Mirua Privacy Policy — English Reference

Revision: 1.8.0
Effective date: 2026-10-20
Last revised: 2026-09-20

Reference document: English Terms

This is a reference translation. The Korean policy is authoritative for Korean users, and the Japanese policy applies to Japanese users. In case of any discrepancy, the applicable Korean or Japanese version prevails.

1. Controller

Mirua, represented by OH YUJUN, Korean business registration number 339-29-01761. Address: Unit 901-346, 9F, 33 Dongtanjungsimsangga 1-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do 18455, Republic of Korea. Privacy contact: [email protected], +82-70-8058-8479.

2. Data and purposes

Mirua processes:

Mirua does not collect payment-card, bank-account, or Korean resident-registration numbers. After paid diamonds are enabled, Apple or Google handles the payment method and Mirua receives only transaction information needed for verification.

3. AI processing

Before member AI chat and the creation-consultation feature that reviews or rewrites free-text drafts, Mirua obtains separate consent to process sensitive data the user directly enters, including health, political views, religion or belief, sex life, and criminal history, to generate AI responses and provide the conversation. Such content may remain in chat messages for up to 90 days after last activity, or, if sooner, until the user deletes the chat or account. Refusal or withdrawal disables AI chat and creation consultation, while donations, rewards, coupons, saving creations, purchases, legal documents, support, account deletion, and logout remain available. When withdrawing, the user may choose to also delete all stored conversations, including chat memory, at the same time; after withdrawal, existing conversations are not used for new AI processing.

AI responses and memory processing use Mirua's own AI models. Chat text is not sent to external commercial generative-AI services operated by other companies. By default this processing runs on private servers in the Republic of Korea controlled by Mirua; when additional processing capacity is needed, Mirua temporarily runs the same models on GPU servers rented by the hour from external GPU providers (Runpod Inc., Nebius B.V., and DataCrunch Oy (Verda) — see Section 6). A conversation assigned to an external server may continue to be processed there after domestic capacity recovers, to keep the connection and finish the processing. Mirua starts and stops those servers; only while one is running is conversation content used in that server's memory to generate responses and to extract memories after a conversation; while domestic servers cannot serve memory-search vector computation because of an outage or their state cannot be confirmed, that computation runs there too on the same conditions; when a domestic server is confirmed healthy, it stays domestic. Memory is not wiped the moment a response completes: a temporary cache computed from the conversation may remain in the inference process's memory for reuse and is released when it is replaced or the process ends. Ordinary request-body logging is disabled and the servers are configured not to write conversation content to the provider's storage; Mirua verifies this by measurement. Mirua uses an external GPU provider only after the applicable data processing agreement has been concluded and the processing scope (including sensitive information entered by users and information of minor users) has been confirmed, and sends no user personal data to a provider for which that confirmation is not complete. User conversations, memories, and creations are not used to train AI models, including pretraining, fine-tuning, or building training datasets. Sensitive topics are not blocked based on keywords alone, and sensitive facts are excluded before storage in long-term memory. Secret identifiers and credentials are masked before transmission.

4. Retention

The periods for inactive AI chats, memory-retrieval logs, server operational logs and connection-time aggregates are defaults. A setting of 0 disables their scheduled cleanup; it does not mean a shorter retention period. A shorter positive setting applies as configured. Account purge is separate, and statutory retention records are handled separately.

5. Deletion

An account-deletion request immediately disables active sessions and the push token. A seven-day recovery period follows. After it expires, chats, memories, private creations, device links, support data, notifications, interactions, current reward balances, inventory, progress, and attendance state are deleted; authentication credentials are purged; and public identifiers and profile or activity metadata are replaced with non-identifying substitute values. A user-created item adopted into the official catalog is immediately deactivated and its internal creator linkage is removed. A narrowly scoped internal linkage key may remain in access-restricted reward and participation integrity records for one year by default and no more than five years. Upon account deletion, Mirua also attempts to revoke Google or Apple authorization on the provider side (and Kakao or LINE once those logins are offered); if this cannot be completed immediately, the required credential is kept encrypted for a limited time while revocation is retried, and is removed once revocation succeeds. Database recovery files on access-restricted company-managed storage use owner-only file permissions and are ordinarily retained for no more than 30 days. Encrypted copies replicated daily to offsite storage operated by Backblaze, Inc. in the United States are also retained for no more than 30 days; the internal file and its external replica are copies of the same data, not independent originals. Separate image-storage backups are kept on a rotation of no more than 14 days. A restored backup must be checked against deletion records and re-purged before production use.

Accounts whose registration remains incomplete more than 30 days after creation automatically enter the seven-day deletion grace period. Accounts already registered when processed are excluded.

An internal copy tied to a schema-change recovery point takes priority over ordinary rotation and may remain beyond 30 days until that binding is updated.

6. Providers and international processing

Mirua uses the following providers and international-processing paths:

When you access Mirua web pages (the account-deletion page or legal-document pages), Cloudflare may set security cookies for security and bot protection. The app does not use cookies.

Your acknowledgment that you have read the Privacy Policy records delivery of this notice; it does not constitute blanket consent to all processing. Service-essential processing is limited to what is necessary under contract performance or another applicable lawful basis, and any processing that requires separate consent remains separate. Rewarded advertising remains unavailable until separate consent is obtained and the actual mediation partners, countries, data categories, and retention periods are confirmed. If activated, AppLovin and each actual advertising partner will be disclosed immediately before the request. Refusal affects only the optional ad feature.

Firebase Analytics-based usage analytics is not currently collected. Any future activation requires prior disclosure in this Policy, completion of the notice procedure, and the user's separate opt-in in the app; no events are sent before consent. Ad storage and ad-personalization signals are always disabled. Rewarded advertising is currently unavailable, and the AppLovin SDK is not initialized or used to request ads. Any future activation requires the disclosure, separate-consent, and withdrawal conditions to be completed first.

7. Rights and safeguards

Users may request access, correction, deletion, suspension of processing, data portability, consent withdrawal, and account deletion. Requests are received primarily through app settings and the in-app support channel, and requests that need identity documents are also handled safely inside the app.

If you need to report or consult about a personal-data violation in Korea, you may contact the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the Supreme Prosecutors' Office Cyber Investigation Division (1301, spo.go.kr), or the Korean National Police Agency National Office of Investigation Cyber Bureau (182, ecrm.police.go.kr).

If you cannot access the app, you may apply through the public account-deletion page (https://aimirua.com/account/delete) or [email protected]. Please do not attach sensitive documents such as ID cards to email — Mirua will separately guide you through any required verification. Mirua verifies the requester and responds within the applicable legal period, explaining any lawful restriction.

Mirua applies least-privilege access, administrator authentication, encrypted transport, encryption for sensitive chat fields, environment-separated secrets, integrity records, rate limits, controlled backups, regular vulnerability checks, and incident response. Required regulator and user notices are provided after a qualifying incident.

8. Children, optional choices, and updates

Users under 14 may not register. Your date of birth is required at sign-up so that Mirua can verify that you are 14 or older; it checks the date of birth you enter and does not proceed with registration if you are under 14. Gender is optional, and leaving it blank changes nothing about registration or use. Consent to marketing notifications and consent to night-time (9 p.m. to 8 a.m.) notifications are each optional and can be withdrawn at any time in Settings. For users aged 14 or older who are minors, legal-representative consent may still be required depending on the information or contract involved. Push notifications, marketing, personalized advertising, and rewarded ads are optional and separate from required service consent.

Changes that do not affect users' rights or obligations, such as corrections of typographical errors or contact details, are announced in the app or by similar means at least 3 days before they take effect, and changes to rights or obligations that are not adverse to users at least 7 days before. Changes that are adverse to users or that change the scope of consent are announced in the app or by similar means at least 30 days before they take effect and notified individually through in-app notices and an individual notice screen on your next access, and, where consent is required, renewed consent is requested only for the items that changed. Changes that materially expand purposes or third-party disclosure receive any separate consent required by law.

Requests are accepted at any time. Staffed support hours are Korean business days, 10:00–17:00 KST, excluding weekends and Korean public holidays. Mirua aims to provide an initial response within three business days.

9. Revision history

Version Notice date Effective date Class Summary
1.8.0 2026-09-20 2026-10-20 Material (re-consent) Aligned actual processing, retention, reporting, rights and translations; corrected individual notices to in-app notices and a next-access screen
1.0.0 2026-07-18 2026-07-18 Initial release Initial public version
1.1.0 2026-08-09 2026-08-16 General (clarification) ① Retroactive correction of the change applied on 2026-07-23: the operations-log category now explicitly lists daily aggregates of AI usage (token and reply counts) with their retention rule (user linkage removed after 90 days, kept only as anonymous totals). This clarifies an already-disclosed category without expanding purposes or third-party disclosure, so no re-consent is required; that change had been applied to the body without a version bump or notice, which this version corrects. ② The Gmail-based email support channel is now listed as an overseas processor.
1.2.0 2026-09-01 2026-09-08 Minor (disclosure update) ① The contact email address collected at registration (feature introduced 2026-08-30) is now listed as a data category. ② Resend(Plus Five Five, Inc.) is listed as the email delivery processor (overseas processing in the United States). ③ The unconditional Firebase Analytics statement is replaced with a conditional disclosure (no collection before listing, notice, and separate opt-in). This updates disclosures for processing already performed under the contract, without expanding purposes or third-party disclosure, so no re-consent is required.
1.3.0 2026-09-02 2026-09-09 General (clarification) Revised the rights-request guidance in Section 7: requests are received primarily through app settings and the in-app support channel, email remains as a fallback for users who cannot access the app, and a warning against attaching sensitive documents to email was added. This clarifies the reception path without changing purposes, data categories, or third-party disclosure, so no re-consent is required.
1.4.0 2026-09-03 2026-09-10 Minor (disclosure update) ① The support email channel moved to a company-domain address ([email protected]) in every contact notice. ② Cloudflare, Inc. is listed as the support-email forwarding processor and the mailbox-provider entry is restated for the new channel (Section 6). This is a contact-address change and processor-disclosure update with no expansion of purposes or data categories, so it does not require renewed consent.
1.4.1 2026-09-04 2026-09-11 General (contacts) Remedy-body contacts (KISA 118, Dispute Mediation Committee 1833-6972, prosecution 1301, police 182) added to §7
1.4.2 2026-09-05 2026-09-12 Minor (security disclosure) Clarified Cloudflare security cookies on account-deletion and legal-document web pages and that the app does not use cookies
1.5.0 2026-09-07 2026-09-09 Material (overseas processor added) ① Listed the temporary processing on which Mirua runs its own AI models on GPU servers rented from external providers (Runpod Inc., Nebius B.V., DataCrunch Oy (Verda)) when Mirua's own servers need additional capacity, in the processor and international-processing disclosure (Section 6), and revised the AI processing-location statement in Section 3 accordingly. ② This is processing on Mirua's instructions with Mirua's own models; to the extent necessary to perform the service contract a user has requested it relies on PIPA Article 28-8(1)(3)(a) (statutory disclosure in this Policy) and, within that scope, is not a third-party disclosure or an expansion of purposes and does not require separate consent. Because the processing location of conversation content extends abroad, it is treated as a material change. ③ No data is sent to a provider for which the data processing agreement and processing scope have not been confirmed. ④ This version takes effect on 2026-09-09 after a short interval: at the time of the announcement the service had zero external users, so there were no existing users whom an advance-notice period could protect. The effective date was still set to the day after publication so that the revised text is actually served in all three languages before it takes effect. Material changes made after the service has users will follow the 30-day advance in-app notice and individual notification stated in Section 8.
1.6.0 2026-09-09 2026-09-10 Material (data items added) ① With the new sign-up details screen, added date of birth and gender (optional) to the account items in Section 2 and added confirming that you are 14 or older, recommendations and service analytics by age group and gender, and notices about birthday perks to the purposes. ② Stated in Section 8 that the date of birth entered at sign-up is used to verify that you are 14 or older, that gender is optional, and that marketing and night-time notification consents are each optional and can be withdrawn at any time. ③ Added a retention line for date of birth and gender (until final account purge) in Section 4. ④ This version takes effect the day after publication: at the time of the announcement the service had zero external users (re-measured, on the same basis as 1.5.0 ④), so there were no existing users whom an advance-notice period could protect. For material changes made after the service has users, Mirua provides the 30 days' advance notice stated in Section 8, in the app and by individual notification.
1.7.0 2026-09-11 2026-09-11 Material (change-notice periods) Restated the change-notice periods in days: 3 days for changes that do not affect rights or obligations, 7 days for non-adverse changes (no renewed consent), and 30 days with individual notification and renewed consent limited to the changed items for adverse changes or changes to the scope of consent
1.7.1 2026-09-11 2026-09-14 General (correction) Aligned the text of Section 8 with Section 10 of the Terms and the 1.7.0 revision-history entry (renewed consent limited to the changed items stated expressly): the 30-day individual-notice sentence now says that, where consent is required, renewed consent is requested only for the items that changed, moving into the text the standard the 1.7.0 entry already stated. Users' rights and obligations do not change, so this does not require renewed consent.