Privacy Policy
Last updated: July 3, 2026
This Privacy Policy explains what information mirv ("mirv", "we", "us") collects when you use the mirv app at go.mirv.app and this website, why we collect it, and the choices you have. We aim to collect as little as possible.
mirv is operated by RATKING LABS PTY LTD (trading as "mirv"), a company incorporated in Australia. RATKING LABS PTY LTD is the controller of the personal information described in this policy.
1. Information we collect
Account information
When you register, we store the email address and password you provide. Passwords are stored only as a salted hash — never in plain text.
Your content
mirv stores the data you create in the app: lists, tasks, subtasks, notes/descriptions, due dates, board state, and related settings. This content belongs to you. We use it only to operate the service for you.
Technical data
Our servers keep standard operational logs (such as IP address, request time, and error details) needed to run the service securely and diagnose problems. We use a session cookie to keep you signed in; it is essential to the app and is not used for advertising.
2. How we use your information
- To provide, maintain, and secure the app and your account.
- To respond to your support requests and communicate about the service.
- To diagnose, fix, and prevent technical problems and abuse.
We do not sell your personal data, and we do not use your content to serve advertising.
3. Cookies, analytics & advertising
Strictly necessary. mirv uses a single essential cookie
(tl_session) to keep you signed in. It is set only after you log in, is marked
HttpOnly and SameSite, carries no advertising or cross-site information, and is always on
because the app can't function without it. If you sign out or clear it, you'll simply need
to sign in again.
Performance & diagnostics. On our website and in the mobile apps we use New Relic to monitor performance, page-load and API timing, and errors so we can keep mirv fast and fix problems. This is first-party diagnostics data (device, session, timing, and error information); it is not used for advertising and is not sold or shared with data brokers. See New Relic's privacy notice.
Analytics & advertising (optional). To understand traffic and measure the ads and campaigns that bring people to mirv, we can load these third-party tools:
- Google Analytics 4 — aggregate usage and traffic statistics. See Google's privacy policy.
- Reddit Pixel & Conversions API — measures whether a visit or sign-up followed one of our Reddit ads. For sign-up measurement we share a hashed (irreversible) form of your email and similar identifiers with Reddit; we never send your tasks, notes, or other content. See Reddit's privacy policy.
- AppsFlyer (mobile apps only) — install/attribution measurement, so we can tell which campaign led to an app install. See AppsFlyer's privacy policy.
These analytics/advertising tools are opt-in. On the web, they do not load until you choose Accept on our cookie banner (in regions where consent is required); if you decline, only the essential session cookie is used. In the iOS and Android apps, they load only if you allow tracking when the app shows Apple's App Tracking Transparency prompt (or, on Android, subject to your system ad-personalisation setting); if you don't allow it, no advertising identifier (IDFA) is used and these tools stay off. You can change your choice at any time — on the web via Manage cookies, and on mobile in your device Settings > Privacy & Security > Tracking. We do not sell your personal data.
4. AI assistant (Mirv) and AI agent access (MCP)
mirv includes an optional in-app AI assistant ("Mirv"). Before your first chat, the app asks for your explicit permission and explains what will be shared; nothing is sent to the AI provider unless you agree, and you can withdraw that permission at any time in Settings → AI assistant privacy (Mirv will then ask again before any future chat).
When you send Mirv a message, that message — together with the workspace data the assistant looks up to answer you, which can include your list and status names, task titles and details, and notes — is sent to OpenRouter, Inc. (United States), our AI model provider, which routes the request to a large-language model to generate a reply. This happens only for the chats you choose to send. OpenRouter processes this data on our behalf as a processor, under contractual terms that require it to protect your data to the same standard we do; see OpenRouter's privacy policy for how it handles data. Neither we nor OpenRouter use your content to train AI models, and your chats are not shared with anyone else.
mirv also offers an optional integration (MCP) that lets AI assistants you control read and update your tasks through an access token you create. This only happens when you generate a token and connect a client; you can revoke a token at any time from the app.
5. Connecting an external calendar
If you choose to connect a calendar (Google Calendar, Microsoft Outlook/Microsoft 365, or an Apple/CalDAV calendar), mirv reads your calendar events and can write events you schedule, so it can fit your tasks around your existing commitments. This happens only after you explicitly connect an account and authorise access, and you can disconnect at any time from the app, which stops further syncing. We request only the calendar permissions needed for this feature and do not access other parts of your account with those providers.
6. Service providers
We rely on a small number of service providers ("processors") that process data on our behalf, solely to operate the service and under obligations to safeguard it:
- Hosting & database: Railway and its managed PostgreSQL host the app and store your account and content.
- Email delivery: Resend sends transactional email — such as password-reset and email-verification messages — which necessarily includes your email address. We do not use it to send marketing.
- AI assistant (only if you opt in): OpenRouter, Inc. processes the messages you send to the Mirv assistant and the workspace data needed to answer them, as described in section 4 — and only after you give your permission in the app.
- Calendar providers: when you connect a calendar, Google, Microsoft, or your chosen Apple/CalDAV host process the calendar data you sync. They are your own accounts with those providers; mirv only exchanges the data needed to keep your tasks and calendar in step.
- Analytics & advertising (only if you opt in): if you accept our cookie banner, Google (Google Analytics) and Reddit (pixel and Conversions API) receive the usage and ad-measurement data described in section 3. Until you accept, nothing is shared with them, and you can withdraw consent at any time.
These providers act as our processors. We do not sell or rent your personal data to anyone. Some processors may store or process data outside your country; where that happens we rely on appropriate safeguards such as standard contractual clauses.
7. Data retention
We keep your account and content for as long as your account is active. When you delete your account, we remove your content from our active systems promptly. Residual copies in our encrypted backups are purged on the normal backup rotation, within 30 days of deletion, and are not used for any other purpose in the meantime.
8. Your choices and rights
- Export & portability: you can download a complete, machine-readable copy of all the personal data in your account — including tasks, notes, attachments, journal, habits, goals, calendar links and settings — from inside the app (Settings → Backup → Download all my data) at any time.
- Access & correction: you can view and edit your content directly in the app.
- Deletion: you can permanently delete your account and all of its content yourself from inside the app (Settings → Delete account), or email us and we'll do it for you.
9. GDPR & CCPA
We aim to honor the following rights for everyone, regardless of where you live.
If you are in the European Economic Area or the UK (GDPR): RATKING LABS PTY LTD is the data controller for your information. We process it on the legal bases of performing our contract with you (running your account), our legitimate interests in securing and maintaining the service, and your consent where it applies. You have the right to access, correct, export (portability), and delete your data, to restrict or object to certain processing, and to lodge a complaint with your local data-protection authority. Your data may be processed on servers outside your country; where that happens we rely on appropriate safeguards.
If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect and how we use it (described above), to request a copy or deletion of it, and not to be discriminated against for exercising these rights. We do not sell or share your personal information, and have not done so in the past 12 months.
To exercise any of these rights, email hello@mirv.app; you can also use the in-app export and delete tools yourself at any time.
10. Security
We use industry-standard measures — encrypted connections (HTTPS), salted password hashing, and access controls — to protect your data. No method of transmission or storage is perfectly secure, but we work to keep your information safe.
11. Children
mirv is not directed to children under 13, and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "Last updated" date above, and significant changes will be communicated where appropriate.
13. Contact
Questions about privacy or your data? Email hello@mirv.app, or write to RATKING LABS PTY LTD (trading as mirv), Queensland, Australia.