Skip to content

Privacy Policy

Effective: 13 August 2026

Applies to: the Mira app and mirafaceapp.com

Controller: CPLEX Management AG

Mira analyses photographs of your face. That is sensitive information, and this policy explains exactly what happens to it — what we collect, who processes it, where it is stored, how long it is kept, and how to have it erased.

1. Who we are

Mira ("Mira", "we", "us") is operated by CPLEX Management AG, a company registered in Baar, Canton of Zug, Switzerland. We are the data controller for the personal data described in this policy.

Contact: hello@miraanalysis.com

This policy covers the Mira iOS application and the website at mirafaceapp.com. It is written to meet the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).

2. Age requirement

Mira is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account or uploaded photographs, email us and we will delete the account and its contents without delay.

3. What we collect

CategoryWhat it isWhere it comes from
AccountEmail address, display name, password credential or Apple sign-in identifierYou, at sign-up
Face dataThe photographs of your face that you submit for analysis. See §4You, from your camera or photo library
QuestionnaireYour answers about goals, routine, sleep, skin and groomingYou, during onboarding
Analysis outputYour reports, scores, detected traits, generated renders and daily scan historyGenerated from your submissions
SubscriptionSubscription status, plan, trial state, renewal and cancellation eventsApple, via RevenueCat. We never receive your card details
Device and usageDevice model, OS version, app version, language, screens viewed, actions taken, crash diagnosticsAutomatically, in the app
Advertising identifiersApple's identifier for advertisers and related attribution signals — only if you allow trackingYour device, after the tracking prompt
NotificationsPush token for your deviceApple Push Notification service
SupportAnything you write to us by emailYou

4. Face data

This section describes everything we do with photographs of your face. It is the complete account of our collection, use, sharing, storage, retention and deletion of face data.

4.1 What face data we collect

We collect photographs of your face and body that you choose to submit:

  • Up to three photographs for each full report: a front-facing photograph, a side-profile photograph, and a full-body or style photograph.
  • One optional photograph per day for a daily scan.

We also generate and store descriptive attributes derived from those photographs — numerical scores for facial features, six anatomical proportion measurements (canthal tilt, facial symmetry, eye shape harmony, lip shape ratio, midface ratio, facial thirds), and descriptive traits including face shape, skin undertone, eye colour, hair colour and hair texture.

We do not create a facial recognition template, faceprint, biometric identifier or face signature. We do not use face data to identify you, to verify your identity, to match you against any database, or to match you against other users. The photographs are used only to produce your own written analysis.

4.2 How we collect it

You take or select the photographs yourself in the app. Nothing is collected in the background, and the camera is never accessed except while you are actively on a photo submission screen.

Before any photograph leaves your device, the app displays a dedicated consent screen that states what will be sent, names the third-party AI providers that will receive it, and requires you to affirmatively agree. If you do not agree, no photograph is uploaded and no analysis takes place.

4.3 How we use it

Face data is used for one purpose: to generate the facial analysis you requested. Specifically:

  • To produce your feature scores, anatomical metrics and detected traits.
  • To generate three AI renders illustrating a possible appearance.
  • To write your action plan and phased roadmap.
  • To display your past reports and plot your daily scan history on your trajectory chart.

4.4 Who it is shared with

Your photographs are transmitted to two third-party AI providers, acting as our processors:

ProviderWhat it receivesWhat it does with it
Anthropic PBCYour submitted photographs and questionnaire answersAnalyses them and writes your scores and assessment
Google LLCYour submitted photographsGenerates the three renders of a possible appearance

Both providers are used under commercial API agreements that contractually prohibit the use of your content to train their models, and that require confidentiality and security protections. We have satisfied ourselves that these providers offer protection for your face data equivalent to that described in this policy. They process your photographs only to return the result to us, and only for as long as is needed to do so and to meet their own limited security and abuse-monitoring obligations.

Your photographs are shared with no one else. They are not shared with advertisers, analytics providers, data brokers, or any other third party. Our product analytics and error-monitoring systems are configured to exclude photographs, photograph file paths and report contents.

4.5 Where it is stored

Photographs and derived analysis data are stored in private, per-user storage operated by Supabase Inc., encrypted in transit and at rest. Storage is not publicly accessible: files are retrieved by the app only through short-lived signed links, and database access is enforced row by row so an account can only ever reach its own records.

Some of our providers are located in the United States. Transfers are covered by the safeguards described in §8.

4.6 How long it is retained

Photographs are retained only while your account is active, so that you can view your past reports and compare your renders over time.

  • When you delete your account, your photographs, renders, reports and daily scan history are deleted immediately and permanently.
  • Deleted data is purged from encrypted backups within 30 days.
  • We do not retain photographs after account deletion for any purpose, including analytics, model improvement or archival.
  • If your subscription lapses but you keep your account, your existing data remains available to you until you delete it.

4.7 How to delete it

You can delete all of your face data at any time, without contacting us, in the app under Profile → Delete account. This is immediate and permanent, and it cannot be reversed by us or by you.

You may also email us and we will action the deletion on your behalf within 30 days.

4.8 What we never do with it

  • We never use your photographs to train AI models, ours or anyone else's.
  • We never use your photographs for advertising, marketing or promotion.
  • We never sell, rent or trade your photographs or any data derived from them.
  • We never show your photographs to other users.
  • We never use your photographs to identify you or anyone else.

4.9 Your consent

Processing of your facial photographs relies on your explicit consent, given on the dedicated consent screen described in §4.2, and constituting explicit consent under Article 9(2)(a) GDPR and the corresponding provisions of the Swiss FADP.

You may withdraw that consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5. Other third-party processors

We share personal data only with service providers who process it on our behalf under written agreements. We do not sell personal data.

ProviderWhat it doesWhat it receives
SupabaseDatabase, file storage, authenticationAccount data, photographs, questionnaire, reports
AnthropicReport generation (see §4.4)Photographs, questionnaire answers
GoogleRender generation (see §4.4)Photographs
AppleDistribution, sign-in, payments, push deliveryPurchase and subscription data, push tokens
RevenueCatSubscription managementAccount identifier, subscription status
PostHogProduct analyticsAccount identifier, app events, device data — no photographs
SentryCrash and error monitoringDiagnostic data, scrubbed of personal content
BrevoAccount and service emailEmail address
Meta, TikTokAdvertising measurementAdvertising identifier and install or purchase signals — only with your consent

We may also disclose data where legally required, to enforce our terms, or to protect the rights and safety of our users. If our business is transferred, personal data may transfer with it, and this policy continues to apply until you are told otherwise.

6. Why we are allowed to use your data

PurposeLegal basis (GDPR)
Processing your facial photographs and deriving appearance attributesYour explicit consent — Art. 9(2)(a), given on the consent screen described in §4.2
Creating and running your account, delivering reports and scans you have paid forPerformance of a contract — Art. 6(1)(b)
Push notifications about your reportContract — Art. 6(1)(b), plus your device permission
Product analytics, crash reporting, fraud prevention and securityLegitimate interests — Art. 6(1)(f)
Advertising measurement and attributionYour consent — Art. 6(1)(a), via Apple's tracking prompt
Accounting, tax and legal claimsLegal obligation — Art. 6(1)(c)

7. Analytics and advertising

We use product analytics to see where the app confuses people — which screens are reached, which steps are abandoned. This is tied to a random account identifier, never to your email address, and never to your photographs.

If you allow tracking when iOS asks, we and our advertising partners may measure whether an advert led to an install or a subscription. If you decline, no advertising identifier is collected and no advertising SDK is initialised. Change this any time in iOS Settings → Privacy & Security → Tracking.

We do not use your photographs, reports or scores for any advertising purpose, whether or not you allow tracking.

8. International transfers

We are based in Switzerland. Some providers are in the United States or other countries outside Switzerland and the European Economic Area. Where data is transferred, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, the Swiss adequacy framework, or equivalent contractual protections. You can request a copy of the safeguards that apply.

9. Retention of other data

Face data retention is covered in §4.6. For everything else:

DataRetention
Account and questionnaireWhile your account is active; deleted on account deletion
Analytics and crash dataUp to 12 months, then deleted or aggregated beyond identification
Billing and tax recordsAs required by Swiss law, normally 10 years. These contain no photographs
Encrypted backupsPurged on a rolling schedule, within 30 days of deletion

10. Security

  • Data is encrypted in transit and at rest.
  • Storage is private per user; files are served only through short-lived signed links.
  • Database access is enforced row by row, so an account can only reach its own records.
  • Server credentials are held in a secrets manager and are never present in the app on your phone.
  • Diagnostic logs are scrubbed of email addresses, photograph paths and report contents.

No system is perfectly secure. If a breach affects your personal data we will notify you and the competent authorities as required by law.

11. Your rights

Under the GDPR and the FADP you may:

  • Access the personal data we hold about you
  • Correct data that is inaccurate or incomplete
  • Delete your data — immediately, in the app, or by asking us
  • Restrict or object to certain processing
  • Withdraw consent at any time, including consent to face-data processing and to tracking
  • Receive a copy of your data in a portable, machine-readable format
  • Not be subject to a decision based solely on automated processing producing legal or similarly significant effects

Email hello@miraanalysis.com to exercise any of these. We respond within 30 days, and may ask you to confirm control of your account email first.

Complaints. Tell us first and we will try to put it right. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, in the EEA or UK, to your local supervisory authority.

12. What Mira is not

Not medical advice. Mira is a cosmetic and appearance analysis tool. It is not a medical device, it does not diagnose or treat any condition, and nothing in a report substitutes for a doctor, dermatologist or other qualified professional.

Renders are illustrations, not predictions. The three potential images are AI-generated estimates produced from your photographs. They are not photographs of you, not a forecast, and not a promise of any outcome.

Scores are relative to you. A harmony score expresses progress toward your own realistic potential. It is not a universal rating, a ranking against other people, or a measure of your worth.

13. Changes to this policy

We update this policy when the app changes. The effective date at the top always shows the current version. If a change materially affects how we handle your face data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

14. Contact

CPLEX Management AG
Baar, Canton of Zug, Switzerland
hello@miraanalysis.com

Questions about this policy, requests about your data, and reports of a suspected minor account all go to the same address, and a person reads them.