Privacy Policy

Last updated: 27 June 2026

1. Data controller

The data controller for Mirvo (mirvo.app) is the Mirvo operator. Contact: privacy@mirvo.app.

2. What we collect

Account data: email address, chosen interface language, native and target languages, subscription status. Service data: messages you exchange with friends, voice recordings you submit for translation/transcription/practice, AI replies and pronunciation scores, daily usage counters. We do not collect special‑category data within the meaning of GDPR Art. 9.

3. Why we process it

To provide the service (translation, messaging, language practice), to enforce free‑plan quotas, to process Pro subscriptions, to send transactional emails (sign‑in links, payment receipts), and to keep the service secure and improve quality.

4. Legal basis

Performance of a contract (Art. 6(1)(b) GDPR) for delivering the service; legitimate interest (Art. 6(1)(f)) for security and abuse prevention; consent (Art. 6(1)(a)) for optional analytics.

5. Voice recordings

Voice recordings are sent to our transcription provider for the sole purpose of converting them to text. Audio is not retained beyond the time required to produce a result. Resulting text may be stored as part of your conversation history if you are signed in.

6. AI processing

Translations, practice feedback and chat auto‑translation are produced by large‑language‑model providers (Anthropic via OpenRouter, OpenAI for text‑to‑speech). Your text is sent to these providers for the purpose of generating the output and is not used by them to train models.

7. Sub‑processors

We use the following sub‑processors: Stripe Payments Inc. (USA, payments) — Standard Contractual Clauses; OpenRouter Inc. (USA, LLM routing) — SCC; Anthropic PBC (USA, LLM) — SCC; Groq Inc. (USA, voice transcription) — SCC; Microsoft Azure (Germany, pronunciation assessment); OpenAI L.L.C. (USA, text‑to‑speech) — SCC; Resend (USA, transactional email) — SCC; Vercel Inc. (USA, hosting of the web app) — SCC; our own VPS in Germany (backend & database).

8. Retention

Account data is kept for as long as the account exists. After deletion, data is removed within 30 days. Server logs are kept for 90 days. Daily usage counters reset every day.

9. Your rights

Under GDPR you can: access your data, correct it, delete it ("right to be forgotten"), port it, object to processing, withdraw consent. Write to privacy@mirvo.app.

10. Cookies and analytics

We use one essential cookie / token to keep you signed in. Optional, privacy‑friendly analytics (Plausible — cookieless, no personal data) only loads after you accept analytics in the cookie banner. You can decline without losing any feature.

11. Security

All traffic is encrypted with HTTPS. Authentication uses email magic‑links signed with HS256 JWTs; passwords are not stored. Database access is restricted to the backend service. Backups are encrypted at rest.

12. International transfers

Some sub‑processors are based in the USA. Data transfers rely on Standard Contractual Clauses approved by the European Commission.

13. Changes

Material changes will be announced inside the app and via email at least 14 days before they take effect.

© 2026 Mirvo · mirvo.app · privacy@mirvo.app