Your health story stays yours.

Health information is deeply personal. We design Mirae to be clear about what we collect, why we use it, and who can see it.

You stay in control

Your information should work for you, on terms you understand.

You choose what to add

You decide what to tell Mirae and which records or devices to connect.

You control sharing

We only share identifiable health information with your care team when you give explicit consent.

You can ask us to delete it

You can request deletion of your account and personal data, subject to limited legal requirements.

How your data is handled

What we collect

Information you enter in Mirae, plus records or wearable data you choose to connect. We explain what is collected before you connect a source.

Why we use it

To provide the product, help you understand your health, prepare for care conversations, keep Mirae secure, and improve the service.

Who can access it

Access is limited to authorised people and service providers who need it. Your care team only receives identifiable data with your consent.

How we protect it

We use encryption in transit and at rest, access controls, security monitoring, vendor reviews, and incident response processes.

How research works

Research uses de-identified or aggregate data. A study that needs identifiable data requires separate, explicit consent.

What we do not do

We do not sell your personal data, show third-party ads, or let AI providers use your chat data to train their models.

Our compliance journey

We will not present work in progress as a finished credential. These are the standards we are actively preparing for and the scope in which they apply.

In progress

SOC 2

Mirae is currently undergoing a SOC 2 attestation. The work examines controls relevant to security and the reliable operation of our systems. We will update this page when the examination is complete.

In progress

UK & EU GDPR

We are working toward full GDPR readiness across the product and organisation, including privacy by design, data minimisation, consent records, vendor controls, and documented accountability.

Scope dependent

HIPAA

HIPAA does not automatically cover a direct-to-consumer health app. It becomes relevant when Mirae handles protected health information on behalf of a covered care provider.

HIPAA applies through certain care-provider relationships

Mirae's direct-to-consumer service is not a HIPAA covered entity simply because it handles health information. Other privacy and consumer health data laws still apply, alongside the commitments on this page and in our Privacy Policy.

If a covered care provider engages Mirae to create, receive, maintain, or transmit protected health information on its behalf, Mirae would act as a business associate for that work. Before that work begins, we will put the required business associate agreement and safeguards in place.

In that situation, HIPAA protections apply to the protected health information handled through that provider relationship and for the patients it covers. We will be explicit about when this applies.

Read the US Department of Health and Human Services guidance

Scan to download

QR code to download Mirae

Mirae is a mobile app