Privacy Policy
Last updated: April 15, 2026
This Privacy Policy explains how the Miri app (hereinafter "the App", "we") collects, processes, and stores your personal data. By using the App, you accept the practices described below.
1. Data Controller
The data controller is the operator of the Miri App. If you have any questions about data processing, please contact us at the e-mail address listed in the "Contact" section at the bottom of this page.
2. Data We Collect
When you sign in with Google or Facebook, we receive the following data from the provider:
- Email address
- Full name (profile name)
- Profile picture URL (avatar)
- Unique Google or Facebook account ID
During use of the App, we also store:
- Body silhouette photos and wardrobe items you upload for virtual try-ons
- Virtual try-on results (generated images)
- Subscription status and credit purchase history (no payment card numbers)
- Push notification tokens (associated with a device ID)
- Operating system language and language tag
- Last activity timestamps
3. Purpose and Legal Basis for Processing
- Providing the service – account registration and authentication, performing try-ons, managing credits and subscriptions.
- Push notifications – notifying you about try-on status and offers (only if you grant permission at the OS level).
- Payment processing – recording transactions, issuing and consuming credits.
- Security – fraud detection, account blocking, re-registration cooldown after account deletion.
- Legal obligation – retaining financial transaction records as required by tax law.
4. Data Storage and Third-Party Services
Data is stored on Google Cloud infrastructure and may be shared with the following sub-processors:
- Google Cloud Storage – storage of silhouette photos, wardrobe items, and try-on results.
- Firebase Cloud Messaging – delivering push notifications to iOS and Android devices.
- Google Play Billing – handling in-app purchases (credits, subscriptions). Payment card data never reaches our servers.
- Google OAuth / Facebook OAuth – user authentication. We only exchange an authorization token; passwords are never retrieved.
5. Retention Periods
- Account data is retained until you delete your account.
- Upon deletion, personal data is anonymized (email replaced with a pseudonym, name and avatar removed, OAuth IDs cleared). Photos are permanently deleted from Google Cloud Storage.
- After anonymization, we retain only a SHA-256 hash of your email address for 30 days to prevent re-registration during the cooldown period.
- Financial transaction records may be retained for the period required by law (up to 5 years).
6. Your Rights
Under GDPR you have the following rights:
- Access – you may request a copy of your data.
- Rectification – you may correct inaccurate data.
- Erasure – you may delete your account via /account/delete. Data will be anonymized and photos permanently deleted.
- Portability – you may request an export of your data in a machine-readable format.
- Objection – you may object to processing of your data for marketing purposes.
- Complaint – you may lodge a complaint with your local data protection authority.
7. Cookies and Sessions
The mobile app does not use cookies. The web pages (privacy policy, terms of service, account deletion) may use session cookies solely to support the OAuth flow (one-time state tokens). These cookies are deleted when you close your browser.
8. Security
We use TLS encryption for all network connections, secure JWT tokens with rotation, and encryption at rest in Google Cloud Storage. User passwords are not stored — authentication is handled entirely through OAuth.
9. Children
The App is not intended for children under the age of 13. If you learn that a child has provided us with their data without parental consent, please contact us and we will delete it promptly.
10. Changes to This Policy
We will notify you of material changes to this Privacy Policy via a push notification or in-app message. Continued use of the App after a change constitutes acceptance of the updated policy.