Security & data handling

We would rather tell you what we do than promise what nobody can.

No system is perfectly secure. Here is exactly how Mira handles your credentials, your data, and the third parties that touch it.

What Mira never sees

Your banking credentials

You enter them directly into a regulated bank-connection provider’s own secure interface. They never pass through Mira. We hold only a revocable access token.

Your data, for advertising

We do not sell personal information, we do not share it with advertisers or data brokers, and this policy does not reserve the right to start.

Your statements, in the AI features

The assistant sends only an anonymous summary of the figures relevant to your question. Under our agreement with Anthropic, your data is not used to train their models.

How your data is protected

Encrypted in transit and at rest

TLS on every connection, encryption at rest in the database and in file storage.

Isolation enforced at the database

Row-level access rules mean one account cannot read another’s data even if an app client were to ask for it.

Institution tokens are server-only

Access tokens are stored so that no app client can read them back — only our own server processes can use them.

Device lock

Add a Face ID, Touch ID, or passcode lock inside the app, independent of your phone’s own lock.

Session control

Review every device signed in to your account and sign the others out.

Analytics off by default

Product analytics stay off until you opt in, and never include balances, amounts, merchant names, or account numbers.

Deletion that actually deletes

Deleting your account removes your data from live systems promptly, ages it out of encrypted backups within 30 days, and revokes your institution tokens at the same time.

Export, any time

CSV, JSON, PDF, or QFX from Settings → Export. Your data is never hostage.

Every third party that touches your data

The full list, and what each one receives. Nothing goes to an advertiser or a data broker, because we do not work with any.

ProviderWhat it doesWhat it receives
SupabaseDatabase, authentication, file storage, server functionsAll app data, encrypted at rest and in transit
PlaidBank and investment account connectionsYour banking credentials (directly, never through us) and account data
Mastercard Open FinanceBank and investment account connectionsYour banking credentials (directly, never through us) and account data
MXBank and investment account connectionsYour banking credentials (directly, never through us) and account data
AnthropicThe in-app assistant, receipt reading, and portfolio commentaryOnly the content needed for your request; not used to train models
FinnhubMarket prices and security reference dataTicker symbols only — never your holdings, quantities, or identity
StripeSubscription billing on the webYour email and payment details, which Stripe handles directly
AppleSubscription billing in the App StorePurchase records; Apple does not give us your payment details
ResendTransactional email such as invitations and alertsYour email address and the message content
Google FirebasePush notification deliveryA device token and the notification text
PostHogProduct analytics, only if you opt inFeature usage events — no balances, amounts, or account numbers
SentryCrash and error reportingTechnical diagnostics and device information

Mira is operated from the United States and your data is processed there. Full detail is in the Privacy Policy.

Found something? Tell us.

If you believe you have found a vulnerability, write to us before disclosing it publicly. We will acknowledge you and keep you updated while we fix it.

Report a security issue