mirr

Privacy Policy

Draft v1 — 2026-04-23. Operator legal name, business address, and DPO contact (if applicable) are placeholders pending legal review.

Privacy Policy

Effective date — TBD · Last updated: 2026-04-23

This policy describes what data mirr tarot ("mirr", "we", "us") collects, how we use it, and what rights you have. It applies to the mirr Telegram Mini App and related web pages on mirr-edi.pages.dev.

1. Data we collect

From you

DataSourcePurpose
Telegram user id (numeric) Telegram initData signature Authenticate you across sessions; attribute usage and payments
Language preference (ko / en) language_code field or user toggle Render UI and AI responses in the right language
Prompts you send to mirr Your messages Generate AI responses; ephemeral — see §3
Payment payload TON on-chain comment / Telegram invoice metadata Verify and record purchases
Approximate event timestamps (DAU / Opened / ChatTurn) Derived from your usage Operational metrics; no message content

Not collected

2. Where data is stored

3. How your prompts are processed

When you send a message to mirr, we forward it along with your active session context, compact summaries of recent sessions (topic, keywords, one-to-two sentence summary, emotional tone — see §2), and the mirr system prompt to our LLM provider (DeepSeek V3.2, accessed through Nebius AI Studio). The provider generates a streamed response that we pass back to you. The request is ephemeral — we do not persist prompts or session summaries in our database beyond the in-flight request window.

We do not train any AI model on your messages. The provider's handling is governed by their privacy policy (see §7).

4. Legal basis (GDPR)

If you are in the European Economic Area, the United Kingdom, or a jurisdiction with equivalent protections, our legal basis for processing is:

5. Data retention

6. Your rights

Depending on your jurisdiction, you have the right to:

Self-service (preferred): tap the mirr wordmark 5 times to open the settings panel. Export my data downloads a JSON file of your server record + browser-stored session histories (rate-limited to once per 24 hours). Delete my account performs a double-confirmed deletion — all identifiers are removed; payment records are tombstoned (status marked, other fields retained) for 90 days to satisfy accounting/legal obligations, then aged out by KV TTL.

Otherwise, contact rlllgk@gmail.com. We respond within 30 days.

6.1 Daily signal push — opt-out paths

If you have enabled daily push notifications (one card per day from mirr), you can withdraw consent in any of the following ways:

The daily push feature is opt-in by default (enabled=false). We do not send daily signals unless you explicitly turn them on.

7. Sub-processors we use

ProviderPurposeLocation
CloudflareWorkers, Pages, KV storage, CDNGlobal edge
Nebius AI StudioLLM inference (DeepSeek V3.2)EU
TelegramMini App platform, Stars paymentsGlobal
TON Foundation (Toncenter)TON blockchain queryGlobal
SentryError trackingEU
AmplitudeProduct analyticsEU

8. Children

mirr is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has used the Service, contact us and we will delete the account.

9. International transfers

Data may be processed in countries other than where you reside. Our sub-processors operate under appropriate safeguards (Standard Contractual Clauses or equivalent) where required by applicable law.

10. Security

We use HTTPS, HMAC-verified Telegram initData, constant-time admin auth, server-authoritative payment verification, and KV write idempotency. No system is perfect — if you suspect a security issue, please contact us at rlllgk@gmail.com.

11. Changes

We may update this policy. Material changes will be announced in-app or via the Signal Log. The "Last updated" date at the top of this page will reflect the revision.

12. Contact

mirr tarot · operated by [Operator Name]
Email: rlllgk@gmail.com
Telegram: t.me/rlllgk


개인정보처리방침 (한국어 요약)

영문 원문과 해석 차이 발생 시 영문이 우선합니다.

1. 수집 항목

수집하지 않는 항목: 전화번호, 이메일, 이름, 프로필 사진, 정확한 위치, 디바이스 식별자.

2. 저장 위치

3. AI 학습 사용

메시지와 위 §2의 세션 요약본은 DeepSeek V3.2 (Nebius 경유) 추론에만 사용되며, mirr 측에서는 어떤 AI 모델 학습에도 사용하지 않습니다.

4. 보유 기간

5. 이용자 권리

열람·수정·삭제·반출·이의제기·감독기관 민원 제기 권리. 셀프서비스로 mirr 워드마크 5번 탭 → 설정 패널 → 데이터 내보내기/계정 삭제 가능 (내보내기는 24시간에 1회 제한). 결제 기록은 법적 의무로 tombstone 마킹 후 90일간 보관됩니다. 그 외 문의: rlllgk@gmail.com. 30일 내 응답.

5.1 일일 시그널 푸시 해지

mirr가 하루 1장 카드를 텔레그램 DM으로 보내는 일일 시그널 푸시를 켰다면, 아래 경로로 언제든 해지할 수 있습니다.

기본값은 꺼짐입니다. 사용자가 명시적으로 켜지 않으면 발송되지 않습니다.

6. 하위 처리자

Cloudflare / Nebius AI / Telegram / Toncenter / Sentry / Amplitude. 자세한 위치·목적은 영문 §7 참조.

7. 문의

이메일: rlllgk@gmail.com
Telegram: t.me/rlllgk


プライバシーポリシー(日本語まとめ)

英語原文との解釈差異が生じた場合は英語が優先します。

1. 収集する情報

収集しないもの:電話番号、メール、氏名、プロフィール写真、正確な位置、 デバイス識別子。

2. 保存場所

3. AI 学習への利用

メッセージおよび §2 のセッション要約は DeepSeek V3.2(Nebius 経由)の 推論にのみ使われ、mirr 側ではいかなる AI モデルの学習にも使いません。

4. 保持期間

5. あなたの権利

閲覧・訂正・削除・データポータビリティ・異議申立・監督機関への苦情申立の権利があります。 行使は rlllgk@gmail.com まで。30日以内に応答します。

6. 下請処理者

Cloudflare / Nebius AI / Telegram / Toncenter / Sentry / Amplitude。詳細は英語原文 §7 をご参照ください。

7. お問い合わせ

Email:rlllgk@gmail.com
Telegram:t.me/rlllgk


隐私政策(简体中文摘要)

与英文原文解释不一致时,以英文为准。

1. 收集的信息

不收集的项目:电话号码、邮箱、姓名、头像、精确位置、 设备标识符。

2. 存储位置

3. 是否用于 AI 训练

消息以及上述 §2 的会话摘要仅用于 DeepSeek V3.2(经 Nebius)推理,mirr 不会把它们放进任何 AI 模型的训练数据集。

4. 保留期限

5. 你的权利

你有查阅、更正、删除、可携权、反对处理以及向监管机构投诉的权利。 行使请联系 rlllgk@gmail.com,我们会在 30 天内回应。

6. 子处理方

Cloudflare / Nebius AI / Telegram / Toncenter / Sentry / Amplitude。详情见英文原文 §7。

7. 联系方式

邮箱:rlllgk@gmail.com
Telegram:t.me/rlllgk