Last updated: 27 June 2026
The data controller for Mirvo (mirvo.app) is the Mirvo operator. Contact: privacy@mirvo.app.
Account data: email address, chosen interface language, native and target languages, subscription status. Service data: messages you exchange with friends, voice recordings you submit for translation/transcription/practice, AI replies and pronunciation scores, daily usage counters. We do not collect special‑category data within the meaning of GDPR Art. 9.
To provide the service (translation, messaging, language practice), to enforce free‑plan quotas, to process Pro subscriptions, to send transactional emails (sign‑in links, payment receipts), and to keep the service secure and improve quality.
Performance of a contract (Art. 6(1)(b) GDPR) for delivering the service; legitimate interest (Art. 6(1)(f)) for security and abuse prevention; consent (Art. 6(1)(a)) for optional analytics.
Voice recordings are sent to our transcription provider for the sole purpose of converting them to text. Audio is not retained beyond the time required to produce a result. Resulting text may be stored as part of your conversation history if you are signed in.
Translations, practice feedback and chat auto‑translation are produced by large‑language‑model providers (Anthropic via OpenRouter, OpenAI for text‑to‑speech). Your text is sent to these providers for the purpose of generating the output and is not used by them to train models.
We use the following sub‑processors: Stripe Payments Inc. (USA, payments) — Standard Contractual Clauses; OpenRouter Inc. (USA, LLM routing) — SCC; Anthropic PBC (USA, LLM) — SCC; Groq Inc. (USA, voice transcription) — SCC; Microsoft Azure (Germany, pronunciation assessment); OpenAI L.L.C. (USA, text‑to‑speech) — SCC; Resend (USA, transactional email) — SCC; Vercel Inc. (USA, hosting of the web app) — SCC; our own VPS in Germany (backend & database).
Account data is kept for as long as the account exists. After deletion, data is removed within 30 days. Server logs are kept for 90 days. Daily usage counters reset every day.
Under GDPR you can: access your data, correct it, delete it ("right to be forgotten"), port it, object to processing, withdraw consent. Write to privacy@mirvo.app.
We use one essential cookie / token to keep you signed in. Optional, privacy‑friendly analytics (Plausible — cookieless, no personal data) only loads after you accept analytics in the cookie banner. You can decline without losing any feature.
All traffic is encrypted with HTTPS. Authentication uses email magic‑links signed with HS256 JWTs; passwords are not stored. Database access is restricted to the backend service. Backups are encrypted at rest.
Some sub‑processors are based in the USA. Data transfers rely on Standard Contractual Clauses approved by the European Commission.
Material changes will be announced inside the app and via email at least 14 days before they take effect.