privacy policy

last updated: 25 July 2026

mirrah is a nervous-system regulation app for the moments right after something sets you off. this page explains, in plain language, what we collect, what we don't, and what choices you have. if anything here is unclear, email us at luna@mirrah.app and we'll explain it in even plainer language.

the short version

what stays on your device

almost everything mirrah asks you — your name, the situations that trigger you, what those moments cost you, your goals, the body sensations you tap on, the emotions you name, any journal or reflection text, and your full session history — is stored only on your phone, in a protected local file. this data:

the anonymous analytics we do collect

to understand which parts of onboarding or the exercise flow are confusing (not what you personally said or felt), mirrah sends a small number of anonymous behavioral signals to TelemetryDeck, a privacy-first analytics service. these signals are things like "a user reached this screen" or "a user completed this step" — counts, screen names, and timing, never free text.

our code has a built-in safeguard: before any signal leaves your phone, it's checked against a strict format. anything that looks like a sentence, a name, or written content — rather than a short fixed label — is automatically blocked from being sent, even if a future update accidentally tried to include it.

a note on two sensitive questions: during onboarding mirrah asks whether you identify as having ADHD and about your attachment style, so it can personalize the experience. your real answer is saved only on your device. before the "you reached this question" signal is sent anonymously for product analytics, your specific answer is replaced with just "answered" or "skipped" — the actual answer itself never reaches our analytics.

TelemetryDeck does not use advertising identifiers, does not build cross-app profiles, and is not an ad network. we cannot connect these anonymous signals back to you individually.

what we don't do

crash reporting

mirrah's codebase includes optional support for Sentry, a standard crash-reporting tool, with built-in safeguards to strip any free text before it could ever be sent. as of this policy's last update, that connection is not active — no crash data is currently being sent anywhere. if we turn it on in a future version, this page will be updated first, and the same content-free safeguards described above will already be in place.

your rights (GDPR / UK GDPR)

mirrah is available worldwide. if you're in the EU, UK, or a similar jurisdiction, here's how the data protection rules apply to what little we hold.

data controller

Yaniv Rozenblat, reachable at luna@mirrah.app, is the controller for the anonymous analytics described above. because your on-device data (journal entries, sessions, sensations) never reaches us, we are not a controller or processor for that data at all — it simply never leaves your phone.

lawful basis

the anonymous product-analytics signals are processed on the basis of our legitimate interest in understanding and improving the app, weighed against your privacy — which is why the data is anonymous and content-free by design. where consent is legally required for any future collection, we will ask for it first.

your rights

data retention

on-device data is kept for as long as the app is installed, or until you delete it yourself — whichever comes first. TelemetryDeck does not publish a fixed retention period for the anonymous signals it receives; their policy states that data is deleted once it is no longer needed for its purpose and no legal obligation requires keeping it. you can read their current policy at telemetrydeck.com/privacy.

international transfers

because on-device data never leaves your phone, there is no international transfer of it to worry about. the anonymous analytics signals go to TelemetryDeck GmbH, a company based in Augsburg, Germany, which stores usage data on servers inside the European Union. TelemetryDeck's own position is that the signals it receives are anonymous and therefore are not personal data under Article 4(1) of the GDPR. we describe them here anyway, because you deserve to know what leaves your phone regardless of how it is classified.

children's privacy

mirrah is not directed at children. it isn't intended for anyone under 13 (or under 16 in the EEA, where that's the applicable age). we don't knowingly collect data from children. if you believe a child has used the app and you have concerns, contact us at luna@mirrah.app.

changes to this policy

if this policy changes in a meaningful way, we'll update the "last updated" date at the top of this page. we won't quietly change how your data is handled without saying so here first.

questions

reach us anytime at luna@mirrah.app. for general support, see the support page.