Privacy policy
Effective 16 May 2026
The short version
Your photo is analyzed and deleted immediately. It never touches our servers beyond the instant of processing. Everything about your skin (observations, routine, progress) stays on your device unless you choose to create an account. If you do, it syncs to a database hosted in Frankfurt (EU). We do not sell your data. We do not share it with anyone who is not essential to running the service.
Who we are
MIRU is an independent, privacy-first skin companion. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the data controller is the operator of MIRU. For any privacy matter, including a request for the controller’s registered details, write to privacy@miru.skin and we will respond within 30 days, the statutory maximum under Article 12(3).
What we collect and why
Your photo
When you use the scan feature, you upload a photo. That photo is sent directly to our AI provider (OpenAI) for analysis and deleted from our servers immediately after the response is returned. Typically within a few seconds. We never store, cache, or log your photo. OpenAI processes it under their data processing agreement and does not use it to train their models (via our API agreement). We also send the request with retention switched off, so the image is not kept on their side for abuse monitoring either.
What the analysis reads: texture, light and the visible signals in your skin. Your skin tone is one of those inputs, deliberately. You can tell MIRU your tone before a scan, and the analysis also estimates it from the photo. A read calibrated to your own tone is more accurate than one calibrated to a single narrow band.
MIRU uses your tone to read you against yourself. It is never used to rank you, grade you, or compare you with anyone else. We do not sell it and we do not share it with advertisers.
Legal basis: legitimate interests (Article 6(1)(f) GDPR). You asked for a skin analysis, which requires processing the photo to provide it. The photo is deleted immediately, so retention is zero.
Skin observations and routine data
The result of your scan (focus area, observations, suggested routine) is stored in your browser’s local storage on this device only. It does not leave your device unless you are signed in, in which case it syncs to our Supabase database (Frankfurt, EU).
Legal basis: contract performance (Article 6(1)(b)) for signed-in users; legitimate interests for device-only storage.
Account data (if you sign in)
If you choose to create an account, we store your email address, your skin profile (skin type, concerns, onboarding answers), and your scan history in Supabase. This lets your data survive a device change.
We use magic-link email authentication, no password is created or stored. Legal basis: contract performance.
Payment data (Pro subscribers)
Payments are handled by Stripe. MIRU never sees or stores your card details. Stripe is the data controller for payment information; their privacy policy applies. We store only your subscription status (active / cancelled / trial) and its renewal date.
Email address (scan summaries)
If you choose to receive a scan summary by email, we store your email address to send it. You can ask us to delete it at any time by emailing privacy@miru.skin.
Analytics (anonymous and cookieless)
We use PostHog in a cookieless, anonymous mode to understand how people use MIRU. Which pages are visited, where people drop off, which features are used. No cookies are set, no persistent device identifier is stored, and we never call any “identify” function. Each visit is an anonymous session that is not linked to you or to other sessions. No photos. No skin observations. No name or email. No cross-site tracking.
Product analytics are off by default. Nothing is sent unless you explicitly switch analytics on (during onboarding or in Settings → Data & privacy), and you can switch them off again at any time. With analytics off, no behavioural event about you is recorded.
Separately, and regardless of that setting, MIRU keeps a small operational record of its own machinery so we can tell whether the product is working: that a scan finished or failed, how long it took, which model served it, and the failure category. Alongside it we keep an anonymous count of the product being used: that a screen was opened and which public page it was, that a scan was started or finished, that a product check was run, that a partner link was tapped. These rows carry no session identifier, no account, no cookie, no device identifier, no photo, no skin observation and no free text. Nothing is stored on or read from your device to produce them, they carry no properties beyond the fact that the thing happened, and they cannot be joined to each other or traced back to a person. We keep them because a founder who cannot see that scans are failing, or that a feature is unused, cannot fix it. Our lawful basis is legitimate interests. This is not behavioural analytics and it is never used to build a picture of you.
Error data
We use Sentry to capture technical errors so we can fix them. Before any error is reported, our code strips photos, skin observations, and email addresses. Sentry receives only technical crash data (stack traces, route names, browser version). Legal basis: legitimate interests.
Affiliate clicks
When you click a product link, the affiliate network receives a click identifier embedded in the URL. This is standard for affiliate links and is disclosed in our affiliate disclosure. No profile data, no photo, no questionnaire answers are shared with affiliate networks.
Who we share data with
We share data only with the service providers listed below, all of whom act as data processors under our agreements:
- OpenAI. Photo analysis. Photo only, deleted immediately. Hosted in the US. Standard Contractual Clauses apply.
- Supabase. Account data storage. Frankfurt (EU-Central-1).
- Stripe. Payment processing. Independent data controller for card data.
- Resend. Transactional email delivery (scan summaries, magic-link auth). Email address only.
- PostHog. Anonymous, cookieless usage analytics with no persistent identifier. Off by default; runs only if you opt in via Settings → Data & privacy.
- Sentry. Error tracking, PII stripped before transmission.
- Awin, Amazon Associates, and other affiliate networks. Click tracking only via URL parameters. No profile data.
We do not sell your data. We do not share your data with data brokers, advertisers, or any party for the purpose of targeted advertising.
How long we keep your data
- Photos: 0 days. Deleted immediately after analysis.
- Device-only data (no account):stored in your browser until you clear it or use “Erase everything” in Settings.
- Account data: kept until you delete your account. Use Settings → Erase everything, or email privacy@miru.skin.
- Subscription records: retained for the period required by applicable financial regulation (typically 7 years), after which they are deleted.
- Analytics data: anonymous and cookieless; retained by PostHog per their data retention settings (90 days on our plan).
Your rights (GDPR)
If you are in the UK or EU, you have the following rights:
- Access (Article 15): use the Export button in Settings to download everything MIRU holds about you on this device.
- Erasure (Article 17):use “Erase everything” in Settings to wipe device data. To erase account data, email privacy@miru.skin.
- Portability (Article 20): use the Export button. Data is downloaded as JSON.
- Rectification (Article 16): update your profile in Settings, or email us.
- Restriction and objection (Articles 18–21): email privacy@miru.skin.
- Object to analytics (Article 21):switch off product analytics in Settings → Data & privacy at any time. Doing so does not affect the lawfulness of any processing before then.
If you believe we have handled your data incorrectly, you have the right to lodge a complaint with your national data protection authority (in the UK: the Information Commissioner’s Office; in the EU: your member-state DPA).
Cookies and local storage
MIRU uses browser local storage (not cookies) to store your profile and scan history on your device. This is essential for the service to work; it does not require consent.
We do not use analytics cookies. Product analytics (PostHog) are cookieless and anonymous, with no persistent identifier, and they are opt-in: nothing runs until you switch analytics on in onboarding or Settings → Data & privacy, and you can switch them off again at any time.
We run no third-party affiliate script on this site. Retailer links carry a tracking parameter in the URL and nothing more, so no cross-site cookie is set from any page you visit here. Whatever the retailer does once you arrive is governed by their own policy.
International transfers
OpenAI is hosted in the United States. Transfers from the EU/UK are covered by Standard Contractual Clauses (SCCs) under our API agreement with OpenAI. All other processors listed above either operate within the EU/UK or are covered by SCCs or adequacy decisions.
Children
MIRU is intended for users aged 18 and over. We do not knowingly collect data from children under 18. If you believe a child has used MIRU, contact privacy@miru.skin and we will delete the data.
Changes to this policy
We will update this page when our data practices change. If the change is material, we will notify signed-in users by email at least 14 days before it takes effect. Continued use of MIRU after the effective date constitutes acceptance.