Legal
Privacy Policy
Last updated 23 July 2026
Draft product policies for preview. Replace placeholder operator details and have counsel review before public launch.
1. Who we are
Mirrel is operated by [Operator Name]. For privacy requests contact support@mirrel.me. This Policy explains how we process personal data when you use the Service in the EU/EEA, UK, and United States.
2. What we process
Depending on how you use Mirrel, we may process:
- Wardrobe images and metadata you upload (stored in your Mirrel account via Supabase, scoped to your user)
- Snapshots — camera and try-on captures you save from the camera or live try-on (stored in your account)
- Account preferences such as display name, plan selection UI state, and settings (some drafts still in browser storage)
- Camera video when you start the fitting room (processed in real time for try-on)
- Face presence signals from on-device MediaPipe face detection (used as a gate so try-on only starts when a face is visible; not used to identify you)
- Technical data such as browser type, approximate usage needed to run the app, and consent choices
- Support messages if you email us
3. Why we process it (purposes & legal bases)
- Provide the Service — run your wardrobe and live try-on (contract / legitimate interests; consent where required for camera)
- Security and abuse prevention — protect API routes and usage (legitimate interests)
- Preferences & consent records — remember cookie/analytics choices (consent / legal obligation)
- Communications — respond to support requests (legitimate interests / contract)
We do not sell your personal information. We do not use wardrobe photos for advertising.
4. Camera, biometrics-adjacent processing, and Decart
When you enable the camera and start try-on, live frames and the selected garment image are sent to Decart to run virtual try-on. Decart acts as our processor / service provider for that feature. Processing is session-based for generating the try-on stream.
Face detection for “is someone in frame?” runs in your browser with MediaPipe. It is not intended to create a biometric identity template for recognition across sessions.
You can stop the camera or try-on at any time. See also our Cookie Policy.
5. Where data lives today
The preview is local-first: wardrobe and most account UI state stay on your device. Our application server may mint short-lived tokens so the Decart API key is not exposed in the browser. We do not operate a cloud wardrobe database in this preview.
If Decart or other providers process data outside your country, transfers rely on appropriate safeguards (such as SCCs) as described in their documentation. Replace this section with your DPA details before launch.
6. Retention
Local wardrobe and preferences remain until you delete them in the app or clear browser site data. Consent records remain until you change them. Support emails are retained as needed to handle your request. Try-on streams are processed in real time; we do not operate a long-term video archive in this preview.
7. Your rights (EU/EEA/UK)
Subject to applicable law, you may have rights to:
- Access, rectify, or erase personal data
- Restrict or object to certain processing
- Data portability
- Withdraw consent (e.g. camera, analytics) without affecting prior lawful processing
- Lodge a complaint with your local supervisory authority
In this preview, erase/export for wardrobe data is primarily via in-app delete / clearing browser storage. Contact us for assistance: support@mirrel.me.
8. US state privacy rights
Depending on your state (e.g. California CCPA/CPRA), you may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information. We do not sell personal information. To exercise rights, email support@mirrel.me. We will not discriminate against you for exercising privacy rights.
9. Children
The Service is not directed to children under 16 (or the minimum age required in your country). Do not use Mirrel if you are under that age.
10. Changes
We may update this Policy and will revise the “Last updated” date. Material changes will be highlighted in-product when feasible.
11. Contact
Privacy questions: support@mirrel.me. Operator: [Operator Name]. Jurisdiction reference: [Jurisdiction, e.g. Sweden].