You choose what to add
You decide what to tell Mirae and which records or devices to connect.
Health information is deeply personal. We design Mirae to be clear about what we collect, why we use it, and who can see it.
Your information should work for you, on terms you understand.
You decide what to tell Mirae and which records or devices to connect.
We only share identifiable health information with your care team when you give explicit consent.
You can request deletion of your account and personal data, subject to limited legal requirements.
Information you enter in Mirae, plus records or wearable data you choose to connect. We explain what is collected before you connect a source.
To provide the product, help you understand your health, prepare for care conversations, keep Mirae secure, and improve the service.
Access is limited to authorised people and service providers who need it. Your care team only receives identifiable data with your consent.
We use encryption in transit and at rest, access controls, security monitoring, vendor reviews, and incident response processes.
Research uses de-identified or aggregate data. A study that needs identifiable data requires separate, explicit consent.
We do not sell your personal data, show third-party ads, or let AI providers use your chat data to train their models.
We will not present work in progress as a finished credential. These are the standards we are actively preparing for and the scope in which they apply.
Mirae is currently undergoing a SOC 2 attestation. The work examines controls relevant to security and the reliable operation of our systems. We will update this page when the examination is complete.
We are working toward full GDPR readiness across the product and organisation, including privacy by design, data minimisation, consent records, vendor controls, and documented accountability.
HIPAA does not automatically cover a direct-to-consumer health app. It becomes relevant when Mirae handles protected health information on behalf of a covered care provider.
Mirae's direct-to-consumer service is not a HIPAA covered entity simply because it handles health information. Other privacy and consumer health data laws still apply, alongside the commitments on this page and in our Privacy Policy.
If a covered care provider engages Mirae to create, receive, maintain, or transmit protected health information on its behalf, Mirae would act as a business associate for that work. Before that work begins, we will put the required business associate agreement and safeguards in place.
In that situation, HIPAA protections apply to the protected health information handled through that provider relationship and for the patients it covers. We will be explicit about when this applies.
Questions about privacy or security? privacy@miraehealth.com
Last reviewed: August 13, 2026