Effective date: September 3, 2026
Miraz is local-first: retouching, filters, cropping and face analysis run on your device. We do not receive or keep a server copy of photos used for these core editing features.
1. Who we are
Miraz: Face & Photo Editor ("Miraz", the "App" or the "Service") is provided by GreenPixel Ltd ("GreenPixel", "we", "our" or "us"). For privacy questions or requests, email support@miraz.app.
2. Information we process
Depending on which features you use, we may process:
- Photos you select. Core edits remain on your device. A selected photo is processed in the cloud only when you choose to run an AI effect.
- Account information. If you sign in, Firebase Authentication processes your email address, sign-in method and a Firebase user identifier. One-time sign-in links are credentials and are not sent to analytics.
- Purchase information. App stores, Stripe and Adapty process purchases and subscriptions. We receive subscription status, product and transaction identifiers, and limited delivery metadata; we do not receive full card details.
- Usage and attribution information. If enabled, Amplitude and AppsFlyer receive limited events such as feature opened or purchase completed, together with app/device metadata and random user or installation identifiers. Events do not include photos, names, email addresses, free text or face landmarks.
- Technical diagnostics. Google ML Kit performs face detection on-device and sends Google its own API performance and utilization metrics, such as app/device versions, a diagnostic identifier and timing data. It does not send your photo or face landmarks.
- Support information. If you contact us, we process the email and message you send, plus information reasonably needed to answer your request.
3. Photo editing on your device
Retouching, filters, crop, adjustments and face analysis are performed locally. Photos remain in your gallery or temporary app storage while you edit. Saved edits have EXIF, GPS and other embedded metadata removed before they are written to your gallery.
4. Optional cloud AI effects
When you choose an AI effect, Miraz creates a downscaled copy of that photo, removes EXIF and GPS data, and sends it to Google Gemini through a GreenPixel-operated proxy. The proxy keeps the provider key out of the App and does not create a first-party photo library. We use a paid API tier under which submitted content is not used to train the provider's models and is not retained after processing, subject to the provider's security and abuse-prevention terms.
You can turn cloud AI off in Settings. If it is off, Miraz does not upload photos for AI processing.
5. Accounts, web purchases and email
Optional accounts use Firebase Authentication. If you buy through a Miraz web funnel, FunnelFox and Stripe process the checkout, and our isolated integration service stores the minimum account, purchase-delivery and subscription-linkage data needed to connect that purchase to the correct account. Mailchimp Transactional may receive your email address and purchase-email fields to deliver a receipt or welcome/sign-in email. Magic links, tokens and full payment card details are not placed in analytics.
6. Service providers
We use the following providers for specific purposes:
- Google Firebase — authentication and one-time email sign-in links.
- Google ML Kit — on-device face detection and API performance metrics.
- Google Gemini — optional cloud AI effects, accessed through our proxy.
- Apple App Store and Google Play — mobile distribution, purchases and native subscription management.
- Stripe — web payments and the customer subscription portal.
- Adapty — subscription entitlement and purchase lifecycle management.
- Amplitude — optional product analytics.
- AppsFlyer — install attribution and limited product events; advertising-identifier collection is disabled, with iOS tracking subject to your system permission.
- FunnelFox and Mailchimp Transactional — web-funnel processing and transactional email delivery.
These providers may process information in countries other than yours under their own privacy terms and appropriate contractual safeguards.
7. Our website
The public pages at miraz.app are static and do not include advertising pixels or analytics scripts. They do not set first-party tracking cookies. Links to the app stores and Stripe open third-party services, whose own privacy policies apply.
8. Why we use information
We use information to provide requested editing, sign-in and subscription features; maintain account and purchase access; deliver transactional messages; prevent fraud and abuse; provide support; comply with law; and, where enabled, understand feature use and attribution so we can improve Miraz.
9. Retention
Core photo edits are not stored on our servers. Firebase retains account data while the account exists. Subscription providers retain transaction records as required for billing, fraud prevention and law. Our funnel integration keeps raw webhook payloads for a limited operational period (normally up to 30 days) and retains extracted account/purchase linkage only as long as needed for the subscription, support, deletion requests and legal obligations. Support correspondence is retained only as reasonably necessary.
10. Your choices and rights
- Turn cloud AI or usage statistics off in the App's Settings.
- Decline iOS tracking permission or change it later in system Settings.
- Manage a native subscription through Apple or Google, or a web subscription through the Stripe customer portal.
- Delete local edits by removing them from your device and remove App data by uninstalling.
- Request access, correction or deletion of account-related data by contacting us. We may need to verify your identity before completing a request.
11. Children
Miraz is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us so we can review and remove it where appropriate.
12. Security
We use technical and organizational measures designed to protect information, including transport encryption, restricted service credentials, verified authentication tokens and data minimization. No system can guarantee absolute security.
13. Changes
We may update this policy when Miraz or applicable requirements change. We will update the effective date and provide additional notice when required.
14. Contact
Email privacy questions and requests to support@miraz.app.