Privacy Policy
Mira is a web-based 3D platform for designing interiors — you upload a photo or a floorplan, and Mira turns it into an interactive 3D scene you can furnish, collaborate on, and shop from. This policy explains what information we collect when you use it, why we collect it, who we share it with, and the choices you have.
Contents
- Who we are
- Scope of this policy
- Information we collect
- How we use information
- Your content and AI features
- Connected accounts
- How we share information
- Cookies and analytics
- How long we keep information
- Security
- Where we process information
- US state privacy rights
- Children's privacy
- Third-party links and retailers
- Changes to this policy
- Contact us
1. Who we are
Mira ("Mira", "we", "us", "our") is a product of Mira Labs, Inc., a Delaware corporation located at 169 Madison Ave STE 15574, New York, NY 10016. We are the controller of the personal information described in this policy, except where we act as a processor on behalf of a business customer (see Section 2).
You can reach us any time at hello@usemira.co.
2. Scope of this policy
This policy applies to the Mira marketing site at usemira.io, the Mira application at app.usemira.io, and any related services, features, and communications (together, the "Services").
Where an organization (for example, a design studio or an employer) provides Mira to you under a business plan, that organization controls the workspace and its content. In that case we process workspace data on their instructions as a service provider or processor, and their own privacy notice governs how they use it. Direct questions about that data to your workspace administrator.
This policy does not apply to third-party websites we link to, including retailer and manufacturer sites reached through shopping features.
3. Information we collect
3.1 Information you give us
- Account information — name, email address, password (stored hashed) or the identifier from a single sign-on provider such as Google or Apple, and optional profile details like a photo or company name.
- Design content — the photos, floorplans, room dimensions, sketches, 3D scenes, furniture and material selections, project names, and version history you create or upload.
- Prompts and chat — the text instructions you send to Mira's AI features, and the outputs generated in response.
- Collaboration data — comments, invitations, shared links, and the identity of collaborators you add to a project.
- Billing information — plan, billing address, and transaction history. Card details are collected and stored by our payment processor, not by us.
- Support and other communications — messages you send us, survey and interview responses, and beta or waitlist sign-ups.
3.2 Information we collect automatically
- Usage data — pages and features viewed, actions taken in the editor, session length, referring URLs, and error events.
- Device and log data — IP address, browser type and version, operating system, device type, screen and GPU capabilities (used to select an appropriate 3D rendering path), language, and timestamps.
- Cookies and similar technologies — see Section 8.
3.3 Information from third parties
- Authentication providers, when you sign in with Google, Apple, or a similar service — typically your name, email address, and provider user ID.
- Payment processors — confirmation of payment, the last four digits of a card, and billing country.
- Analytics and marketing partners — aggregate campaign and attribution data.
- Connected accounts, when you choose to link an account you hold with another service — the account identifier, the names of the collections you select, and the items those collections contain (imagery and metadata). We ask only for the read permissions the feature needs, and we retrieve content only from the collections you pick, at the moment you ask us to. See Section 6.
- Furniture and material catalog partners — product data, imagery, pricing, and availability. These are business records, not personal information about you.
Sensitive information. We do not ask for government ID numbers, health data, precise geolocation, or biometric identifiers, and we ask that you do not upload them. Photographs of your home may show people or personal effects — please remove anything you do not want processed before uploading.
4. How we use information
| Purpose | What this means in practice |
|---|---|
| Providing the Services | Creating your account, converting your images and floorplans into 3D scenes, saving projects and versions, rendering and exporting. |
| AI features | Generating layouts, furniture suggestions, style variations, and answers to your prompts. See Section 5. |
| Collaboration | Sharing projects with people you invite and showing who changed what. |
| Shopping features | Matching items in your scene to comparable real-world products and showing prices and links. |
| Billing | Processing subscriptions, invoices, refunds, and tax. |
| Support | Responding to your questions and troubleshooting problems, which may include looking at a project you tell us about. |
| Improving the Services | Understanding which features are used, diagnosing crashes and performance issues, and testing changes — generally using aggregated or de-identified data. |
| Security and abuse prevention | Detecting fraud, spam, scraping, and unauthorized access, and enforcing our terms. |
| Communications | Sending service notices, product updates, and — where you have opted in or where permitted — marketing email you can unsubscribe from at any time. |
| Legal compliance | Meeting our legal obligations and responding to lawful requests. |
5. Your content and AI features
You own your content. The images, floorplans, prompts, and designs you bring to or create in Mira remain yours. We use them to operate the Services for you, as described above.
How AI processing works. To generate 3D scenes, layouts, and suggestions, we send the relevant content — for example an uploaded room photo or a text prompt — to AI models. Some of these run on our own infrastructure and some are operated by third-party model providers acting as our service providers under contract. Those providers are permitted to use the content only to return a result to us.
Training. We do not use your project content or your prompts to train generative models. Our third-party model providers are contractually prohibited from using them for training either — they may process your content only to return a result to us. If we ever want to change this, we will ask for your consent first; we will not switch it on by default. The same applies to anything we retrieve from a connected account: we do not use it to train, fine-tune, or otherwise develop or improve any model, and neither do our providers.
Accuracy. AI output — including dimensions, product matches, prices, and availability — can be wrong. Verify anything you rely on for a purchase or a build.
6. Connected accounts
Mira can connect to an account you already hold with another service — an image, design, or file service where you keep references and inspiration — so you can work from material you have already gathered. Throughout this section we call that service the provider, and we call a board, album, folder, or similar grouping inside it a collection. Connecting is entirely optional, always started by you, and can be undone at any time.
How the connection is made. You authorize Mira through the provider's own sign-in screen (OAuth). We never ask for, see, or store your password for that account. We request the narrowest read permissions the feature needs, and we take no action on your account — we do not post, publish, comment, follow, or change anything on your behalf.
What we access. Your account identifier and display name; the list of your collections, so you can choose which to work from; and the items inside the collections you specifically select — their imagery and their metadata, such as title, description, and source link. We do not read collections you did not select.
How we process it. When you ask Mira to work from a connected collection, we call the provider's API at that moment, process the content to produce the result you asked for — for example recognizing the style of a room or identifying a piece of furniture — and then discard it. We do not build or keep a copy of your collections, and we do not use the provider's content to build any dataset, index, catalog, or model.
What we keep. Only the access token that maintains the connection, and the work you create — your Mira scene and the choices you made in it — together with a reference identifier for the original item so that we can link back to it and credit its source. We do not retain the provider's imagery.
Attribution. Where content from a connected account is shown in Mira, we identify where it came from and link back to the original on the provider's site. We do not alter, filter, or obscure it, and we do not redistribute it.
Disconnecting. You can disconnect a linked account at any time in Mira's settings, or revoke Mira's access from within the provider's own account settings. Either way our access ends immediately, we delete the stored access token, and we purge anything still held in transient processing. Scenes you already created stay in your account, because they are your work — you can delete them separately at any time.
The provider's own rules still apply. Your account with a connected provider remains governed by that provider's terms and privacy policy. We use each provider's API only in the ways its developer policies allow, and nothing in this section grants you or us rights in content owned by someone else.
9. How long we keep information
- Account and project data — the account details, uploads, and scenes you create — for as long as your account is active.
- Content from connected accounts — not retained. It is processed transiently to produce the result you asked for and then discarded; we keep only a reference identifier so we can link back to the original. See Section 6.
- Access tokens for connected accounts — kept only while the connection is active, and deleted as soon as you disconnect or revoke access.
- Deleted projects — removed from the application immediately and purged from backups within 90 days.
- Closed accounts — deleted or de-identified within 90 days of closure, except where we must keep records longer.
- Billing and tax records — kept for the period required by law, typically seven years.
- Logs and analytics — typically retained for 12 months, then aggregated or deleted.
10. Security
We use industry-standard safeguards including encryption in transit (TLS) and at rest, access controls and least-privilege permissions for staff, logging and monitoring, and regular dependency and infrastructure review. No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.
Protect your own account by using a strong, unique password, enabling multi-factor authentication where available, and being careful with share links — anyone holding a link can open the project it points to.
11. Where we process information
We are based in the United States. Your information is processed in the United States and in the other countries where our service providers operate.
12. US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have rights to know, access, correct, delete, and obtain a portable copy of their personal information, and to appeal a refusal of a request.
In the twelve months preceding the date of this policy we collected the categories of personal information described in Section 3 (identifiers, commercial information, internet activity, audio/visual information in the form of uploaded images, and inferences), for the purposes in Section 4, and disclosed them to the categories of recipients in Section 7.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
You can access, edit, export, and delete most of your data directly in the application. For anything else, email hello@usemira.co. We will respond within the time required by applicable law (generally 30 days) and may need to verify your identity first. We will not discriminate against you for exercising these rights.
You may use an authorized agent to submit a request on your behalf, with proof of authorization.
13. Children's privacy
Mira is not directed to children. You must be at least 13 years old to create an account. We do not knowingly collect personal information from children under 13. If you believe a child has given us information, contact us and we will delete it.
14. Third-party links and retailers
Shopping features link out to retailer and manufacturer websites. Once you follow a link, that site's own privacy policy applies — we have no control over what it collects. Some links may be affiliate links, in which case we may earn a commission on a purchase; this does not change the price you pay and does not give us access to your purchase details beyond aggregate reporting.
15. Changes to this policy
We may update this policy as the Services change or the law requires. We will revise the "Last updated" date above, and for material changes we will give notice in the application or by email before they take effect. Continuing to use Mira after a change takes effect means you accept the updated policy.
16. Contact us
Questions, requests, or complaints about privacy:
Mira Labs, Inc.
169 Madison Ave STE 15574
New York, NY 10016
hello@usemira.co