Privacy Policy

Last updated: 20 August 2026

Mirafold is designed to see as little of your data as technically possible. This policy tells you exactly what that means — what is processed, by whom, and for how long. The honest summary is: almost nothing.

The short version, for the coding software and the Pro relay. Your code, your API keys, and your conversations never leave your machine in a form we can read. The paid relay forwards only end-to-end-encrypted traffic — it cannot decrypt your content. We run no analytics and set no cookies. The only personal data involved is a small amount of connection metadata (such as IP addresses) that any internet service unavoidably handles, the billing details you give our payment provider when you subscribe, and — if you join our early-access waitlist — the email address you give us for that.

Mirafold Chat is the exception, and we want to be plain about it. Chat is a hosted app: the assistant runs on our servers, not yours. So unlike everything else here, we do store your conversations — that is what makes your history available when you come back — and your messages are sent to the AI provider that generates the replies. Section 4a says exactly what is kept, who sees it, and how to delete it.

1.Who we are

Mirafold is operated by Kyle Serrecchia, an individual doing business as “Mirafold” (“we”, “us”). For the personal data described below, we are the data controller. You can reach us at support@mirafold.com.

2.The local software

The core Mirafold software runs entirely on your own machine. Your API keys stay in your local environment and are never sent to the browser or to us. Your code and your agent conversations are processed locally by the coding agent you already use. We do not collect, receive, or store any of this. The software contains no analytics or telemetry.

3.The website (mirafold.com)

This website is a set of static pages served through Cloudflare. It sets no cookies and runs no analytics or tracking. As with any website, our hosting provider (Cloudflare) processes standard request information — such as your IP address and the page requested — in its edge logs to deliver the site and protect it from abuse. We do not use this for tracking or advertising.

4.The Mirafold Pro relay

Mirafold Pro adds a hosted relay that lets your devices reach your local sessions. The relay is end-to-end encrypted and content-blind: it forwards ciphertext between your devices and never holds the keys needed to read it. It therefore cannot see, and does not store, your code, your API keys, or your conversations.

To move that traffic and keep the service safe, the relay necessarily handles a small amount of connection metadata:

We minimize even this. Our relay application keeps client IP addresses in memory only, for rate-limiting, and does not write them to its own application logs. IP addresses may be recorded transiently at the network layer by our hosting provider (Fly.io) as part of standard infrastructure operation. We keep no separate long-term log of your relay activity — what isn’t retained can’t be lost or disclosed.

4a.Mirafold Chat

Mirafold Chat (chat.mirafold.com) is a hosted application, so it necessarily processes more than anything else described here. This is what it stores, all of it in a managed database located in the United States:

Who else sees your messages. To generate a reply, your message and the recent conversation are sent to OpenRouter, which routes them to the open-weight model that produces the answer. Messages may also be submitted to OpenAI’s automated safety (moderation) service. When an answer needs current information from the web — a forecast, a price, the news — the assistant can run a web search through our search provider, Brave. Brave receives the search query, which the assistant composes from the substance of your request and is instructed to keep free of personal details; it never receives your conversation or your account information, and every search is disclosed in the chat at the point it happened. If you use voice dictation, turning your speech into text is done by your browser’s own dictation service (Apple’s or Google’s, depending on your device) under that provider’s terms — the audio goes to them directly, and we only ever receive the text that lands in the message box. We do not use your conversations to train any model, we do not sell them, and we do not share them with anyone else.

Deleting it. You can delete a conversation from within the app at any time. To delete your account and everything stored with it, email support@mirafold.com and we will remove it.

5.Billing (Mirafold Pro and Mirafold Chat)

Payment for both live products is currently handled by our merchant of record, Paddle. Paddle collects the details needed to take payment — such as your name, email, billing address, and card information — and uses them to process the transaction, prevent fraud, and meet tax obligations. For this billing relationship, Paddle acts as an independent data controller, not as our processor, and its own privacy notice governs how it handles your payment data. We receive only the limited information needed to manage your subscription (for example, that an active subscription exists and the email associated with it). We never see or store your full card number.

6.The early-access waitlist

If you sign up for early access to a Mirafold product (for example at mirafold.com/early), we store the details needed to run that list and to prove you asked to be on it:

We use this list for exactly two things: a single welcome email confirming your signup, and letting you know when the product launches. We do not share the list with anyone or use it for anything else. Emails are sent through our email provider, Resend (see section 7), and every email includes an unsubscribe link. Unsubscribing stops all further email immediately; if you would also like the record itself deleted, email support@mirafold.com and we will remove it.

7.Service providers (subprocessors)

We rely on a small number of infrastructure providers that process data on our behalf:

Where cross-border transfer rules apply, we use the contractual or recognized transfer safeguards available from the applicable provider. The queries Brave receives are not linked to your identity. Paddle handles payment transactions under its own privacy notice and therefore sits outside this subprocessor list.

8.Why we process this data, and our legal basis

We process the limited data above to (a) deliver the website, the Pro relay, and Mirafold Chat, (b) keep them secure and prevent abuse, (c) manage your subscription, and (d) run the early-access waitlist you asked to join. Where the GDPR applies, our legal bases are the performance of our contract with you (providing Pro, and providing Chat — storing your conversations and sending them to the model provider is how the app delivers what you subscribed to), our legitimate interests in operating and securing the service, and — for the waitlist — your consent, which you can withdraw at any time by unsubscribing. Outside Mirafold Chat, we retain so little that most of this data exists only transiently.

9.Retention

Mirafold Chat is the one place we retain content: your account and its conversations are kept until you delete them or ask us to delete your account, at which point they are removed. Sign-in codes expire within minutes and are single-use.

Everywhere else, we do not retain your content or conversations at all — the relay never holds them in readable form. Connection metadata is not written to our own persistent logs; any infrastructure-level records our providers keep are held only for their standard, short operational periods. Billing records are retained by Paddle as required for tax and accounting purposes. Waitlist records are kept until the launch announcement that list exists for has been sent, or until you unsubscribe and ask us to delete your record, whichever comes first.

10.Your rights

Depending on where you live (including under the GDPR and the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to lodge a complaint with your data-protection authority. To exercise any of these, email support@mirafold.com and we will respond as the law requires. For payment data held by Paddle as an independent controller, you can also contact Paddle directly. We do not sell your personal data, and we run no advertising or tracking.

11.Children

Mirafold is not directed to children, and Mirafold Chat is for adults only — you must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18 in connection with Mirafold Chat, or from anyone under 13 anywhere; if we learn we have, we will delete it. Paid subscriptions require you to be at least 18.

12.Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify subscribers.

13.Contact

Questions about your privacy, or want to exercise a right above? Email support@mirafold.com or see the contact page.

back to mirafold.com