Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains what information MIRA collects, how we use and protect it, and the choices and rights you have. It covers both your data as our customer and the customer-conversation data MIRA processes on your behalf.
1. Who we are
MIRA (“MIRA”, “we”, “us”, “our”) is a WhatsApp-native AI operations assistant for Indian small and medium businesses, operated by [Legal Entity Name], [Registered office address] (the “Company”). This policy applies to the MIRA marketing website, web dashboard, APIs and related services (together, the “Service”).
2. Roles: who controls the data
Two kinds of personal data flow through MIRA, and our role differs for each:
- Your account data — information about you, our business customer. For this, we act as the data controller / data fiduciary.
- Your customers’ conversation data — messages, voice notes and contact details your end-customers send to your WhatsApp number. For this, you are the controller and MIRA is a processor acting on your instructions. You are responsible for having a lawful basis (such as consent) to message your customers.
3. Information we collect
Account data
Your name, work email, mobile number, business / workspace name, role, a securely hashed password, and the business and AI settings you configure.
Billing data
Your plan, billing contact and GST details, and payment metadata. Card / UPI / net-banking details are collected and processed by our payment processor (Razorpay) — MIRA does not store full payment-instrument details.
Usage data
How you interact with the Service: features used, requests and timestamps, approximate location derived from IP address, device and browser type, and aggregate usage counters used to enforce plan limits and calculate billing.
Conversation & content data (processed on your behalf)
WhatsApp messages and voice notes exchanged between your business and your customers, customer phone numbers and WhatsApp profile names, the lead records and notes MIRA generates, and any documents you upload to your knowledge base.
4. How we use information
- To provide, operate, secure and improve the Service.
- To authenticate you and maintain your session.
- To generate AI replies, transcriptions, lead scores and automations.
- To enforce plan limits and process subscriptions and billing.
- To provide support and send service / transactional messages.
- To monitor performance, debug errors, and prevent abuse and fraud.
- To comply with legal obligations.
We do not sell your personal data, and we do not use your or your customers’ conversation content to advertise to you.
5. Cookies & local storage
MIRA is designed to use the minimum necessary. We store your authentication token and preferences (such as light / dark theme) in your browser’s local storage to keep you signed in and remember your settings, and we use strictly-necessary cookies for security and session integrity. We do not use third-party advertising or cross-site tracking cookies. You can clear cookies and local storage in your browser at any time; doing so will sign you out.
6. Analytics
We may use privacy-respecting product analytics and error-monitoring tools (for example, Sentry) to understand aggregate usage, measure reliability and diagnose problems. Where used, these process technical and usage data — not your customers’ message content — and are bound by the obligations described in “Third-party providers” below.
7. AI processing
MIRA uses large-language and voice models to understand messages and generate replies:
- Text is processed by Anthropic (Claude) as the primary provider, with OpenAI as a fallback.
- Voice notes are transcribed and synthesised using providers such as Sarvam and ElevenLabs.
Message content and relevant context (such as your knowledge-base documents) are sent to these providers solely to generate a response for you. Under these providers’ API terms, your inputs and outputs are not used to train their models. AI output can be imperfect — you remain responsible for reviewing AI-assisted communications. See our Terms of Service.
8. WhatsApp integration
MIRA connects to WhatsApp through Meta’s official WhatsApp Business Cloud API. Messages between your business and your customers are transmitted and processed by Meta under the WhatsApp Business Terms and Meta’s policies, in addition to this policy. You must comply with WhatsApp’s Business and Commerce policies and obtain any opt-in required before messaging your customers.
9. Third-party providers (sub-processors)
We share data with vetted providers only to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Meta (WhatsApp Cloud API) | Message delivery | Conversation content, phone numbers |
| Anthropic | Primary LLM | Message content & context |
| OpenAI | Fallback LLM | Message content & context |
| Sarvam / ElevenLabs | Voice transcription & synthesis | Voice notes, text |
| Razorpay | Payments & subscriptions | Billing & payment metadata |
| Vercel | Website & app hosting | Requests & technical data |
| Cloud infrastructure & monitoring | Hosting, storage, error tracking | Service & technical data |
We require each provider to protect the data and use it only for the contracted purpose.
10. Data retention
We keep account and billing data for as long as your account is active and as required for legal, tax and accounting purposes. Conversation, lead and knowledge-base data are retained while your workspace is active; you can delete individual records, and we delete or anonymise your data after account closure within a reasonable period, except where retention is legally required. Backups are purged on a rolling schedule.
11. Data security
We apply reasonable technical and organisational safeguards, including encryption in transit, hashed passwords (bcrypt), signed session tokens, role-based access control, and strict per-tenant isolation (database row-level security) so one workspace cannot access another’s data. No system is perfectly secure; please use a strong, unique password and keep your credentials confidential.
12. International transfers
Some providers listed above may process data outside India. Where they do, we rely on appropriate contractual and security safeguards for the transfer.
13. Your rights
Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023), you may:
- access the personal data we hold about you;
- correct or update inaccurate data;
- request deletion of your account data;
- export your data;
- withdraw consent where processing is based on consent; and
- raise a grievance with our Grievance Officer.
To exercise these rights, email privacy@hiremira.in. For your customers’ personal data, your customers should contact you (the controller); we will assist you as processor.
14. Grievance Officer
In accordance with applicable Indian law, you may contact our Grievance Officer: [Grievance Officer Name], [Legal Entity Name], privacy@hiremira.in, [Registered office address]. We aim to acknowledge grievances within a reasonable time.
15. Children
The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal data from children.
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Service or by email, and the “Last updated” date above will change. Continuing to use the Service after changes take effect means you accept the updated policy.
17. Contact
Questions about privacy? Email privacy@hiremira.in or visit our Contact page.