identity API (token cached by Chrome, never sent to us) and Microsoft Calendar access uses a refresh token stored locally in the browser, encrypted with the Web Crypto API. This calendar data never leaves your device or reaches our servers.
- Company Focus Blocks are a separate, explicitly distinct feature: if your organization's admin configures scheduled focus blocks, a separate calendar OAuth grant with read and write access is used, and the resulting refresh token is held on our servers (not on your device), so scheduled focus-block events can be created on your calendar automatically. You can see whether this grant exists (yes/no) but the token itself is never exposed to any client, including admins.
3.7 MIRA Card
Tapping your NFC card sends its hardware serial number to our servers as a validity check — confirming it's a genuine MIRA card. It is not linked to your identity beyond that check.
3.8 Slack / Microsoft Teams (optional)
If you connect Slack or Teams to automatically set your status during a focus session, the resulting OAuth token is held entirely on our servers (never sent to any device) and used only to set and restore your status message.
3.9 Cookies and local browser preferences (admin dashboard)
- A Firebase session cookie (httpOnly, expires after 14 days) keeps you signed in to the admin dashboard.
- Locale preference is stored in a cookie; theme and time-format preferences are stored in your browser's local storage. None of these ever leave your browser.
3.10 Error and diagnostic data
We use Sentry to catch and diagnose crashes and errors in the admin dashboard. Sentry is configured not to collect your IP address or the contents of your requests — it captures stack traces and error context only.
4. What we deliberately don't collect
- No advertising or marketing tracking SDKs, of any kind.
- No general-purpose analytics SDK (no Google Analytics, Mixpanel, Segment, etc.).
- No location data — MIRA does not request or use device location on any platform.
- No browsing history and no page/message content. Where the product technically touches network traffic (see below), it's engineered specifically to avoid seeing this.
5. No purchases inside the app
MIRA apps are, and will always remain, free to install and free to use — including for anyone signed in without an active company entitlement, per Apple and Google's requirements for this kind of app. We do not sell subscriptions, seats, or anything else inside any MIRA app. Companies purchase seats exclusively through our website via Stripe Checkout or invoice. No app contains purchase links, pricing information, or in-app purchase flows of any kind. What actually determines whether a signed-in user's account has full functionality is a company purchasing and issuing them a physical MIRA NFC card or Button — the entitlement check happens on our servers, not through any app-store purchase mechanism.
6. Employer visibility — what your company can and can't see
This is a core commitment of the product, not just a policy statement:
Sessions you mark Personal report nothing about you to your employer, ever — individually or in any aggregate number. This is a choice you make per session, in the app's Timer Settings before it starts (see 3.4) — not something tied to which physical device you're using.
Your employer's admin dashboard shows org-wide aggregate statistics (total focus hours, adoption rate, active-usage percentage, cross-device coverage, sessions started) and a per-member table (focus hours, session count, and consistency) — built only from sessions you've marked Work. Your employer never sees what you did during any session, which apps or sites you opened or were blocked from, or anything about a session you marked Personal.
The rest of what an admin can see is account-administration data: your email, role, invite/activation status, department, calendar-connection status, the platform/device name of every device you've connected, and — built only from Work sessions — your most recent active timestamp — see 3.2.
7. Purposes and legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the core product (sessions, blocking, sync across your devices) | Performance of a contract (with your employer, as processor) |
| Company Focus Blocks (admin-configured calendar scheduling) | Performance of a contract, on your employer's instructions |
| Admin dashboard, roster management, billing | Performance of a contract with the company (MIRA as controller) |
| Error monitoring and product security | Legitimate interest |
| Accounting, tax, and legal compliance | Legal obligation |
We do not use your data for advertising, and we do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
8. Third parties and sub-processors
| Provider | Purpose |
|---|---|
| Firebase / Google Cloud | Authentication, database (Firestore), push notifications, hosting |
| Stripe | Payment processing for company purchases |
| Resend | Transactional email (e.g., password reset) |
| Sentry | Error and crash monitoring (admin dashboard) |
| Apple | Family Controls / Screen Time framework, EventKit (calendar), push notifications (iOS/macOS only) |
| Google Sign-In / Microsoft Authentication Library | Only if you connect a Google or Microsoft calendar, or your company uses Google/Microsoft sign-in |
| Sparkle | macOS app auto-updates (direct-download distribution) |
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
9. International data transfers
Our infrastructure runs on a single Firebase/Google Cloud project, with our primary database (Firestore) located in Google's US multi-region. If you're located in the EU/EEA, this means your data is transferred outside the EU/EEA. We rely on the European Commission's Standard Contractual Clauses and Google Cloud's own GDPR commitments as the safeguard for this transfer.
10. Data retention
11. Security
We use industry-standard measures including encryption in transit (TLS) and at rest (via Google Cloud/Firebase), Keystore/Keychain-bound encryption for locally-cached sensitive tokens, and role-restricted access to production systems. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Account and data deletion
You can delete your account and associated data directly from the iOS or Android app (Settings → Delete Account), which deletes your personal data and account across all your devices. Company administrators can also remove or delete accounts and organization data directly from the admin dashboard.
If you don't have access to a mobile device or admin access, contact us at mathias@miradial.com and we will process your deletion request manually.
13. Your rights
If you're located in the EU/EEA, you have the right to:
- Be informed about how your data is collected and used (this policy).
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erasure (“right to be forgotten”) of your data in certain circumstances.
- Restrict processing of your data temporarily.
- Data portability for data processed on the basis of consent or contract.
- Object to processing based on legitimate interest.
- Not be subject to solely automated decisions with legal or similarly significant effects.
- Withdraw consent at any time, where processing is based on consent.
If your account was created by an employer, please contact them first for requests involving your roster and session data, since they are the controller for that data and instruct us on it — we will support them (or you directly) in fulfilling the request either way. To exercise your rights or make a request, contact mathias@miradial.com. We'll verify your identity before processing any request.
You also have the right to lodge a complaint with your local data protection authority.
14. Children's privacy
MIRA is a workplace productivity tool intended for use by adult employees of business customers. It is not directed at, and we do not knowingly collect data from, children.
15. Changes to this policy
We may update this policy to reflect changes to the product or the law. We'll update the "Last updated" date above, and notify company admins of material changes.
16. Contact us
We wish to resolve disagreements through negotiations first. You have the right to file a complaint with the Data Protection Inspectorate (www.aki.ee).