Security & data handling
We would rather tell you what we do than promise what nobody can.
No system is perfectly secure. Here is exactly how Mira handles your credentials, your data, and the third parties that touch it.
What Mira never sees
Your banking credentials
You enter them directly into a regulated bank-connection provider’s own secure interface. They never pass through Mira. We hold only a revocable access token.
Your data, for advertising
We do not sell personal information, we do not share it with advertisers or data brokers, and this policy does not reserve the right to start.
Your statements, in the AI features
The assistant sends only an anonymous summary of the figures relevant to your question. Under our agreement with Anthropic, your data is not used to train their models.
How your data is protected
Encrypted in transit and at rest
TLS on every connection, encryption at rest in the database and in file storage.
Isolation enforced at the database
Row-level access rules mean one account cannot read another’s data even if an app client were to ask for it.
Institution tokens are server-only
Access tokens are stored so that no app client can read them back — only our own server processes can use them.
Device lock
Add a Face ID, Touch ID, or passcode lock inside the app, independent of your phone’s own lock.
Session control
Review every device signed in to your account and sign the others out.
Analytics off by default
Product analytics stay off until you opt in, and never include balances, amounts, merchant names, or account numbers.
Deletion that actually deletes
Deleting your account removes your data from live systems promptly, ages it out of encrypted backups within 30 days, and revokes your institution tokens at the same time.
Export, any time
CSV, JSON, PDF, or QFX from Settings → Export. Your data is never hostage.
Every third party that touches your data
The full list, and what each one receives. Nothing goes to an advertiser or a data broker, because we do not work with any.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All app data, encrypted at rest and in transit |
| Plaid | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Mastercard Open Finance | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| MX | Bank and investment account connections | Your banking credentials (directly, never through us) and account data |
| Anthropic | The in-app assistant, receipt reading, and portfolio commentary | Only the content needed for your request; not used to train models |
| Finnhub | Market prices and security reference data | Ticker symbols only — never your holdings, quantities, or identity |
| Stripe | Subscription billing on the web | Your email and payment details, which Stripe handles directly |
| Apple | Subscription billing in the App Store | Purchase records; Apple does not give us your payment details |
| Resend | Transactional email such as invitations and alerts | Your email address and the message content |
| Google Firebase | Push notification delivery | A device token and the notification text |
| PostHog | Product analytics, only if you opt in | Feature usage events — no balances, amounts, or account numbers |
| Sentry | Crash and error reporting | Technical diagnostics and device information |
Mira is operated from the United States and your data is processed there. Full detail is in the Privacy Policy.
Found something? Tell us.
If you believe you have found a vulnerability, write to us before disclosing it publicly. We will acknowledge you and keep you updated while we fix it.
Report a security issue