Mirari

Mirari privacy policy

This is the policy at https://mirari.au/privacy and the one linked from the App Store listing. It is short because there is not much to say.

The short version

Mirari has no accounts and no servers that know who you are. Your readings, your question, your profile, and any photos of your own cards stay on your iPhone. The only time anything leaves your phone is when you ask for a deep reading, and what leaves is your drawn cards, your question, your sun sign, and your life path number, together with proof that the reading is paid for (Apple's receipt, or a one-time DeviceCheck token for the included reading). Nothing that identifies you goes with it. No analytics, no advertising, no tracking, nothing sold.

What we collect about you on our servers

Nothing. We do not run a database of people. There is no sign-up, no email address, no account, and no identifier of any kind that ties a reading or a purchase to a person.

What lives on your iPhone

Everything below is stored only on your phone, in the app's own storage:

The app's storage folder is excluded from iCloud device backup, so your readings do not end up in a phone backup without you deciding to sync them.

iCloud sync

Mirari is built to sync readings through your own iCloud private database, which belongs to you and which we cannot read. In this release that sync is switched off, and the Sync row in Settings says so ("Sync off"). If a later release turns it on, this policy will say so first, and the data will go only to your own iCloud, never to us.

The deep reading: exactly what is sent

A deep reading is written by a larger model in the cloud. When you ask for one, your phone sends one request to a small server we run, hosted by Cloudflare, which adds the model key and forwards the reading request to Anthropic. The request contains:

It does not contain your name, your date of birth, your birth time or place, your reading history, your photos, your email, your Apple ID, or any advertising or device identifier.

Our server does not store the request or the reading. It streams the reading back to your phone as it is written, and that is the end of it. Two companies handle the request on the way: Cloudflare, which hosts the server and carries the traffic, and Anthropic, which runs the model. Both are described below.

On an iPhone that cannot run readings on its own

Some iPhones cannot run Apple Intelligence. On those, every reading is a deep reading in the cloud (the first is included), and the app tells you that on the welcome screen. The request is exactly the one described above.

The free reading

On an iPhone that runs Apple Intelligence, the free reading is written on the phone. Nothing is sent anywhere. The same is true of the optional "clarify" step that helps you word your question.

What our server keeps

The server keeps two kinds of small records, neither of which is about you:

A spend record per purchase. When you buy deep readings, Apple issues a signed receipt. The server keeps a record keyed to Apple's transaction number for that purchase, holding how many readings from it have been used, whether Apple has told us it was refunded, and two timestamps. This is what stops a receipt being replayed for free readings, and what remembers that a refunded purchase is spent. It holds no name, no device, no question, no reading. We cannot map a transaction number back to a person; only Apple can. Each record is deleted a year after it was last used or refunded.

A rate-limit counter. Like any server, ours sees the internet address a request comes from. Our code uses that address for two things only: a per-minute burst limit, and a daily count of included (unpaid) readings per address, discarded within two days. Our code never writes the address to its log. Cloudflare, which hosts the server, keeps its own request records under Cloudflare's privacy policy; see the section on Cloudflare below.

App Store Server Notifications

Apple sends our server a signed message when a purchase is refunded, revoked, or a refund is reversed. The server checks Apple's signature, reads the kind of message and confirms it is about Mirari, and flips the refund flag on that purchase's spend record. It keeps the time Apple signed the message on that record, so an older message cannot undo a newer one. The message itself is not stored.

DeviceCheck

Your first deep reading is included and needs no purchase, so there is no receipt to prove it. To stop that credit being claimed over and over, the app asks Apple's DeviceCheck service for a one-time token and sends it with the included reading. Apple keeps two bits per device for us; after the included reading is written, the server sets one of them to mean "this iPhone has had its included reading". That is all the bits can mean. They cannot be read as anything else, cannot be linked to you by us, and we store nothing about the device. If your iPhone cannot make a token, the included reading may be refused. Purchased readings never use DeviceCheck and are not affected.

Cloudflare, the company that hosts the server

Our server runs on Cloudflare's network. Cloudflare terminates the connection from your phone, so it handles the request in transit, and it keeps its own operational records of requests to the services it hosts (things like the time, the outcome, and the connecting address) under Cloudflare's privacy policy (https://www.cloudflare.com/privacypolicy/). Cloudflare does not receive anything from us beyond the request itself, and we do not use Cloudflare's records for anything but keeping the service running.

Anthropic, the company that runs the model

Deep readings are written by Claude, a model made by Anthropic. Anthropic receives the request described above, with nothing that identifies you, and returns the reading. What Anthropic does with it is governed by their commercial terms, not by their consumer privacy policy, because Mirari uses their API as a business customer. Read on 2 September 2026:

So, plainly: Anthropic may hold your question and your reading for up to 30 days, without your name or any identifier, and does not train on them. We will re-read these terms at each release and update this section if they change.

What is logged

When something goes wrong, our code writes a one-line category to its log ("rate limited", "upstream failure", "entitlement refused") and nothing else; a successful reading writes nothing. It never writes the question, the cards, the reading, the receipt, the DeviceCheck token, or the address the request came from. Cloudflare keeps its own record of each request, as described above.

Payments

Purchases go through Apple's App Store. Apple handles the payment and knows who you are; we do not. We receive the signed receipt Apple gives the app, which carries the transaction number, the product, the date, and the storefront, and nothing that names you. Deep readings are one-off purchases, not subscriptions.

Crisis content

If what you type suggests you might be in a hard place, the app checks for that on your phone before drawing the cards and before any model is involved. It shows Australian support services instead of a reading. Nothing is generated, nothing is saved, and nothing is sent.

No analytics, no advertising, no third-party code

The app contains no analytics kit, no advertising kit, and no third-party software libraries of any kind. It does not track you across apps or websites, and it has no way to.

Your rights and your controls

Children

Mirari is not directed at children under 13. The App Store lists it for ages 13 and up.

Changes

If this policy changes, the date at the top changes with it and the release notes for that version say what moved. We do not change what the app sends without saying so here first.

Contact

support@mirari.au