Legal
Privacy
Policy
MIRA is the phone end of a server you run yourself — like an email app talking to your own mail server. This policy explains what the mobile apps access, why, and what never leaves your device.
The short version
MIRA is a client app for a self-hosted server that you run (a Vexillon/MIRA server). MIRA is the “phone end” of that setup — think of an email app talking to your own mail server.
- We (the publisher) do not operate a server that receives your conversations. Your messages, and any images/audio/video you send in a chat, go directly to the server address you configure — your own machine or hosting.
- We do not sell your data, show ads, or run third-party analytics or tracking in the app.
- The only data that reaches a third party is (a) what’s technically required to deliver push notifications to your device, if you enable them, and (b) if you use the optional hosted demo, the messages processed by our AI provider to generate replies — disclosed, with your consent, before the demo starts (details below).
Because you choose and control the server, the server’s own privacy practices are set by you (or whoever runs it), not by this app.
What data the app collects, and how it’s used
The MIRA app collects only what it needs to do its job — connect you to your server, generate replies, run searches you ask for, and deliver notifications. Every item below is used solely to provide the app’s functionality. None of it is used for advertising, analytics, or tracking; none of it is sold; and none of it is shared with data brokers.
- Your name (as you set it in chat) — you provide it; used to personalise the assistant’s replies.
- Photos, videos, and audio you attach to a message — you choose and attach them; sent to the server processing your message so the assistant can respond to them.
- Chat, memory, and wiki content — the messages you send and the notes and facts you save; used to carry on the conversation and to remember what you’ve asked the assistant to remember.
- Search queries — text you ask the assistant to look up; used only to return results for that request.
- Your account / user ID — the identifier for your login on the server you connect to; used to authenticate you and keep your data separate from other users on that server.
- A device push token — a delivery identifier issued by Apple (APNs) or Google (FCM), only if you enable push; used solely to deliver the notifications you’ve asked for (see Push notifications, below).
You provide or attach all message content yourself; the account ID and push token are technical identifiers the app handles automatically for sign-in and notification delivery. What happens to your message content next depends on how you use MIRA — see Where your messages are processed, below.
Where your messages are processed
MIRA is a client for a server you choose. What processes your messages, and who can see them, depends on which server you connect to.
Your own self-hosted server (the normal case)
When you connect the app to your own MIRA server, your messages and attachments go directly to that server and are processed by whatever AI backend you have configured it to use — a fully local model, or a cloud AI provider that you chose and set up. We (Vexillon) have no visibility into or control over this. The server is yours; its data practices, including any AI provider it talks to, are determined by you or whoever operates it, under that provider’s terms.
The hosted demo (optional, no account)
If you use the optional “Try the demo” experience — which needs no account — your messages are sent to a demo server we operate and are processed by OpenRouter, a third-party AI routing service, solely to generate the assistant’s reply. This is the only case in which we route your data through a third party ourselves. The app discloses this and asks for your consent before the demo begins. The demo is deliberately limited: sessions are sandboxed and temporary, and are wiped automatically.
We send OpenRouter only the message content needed to generate that reply, and only for that purpose. We have enabled OpenRouter’s Zero Data Retention for the demo: requests are routed only to model-provider endpoints that do not store your data, and any request that would require data retention is rejected. Because those endpoints do not keep your prompts, your demo messages are not retained and are not used to train any model. OpenRouter itself does not use inputs or outputs for training and does not sell personal data (see OpenRouter’s privacy policy). We do not use this data for advertising or profiling, and we do not sell it or share it with data brokers.
Equal protection. Any third party with whom this app shares user data — Apple (APNs) and Google (FCM) for push delivery, and OpenRouter for the hosted demo — is required to provide the same or equal protection of that data as stated in this policy: it is used only to provide the specific function, and never for advertising, profiling, sale, or sharing with data brokers.
What the app accesses, and why
Microphone / audio
Microphone access is requested only for the optional hands-free / wake-word feature (“Hey MIRA” and similar):
- Audio is processed on your device, in real time, to detect the wake word.
- Wake-word listening is off until you turn it on, and runs only while the hands-free screen or its listening mode is active.
- The app does not record, store, or upload this audio stream for wake-word detection.
- When you deliberately send a voice message in a chat, that audio is transmitted to your configured server, the same as any other message you send.
On both iOS/iPadOS and Android, microphone access is optional — the rest of the app works without it, and you can grant or revoke it at any time in your device’s system settings.
Network / internet
To connect to your server and to detect network changes so the app can switch between your server’s local (LAN) and remote (VPN/tunnel) addresses. Plain http:// connections are permitted only to local/private network addresses; connections to servers over the public internet are required to use https://.
Notifications and background delivery
To show notifications you’ve asked for and to keep a live chat stream running while you’re using it. On both platforms, notifications are permission-gated — you grant them on first use and can turn them off at any time in your device’s system settings.
Camera / QR pairing
MIRA can pair with your server by scanning a QR code that contains your server’s address and a one-time pairing secret. The code is processed on your device; the scanned image is not stored or sent anywhere. Where a platform’s code scanner requires camera access, it is used only for this pairing step.
Data you store, and where it lives
- Your account session (login/refresh tokens for your server) is stored encrypted on your device.
- Chat history and drafts are cached locally on your device so the app can show them quickly.
- Settings (e.g. wake-word choice and sensitivity, server list) are stored locally.
This data stays on your device and in communication with your server. Uninstalling the app removes its local data. If device backup is enabled (Apple iCloud on iOS/iPadOS, or Android Backup), non-sensitive settings may be included in that backup; sensitive credentials are excluded from backup.
Push notifications (optional)
If you enable push notifications, MIRA uses the delivery method appropriate to your platform. In every case, notification content is minimized — the app can fetch the full message from your server after waking.
- iOS / iPadOS — Apple Push Notification service (APNs). To route a notification to your device, a device push token issued by Apple is used, and notifications are delivered via Apple’s APNs infrastructure and a relay operated for this purpose. This is standard for Apple push and is subject to Apple’s Privacy Policy.
- Android — Firebase Cloud Messaging (FCM). A device push token issued by Google is used, and notifications are delivered via Google’s FCM infrastructure and a relay operated for this purpose. This is standard for Android push and is subject to Google’s Privacy Policy.
- Android — UnifiedPush (alternative). A privacy-oriented, self-hostable option: delivery goes through a distributor app that you install and choose (for example, ntfy). Your device registers an endpoint with that distributor; its operator handles delivery under their privacy terms.
If you don’t enable push, none of the above applies.
What we do not do
- We do not run third-party analytics, advertising, or tracking SDKs in the app.
- We do not sell or rent your personal data.
- We do not receive your chat content on any server operated by the publisher.
Children
MIRA is a general-purpose client for a personal AI server and is not directed at children. It includes optional “care network” roles (for example, configuring the app on behalf of a child or an older adult); this is a per-account setting sent to your server and is not used by the publisher for any other purpose.
Your choices and controls
- Microphone: wake-word listening is opt-in and can be turned off at any time; you can also revoke the microphone permission in your device’s system settings.
- Notifications: you can disable push, switch delivery method where your platform offers a choice, or turn off notifications in your device’s system settings.
- Local data: sign out to clear your session, or uninstall to remove all local app data.
- Server data: because your conversations live on your server, requests to access, export, or delete that data are handled by whoever operates that server (which may be you).
Changes to this policy
If the apps’ data practices change, we’ll update this policy and its effective date. Material changes will be reflected here before the updated app version relies on them.
Contact
Questions about this policy: privacy@vexillon.ai.