Privacy Policy
Effective August 9, 2026
Mira is a personal finance app. It only works because you trust it with information about your money, so this policy is written to be read rather than to be survived. It explains what we collect, why, who else touches it, and what you can make us do about it.
The short version
- We do not sell your personal information. We never have and this policy does not reserve the right to start.
- We do not use your financial data for advertising, and we do not share it with advertisers or data brokers.
- We never receive your bank username or password. Those go directly to a regulated bank-connection provider, not to us.
- You can export everything and delete your account from inside the app, at any time.
Who we are
Mira Money provides the Mira app and this website. For any privacy question or request, write to privacy@miramoney.app.
What we collect
Information you give us
- Account details — your email address, your name if you provide one, and your password (stored only as a cryptographic hash, never in readable form). If you sign in with Apple or Google we receive a confirmed identifier from them instead of a password.
- Financial information you enter — manual accounts and balances, transactions, categories, tags, rules, budgets, goals, income streams, property and vehicle details, IOUs and the names of people you split expenses with, and any notes you write.
- Receipt images, if you choose to capture or upload them.
- Messages you send to the in-app assistant.
- Household information — if you invite someone to a household, we process the email address you supply in order to send the invitation.
Information from your connected financial institutions
When you link an account, we receive from our bank-connection providers: account names, types, balances, currency, and masked account numbers; transaction history (typically up to 24 months at first connection) including amounts, dates, and merchant descriptions; investment holdings, cost basis and tax lots, dividends, and options positions; and liability details such as statement balances, minimum payments, and due dates.
We never see or store your online banking credentials. You enter them directly into the provider’s own secure interface. We hold only a revocable access token, and that token is stored so that it cannot be read back by any app client — only our own server processes can use it.
Information collected automatically
- Product analytics — only if you turn them on. Analytics are off by default and stay off until you opt in under Settings → Privacy. When enabled, we record which features you use — for example that you started connecting a bank, or that a paywall was shown — along with device type and app version. These events include the name of an institution you connect. They do not include your balances, transaction amounts, merchant names, or account numbers.
- Crash and error reports — technical diagnostics when something goes wrong, including device model, OS version, and a stack trace.
- Session records — the devices signed in to your account, so you can review them and sign other devices out.
Why we use it, and our legal basis
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Providing the app: syncing accounts, categorising, budgeting, reporting | Performance of our contract with you |
| Connecting to your financial institutions | Your consent, given at the point you link each account |
| AI features: the assistant, receipt reading, portfolio commentary | Your consent, given by choosing to use the feature |
| Notifications and alerts you have enabled | Performance of our contract; consent for optional marketing |
| Security, fraud prevention, and abuse investigation | Our legitimate interest in operating a secure service |
| Product analytics | Your consent — analytics are off unless you enable them |
| Crash and error reporting | Our legitimate interest in a working, diagnosable app |
| Billing, tax, and accounting records | Compliance with a legal obligation |
Who we share it with
We share personal information only with the service providers that make the app function, and only to the extent each one needs. They are contractually bound to protect it and to use it solely for the service they provide to us.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All app data, encrypted at rest and in transit |
| Plaid | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Mastercard Open Finance (Finicity) | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| MX | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Anthropic | The in-app assistant, receipt reading, and portfolio commentary | Only the content needed for your request — see “AI features” below |
| Finnhub | Market prices and security reference data | Ticker symbols only — never your holdings, quantities, or identity |
| Stripe | Subscription billing on the web | Your email and payment details, which Stripe handles directly |
| Apple | Subscription billing in the App Store | Purchase records; Apple does not give us your payment details |
| Resend | Transactional email such as invitations and alerts | Your email address and the message content |
| Google Firebase | Push notification delivery | A device token and the notification text |
| PostHog | Product analytics, only if you opt in | Feature usage events — no balances, amounts, or account numbers |
| Sentry | Crash and error reporting | Technical diagnostics and device information |
We may also disclose information if the law requires it, to enforce our terms, to protect someone’s safety, or in connection with a merger or acquisition — in which case we will tell you before your information becomes subject to a different policy.
AI features
Three features send data to Anthropic’s API to work: the assistant, receipt reading, and portfolio commentary. Each sends only what that request needs — a summary of the financial figures relevant to your question, the image of a receipt you chose to capture, or your portfolio’s holdings. Under our agreement with Anthropic, your data is not used to train their models. If you would rather not use these features, simply do not use them; the rest of the app is unaffected.
Household sharing
If you join a household, other members see only the accounts you have explicitly chosen to share, and only what their role allows. Sharing is off by default and per-account. A change log records who changed shared financial data, so household members can see what happened and when. You can stop sharing an account or leave a household at any time.
How long we keep it
We keep your information for as long as your account is open. When you delete your account we delete your personal data from our live systems promptly, and it ages out of encrypted backups within 30 days. We revoke the access tokens for your connected institutions at the same time. We retain the minimum billing and tax records that law requires us to keep, and anonymous aggregate statistics that cannot be traced back to you.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. The app has export and account-deletion built in, so you do not have to ask us for the common cases.
- Export — Settings → Export produces your data as CSV, JSON, PDF, or QFX.
- Delete — Settings → Account → Delete account removes your account and data.
- California residents may exercise rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising a right.
- UK and EU residents may exercise rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and may complain to your local supervisory authority.
To make a request, write to privacy@miramoney.app. We will verify that the request comes from you and respond within the time the applicable law allows.
Security
Data is encrypted in transit (TLS) and at rest. Access to your records is enforced at the database level, so one account cannot read another’s data even if an app were to ask for it. Institution access tokens are readable only by our server processes. You can add a Face ID, Touch ID, or passcode lock in the app, review your active sessions, and sign other devices out. No system is perfectly secure, but we would rather tell you what we do than promise what nobody can.
Where your data is processed
Mira is operated from the United States and your information is processed there. If you use Mira from outside the US, you are sending your information to a country whose data protection laws may differ from your own. Where required, we rely on the European Commission’s standard contractual clauses with our processors.
Children
Mira is not directed to children and is not for use by anyone under 13. We do not knowingly collect information from children under 13. A household owner may create a limited, scoped view for a family member; the household owner remains responsible for that use. If you believe a child has given us information, contact us and we will delete it.
Changes
If we change this policy we will update the date at the top, and for anything material we will tell you in the app or by email before it takes effect.
Contact
Privacy questions and requests: privacy@miramoney.app. Anything else: support@miramoney.app.