MiraPic

Privacy Policy

Effective: September 11, 2026

1. Summary and your choice

MiraPic turns the photo you choose into an AI-generated portrait or restored image. Before each generation, the app asks you to confirm your right to use the photo and separately allow sending the photo, including any faces, and your generation instructions to MiraPic and OpenAI. Neither choice is selected in advance. If you decline or close the notice, that generation does not upload the photo or spend credits. You can browse the app without agreeing to a generation.

2. Photos and face data we collect

We process the photo you select or take, including any visible face, facial features and other information contained in the image, together with the style and editing choices you submit. The AI uses the visible appearance to create the image you request while preserving the subject's likeness. MiraPic does not use Apple TrueDepth, ARKit face tracking or Face ID data, and does not build a facial-recognition database, biometric identity template or face embedding for identifying or authenticating people. A whole-file hash retained for operational purposes is not a facial measurement or biometric template.

Only choose photos you have permission to use, including permission from other identifiable people shown. We do not upload your entire photo library. Any metadata embedded in the selected image may accompany the image; do not select files containing information you do not want processed.

3. Face data use and AI sharing

After your explicit permission for that generation, the app sends the selected photo and generation choices over HTTPS to the MiraPic application server. MiraPic sends the photo and an instruction prompt containing the selected style and editing choices to OpenAI, the third-party AI provider, through its image-editing API. OpenAI processes the image and instructions and returns the requested result. MiraPic does not intentionally send your email, login credentials, payment details or device identifier as part of that AI request.

We use the photo and face data to provide the generation you requested and to operate that request safely. We do not sell face data, use it for advertising, identify people across photos or use it to build our own training dataset. OpenAI's standard API policy does not use API inputs or outputs for model training by default. This service uses the API, not a consumer ChatGPT conversation.

4. Face data storage, retention and deletion

On MiraPic: the original photo is held in a restricted temporary file on the MiraPic application server during processing. The normal completion and error paths delete it when the request finishes. An hourly cleanup removes interrupted-request temporary files older than one hour; this gives an operational maximum of approximately two hours when the cleanup service is running. Cleanup failures are treated as incidents, not permission to retain images. Generated image bytes are returned to the device and are not saved as a server-side image gallery.

At OpenAI: the image-editing API has no persistent application-state storage. Under OpenAI's standard API controls, content may be retained in abuse-monitoring logs for up to 30 days. Longer retention can apply for legal or safety reasons; images flagged as potential child sexual abuse material may be retained for manual review. MiraPic does not claim Zero Data Retention. Deleting your MiraPic account does not immediately delete OpenAI's safety or legally required records.

On your device: generated photos are stored in the app's private local gallery until you delete them or clear the app's local data. Account deletion also requests removal of the private gallery; device filesystem failures can prevent individual files from being removed. Photos exported to your device library, shared elsewhere or included in device/cloud backups are separate copies managed by you and those services. Deleting an in-app photo does not remove these copies.

5. Processors, protection and processing locations

Face images are processed on the secured MiraPic application server and OpenAI's systems; the generated gallery is on your device. Processing may occur outside your country, including in countries where OpenAI and its subprocessors operate. We do not promise processing exclusively within your country.

We require service providers processing personal data for MiraPic to protect it to at least the level described in this policy, including restricted purposes, confidentiality and appropriate security safeguards. OpenAI's business processing is governed by its applicable service terms and data-processing commitments. See OpenAI API data controls, its Data Processing Addendum and subprocessor list for protection and location details.

Google Firebase handles authentication, app integrity, notifications and analytics/crash diagnostics when enabled. Apple or Google Play handles purchases. These are separate from the OpenAI image-processing request; MiraPic does not send face photos to advertising networks.

6. Other data and retention

We process account identifiers and sign-in details supplied by Firebase, installation identifiers, language/platform, optional push tokens, purchase references and status, credit transactions, and security/rate-limit events. Generation metadata includes the template and editing choices, timestamps, request status, a whole-file hash and provider request reference, but not a stored face image or face embedding. These records support credits, fraud prevention, troubleshooting and account services.

Deleting a gallery item removes its local image and requests that the server history entry be hidden; operational metadata may remain. Account deletion removes personal account and generation records from the active MiraPic database. Store transaction records and irreversible free-trial anti-fraud records may remain for financial, dispute, security or legal purposes. Restricted database backups can retain earlier operational records after active-account deletion until those backups are retired; account deletion does not instantly erase every backup. They are not an image gallery and are not used for new AI processing.

7. Your controls and security

You can refuse each AI request, deny optional notifications, delete generated images from the in-app gallery, and delete your account under Profile → Delete my account. If a request is already submitted, refusing a later request does not recall data already processed by the provider. Cancel subscriptions separately in Apple or Google account settings. Transport uses HTTPS; source temporary files have restricted filesystem access. No service can guarantee absolute security.

8. Children

MiraPic is not directed to children under 13, or the higher minimum age required in their country. A parent or guardian must supervise any permitted minor and ensure permission for each uploaded image.

9. Contact

For privacy, access or deletion requests, use the MiraPic support page. Include your request, not additional sensitive face photos. Account deletion is also available directly inside the app.

Also available: Terms of Use.