Mirrors← Back to the site

Privacy & cookies

Two kinds of information reach us: ordinary analytics about people visiting this website, and the content you send us so we can build and replay an environment. Here is what happens to both.

Last updated 28 July 2026

  • We do not sell your information, and we run no advertising or cross-site tracking.
  • We do not use your content to train models.
  • In the EU, EEA, UK and Switzerland, nothing is stored on your device and no session is recorded until you allow it. Elsewhere you can turn it off at any time.
  • Ask us to delete your data and we do it within 30 days.

Visiting this website

We use a privacy-focused analytics service to see which pages help and where the product confuses people: pages viewed, what gets clicked, and how fast things load. Choose “Stay cookieless” and it runs without cookies, without linking your visits together, and without recording sessions. In the EU, EEA, UK and Switzerland those protections apply before you make any choice.

With cookies allowed, an identifier is stored so your visits connect across reloads, and session replay turns on: a recording of what happened on screen, which is how we find a broken flow instead of guessing at it. Anything you type into a form field is masked, passwords included. We also collect crash reports when something breaks, with no IP address or cookies attached.

Your account and what you send us

Signing up needs an email address and a password. Your password goes straight to our authentication provider and never reaches our own systems. We store your email address, an account id and your workspace, and we send you service email such as billing and usage notices.

To build an environment we take in the traces you send, the files you upload, and everything derived from them: the environment itself, your eval cases, and your replay results. That content is yours. We use it only to run the product for you and to help you when you ask. We do not use it to train models, we do not sell it, and it is not visible to other customers.

Running a replay calls a language model, and that call carries the content of the run. Those calls are sent with zero data retention requested, so the provider is asked not to store them.

Card details are entered on our payment processor's own checkout and never reach us. If you connect an integration, it accesses only what you point it at.

Cookies and local storage

We set no advertising cookies and no third-party trackers.

Cookie / storagePurpose
mirrors.cookie-consent
Remembers your cookie choice. Strictly necessary, and kept in local storage rather than a cookie.
ph_*
Analytics identifier. Not set while you are cookieless. In the EU, EEA, UK and Switzerland it is set only after you allow cookies.
sb-*
Your sign-in session. Set when you sign in, and strictly necessary for the product to work.
mirrors:last-authmirrors.nav.collapsed
Small preferences the app remembers: how you last signed in, and whether the sidebar is collapsed. No tracking.

Who else handles it

We use a small number of established service providers, each bound to use your data only to provide their service to us:

  • Cloud hosting, storage and compute, where the product runs
  • Model providers, for the calls your agents make while replaying
  • Payment processing, for subscriptions and invoices
  • Analytics and error reporting, to see how the product is used and what breaks
  • Email delivery, for confirmations and account notices

If you need the named list for a vendor review or a data processing agreement, email us and we will send it. Data is processed in the United States, so using Mirrors from elsewhere means your information is transferred there.

How long we keep it, and how to remove it

Your content stays until you delete it. Deleting an environment removes what it was built from and everything built from it. Ask us to delete an account or a workspace and we complete it within 30 days. Billing records are kept afterwards for accounting, and hold no content from your runs. Copies can persist briefly in encrypted backups before they age out.

Security

Everything travels over TLS, credentials are stored hashed rather than in plain text, and every request is scoped to the workspace it belongs to. Access by us is limited to the people who operate the service, and we look at your content only to run the product or when you ask us to help.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it, and you can change your cookie choice at any time. If you are in the EU, EEA, UK or Switzerland you may also object to or restrict how we use your data and complain to your local data protection authority. If you are in California, you may ask what categories of personal information we collect and ask us to delete them: we do not sell or share personal information as those terms are defined there. Mirrors is sold to businesses and is not directed at children under 16.

Changes and questions

When this policy changes we update the page and the date at the top, and we tell account holders directly if a change materially affects how we handle their data. Any question, including a request about your data or a security review, goes to devs@runmirrors.com, or through the contact form. We answer within 30 days, and usually much sooner.