1. Introduction
Miratints ("the Service"), operated by Go Nakamura, respects your privacy. This Privacy Policy describes what personal information we collect, how we use it, who we share it with, and the rights you have over your data. By using the Service you acknowledge this Policy.
2. Information We Collect
2.1 Account information• Email address (and provider identity if you sign in with Apple or Google)• Display name and username• Profile photo (optional)• Authentication data (password hash held by our auth provider, OAuth tokens, two-factor secrets)2.2 Onboarding answers• Gender• Height and weight• Birthdate (used to compute age band only)• How you heard about us (referral source)2.3 Content you create• Photos and videos you upload (including drafts visible only to you)• Captions, comments, likes, bookmarks, follows• Direct messages (visible only to the sender and the recipient)• Location (city / country) when you explicitly attach it to a post2.4 Automatic data• Device model, OS version, app version, language• IP address (truncated where feasible)• Usage events and screen views (sampled)• Crash reports and performance traces
3. How We Use Your Information
We use your information to:• Provide, maintain, and secure the Service• Run the AI fashion analysis pipeline on photos you upload• Aggregate anonymized data into regional and global trend insights• Personalize recommendations and rankings• With your consent, provide anonymized fashion-trend data to our business analytics service (Miratints Insights)• With your consent, analyze usage to improve the Service• Send transactional emails (sign-in codes, security notices)• Detect fraud, abuse, and policy violations• Comply with legal obligations
4. AI Analysis
4.1 What runs on your photos• A vision-language model run by an external AI service extracts item categories, colors, patterns, and style descriptors.• As part of the analysis, the AI may estimate an age range and gender from the image. These estimates are auxiliary analysis output and are never used for decisions with legal or similarly significant effects.• An external image-analysis service performs brand-logo detection to populate the "brand" field on detected items.• If you scan a video, several frames extracted from the video are used for analysis.4.2 What we keep• The extracted metadata and AI-generated captions are stored against your account so the result screen, trend aggregates, and your own analytics can use them.• We store a hash of each image to avoid re-analyzing duplicates; if the same image has already been analyzed, we may reuse the existing analysis result.• Anonymized aggregates do not contain personally identifying information.4.3 What we do not do• We do not sell raw photos to third parties.• We do not use your photos to train third-party foundation models.
5. Service Providers and Data Sharing
We share the minimum necessary data with providers that process information on our behalf under contract:• Core infrastructure — a cloud provider hosting our database, storage, authentication, and server-side processing• AI analysis — an external AI service hosting the vision-language model for outfit analysis (image data + text prompt), and an image-analysis service for brand-logo detection (image data only)• Subscriptions — billing via the Apple App Store, Google Play, or Stripe, plus a subscription-management service (we never hold your card number or other payment details)• Email — a transactional email delivery service• Push notifications — Apple's and Google's notification infrastructure and a delivery-management service• Crash reports and analytics — a crash-reporting tool and consent-based usage-analytics tools (user inputs are masked)• Anti-bot protection — a verification service protecting sign-up and similar flows (being rolled out)Our business service, Miratints Insights, only ever receives aggregated, anonymized statistics grouped by region and time period. Personally identifiable information, photos, and comments are never shared with business customers.Tapping a product link in the app (Rakuten, ZOZOTOWN, Amazon, eBay, etc.) takes you to an external e-commerce site; their privacy policies apply there.We do not sell your personal information. We may disclose information when required by law or to protect rights, property, or safety. The names of our current processors are available on request via privacy@miratints.com.
6. Storage and Security
• Session credentials on your device are stored encrypted in the secure storage provided by the operating system (e.g. the system keychain).• Data at rest in our database is encrypted by the underlying cloud platform.• Two-factor authentication (TOTP or email OTP) is available and recommended.• We perform periodic security reviews, rate-limit sensitive operations, and enforce row-level access controls on user data.• Active accounts: data retained for the life of the account.• Deleted accounts: deletion within 30 days, except records we are legally required to retain (e.g. transaction history).
7. Your Rights
Depending on where you live (GDPR, CCPA, APPI, and similar laws), you may have the right to:• Access the personal information we hold about you• Correct inaccurate information• Delete your account and associated data• Export your data in a portable format• Object to or restrict certain processing• Withdraw consent for optional processing (usage analytics, trend-data provision)You can delete your account from Settings → Account, and change your consents from Settings → Data & Privacy. For data exports and other requests, email privacy@miratints.com — we respond within the statutory period (generally one month).
8. Children's Privacy
The Service is not directed at children under the minimum age for their region — 13 in most regions, or 16 in the EU/EEA, the United Kingdom, Switzerland, and Australia. Age is verified against the birthdate provided at sign-up. If we learn that we have unknowingly collected personal information from a child under the applicable age, we will delete the account and its data. If you believe this has happened, contact privacy@miratints.com.
9. International Data Transfers
We operate globally. Personal information may be processed in Japan, the United States, and the European Union depending on the cloud region of the underlying provider. Transfers from the EU/UK are made under standard contractual safeguards where required.
10. Cookies and Tracking Technologies
The mobile app does not use cookies and does not collect advertising identifiers (IDFA / AAID).Usage-analytics events are collected on the basis of consent. In the EU/EEA, the United Kingdom, and Switzerland the default is off (opt-in); elsewhere the default is on and you can turn it off at any time (opt-out). Provision of anonymized data to business trend analytics follows the same regional defaults. Both can be changed at any time from Settings → Data & Privacy; turning a toggle off stops further collection or provision from that moment.Crash reports are collected regardless of consent on the basis of our legitimate interest in keeping the app stable (contents are masked). The web companion (miratints.com / insights.miratints.com) uses a small number of essential cookies for login and locale preference.
11. Two-Factor Authentication Data
If you enable TOTP two-factor authentication, the shared secret is stored encrypted by our auth provider (Supabase Auth) and is never exposed to the app outside of the enrollment QR code. If you enable email OTP, codes are hashed and expire after 5 minutes. We do not retain successful OTP plaintext.
12. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We will note the date at the top and, for material changes, notify you in-app or via email before the change takes effect. Continued use after the effective date constitutes acceptance of the updated Policy.
13. Contact and Governing Law
For privacy questions, requests, or to exercise your rights:• In-app Settings → Contact us• Email: privacy@miratints.comThis Privacy Policy is governed by the laws of Japan. We endeavour to comply with applicable laws in other jurisdictions where we operate, including the GDPR (EU), UK GDPR, CCPA / CPRA (California), and APPI (Japan).
MiratintsOperated by Go Nakamura© 2026 All Rights Reserved