Legal
Privacy Policy
Effective August 9, 2026
Mira is a personal finance app. It only works because you trust it with information about your money, so this policy is written to be read rather than to be survived. It explains what we collect, why, who else touches it, and what you can make us do about it.
The short version
- We do not sell your personal information. We never have and this policy does not reserve the right to start.
- We do not use your financial data for advertising, and we do not share it with advertisers or data brokers.
- We never receive your bank username or password. Those go directly to a regulated bank-connection provider, not to us.
- You can export transactions, download an account archive, and delete your account from inside the app at any time. Other eligible records are available through a verified privacy request.
Who we are
Sara Ventures LLC provides the Mira app and this website. For any privacy question or request, write to privacy@miramoney.app.
What we collect
Information you give us
- Account details — your email address, your name if you provide one, and your password (stored only as a cryptographic hash, never in readable form). If you sign in with Apple or Google we receive a confirmed identifier from them instead of a password.
- Financial information you enter — manual accounts and balances, transactions, categories, tags, rules, budgets, goals, income streams, property and vehicle details, IOUs and the names of people you split expenses with, and any notes you write.
- Household information — if you invite someone to a household, we process the email address you supply in order to send the invitation.
- Support correspondence — when you email one of Mira's support, privacy, or general mailboxes, we receive your sender address, message content, and any attachment you choose to include. Do not send passwords, one-time codes, bank credentials, full statements, or full payment receipts by ordinary email.
Information from your connected financial institutions
When you link an account, we receive from our bank-connection provider: account names, types, balances, currency, and masked account numbers; transaction history (typically up to 24 months at first connection) including amounts, dates, and merchant descriptions; investment holdings, cost basis and tax lots, dividends, and options positions; and liability details such as statement balances, minimum payments, and due dates.
We never see or store your online banking credentials. You enter them directly into the provider’s own secure interface. We hold only a revocable access token, and that token is stored so that it cannot be read back by any app client — only our own server processes can use it.
Information collected automatically
- Product analytics — only if you turn them on. Analytics are off by default and stay off until you opt in under Settings → Privacy. When enabled, we record which features you use — for example that you started connecting a bank, or that a paywall was shown — along with device type and app version. Institution names are not sent to PostHog. These events do not include your balances, transaction amounts, merchant names, or account numbers.
- Crash and error reports — technical diagnostics when something goes wrong, including device model, OS version, and a stack trace.
- Session records — the devices signed in to your account, so you can review them and sign other devices out.
Why we use it, and our legal basis
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Providing the app: syncing accounts, categorising, budgeting, reporting | Performance of our contract with you |
| Connecting to your financial institutions | Your consent, given at the point you link each account |
| Notifications and alerts you have enabled | Performance of our contract; consent for optional marketing |
| Security, fraud prevention, and abuse investigation | Our legitimate interest in operating a secure service |
| Product analytics | Your consent — analytics are off unless you enable them |
| Crash and error reporting | Our legitimate interest in a working, diagnosable app |
| Billing, tax, and accounting records | Compliance with a legal obligation |
Who we share it with
We share personal information only with the service providers that make the app function, and only to the extent each one needs. They are contractually bound to protect it and to use it solely for the service they provide to us.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All app data, encrypted at rest and in transit |
| Vercel | Website hosting and delivery | Web request metadata such as IP address, browser and requested page |
| Plaid | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Optional Google account sign-in and support mailbox hosting | The sign-in request and profile details you authorize; support message content, sender address, and any attachment you choose to email | |
| Finnhub | Market prices and security reference data | Ticker symbols and company-name search text — never your holdings, quantities, balances, or Mira account identity |
| Yahoo Finance | Public daily price candles and dividend-event history | Public ticker symbols from our server — never your holdings, quantities, balances, or Mira account identity |
| Stripe | Legacy web-subscription management and billing records; no new Stripe checkout at launch | Existing web subscribers’ email and billing details, which Stripe handles directly |
| Apple | Optional Apple sign-in, App Store subscription billing, and push notification delivery | The Apple sign-in request and authorized account identifier; App Store purchase records (not payment-card details); and, for each alert, a device token and notification text |
| Resend | Transactional email such as invitations and alerts | Your email address and the message content |
| PostHog | Product analytics, only if you opt in | Feature usage events — no balances, amounts, or account numbers |
| Sentry | Crash and error reporting | Technical diagnostics and device information |
We may also disclose information if the law requires it, to enforce our terms, to protect someone’s safety, or in connection with a merger or acquisition — in which case we will tell you before your information becomes subject to a different policy.
Artificial intelligence
Mira does not send your financial data to any AI model provider. Earlier versions offered an assistant, receipt reading and AI-written portfolio commentary, each of which called a third-party model. Those features and their model calls were removed before launch, and the assistant conversations they had stored were deleted in September 2026. What that provider may still hold from the earlier calls is governed by its own retention terms, which we do not control. Everything the app now tells you — insights, the portfolio narrative, categorisation — is computed from your own records by code, not generated.
Household sharing
If you join a household, other members see only the accounts you have explicitly chosen to share, and only what their role allows. Sharing is off by default and per-account. A change log records who changed shared financial data, so household members can see what happened and when. You can stop sharing an account or leave a household at any time.
How long we keep it
We keep your information for as long as your account is open. When you delete your account we delete your personal data from our live systems promptly, and it ages out of encrypted backups within 30 days. We revoke the access tokens for your connected institutions at the same time. We retain the minimum billing and tax records that law requires us to keep, and anonymous aggregate statistics that cannot be traced back to you.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. The app has export and account-deletion built in, so you do not have to ask us for the common cases.
- Transaction exports — Settings → Your data → Export your data produces the transactions you can view, filtered by date/account/category if you choose, as CSV, JSON, PDF, or QFX.
- Account archive — Settings → Your data → Download full account archive produces a full JSON account archive of the current app tables implemented by that archive. It intentionally excludes security secrets and credentials: PIN hashes and salts, invite tokens, full purchase receipts, provider access and refresh tokens, and device push tokens.
- Additional records — for eligible additional records not included in the self-service archive, write to privacy@miramoney.app. We verify your identity before releasing records and respond within the time that applies to the request.
- Delete — Settings → Personal info → Delete account removes your account and data immediately. There is no grace period and it cannot be undone, so export first if you want a copy.
- California residents may exercise rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising a right.
- UK and EU residents may exercise rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and may complain to your local supervisory authority.
To make a request, write to privacy@miramoney.app. We will verify that the request comes from you and respond within the time the applicable law allows.
Security
Data is encrypted in transit (TLS) and at rest. Access to your records is enforced at the database level, so one account cannot read another’s data even if an app were to ask for it. Institution access tokens are readable only by our server processes. You can add a Face ID, Touch ID, or passcode lock in the app, review your active sessions, and sign other devices out. No system is perfectly secure, but we would rather tell you what we do than promise what nobody can.
Where your data is processed
Mira is operated from the United States and your information is processed there. If you use Mira from outside the US, you are sending your information to a country whose data protection laws may differ from your own. Where required, we rely on the European Commission’s standard contractual clauses with our processors.
Children
Mira is not directed to children and is not for use by anyone under 13. We do not knowingly collect information from children under 13. A household owner may create a limited, scoped view for a family member; the household owner remains responsible for that use. If you believe a child has given us information, contact us and we will delete it.
Changes
If we change this policy we will update the date at the top, and for anything material we will tell you in the app or by email before it takes effect.
Contact
Privacy questions and requests: privacy@miramoney.app. Anything else: support@miramoney.app.