Privacy Policy
Mirrela works on photographs of people, so this document matters more than most. It says plainly what happens to the photo you upload, what never leaves your phone, and what we are unable to see even if we wanted to.
Last updated 22 August 2026
The short version
- Your photo is sent to Google to be processed, and the result comes back. We do not keep a copy on our servers.
- Everything you make — results, saved looks, your wardrobe, your history — is stored on your own device, not with us.
- There are no accounts and no advertising. Nothing is sold or shared.
- We measure how the app is used — which screens, which filters, whether a generation worked. Never your photo, never anything you type.
- Clearing your browser data for this site deletes everything the app holds about you.
Who is responsible
[Company legal name], [Registered address], operates Mirrela and is the data controller for the processing described here. For anything in this document, write to [privacy@example.com].
Photographs you upload
To generate a preview we need the photo you choose. It may show your face, your hands, your feet, your ear or your whole body. It is sent over an encrypted connection to Google's Gemini API, which produces the image, and the result is returned to your browser. Anything you type in the free-text box — “anything specific?” — goes with it, because it is part of the instruction. Please do not put anything in there you would not want read by a machine on somebody else's server.
We do not write your photo to disk, put it in a database, or keep it after the request finishes. We do not use it to train anything, and we never publish it — every picture in our catalogue was made by us for that purpose.
We also do not use your photo to identify or recognise you. The service edits an image; it does not measure a face or match it against anyone.
What stays on your device
Generated images, the looks you save, the clothes in your wardrobe, your history and whether you have a plan are stored by your browser on your own device, using IndexedDB and local storage. None of it is uploaded to us, which also means we cannot restore it for you: if you clear your browser data or switch devices, it is gone.
What our servers record
- Standard hosting logs kept by our host, Vercel — IP address, browser type, page requested, time — used to keep the service running and to stop abuse. When something fails, the error is logged too.
- A cost log of our own: which model ran, for which category, how many images it made, what it cost, how long it took and whether it worked. No photographs, nothing you typed, no IP addresses — there is no field for any of it.
If the site is temporarily protected by a shared access password, the app sets one technical cookie so you do not have to type it again. That is the only cookie the app itself sets.
Measuring how the app is used
We load Google Tag Manager, which is how Google Analytics gets onto a site. What it is there to collect is a list of actions: a section opened, a filter tapped, a generation started and whether it succeeded, an image saved or shared, a price screen opened, a link to a shop followed. Each one carries a few short labels — the category, the filter chosen, the name of a catalogue look, whether you were on a free try or a plan.
What it never carries is the content: not the photo, not a link to it, not the name of the file, not a word of what you typed, not the text of an error. There is no field of that kind in the code that sends these events, which is a stronger statement than a promise — adding one would mean changing the type that every call is checked against.
Leaving the app: shops and specialists
Under a result you can tap through to a shop, or to look for someone who does this work near you. Those links open a third-party site — a shop, Google Maps, Instagram, a booking page — and from that moment you are in their hands, under their policy, not ours.
What travels with you is the search words for the thing in the picture — “black satin slip dress”, “piercing studio” — and nothing else. Not your photo, not the result, not an identifier of any kind. We do not currently earn anything from these links; if that changes, it will be written here.
Why we are allowed to do this (GDPR)
Processing your photo is necessary to perform the service you asked for — Article 6(1)(b). Keeping security and cost logs rests on our legitimate interest in running a service that is not abused — Article 6(1)(f). Measurement is different: it is not necessary for the service and we do not pretend otherwise, so it runs on your consent — Article 6(1)(a), and Article 5(3) of the ePrivacy Directive for the storage it needs on your device. That is why it waits for the banner rather than starting on its own.
A photograph of a person is not automatically special category data under Article 9; it becomes so when it is processed to identify somebody uniquely, which is exactly what we do not do. Where consent is nonetheless the appropriate basis in your country, you give it by choosing a photo and asking for a result, and you can withdraw it at any time by stopping — there is nothing retained to withdraw from.
Who else is involved
- Google (Gemini API) — generates the images. Receives the photo and the description of what to change.
- Vercel — hosts the site. Receives the technical request data listed above.
- Google (Tag Manager and Analytics) — measurement. Loading the container is itself a request to Google, so it sees your IP address and browser even while there are no tags in it. Once there are, and once you have agreed, it receives the actions described above.
All three act as processors under written terms. We do not sell personal information, we do not share it for advertising, and we have no other recipients. Google Analytics advertising features — the ones that make an audience out of a visitor — are not enabled, and turning them on would be a change we would have to describe here first.
International transfers
Google and Vercel process data in the United States and other countries. Those transfers rely on the European Commission's Standard Contractual Clauses, included in the terms we have with each of them, together with the safeguards each provider publishes.
How long anything is kept
Your photo: for the length of the request, and no longer. Hosting logs and error logs: for the retention period our host applies to them. The cost log: written to a temporary file that the server loses when it restarts, and to those same hosting logs, where it lives as long as they do — it contains nothing about you either way. Measurement, once it is switched on: for the retention period set in Google Analytics, which we will name here when we set it. Everything else lives on your device until you delete it.
Your rights in the EU and the UK
You have the right to access your data, correct it, have it erased, restrict or object to its processing, and receive it in a portable form. Write to [privacy@example.com] and we will answer within one month.
In practice most of these are satisfied faster by you than by us: we hold no account, no photo and no gallery, so clearing this site's data in your browser erases everything there is. You also have the right to complain to your national data protection authority.
Your rights in California
Over the past twelve months we have collected the categories described above: images you choose to upload, processed only to produce the result you asked for, and internet activity in the form of standard server logs and — once measurement is switched on and you have agreed to it — which screens and features you used. We have not collected precise geolocation, and we do not infer characteristics to build a profile.
We do not sell personal information and we do not share it for cross-context behavioural advertising. The advertising features that would make that possible are switched off in Google Analytics, and switching them on is a change we would have to publish here before making. You have the right to know, delete and correct, the right to opt out of sale or sharing, and the right not to be treated differently for exercising any of them. Use [privacy@example.com] for any of these.
Children
Mirrela is not intended for anyone under 16. We do not knowingly process the data of children, and do not want photographs of children uploaded at all — including by adults. If you believe a child has used the service, write to [privacy@example.com] and we will act on it.
Changes
If this policy changes we will update the date at the top. If a change is significant — a new recipient, a new purpose — we will say so on the site rather than hope you re-read the page.
Questions about this document? Write to [privacy@example.com]. You can also read the Terms and the Privacy Policy.