Privacy Policy

Last updated: July 3, 2026

This Privacy Policy explains what information mirv ("mirv", "we", "us") collects when you use the mirv app at go.mirv.app and this website, why we collect it, and the choices you have. We aim to collect as little as possible.

mirv is operated by RATKING LABS PTY LTD (trading as "mirv"), a company incorporated in Australia. RATKING LABS PTY LTD is the controller of the personal information described in this policy.

1. Information we collect

Account information

When you register, we store the email address and password you provide. Passwords are stored only as a salted hash — never in plain text.

Your content

mirv stores the data you create in the app: lists, tasks, subtasks, notes/descriptions, due dates, board state, and related settings. This content belongs to you. We use it only to operate the service for you.

Technical data

Our servers keep standard operational logs (such as IP address, request time, and error details) needed to run the service securely and diagnose problems. We use a session cookie to keep you signed in; it is essential to the app and is not used for advertising.

2. How we use your information

We do not sell your personal data, and we do not use your content to serve advertising.

3. Cookies, analytics & advertising

Strictly necessary. mirv uses a single essential cookie (tl_session) to keep you signed in. It is set only after you log in, is marked HttpOnly and SameSite, carries no advertising or cross-site information, and is always on because the app can't function without it. If you sign out or clear it, you'll simply need to sign in again.

Performance & diagnostics. On our website and in the mobile apps we use New Relic to monitor performance, page-load and API timing, and errors so we can keep mirv fast and fix problems. This is first-party diagnostics data (device, session, timing, and error information); it is not used for advertising and is not sold or shared with data brokers. See New Relic's privacy notice.

Analytics & advertising (optional). To understand traffic and measure the ads and campaigns that bring people to mirv, we can load these third-party tools:

These analytics/advertising tools are opt-in. On the web, they do not load until you choose Accept on our cookie banner (in regions where consent is required); if you decline, only the essential session cookie is used. In the iOS and Android apps, they load only if you allow tracking when the app shows Apple's App Tracking Transparency prompt (or, on Android, subject to your system ad-personalisation setting); if you don't allow it, no advertising identifier (IDFA) is used and these tools stay off. You can change your choice at any time — on the web via Manage cookies, and on mobile in your device Settings > Privacy & Security > Tracking. We do not sell your personal data.

4. AI assistant (Mirv) and AI agent access (MCP)

mirv includes an optional in-app AI assistant ("Mirv"). Before your first chat, the app asks for your explicit permission and explains what will be shared; nothing is sent to the AI provider unless you agree, and you can withdraw that permission at any time in Settings → AI assistant privacy (Mirv will then ask again before any future chat).

When you send Mirv a message, that message — together with the workspace data the assistant looks up to answer you, which can include your list and status names, task titles and details, and notes — is sent to OpenRouter, Inc. (United States), our AI model provider, which routes the request to a large-language model to generate a reply. This happens only for the chats you choose to send. OpenRouter processes this data on our behalf as a processor, under contractual terms that require it to protect your data to the same standard we do; see OpenRouter's privacy policy for how it handles data. Neither we nor OpenRouter use your content to train AI models, and your chats are not shared with anyone else.

mirv also offers an optional integration (MCP) that lets AI assistants you control read and update your tasks through an access token you create. This only happens when you generate a token and connect a client; you can revoke a token at any time from the app.

5. Connecting an external calendar

If you choose to connect a calendar (Google Calendar, Microsoft Outlook/Microsoft 365, or an Apple/CalDAV calendar), mirv reads your calendar events and can write events you schedule, so it can fit your tasks around your existing commitments. This happens only after you explicitly connect an account and authorise access, and you can disconnect at any time from the app, which stops further syncing. We request only the calendar permissions needed for this feature and do not access other parts of your account with those providers.

6. Service providers

We rely on a small number of service providers ("processors") that process data on our behalf, solely to operate the service and under obligations to safeguard it:

These providers act as our processors. We do not sell or rent your personal data to anyone. Some processors may store or process data outside your country; where that happens we rely on appropriate safeguards such as standard contractual clauses.

7. Data retention

We keep your account and content for as long as your account is active. When you delete your account, we remove your content from our active systems promptly. Residual copies in our encrypted backups are purged on the normal backup rotation, within 30 days of deletion, and are not used for any other purpose in the meantime.

8. Your choices and rights

9. GDPR & CCPA

We aim to honor the following rights for everyone, regardless of where you live.

If you are in the European Economic Area or the UK (GDPR): RATKING LABS PTY LTD is the data controller for your information. We process it on the legal bases of performing our contract with you (running your account), our legitimate interests in securing and maintaining the service, and your consent where it applies. You have the right to access, correct, export (portability), and delete your data, to restrict or object to certain processing, and to lodge a complaint with your local data-protection authority. Your data may be processed on servers outside your country; where that happens we rely on appropriate safeguards.

If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect and how we use it (described above), to request a copy or deletion of it, and not to be discriminated against for exercising these rights. We do not sell or share your personal information, and have not done so in the past 12 months.

To exercise any of these rights, email hello@mirv.app; you can also use the in-app export and delete tools yourself at any time.

10. Security

We use industry-standard measures — encrypted connections (HTTPS), salted password hashing, and access controls — to protect your data. No method of transmission or storage is perfectly secure, but we work to keep your information safe.

11. Children

mirv is not directed to children under 13, and we do not knowingly collect their data.

12. Changes to this policy

We may update this policy from time to time. When we do, we'll revise the "Last updated" date above, and significant changes will be communicated where appropriate.

13. Contact

Questions about privacy or your data? Email hello@mirv.app, or write to RATKING LABS PTY LTD (trading as mirv), Queensland, Australia.