❯Privacy Policy
Last updated: 20 August 2026
Mirafold is designed to see as little of your data as technically possible. This policy tells you exactly what that means — what is processed, by whom, and for how long. The honest summary is: almost nothing.
The short version, for the coding software and the Pro relay. Your code, your API keys, and your conversations never leave your machine in a form we can read. The paid relay forwards only end-to-end-encrypted traffic — it cannot decrypt your content. We run no analytics and set no cookies. The only personal data involved is a small amount of connection metadata (such as IP addresses) that any internet service unavoidably handles, the billing details you give our payment provider when you subscribe, and — if you join our early-access waitlist — the email address you give us for that.
Mirafold Chat is the exception, and we want to be plain about it. Chat is a hosted app: the assistant runs on our servers, not yours. So unlike everything else here, we do store your conversations — that is what makes your history available when you come back — and your messages are sent to the AI provider that generates the replies. Section 4a says exactly what is kept, who sees it, and how to delete it.
1.Who we are
Mirafold is operated by Kyle Serrecchia, an individual doing business as “Mirafold” (“we”, “us”). For the personal data described below, we are the data controller. You can reach us at support@mirafold.com.
2.The local software
The core Mirafold software runs entirely on your own machine. Your API keys stay in your local environment and are never sent to the browser or to us. Your code and your agent conversations are processed locally by the coding agent you already use. We do not collect, receive, or store any of this. The software contains no analytics or telemetry.
3.The website (mirafold.com)
This website is a set of static pages served through Cloudflare. It sets no cookies and runs no analytics or tracking. As with any website, our hosting provider (Cloudflare) processes standard request information — such as your IP address and the page requested — in its edge logs to deliver the site and protect it from abuse. We do not use this for tracking or advertising.
4.The Mirafold Pro relay
Mirafold Pro adds a hosted relay that lets your devices reach your local sessions. The relay is end-to-end encrypted and content-blind: it forwards ciphertext between your devices and never holds the keys needed to read it. It therefore cannot see, and does not store, your code, your API keys, or your conversations.
To move that traffic and keep the service safe, the relay necessarily handles a small amount of connection metadata:
- IP addresses of connecting devices
- Pairing identifiers used to connect your devices to each other
- Connection timing (when a connection opens and closes)
- The volume of data forwarded (byte counts)
We minimize even this. Our relay application keeps client IP addresses in memory only, for rate-limiting, and does not write them to its own application logs. IP addresses may be recorded transiently at the network layer by our hosting provider (Fly.io) as part of standard infrastructure operation. We keep no separate long-term log of your relay activity — what isn’t retained can’t be lost or disclosed.
4a.Mirafold Chat
Mirafold Chat (chat.mirafold.com) is a hosted application, so it necessarily processes more than anything else described here. This is what it stores, all of it in a managed database located in the United States:
- Your email address. It is the whole of your account — there is no password. Signing in sends a short numeric code to that address; the codes are stored hashed, are single-use, and expire.
- Your conversations. The messages you send and the assistant’s replies, including the components it draws, are stored and linked to your account so your history is there on any device you sign in from. They are readable by us in principle — they are not end-to-end-encrypted, and we would not be able to show you your own history if they were.
- Usage counts. Token counts and the resulting cost per message, used to operate the monthly allowance and to understand what the service costs to run.
- A session cookie, which keeps you signed in. It is strictly necessary for the app to function; we set no analytics or advertising cookies anywhere.
Who else sees your messages. To generate a reply, your message and the recent conversation are sent to OpenRouter, which routes them to the open-weight model that produces the answer. Messages may also be submitted to OpenAI’s automated safety (moderation) service. When an answer needs current information from the web — a forecast, a price, the news — the assistant can run a web search through our search provider, Brave. Brave receives the search query, which the assistant composes from the substance of your request and is instructed to keep free of personal details; it never receives your conversation or your account information, and every search is disclosed in the chat at the point it happened. If you use voice dictation, turning your speech into text is done by your browser’s own dictation service (Apple’s or Google’s, depending on your device) under that provider’s terms — the audio goes to them directly, and we only ever receive the text that lands in the message box. We do not use your conversations to train any model, we do not sell them, and we do not share them with anyone else.
Deleting it. You can delete a conversation from within the app at any time. To delete your account and everything stored with it, email support@mirafold.com and we will remove it.
5.Billing (Mirafold Pro and Mirafold Chat)
Payment for both live products is currently handled by our merchant of record, Paddle. Paddle collects the details needed to take payment — such as your name, email, billing address, and card information — and uses them to process the transaction, prevent fraud, and meet tax obligations. For this billing relationship, Paddle acts as an independent data controller, not as our processor, and its own privacy notice governs how it handles your payment data. We receive only the limited information needed to manage your subscription (for example, that an active subscription exists and the email associated with it). We never see or store your full card number.
6.The early-access waitlist
If you sign up for early access to a Mirafold product (for example at mirafold.com/early), we store the details needed to run that list and to prove you asked to be on it:
- the email address you enter
- the date and time you signed up, and the IP address the signup came from — kept as proof of your opt-in consent
- if present, a short marker for the page or video that brought you, and the referring page your browser reported
We use this list for exactly two things: a single welcome email confirming your signup, and letting you know when the product launches. We do not share the list with anyone or use it for anything else. Emails are sent through our email provider, Resend (see section 7), and every email includes an unsubscribe link. Unsubscribing stops all further email immediately; if you would also like the record itself deleted, email support@mirafold.com and we will remove it.
7.Service providers (subprocessors)
We rely on a small number of infrastructure providers that process data on our behalf:
- Fly.io — hosts the Pro relay and Mirafold Chat. Handles connection metadata and application traffic as described in sections 4 and 4a.
- Cloudflare — serves this website and its email routing, and stores the early-access waitlist described in section 6. Handles standard request metadata as described in section 3.
- Resend — sends the early-access waitlist emails described in section 6 and Mirafold Chat’s sign-in codes, and processes the email addresses involved on our behalf.
- Neon — hosts the managed United States database in which Mirafold Chat stores accounts, conversations, and usage counts (section 4a).
- OpenRouter — receives Mirafold Chat messages and routes them to the open-weight model that produces the answer (section 4a).
- OpenAI — may receive Mirafold Chat input for automated safety screening (section 4a).
- Brave — receives the web-search queries the Mirafold Chat assistant runs when an answer needs current information from the web (section 4a). Queries arrive with no account information attached.
Where cross-border transfer rules apply, we use the contractual or recognized transfer safeguards available from the applicable provider. The queries Brave receives are not linked to your identity. Paddle handles payment transactions under its own privacy notice and therefore sits outside this subprocessor list.
8.Why we process this data, and our legal basis
We process the limited data above to (a) deliver the website, the Pro relay, and Mirafold Chat, (b) keep them secure and prevent abuse, (c) manage your subscription, and (d) run the early-access waitlist you asked to join. Where the GDPR applies, our legal bases are the performance of our contract with you (providing Pro, and providing Chat — storing your conversations and sending them to the model provider is how the app delivers what you subscribed to), our legitimate interests in operating and securing the service, and — for the waitlist — your consent, which you can withdraw at any time by unsubscribing. Outside Mirafold Chat, we retain so little that most of this data exists only transiently.
9.Retention
Mirafold Chat is the one place we retain content: your account and its conversations are kept until you delete them or ask us to delete your account, at which point they are removed. Sign-in codes expire within minutes and are single-use.
Everywhere else, we do not retain your content or conversations at all — the relay never holds them in readable form. Connection metadata is not written to our own persistent logs; any infrastructure-level records our providers keep are held only for their standard, short operational periods. Billing records are retained by Paddle as required for tax and accounting purposes. Waitlist records are kept until the launch announcement that list exists for has been sent, or until you unsubscribe and ask us to delete your record, whichever comes first.
10.Your rights
Depending on where you live (including under the GDPR and the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to lodge a complaint with your data-protection authority. To exercise any of these, email support@mirafold.com and we will respond as the law requires. For payment data held by Paddle as an independent controller, you can also contact Paddle directly. We do not sell your personal data, and we run no advertising or tracking.
11.Children
Mirafold is not directed to children, and Mirafold Chat is for adults only — you must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18 in connection with Mirafold Chat, or from anyone under 13 anywhere; if we learn we have, we will delete it. Paid subscriptions require you to be at least 18.
12.Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify subscribers.
13.Contact
Questions about your privacy, or want to exercise a right above? Email support@mirafold.com or see the contact page.