Legal

Privacy Policy

Effective Date: 1 October 2026

1. Who we are

Controller: Pokka Services Oy, Rovaniemi, Finland

Contact: support.mirameapp@gmail.com

This policy describes what Mirame does with your data. It is written to match what the app actually does; where something is a limitation rather than a promise, it says so.

Pokka Services Oy ("we") is the controller of the personal data described here. You can reach us at support.mirameapp@gmail.com for any question about this policy or to exercise any of the rights in section 8.

2. How you sign in

Mirame has no passwords. You sign in with Sign in with Apple or Sign in with Google, and we receive from them an account identifier and the email address you choose to share. We never see your Apple or Google password, and we do not store one of our own.

3. What we collect

Account

  • The email address passed to us by Apple or Google
  • A display name, if you enter one — Mirame works without it
  • The account identifier issued by Apple or Google

Your body

  • Photos you take or choose: a profile photo, body-scan photos, and photos of garments
  • Height, weight, shoulders, chest/bust, waist, hips, inseam, arm length and shoe size — either entered by you or estimated by the body scan
  • Values derived from those: body-mass index and an estimated body shape

Your wardrobe

  • Photos, names, brands, categories, sizes, prices and shop links for the items you add
  • Generated try-on images and the looks you save
  • The occasions and style requests you ask MiraBot for

Location — only when you ask for it

  • If you turn on weather-aware styling, we read your device's location once and send the coordinates to a weather service to look up the current conditions. If you never use that feature, we never request your location.

Subscription

  • Whether you have an active subscription and which tier, via our billing provider. Apple and Google handle the payment itself; we never see your card.

Support

  • The content of any email you send us.

We do not run analytics or advertising software in the app. We do not track you across other apps or websites, and we have no advertising identifier.

4. Why we may use it (legal bases)

  • Performing our contract with you (GDPR Art. 6(1)(b)) for everything the app does at your request: rendering try-ons, estimating measurements, recommending sizes, keeping your wardrobe, running your subscription.
  • Legitimate interests (Art. 6(1)(f)) for keeping the service secure and preventing abuse.
  • Legal obligation (Art. 6(1)(c)) for accounting records of purchases.

On photographs of your body. We use your photos to render try-on images and to estimate your measurements. We do not use them to recognise or identify you, and we do not match them against any other person. On that basis we do not treat them as biometric data within the meaning of Art. 4(14), which turns on processing for the purpose of uniquely identifying a natural person. We recognise that these are nonetheless intimate images, and we handle them as described below.

5. Who else sees it

We use the following processors and services. Each receives only what the column says, and nothing else.

ServiceWhereWhat it receives
SupabaseEU regionYour account row, your profile, wardrobe and saved looks, including the images stored inside them
Google (Gemini)Via our own gatewayThe photos you choose, your measurements and sizes, your wardrobe items and your style requests — to produce your result, and for nothing else
AnthropicVia our own gatewayProduct information only: a shop's size chart and brand name. Never your photos, and never your measurements
ElevenLabsVia our own gatewayThe text of the spoken guidance lines during a body scan. These are fixed phrases written by us; they contain nothing about you
Open-MeteoYour coordinates, only when you use weather-aware styling
RevenueCatYour subscription status and a pseudonymous identifier
ResendYour email address, to send the welcome message
Apple, GoogleSign-in, and billing for subscriptions

Google does not use your data to train its models and deletes it after a short abuse-monitoring period. We do not sell your data, and we do not share it for anyone else's advertising.

Some of these providers process data outside the EU/EEA. Those transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We will send you the relevant terms on request.

6. Where it is stored

Your account, profile, wardrobe and saved looks are stored by Supabase in the EU region. Photos and generated images are stored inside those records rather than in separate file storage.

The app also keeps a copy on your device so it works offline. Deleting the app removes that copy; it does not delete the copy on our servers — use section 7 for that.

7. Deleting your account

Settings → Delete account removes, immediately and permanently:

  • Your profile, including every measurement and your profile photo
  • Your wardrobe and every image in it
  • Your saved looks
  • Your account row and your Apple/Google sign-in link

This cannot be undone, and we cannot recover it for you afterwards.

Deleting your account does not cancel an active subscription. Apple bills that, and you cancel it in your Apple Account settings.

Encrypted backups of our database are retained for up to 30 days and are then overwritten; we do not restore individual records from them. Accounting records of purchases are kept for as long as Finnish accounting law requires, separately from the data above.

8. Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, erase it, restrict how we use it, or hand it to another provider. You may also object to processing based on our legitimate interests.

The app deletes your account for you at any time. For anything else — including a machine-readable copy of your data — email support.mirameapp@gmail.com and we will answer within one month.

If you think we have handled your data wrongly you can complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or to the authority where you live.

9. Children

Mirame is not for anyone under 16. We do not ask your age and we have no way to verify it, so we rely on you. If we learn that an account belongs to someone under 16 we delete it.

10. Changes

If we change this policy we will update the date at the top and, where the change is significant, tell you in the app before it takes effect.