Privacy Policy

Last updated: May 14, 2026

Your data belongs to you

Miray is built local-first. Your baby's tracking data lives on your devices and in your own family's Supabase row. We never sell it or use it for advertising, and it is never used to train any AI model. The only time it leaves our systems is when you choose to use Nora, our AI assistant — then, with your consent, the relevant data is sent to an AI provider to generate a reply (see section 3). This page explains exactly what we collect, why, who we share it with, and the choices you have.

1. What we collect

We collect only what is needed to run Miray:

  • Account data — email, display name, encrypted password.
  • Family + baby profile — family name, baby name, date of birth, optional photo, gender (if provided).
  • Tracking events — feedings, diapers, sleep, growth, medications, temperatures, pumping sessions you log.
  • AI conversation history (if you use Nora) — your messages and her replies, stored per family.
  • Subscription + payment metadata — handled by Stripe; we store only the subscription status and plan, never card numbers.
  • Technical metadata — device client ID, timestamps, last-active time for sync coordination.

2. What we do NOT collect

We deliberately do not collect:

  • Location data, contacts, photos beyond the optional baby photo, or microphone recordings (voice transcription happens on-device and is sent only to your chosen AI provider for parsing).
  • Advertising identifiers, third-party trackers, or any analytics that profile you across the web.
  • We never sell your data. There is no advertising business in Miray.

3. How AI works & what we share with AI providers

Nora is optional. The first time you use her, we ask for your explicit consent before any data is sent. When you send a message (typed or by voice), your message plus a snapshot of your baby's tracking data — feeds, sleep, diapers, growth, temperature, medications, and your notes — is sent to a third-party AI provider to generate the reply. By default that provider is Anthropic (Claude), using our account. If you add your own API key (BYOK) in Settings, the request instead goes to the provider you chose (OpenAI, Google, or Anthropic). These providers process the data under their commercial API terms, which provide data protection equal to or greater than what this policy describes and, for API traffic, do not use your data to train their models (Anthropic and OpenAI both state this for API usage). We never send your password or payment details to any AI provider. You can decline the AI entirely and keep using the rest of Miray.

4. Where your data lives

Account, family, and event data are stored in Supabase (PostgreSQL) in the eu-central-1 region. Row-Level Security policies guarantee that you can only read or write rows scoped to your family. Local copies live in your browser via IndexedDB (Dexie) so the app works offline.

5. Sharing

Caregivers you invite to your family can read and write all events for that family — that is the entire point of inviting them. No one outside your family workspace can see your data, including Miray staff (we cannot decrypt your row contents without your authorization for support).

6. Your rights

You can export, modify, or delete any data at any time. Email amir.amon23@gmail.com to request a data export or full account deletion. We delete account + family rows within 7 days of a verified request.

7. Children

Miray stores information about your baby — but the account holder is you, the caregiver. You are responsible for the data you log. If you wish to delete your baby's profile, you can do so from Settings → Baby Profile.

8. Contact

Questions, requests, or concerns? Reach the developer at amir.amon23@gmail.com.

Privacy Policy — Miray | Miray