Privacy Policy
Effective Date / Last Updated
Effective Date: April 10, 2026 Last Updated: April 10, 2026
1. Introduction
Welcome to MiroFish ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our AI scenario prediction service at mirofishai.org (the "Service").
MiroFish helps you stress-test decisions, policies, and "what-if" scenarios by simulating how different stakeholders are likely to react. The Service generates structured prediction reports based on your topic and any optional supporting documents you upload.
By using the Service, you agree to the practices described in this Policy.
2. Information We Collect
2.1 Account Information
When you create or use an account, we may collect:
- Email address
- Name (if provided)
- Authentication profile data from third-party login providers (e.g., Google) if you choose to sign in with them
- Locale and language preference
2.2 Content You Provide (Prediction Inputs & Outputs)
To provide the Service, we process and may store:
- Text topics and questions you submit for prediction
- Optional documents you upload (PDF, Markdown, or plain text, up to 30 MB) used as additional context for the prediction
- Generated prediction reports, including stakeholder analysis, sentiment trajectories, narrative breakdowns, risks, and confidence scores
- Report metadata such as generation timestamp, model used, token usage, and plan/usage counters
- Your prediction history and any preferences you set
Note on uploaded documents: Document content is sent to our AI providers only for the purpose of generating that single prediction. The original document text is not retained in any persistent context after the prediction completes. The generated report itself is stored in your account and remains accessible to you (see Section 7).
You can request deletion of your account and all associated data (see Section 8).
2.3 Usage, Device, and Technical Data
We automatically collect certain data, such as:
- Feature usage patterns (e.g., which prediction features are used)
- Access times, pages viewed, and interactions
- IP address and device identifiers (where available)
- Browser type/version, operating system
- Referring URLs and approximate location inferred from IP (city/region level)
2.4 Payment and Subscription Information
Paid plans are processed by PayPal and Creem. We do not store full card numbers or payment account credentials. Payment processors may collect:
- Payment information (processed by PayPal or Creem)
- Billing address and tax-related details (if required)
- Transaction and subscription records
We may store limited payment-related data such as customer/subscription IDs, plan tier, and subscription status to manage billing and access.
For details, see:
- PayPal's privacy policy: https://www.paypal.com/us/legalhub/privacy-full
- Creem's privacy policy: https://www.creem.io/privacy
3. How We Use Information
We use information to:
- Provide, operate, and maintain the Service
- Generate prediction reports and deliver outputs you request
- Manage accounts, subscriptions, usage limits, and credits
- Send service-related messages (e.g., receipts, critical notices, policy updates)
- Provide customer support and respond to inquiries
- Improve performance, reliability, and user experience
- Prevent fraud, abuse, and security incidents
- Comply with legal obligations
4. Cookies and Analytics
4.1 Cookies
We use cookies and similar technologies for:
- Essential functionality (session, authentication, security)
- Preferences (language, theme)
- Analytics
You can control cookies through your browser settings. Some cookies are necessary for the Service to function.
4.2 Analytics Tools
We may use analytics tools to understand usage and improve the Service. These tools may use cookies or similar technologies to collect usage data.
5. How We Share Information
We may share information only as needed:
- Service Providers / Processors: hosting, CDN, security, analytics, database, authentication, payment, and AI inference providers that help us operate the Service
- Legal and Safety: to comply with law, enforce terms, or protect rights/safety
- Business Transfers: in connection with a merger, acquisition, financing, or sale of assets (with appropriate safeguards)
We do not sell your personal information.
6. Third-Party Services (Key Providers)
Our Service integrates with the following providers:
- OpenRouter (AI model gateway): your topic, question, and any uploaded document content are sent to OpenRouter for processing. OpenRouter routes requests to the underlying AI models listed below.
- Google Gemini 2.5 Flash (via OpenRouter): used to extract stakeholders, generate role profiles, and simulate multi-round discussions.
- Anthropic Claude Opus 4.6 (via OpenRouter): used to analyze the simulation data and produce the final structured report.
- PayPal and Creem (payments)
- Cloudflare (hosting, CDN, security, document storage via R2)
- Neon (PostgreSQL database)
- Resend (email delivery for verification codes and account notifications)
- Authentication providers (e.g., Google)
Each provider's handling of data is governed by their own policies.
7. Data Retention
We retain information only as long as necessary:
- Account & settings: while your account is active
- Prediction history & reports: while your account is active, or as long as needed to provide the Service
- Uploaded documents: retained only for the duration needed to generate the prediction; the report and a reference to the upload may persist in your history
- Logs/security records: for a limited period for security, abuse prevention, and troubleshooting
- Billing records: as required for accounting, tax, and legal compliance
You may request deletion at any time (see Section 8).
8. Your Rights and Choices
Depending on your location, you may have rights to:
- Access and receive a copy of your personal data
- Correct inaccurate data
- Delete your data (subject to legal/contractual retention)
- Export your data (where applicable)
- Object to or restrict certain processing
- Withdraw consent (where processing is based on consent)
To exercise these rights, contact: support@mirofishai.org
9. International Data Transfers
We may process and store data in the United States and other locations where our service providers operate. If you access the Service from outside the U.S., you understand your data may be transferred internationally.
10. Security
We use reasonable technical and organizational measures to protect information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal data, contact us so we can take appropriate action.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version on this page and update the "Last Updated" date.
13. Contact Us
Email: support@mirofishai.org Website: https://mirofishai.org
