Privacy Policy

Application: Mirth AI Last Updated: June 15, 2026

Mirth AI ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Mirth AI mobile application (available on Google Play), our related websites, and any associated services (collectively, the "Services").

By accessing or using the Services, you acknowledge that you have read, understood, and agreed to this Privacy Policy and our Terms of Service. If you do not agree, please refrain from using the Services.

Personal Data means information that can identify or be reasonably associated with a specific individual. Aggregated or anonymous data that cannot identify you is not Personal Data and may be used without restriction.

1 Information We Collect

Overview

We collect information in three categories: (a) information you voluntarily provide, (b) media you choose to upload for AI processing, and (c) technical information generated automatically as you use the Services. The sections below describe each category in detail.

Examples of information you may voluntarily provide include your email address, username, and social-network information when you register, contact us, or use the Services. For details, see Section 2 (Login & Account Information) and Section 3 (Photos, Videos & Service Data).

2 Login & Account Information

2.1 Certain features (such as sharing content) require you to complete a login process.

2.2 If you create an account through a third-party service (such as Google, Facebook, or Apple ID), we receive information associated with that account, including your name, email address, username, and any other information you submit during registration.

2.3 All login-related information is deleted simultaneously when you delete your account.

2.4 You may delete your account and its associated data at any time through in-app self-service, or by contacting our support team. See Section 14 for details.

3 Photos, Videos & Service Data

3.1 Access to Photos and Videos

To use the AI image or video generation features, you must upload photos or videos. The Application will request explicit permission to access your local media or files. You may revoke this permission at any time through your device settings.

3.2 Secure Transmission

All uploaded content is transmitted via encrypted connections (SSL/TLS), and we adopt reasonable technical measures to protect data during transmission and processing.

3.3 Use and Deletion of Service Data

It is your responsibility to save generated results before they are deleted.

4 How We Use Uploaded Media

4.1 Depending on the model, our Services may perform body (outline) detection, facial-region detection, facial-feature detection, key skeletal-point detection (e.g. head, neck, shoulders, torso, wrists), and clothing detection on uploaded images or videos. This data is used exclusively to generate the requested results, is temporarily cached in server memory during processing, and is deleted immediately after generation completes.

4.2 We do not use any user photos, videos, or generated content to train or improve our AI models.

4.3 Facial key points and similar data are not collected without the individual's prior consent (obtained by granting photo-library access).

4.4 Before deletion, such data is stored, transmitted, and protected using standards equivalent to or stricter than those applied to other confidential information used to identify individuals (including login data such as email addresses).

4.5 We do not use facial, key-point, or body-detection data to identify or verify any individual, and we do not create biometric identifiers or user profiles.

4.6 All such data is used exclusively for generating the requested AI output and is deleted immediately after processing; no copies are retained afterward.

5 Technical & Device Information

When you use the Services, certain information related to your device and network activity is automatically generated. We collect the following technical information:

The sole purpose of collecting the above is to ensure the safe, stable operation of the Services, optimize performance, and troubleshoot system faults.

6 How We Use Information

We use the Personal Data and Service Data we collect for the following purposes:

7 Data Sharing & Disclosure

7.1 The photos and videos you upload for AI processing are never disclosed to third parties, except when you voluntarily choose to share the generated results yourself.

7.2 We may share Personal Data (and non-personal information) with service providers acting on our behalf (such as data-management, hosting, and infrastructure providers), and we may share aggregated, non-personally-identifying Log Data for advertising and product promotion. See Section 8 for the third parties involved.

7.3 We may disclose Personal Data only in the following circumstances:

We will not disclose your uploaded images or videos to any service unless you voluntarily share them (together with the results) through the Services or a third-party service.

8 Third-Party Services & SDKs

We may integrate third-party services to support analytics, advertising, or infrastructure stability. These services may collect limited technical data in accordance with their own privacy policies.

Advertising Platforms

Analytics & Infrastructure

All third-party providers are bound by contractual obligations to comply with applicable data-protection laws. Advertising-related third parties may collect advertising identifiers solely for attribution and fraud prevention. You may review their data-processing rules through their official policies or restrict collection via their opt-out mechanisms. We do not authorize any third party to use collected information for purposes unrelated to our Services.

9 Advertising & Tracking

10 Cookies (Third-Party Login Only)

10.1 When you log in using a third-party service (e.g. Google), you may be redirected to a web page provided by that service.

10.2 The third-party service may use Cookies or similar technologies to maintain your login session and complete authentication.

10.3 We do not use Cookies for advertising, tracking, or analytics, nor do we independently access or store these Cookies. Any Cookies used during third-party login are controlled by the relevant third party and governed by its privacy policy.

10.4 Our Application does not use Cookies to track users across different applications or websites.

11 Android Permissions

The Application may request the following permissions, each used strictly for its stated purpose:

12 Data Retention

Exceptions: For legal obligations (e.g. tax records, compliance audits), dispute resolution, or service security, we may retain data beyond the periods above, but not exceeding the maximum required by law (e.g. 5 years under Singapore's Personal Data Protection Act), and only within the scope of necessity.

13 Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

To exercise these rights, submit a written request to the contact in Section 21, including your name, registered email / account ID, contact information, and the right you wish to exercise. Where applicable, provide identity-verification materials. We will respond within 15 working days; if we cannot satisfy the request, we will provide a written explanation of the reasons and legal basis.

14 Account & Data Deletion

You may delete your account and data in any of the following ways:

After deletion, all relevant Personal Data will be deleted, subject to compliance with legal and technical obligations (e.g. backups).

15 Data Security

We use technical and management measures designed to protect your privacy and prevent unauthorized access or misuse, and we continue to update these measures as technology evolves. However, we cannot guarantee that unauthorized third parties will never bypass our security measures. If you use a password to access the Services, you are responsible for keeping it confidential.

15.1 Data Transmission: All data (including uploaded media and Personal Data) is transmitted via TLS 1.2+ encrypted protocols.

15.2 Data Storage: Sensitive data is stored on encrypted servers (AES-256), with access granted only to authorized personnel on a need-to-know basis (requiring multi-factor authentication).

15.3 Access Control: A strict permission-classification system limits internal access to user data, and all access activities are recorded in audit logs.

15.4 Emergency Response: In the event of a data breach, we will notify affected users within 72 hours of discovery (where required by applicable law) and take remedial measures and report to the relevant authorities.

16 Children's Privacy

Minors must obtain prior consent from a parent or legal guardian to use the Services. We recommend that guardians read this Policy carefully and advise minors to obtain guidance before submitting Personal Data.

If you are a guardian and discover that a minor (under the age of 13) has used the Services and submitted Personal Data without authorization, you may submit a deletion request to the contact in Section 21. The request must include the guardian's identity document, proof of the guardianship relationship (e.g. household register, birth certificate), and the minor's account information (if any). We will delete the relevant data within 15 working days of verifying the materials.

COPPA: We respect children's privacy in accordance with the Children's Online Privacy Protection Act. We do not knowingly collect or solicit information from individuals under 13, nor allow such individuals to register. If we discover that we have collected Personal Data from a child under 13 without parental consent, we will delete it as soon as possible. If you believe we may hold such information, please contact us at [email protected].

17 International Data Transfers

User data may be processed on servers located outside your country of residence. We will adopt appropriate safeguards (such as standard contractual clauses where required) to protect such transfers in accordance with applicable data-protection laws.

18 Legal Bases for Processing (EEA / UK)

For users in the European Economic Area or the United Kingdom, we process Personal Data on the following legal bases:

19 Google Play Data Safety Consistency

This Privacy Policy is consistent with the disclosures in the Google Play Data Safety section. All data collection, use, sharing, and retention practices comply with those disclosures, including the declaration of the following data types and purposes:

We do not share user-provided photos, videos, or generated content with third parties except as described in Section 7 and Section 8.

20 Changes to This Policy

We may update this Privacy Policy from time to time. For material changes (including expansion of the data-collection scope, changes in use purposes, or changes in sharing recipients), we will notify you of the changes and their effective date at least 30 days in advance via in-app notices or email to your registered address. Non-material changes will be announced via in-app notifications. Your continued use of the Services constitutes acceptance of the updated Policy; if you do not agree, you should stop using the Services and delete your account.

21 Contact Us

If you have any questions or requests regarding this Privacy Policy, please contact us at:

Email: [email protected]

We will respond to all privacy-related inquiries within 15 working days.