Security & data handling

We would rather tell you what we do than promise what nobody can.

No system is perfectly secure. Here is exactly how Mira handles your credentials, your data, and the third parties that touch it.

What Mira never sees

Your banking credentials

You enter them directly into a regulated bank-connection provider’s own secure interface. They never pass through Mira. We hold only a revocable access token.

Your data, for advertising

We do not sell personal information, we do not share it with advertisers or data brokers, and this policy does not reserve the right to start.

Your data, in an AI model

Mira sends nothing to an AI model provider. The assistant, receipt reading and AI-written commentary were removed before launch, so no financial summary, receipt image or holdings list leaves Mira for a model to read.

How your data is protected

Encrypted in transit and at rest

TLS on every connection, encryption at rest in the database and in file storage.

Isolation enforced at the database

Row-level access rules mean one account cannot read another’s data even if an app client were to ask for it.

Institution tokens are server-only

Access tokens are stored so that no app client can read them back — only our own server processes can use them.

Device lock

Add a Face ID, Touch ID, or passcode lock inside the app, independent of your phone’s own lock.

Session control

Review every device signed in to your account and sign the others out.

Analytics off by default

Product analytics stay off until you opt in, and never include balances, amounts, merchant names, or account numbers.

Account deletion

A completed account deletion removes your data from live systems, revokes institution access, and lets retained encrypted backups expire on the schedule described in the Privacy Policy.

Export, any time

Export visible transactions as CSV, JSON, PDF, or QFX, or download the implemented account-table archive as JSON. Eligible additional records use a verified privacy request.

Every third party that touches your data

The full list, and what each one receives. Nothing goes to an advertiser or a data broker, because we do not work with any.

ProviderWhat it doesWhat it receives
SupabaseDatabase, authentication, file storage, server functionsAll app data, encrypted at rest and in transit
VercelWebsite hosting and deliveryWeb request metadata such as IP address, browser and requested page
PlaidBank and investment account connectionsYour banking credentials (directly, never through us) and account data
GoogleOptional Google account sign-in and support mailbox hostingThe sign-in request and profile details you authorize; support message content, sender address, and any attachment you choose to email
FinnhubMarket prices and security reference dataTicker symbols and company-name search text — never your holdings, quantities, balances, or Mira account identity
Yahoo FinancePublic daily price candles and dividend-event historyPublic ticker symbols from our server — never your holdings, quantities, balances, or Mira account identity
StripeLegacy web-subscription management and billing records; no new Stripe checkout at launchExisting web subscribers’ email and billing details, which Stripe handles directly
AppleOptional Apple sign-in, App Store subscription billing, and push notification deliveryThe Apple sign-in request and authorized account identifier; App Store purchase records (not payment-card details); and, for each alert, a device token and notification text
ResendTransactional email such as invitations and alertsYour email address and the message content
PostHogProduct analytics, only if you opt inFeature usage events — no balances, amounts, or account numbers
SentryCrash and error reportingTechnical diagnostics and device information

Mira is operated from the United States and your data is processed there. Full detail is in the Privacy Policy.

Found something? Tell us.

If you believe you have found a vulnerability, write to us before disclosing it publicly. We will acknowledge you and keep you updated while we fix it.

Report a security issue