Security & data handling
We would rather tell you what we do than promise what nobody can.
No system is perfectly secure. Here is exactly how Mira handles your credentials, your data, and the third parties that touch it.
What Mira never sees
Your banking credentials
You enter them directly into a regulated bank-connection provider’s own secure interface. They never pass through Mira. We hold only a revocable access token.
Your data, for advertising
We do not sell personal information, we do not share it with advertisers or data brokers, and this policy does not reserve the right to start.
Your data, in an AI model
Mira sends nothing to an AI model provider. The assistant, receipt reading and AI-written commentary were removed before launch, so no financial summary, receipt image or holdings list leaves Mira for a model to read.
How your data is protected
Encrypted in transit and at rest
TLS on every connection, encryption at rest in the database and in file storage.
Isolation enforced at the database
Row-level access rules mean one account cannot read another’s data even if an app client were to ask for it.
Institution tokens are server-only
Access tokens are stored so that no app client can read them back — only our own server processes can use them.
Device lock
Add a Face ID, Touch ID, or passcode lock inside the app, independent of your phone’s own lock.
Session control
Review every device signed in to your account and sign the others out.
Analytics off by default
Product analytics stay off until you opt in, and never include balances, amounts, merchant names, or account numbers.
Account deletion
A completed account deletion removes your data from live systems, revokes institution access, and lets retained encrypted backups expire on the schedule described in the Privacy Policy.
Export, any time
Export visible transactions as CSV, JSON, PDF, or QFX, or download the implemented account-table archive as JSON. Eligible additional records use a verified privacy request.
Every third party that touches your data
The full list, and what each one receives. Nothing goes to an advertiser or a data broker, because we do not work with any.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All app data, encrypted at rest and in transit |
| Vercel | Website hosting and delivery | Web request metadata such as IP address, browser and requested page |
| Plaid | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Optional Google account sign-in and support mailbox hosting | The sign-in request and profile details you authorize; support message content, sender address, and any attachment you choose to email | |
| Finnhub | Market prices and security reference data | Ticker symbols and company-name search text — never your holdings, quantities, balances, or Mira account identity |
| Yahoo Finance | Public daily price candles and dividend-event history | Public ticker symbols from our server — never your holdings, quantities, balances, or Mira account identity |
| Stripe | Legacy web-subscription management and billing records; no new Stripe checkout at launch | Existing web subscribers’ email and billing details, which Stripe handles directly |
| Apple | Optional Apple sign-in, App Store subscription billing, and push notification delivery | The Apple sign-in request and authorized account identifier; App Store purchase records (not payment-card details); and, for each alert, a device token and notification text |
| Resend | Transactional email such as invitations and alerts | Your email address and the message content |
| PostHog | Product analytics, only if you opt in | Feature usage events — no balances, amounts, or account numbers |
| Sentry | Crash and error reporting | Technical diagnostics and device information |
Mira is operated from the United States and your data is processed there. Full detail is in the Privacy Policy.
Found something? Tell us.
If you believe you have found a vulnerability, write to us before disclosing it publicly. We will acknowledge you and keep you updated while we fix it.
Report a security issue