Privacy Policy
Your privacy matters to us. Here's how we handle your data.
Your Photos
Your photos are private by default. We store your original files securely and never share them without your explicit permission. We don't use your photos for training AI models or any purpose other than providing you the service.
Data Collection
We collect only what's necessary to provide the service: your email address, your username, and the photos and videos you upload. We use a cookie to keep you signed in. We do not run third-party analytics, advertising, or tracking of any kind.
We count page views using Plausible, which we run ourselves on our own server. It sets no cookies, does not follow you between sites, and records no information that identifies you — a page address, a referrer, a country, and a browser and device type, and nothing more. It is not shared with anyone. There is no consent banner because there is nothing to consent to.
Photos and Metadata
When you upload a photo we read its EXIF metadata — the date it was taken, the camera and lens, exposure settings, and GPS coordinates if your camera recorded them — and store it in our database so you can sort and search by it.
Every resized copy we display is generated with that metadata removed. Your GPS coordinates are never included in an image we serve, and are never shown to anyone but you.
Your original file is kept exactly as you uploaded it, metadata intact, so that downloading it gives you back precisely what you had. Only you can download your originals.
Sharing beyond Miru
Your account is an ActivityPub actor, which means people on Mastodon and other servers can follow it. When you make a post public or followers only, we deliver a copy of it — the caption and the display-size images, never the original file and never its metadata — to the servers your followers are on. Those servers keep their own copies, and we cannot delete them for you: if you delete the post we tell them to, and it is up to them to comply.
Password-protected and direct posts are never delivered anywhere. Nothing in your library leaves Miru until you post it, and a post's visibility is what decides where it goes.
Taking your data with you
You can export everything from your profile settings: every original file exactly as you uploaded it, plus a JSON file describing your albums, posts and captions. The export is built in the background, downloadable for 7 days, and then deleted.
Data Retention
You can delete any photo, album, or your whole account at any time, from the web or from the app. Deleting your account removes your profile, every photo and video, and every album and post, and erases the stored files from our servers. It cannot be undone and we cannot recover it for you afterwards.