Privacy Policy
This Privacy Policy describes how Mirra AI (“Mirra”, “we”) collects, uses, stores, and protects the personal data of the users (“you”) of its content automation platform. By using Mirra AI, you agree to the practices described here.
Mirra AI is operated by Victor Capobianco Janikian, an individual, in Brazil, and is subject to the Brazilian General Data Protection Law (Law No. 13,709/2018 — “LGPD”).
Territorial scope. Mirra AI is intended for users located in Brazil and is governed by Brazilian law. We do not target or offer the service to users in the European Union, the United Kingdom, or the United States, and we do not intend to subject ourselves to the data protection regimes of those jurisdictions (such as the GDPR or the CCPA). If you access Mirra from outside Brazil, you do so on your own initiative and are responsible for compliance with your local laws.
1. Data we collect
Data you provide to us:
- Registration: name, email, password (stored in encrypted form), and country.
- Content you create: the briefs, editorial parameters, themes, texts, and settings you enter to generate content. This data is yours and is used solely to operate the service you have contracted.
- Integration credentials: when you connect your third-party accounts (such as WordPress, Instagram, or Facebook) so that Mirra can publish on your behalf, we store the necessary access tokens. These tokens are stored encrypted at rest and are not accessible to third parties.
Data collected automatically:
- Usage data and logs: access and activity records on the platform, collected for the security and functioning of the service.
- Cookies and analytics: we use cookies essential to the functioning of the platform and traffic analysis tools, such as Google Analytics, to understand platform usage and improve it.
2. How we use your data
We use your data to: create and manage your account; operate the automatic content generation and publishing service; process payments; publish content to the accounts you connect; ensure the security of the platform; and comply with legal obligations.
The legal basis for this processing is, as applicable, the performance of the contract with you, compliance with a legal obligation, and our legitimate interest in operating and protecting the service.
3. Sharing with third parties
We do not sell your data, we do not share it for third-party advertising purposes, and we do not disclose it to anyone who is not essential to operating the service.
To function, Mirra uses the following providers (processors), which handle data strictly in accordance with our instructions:
- OpenAI — to generate texts and images. The briefs and parameters you create are sent to the OpenAI API to produce the content. In accordance with the OpenAI API policy, this data is not used to train its models.
- Stripe — to process payments. Payment data (such as card details) is handled directly by Stripe; Mirra does not store your full card data.
- Microsoft Azure — for hosting, data storage, and operation of the platform’s infrastructure. Data is stored in Microsoft data centers, which may be located outside Brazil.
- Google Analytics — to analyze traffic and platform usage, in order to understand and improve it.
Some of these providers may process data outside Brazil. In such cases, the international transfer is carried out based on the grounds authorized by the LGPD, seeking to ensure an adequate level of protection for your data.
4. How long we keep your data
We keep your personal data for as long as your account is active and for as long as it is necessary to provide the service.
If you close your account, we delete or anonymize your personal data, except for data we are required to retain by legal obligation:
- Access records (logs): kept for a minimum of 6 months, in accordance with the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014).
- Transaction and payment data: kept for the period required by tax and accounting legislation (as a rule, 5 years).
After these periods, the data is deleted.
5. Your rights as a data subject
Under the LGPD, you may, at any time: confirm the existence of processing; access your data; correct incomplete or outdated data; request the anonymization or deletion of unnecessary data; request portability; withdraw consent; and obtain information about the sharing of your data.
To exercise any of these rights, contact us at support@mirraai.net.
6. Security
We adopt technical and administrative measures to protect your data, including encryption of passwords and access tokens at rest, and access control. No system is 100% secure, but we work to reduce risks and to respond to any incidents in accordance with the law.
7. Minimum age
Mirra AI is intended for individuals aged 18 or older. We do not intentionally collect data from individuals under 18. If we identify such a registration, we may suspend it.
8. Data Protection Officer (DPO)
The officer responsible for the processing of personal data at Mirra AI is:
Victor Capobianco Janikian — Founder Email: info@mirraai.net
9. Changes to this policy
We may update this Policy periodically. Material changes will be communicated through our channels. The date of the last update is shown at the top of this document.
10. Contact
For questions, requests, or the exercise of rights relating to your personal data: Email: info@mirraai.net
