Privacy Policy
Last updated: July 12, 2026
Mirall is built so that we don't have your data — not as a promise, but as an architecture. Your files never pass through a server we control, because there is no such server. This policy sets out precisely what stays on your device, what necessarily leaves it, and the one case where you choose to send something to us.
1. Information we do not collect
1.1 No telemetry, no analytics
Mirall contains no analytics, no tracking, and no automatic crash reporting. We do not measure how you use the app, which features you open, or how often you run it. Mirall sends us no report about what you do with it — not on a schedule, not on a crash, not at all.
1.2 No accounts
There is no sign-up, no password, and no email address required to use Mirall. Your identity is a cryptographic key generated on your device the first time you open the app. We never see it.
1.3 Your files
We never receive, store, or process your files. Mirall serves them in place, directly from your disk to the device of the person downloading them. There is no upload step, and no copy on any infrastructure of ours.
2. What necessarily leaves your device
Mirall connects devices directly. That has consequences worth stating plainly rather than glossing over.
2.1 Your IP address is visible to the people you connect with
For two devices to reach each other directly, each must learn how to reach the other. Mirall discovers peers over a public distributed hash table. Your IP address is therefore visible to the other members of the spaces you join, and to other nodes taking part in that network.
This is inherent to any direct connection, not a flaw in Mirall — it's the same reason a phone call reveals that you're on the line. If you need to keep your IP address from the people you share with, use a VPN. No peer-to-peer application can avoid this and still connect you directly.
2.2 Your profile
Your display name and, if you set one, your avatar are shared with the other members of the spaces you belong to. They are shared with nobody else.
2.3 What a space knows
Inside a space, the names, sizes and origins of shared files are visible to its members, so that everyone can see what is available. This travels encrypted, and a space's contents can only be read once an existing member has approved you. It never reaches us.
2.4 Software updates
Mirall updates itself over the same peer-to-peer network it uses for everything else. A new version is simply a drive that your copy of Mirall follows and replicates, much as it replicates a shared folder.
So that an update is available even when no other user happens to be online, we run one always-on peer of our own that carries the release drive. We should be plain about what that means: it is a machine we control, and like any device you connect to directly, it sees the IP address of the copies of Mirall that replicate from it.
What it is not is an account system. It holds our published releases and nothing else — never your files, your spaces, or anything you share. It has no idea who you are, because Mirall never tells it: there is no identifier, no login, and no profile behind the connection. We do not use what it sees to build a picture of you, and we do not combine it with anything else.
2.5 Connection relays
Mirall never routes your connections through a relay. If a peer you connect to uses one, the network may still carry that connection through it — encrypted end to end, and unreadable to the relay. A relay cannot read your files, your file names, or your messages; it can observe that two devices are connected, when, and how much data passes. Mirall does not operate a connection relay and does not offer one on your behalf.
3. Feedback — the one thing you send us
The only data that ever reaches us is what you deliberately send with Send Feedback inside the app. Nothing is sent automatically, ever. If you never press that button, we receive nothing from you at all.
When you do submit feedback, it carries:
- Your message — the text you wrote.
- Your email address — only if you choose to type one, so we can reply. Leave it blank and we have no way to contact you.
- A screenshot — only if you leave that option ticked.
- The app version and your operating system — so we can reproduce the problem.
- An anonymous install identifier — a random value generated on your device, which lets us recognise several reports as coming from the same installation. It is not derived from your identity key, and it is not linked to your files, your spaces, or the people you share with.
Feedback travels over an encrypted connection to a relay we run at feedback.mirall.app, which forwards it to our team. We keep it for as long as we need it to answer you or fix the problem.
4. What Mirall stores on your device
4.1 Your files
They stay exactly where they are. Sharing a file doesn't move it, copy it, or import it into Mirall. Files you download from others are ordinary files, in the download folder you chose.
4.2 Mirall's own records
Mirall keeps a record of your spaces, their members, the folders you mirror, and your transfers. That record is encrypted at rest with a key tied to your identity, so copying Mirall's data folder off your machine doesn't reveal it.
4.3 Your identity key
Your signing key is wrapped using your operating system's secure keychain, and the plaintext is not kept in Mirall's storage. The Account screen tells you which protection is active on your machine.
To be exact about the limits of this: Mirall encrypts its own records, not your files. Your files are ordinary files on your disk, and what protects them on a lost or stolen device is your operating system's disk encryption, not Mirall.
5. Your control
Because your data is on your device, you don't have to ask us to delete it:
- Leave a space and Mirall drops its records from your device.
- Uninstall Mirall, or delete its data folder, and everything it stored is gone. Your own files, your downloads, and any folder you mirrored are untouched — they're yours.
- Stop sharing a file whenever you like. Copies other members already downloaded stay on their devices; we have no way to reach into them, and neither do you.
The one exception is feedback you have already sent us. To ask what we hold, or to have it erased, write to us at the address below.
6. This website
6.1 Hosting
mirall.app is hosted by Vercel. As any web host must, Vercel processes what is needed to serve you a page — your IP address, your browser's user agent, and the page you asked for — and holds it in short-lived operational logs. We don't combine it with anything else, and we don't use it to build a picture of you.
6.2 Downloading the app
The installers are not served from this site. A download button sends you to dl.mirall.app, our release storage at Cloudflare, which — as any file host must — sees your IP address in order to hand you the file. We keep nothing else about the download, and we don't tie it to anything.
6.3 No analytics, no cookies
This site runs no analytics, no tracking pixels, and no third-party scripts. Fonts, images and code are all served from this domain, so reading these pages causes your browser to contact nobody else. We set no cookies.
Your browser does keep one value in its local storage, remembering which language you last read the site in. It never leaves your browser, and you can clear it from your browser's settings at any time.
6.4 Links to other sites
This site links to places we don't run — our source code on GitHub, for instance. Follow such a link and that site's privacy policy applies, not ours.
7. Your rights
If you are in the European Union or the United Kingdom, data protection law gives you the right to see the personal data an organisation holds about you, to correct it, and to have it erased.
In Mirall's case the answer is short. Unless you have sent us feedback, we hold nothing about you, and so there is nothing to disclose, correct or erase. If you have sent feedback, write to us and we will tell you what it contained and delete it on request.
8. Changes to this policy
We may update this policy as Mirall changes. The date at the top always reflects the current version, and any material change will be announced in the app's release notes rather than made quietly.
9. Contact
Questions about this policy, or about data we hold, go to [email protected].
The data controller for the purposes of the GDPR is named, with a postal address, in the Impressum.
Security issues have their own channel: write to [email protected].