Privacy Policy
Effective: 13 August 2026
Applies to: the Mira app and mirafaceapp.com
Controller: CPLEX Management AG
Mira analyses photographs of your face. That is sensitive information, and this policy explains exactly what happens to it — what we collect, who processes it, where it is stored, how long it is kept, and how to have it erased.
1. Who we are
Mira ("Mira", "we", "us") is operated by CPLEX Management AG, a company registered in Baar, Canton of Zug, Switzerland. We are the data controller for the personal data described in this policy.
Contact: hello@miraanalysis.com
This policy covers the Mira iOS application and the website at mirafaceapp.com. It is written to meet the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
2. Age requirement
Mira is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account or uploaded photographs, email us and we will delete the account and its contents without delay.
3. What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Email address, display name, password credential or Apple sign-in identifier | You, at sign-up |
| Face data | The photographs of your face that you submit for analysis. See §4 | You, from your camera or photo library |
| Questionnaire | Your answers about goals, routine, sleep, skin and grooming | You, during onboarding |
| Analysis output | Your reports, scores, detected traits, generated renders and daily scan history | Generated from your submissions |
| Subscription | Subscription status, plan, trial state, renewal and cancellation events | Apple, via RevenueCat. We never receive your card details |
| Device and usage | Device model, OS version, app version, language, screens viewed, actions taken, crash diagnostics | Automatically, in the app |
| Advertising identifiers | Apple's identifier for advertisers and related attribution signals — only if you allow tracking | Your device, after the tracking prompt |
| Notifications | Push token for your device | Apple Push Notification service |
| Support | Anything you write to us by email | You |
4. Face data
This section describes everything we do with photographs of your face. It is the complete account of our collection, use, sharing, storage, retention and deletion of face data.
4.1 What face data we collect
We collect photographs of your face and body that you choose to submit:
- Up to three photographs for each full report: a front-facing photograph, a side-profile photograph, and a full-body or style photograph.
- One optional photograph per day for a daily scan.
We also generate and store descriptive attributes derived from those photographs — numerical scores for facial features, six anatomical proportion measurements (canthal tilt, facial symmetry, eye shape harmony, lip shape ratio, midface ratio, facial thirds), and descriptive traits including face shape, skin undertone, eye colour, hair colour and hair texture.
We do not create a facial recognition template, faceprint, biometric identifier or face signature. We do not use face data to identify you, to verify your identity, to match you against any database, or to match you against other users. The photographs are used only to produce your own written analysis.
4.2 How we collect it
You take or select the photographs yourself in the app. Nothing is collected in the background, and the camera is never accessed except while you are actively on a photo submission screen.
Before any photograph leaves your device, the app displays a dedicated consent screen that states what will be sent, names the third-party AI providers that will receive it, and requires you to affirmatively agree. If you do not agree, no photograph is uploaded and no analysis takes place.
4.3 How we use it
Face data is used for one purpose: to generate the facial analysis you requested. Specifically:
- To produce your feature scores, anatomical metrics and detected traits.
- To generate three AI renders illustrating a possible appearance.
- To write your action plan and phased roadmap.
- To display your past reports and plot your daily scan history on your trajectory chart.
4.4 Who it is shared with
Your photographs are transmitted to two third-party AI providers, acting as our processors:
| Provider | What it receives | What it does with it |
|---|---|---|
| Anthropic PBC | Your submitted photographs and questionnaire answers | Analyses them and writes your scores and assessment |
| Google LLC | Your submitted photographs | Generates the three renders of a possible appearance |
Both providers are used under commercial API agreements that contractually prohibit the use of your content to train their models, and that require confidentiality and security protections. We have satisfied ourselves that these providers offer protection for your face data equivalent to that described in this policy. They process your photographs only to return the result to us, and only for as long as is needed to do so and to meet their own limited security and abuse-monitoring obligations.
Your photographs are shared with no one else. They are not shared with advertisers, analytics providers, data brokers, or any other third party. Our product analytics and error-monitoring systems are configured to exclude photographs, photograph file paths and report contents.
4.5 Where it is stored
Photographs and derived analysis data are stored in private, per-user storage operated by Supabase Inc., encrypted in transit and at rest. Storage is not publicly accessible: files are retrieved by the app only through short-lived signed links, and database access is enforced row by row so an account can only ever reach its own records.
Some of our providers are located in the United States. Transfers are covered by the safeguards described in §8.
4.6 How long it is retained
Photographs are retained only while your account is active, so that you can view your past reports and compare your renders over time.
- When you delete your account, your photographs, renders, reports and daily scan history are deleted immediately and permanently.
- Deleted data is purged from encrypted backups within 30 days.
- We do not retain photographs after account deletion for any purpose, including analytics, model improvement or archival.
- If your subscription lapses but you keep your account, your existing data remains available to you until you delete it.
4.7 How to delete it
You can delete all of your face data at any time, without contacting us, in the app under Profile → Delete account. This is immediate and permanent, and it cannot be reversed by us or by you.
You may also email us and we will action the deletion on your behalf within 30 days.
4.8 What we never do with it
- We never use your photographs to train AI models, ours or anyone else's.
- We never use your photographs for advertising, marketing or promotion.
- We never sell, rent or trade your photographs or any data derived from them.
- We never show your photographs to other users.
- We never use your photographs to identify you or anyone else.
4.9 Your consent
Processing of your facial photographs relies on your explicit consent, given on the dedicated consent screen described in §4.2, and constituting explicit consent under Article 9(2)(a) GDPR and the corresponding provisions of the Swiss FADP.
You may withdraw that consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5. Other third-party processors
We share personal data only with service providers who process it on our behalf under written agreements. We do not sell personal data.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, file storage, authentication | Account data, photographs, questionnaire, reports |
| Anthropic | Report generation (see §4.4) | Photographs, questionnaire answers |
| Render generation (see §4.4) | Photographs | |
| Apple | Distribution, sign-in, payments, push delivery | Purchase and subscription data, push tokens |
| RevenueCat | Subscription management | Account identifier, subscription status |
| PostHog | Product analytics | Account identifier, app events, device data — no photographs |
| Sentry | Crash and error monitoring | Diagnostic data, scrubbed of personal content |
| Brevo | Account and service email | Email address |
| Meta, TikTok | Advertising measurement | Advertising identifier and install or purchase signals — only with your consent |
We may also disclose data where legally required, to enforce our terms, or to protect the rights and safety of our users. If our business is transferred, personal data may transfer with it, and this policy continues to apply until you are told otherwise.
6. Why we are allowed to use your data
| Purpose | Legal basis (GDPR) |
|---|---|
| Processing your facial photographs and deriving appearance attributes | Your explicit consent — Art. 9(2)(a), given on the consent screen described in §4.2 |
| Creating and running your account, delivering reports and scans you have paid for | Performance of a contract — Art. 6(1)(b) |
| Push notifications about your report | Contract — Art. 6(1)(b), plus your device permission |
| Product analytics, crash reporting, fraud prevention and security | Legitimate interests — Art. 6(1)(f) |
| Advertising measurement and attribution | Your consent — Art. 6(1)(a), via Apple's tracking prompt |
| Accounting, tax and legal claims | Legal obligation — Art. 6(1)(c) |
7. Analytics and advertising
We use product analytics to see where the app confuses people — which screens are reached, which steps are abandoned. This is tied to a random account identifier, never to your email address, and never to your photographs.
If you allow tracking when iOS asks, we and our advertising partners may measure whether an advert led to an install or a subscription. If you decline, no advertising identifier is collected and no advertising SDK is initialised. Change this any time in iOS Settings → Privacy & Security → Tracking.
We do not use your photographs, reports or scores for any advertising purpose, whether or not you allow tracking.
8. International transfers
We are based in Switzerland. Some providers are in the United States or other countries outside Switzerland and the European Economic Area. Where data is transferred, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses, the Swiss adequacy framework, or equivalent contractual protections. You can request a copy of the safeguards that apply.
9. Retention of other data
Face data retention is covered in §4.6. For everything else:
| Data | Retention |
|---|---|
| Account and questionnaire | While your account is active; deleted on account deletion |
| Analytics and crash data | Up to 12 months, then deleted or aggregated beyond identification |
| Billing and tax records | As required by Swiss law, normally 10 years. These contain no photographs |
| Encrypted backups | Purged on a rolling schedule, within 30 days of deletion |
10. Security
- Data is encrypted in transit and at rest.
- Storage is private per user; files are served only through short-lived signed links.
- Database access is enforced row by row, so an account can only reach its own records.
- Server credentials are held in a secrets manager and are never present in the app on your phone.
- Diagnostic logs are scrubbed of email addresses, photograph paths and report contents.
No system is perfectly secure. If a breach affects your personal data we will notify you and the competent authorities as required by law.
11. Your rights
Under the GDPR and the FADP you may:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data — immediately, in the app, or by asking us
- Restrict or object to certain processing
- Withdraw consent at any time, including consent to face-data processing and to tracking
- Receive a copy of your data in a portable, machine-readable format
- Not be subject to a decision based solely on automated processing producing legal or similarly significant effects
Email hello@miraanalysis.com to exercise any of these. We respond within 30 days, and may ask you to confirm control of your account email first.
Complaints. Tell us first and we will try to put it right. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, in the EEA or UK, to your local supervisory authority.
12. What Mira is not
Not medical advice. Mira is a cosmetic and appearance analysis tool. It is not a medical device, it does not diagnose or treat any condition, and nothing in a report substitutes for a doctor, dermatologist or other qualified professional.
Renders are illustrations, not predictions. The three potential images are AI-generated estimates produced from your photographs. They are not photographs of you, not a forecast, and not a promise of any outcome.
Scores are relative to you. A harmony score expresses progress toward your own realistic potential. It is not a universal rating, a ranking against other people, or a measure of your worth.
13. Changes to this policy
We update this policy when the app changes. The effective date at the top always shows the current version. If a change materially affects how we handle your face data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
14. Contact
CPLEX Management AG
Baar, Canton of Zug, Switzerland
hello@miraanalysis.com
Questions about this policy, requests about your data, and reports of a suspected minor account all go to the same address, and a person reads them.