The short version: We only collect data needed to provide the Service. We never sell your financial data. You can export or delete your data at any time by contacting us.
1. Overview
Miraurum, Inc. ("Miraurum," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cash flow intelligence platform ("the Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
Account information — When you register, we collect your name, email address, and billing information.
Financial data — When you connect a bank account via Plaid, we receive read-only access to your transaction history, account balances, and institution names. We store encrypted access tokens to retrieve this data on your behalf.
Usage data — We automatically collect information about how you interact with the Service, including page views, feature usage, and timestamps.
Device and log data — We collect IP addresses, browser type, device identifiers, and server log data for security and debugging purposes.
| Data type | Examples | Purpose |
|---|---|---|
| Account data | Name, email, password hash | Authentication, communication |
| Financial data | Transactions, balances, institutions | Core Service functionality |
| Payment data | Billing address, last 4 digits | Subscription management (via Stripe) |
| Usage data | Feature clicks, session duration | Product improvement |
| Log data | IP address, browser, timestamps | Security, debugging |
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and manage your subscription
- Generate insights, forecasts, and anomaly reports from your financial data
- Communicate with you about your account, updates, and support requests
- Detect, prevent, and respond to fraud, security incidents, and abuse
- Comply with applicable laws and regulations
- Analyze aggregate usage patterns to improve the Service (using anonymized data)
We do not use your financial data to profile you for advertising or make automated decisions that have legal or similarly significant effects on you.
4. Information Sharing
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- Service providers. We share data with trusted vendors who help us operate the Service (Plaid, Stripe, cloud hosting providers, analytics). These parties are contractually bound to use data only as instructed.
- Legal requirements. We may disclose information if required by law, court order, or to protect the rights, property, or safety of Miraurum, our users, or the public.
- Business transfers. If Miraurum is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you in advance and provide options.
- With your consent. We may share information with third parties when you explicitly direct us to.
5. Financial Data and Plaid
Bank account connectivity is provided by Plaid Inc. When you link a financial account, Plaid retrieves your transaction data and passes it to Miraurum. Your relationship with your bank is governed by your bank's agreements and Plaid's End User Privacy Policy.
Miraurum receives read-only access to your transaction data. We never request access to transfer funds or modify your accounts.
You may revoke Miraurum's access to your financial accounts at any time by disconnecting them within the Service or by contacting your bank directly.
6. Data Security
We implement industry-standard safeguards to protect your information:
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Financial access tokens are encrypted at rest using AES-256-GCM authenticated encryption (which rejects any tampered data) and are never exposed in plaintext
- Access to production data is restricted to authorized personnel on a need-to-know basis
- We follow industry-standard security practices and review our security controls on an ongoing basis
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Please notify us immediately at security@miraurum.com if you suspect any unauthorized access.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained until you delete your account, plus 30 days for recovery purposes.
- Financial transaction data is retained for up to 24 months to support historical analysis and forecasting.
- Billing records are retained for 7 years as required by applicable tax law.
- Log data is retained for up to 12 months for security and debugging.
After the applicable retention period, data is securely deleted or anonymized.
8. Cookies and Tracking
We use cookies and similar tracking technologies to operate the Service. Types of cookies we use:
- Essential cookies — Required for authentication, session management, and core Service functionality. Cannot be disabled.
- Analytics cookies — Help us understand how the Service is used in aggregate. You may opt out by adjusting your browser settings.
- Preference cookies — Remember your settings and preferences across sessions.
You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request that we correct inaccurate or incomplete data.
- Deletion — Request deletion of your personal data (subject to legal retention requirements).
- Portability — Request your data in a structured, machine-readable format.
- Restriction — Request that we limit how we process your data.
- Objection — Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@miraurum.com. We will respond within 30 days. For EEA/UK residents, you may also lodge a complaint with your local data protection authority.
10. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us and we will promptly delete it.
11. Third-Party Links
The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party services you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a notice within the Service at least 14 days before the changes take effect.
Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
13. Contact Us
For privacy-related inquiries, data requests, or concerns:
- Email: privacy@miraurum.com
- Security issues: security@miraurum.com
- Address: Miraurum, Inc., 1209 Orange Street, Wilmington, DE 19801
See also: Terms of Service