TL;DR: The short version

1. Who we are

MirrorNotes is a private journaling application for iOS developed by Lokesh Pudhari ("we," "us," or "our"). The app is available on the Apple App Store.

For questions about this policy, contact us at: [email protected]

2. The fundamental privacy guarantee

MirrorNotes is built on a single architectural principle: your journal text never leaves your device.

This is not a policy promise that can be changed by a future update. It is a technical fact about how the app is built:

Maximum text sent to local AI model: 10,000 characters from your recent entries. This processing happens entirely within your device's memory and is not transmitted anywhere.

3. What data we collect and why

The table below summarizes every category of data involved in MirrorNotes's operation:

Data type Purpose Storage Sent to us?
Journal entries
All text you write
Core product On-device (SwiftData) + your iCloud Never
AI-generated insights
Nudges, digests, Ask responses
AI feature cache On-device (SwiftData) Never
Subscription status
Tier, expiry, renewal status
Feature gating RevenueCat servers Yes (RevenueCat)
Purchase receipts
Apple IAP transactions
Subscription validation RevenueCat servers + Apple Apple/RevenueCat
App usage analytics
Crash reports, if enabled
Bug fixing Anonymized crash data only Anonymized only

What we explicitly do not collect

4. Third-party services

RevenueCat (subscription management)

RevenueCat processes in-app purchase receipts from Apple and updates your subscription status. RevenueCat receives your Apple purchase receipts and assigns you a subscriber ID. No journal data is involved.

RevenueCat Privacy Policy: revenuecat.com/privacy

Apple (iCloud + App Store)

Apple CloudKit syncs your entries between your devices using your iCloud account. Apple handles all payment processing for subscriptions. No account or sign-in is required to use MirrorNotes.

Apple Privacy Policy: apple.com/privacy

Note on CloudKit: iCloud sync means your entries are stored on Apple's servers under your Apple ID. This is governed by Apple's terms, not ours. We have no ability to access iCloud data. If you're concerned, you can disable iCloud for MirrorNotes in iOS Settings → [Your Name] → iCloud.

5. On-device AI and local processing

All AI features in MirrorNotes (Daily Nudge, Ask, Weekly Digest) are powered by Gemma 3 1B, a large language model that runs entirely on your device.

There are no API calls to any AI cloud service (no OpenAI, Anthropic, Google Cloud AI, etc.) for AI processing.

6. Data retention and deletion

Your journal entries

Stored on-device. Deleted immediately when you delete them. No server copy exists. If you delete the app, SwiftData is cleared. iCloud copies are managed by your Apple ID settings.

Subscription data

Subscription status is stored by RevenueCat for as long as you have an active subscription. Deleted within 30 days of a deletion request.

How to delete your data

  1. Open MirrorNotes → Settings → Account
  2. Tap "Delete Account"
  3. Confirm deletion

This removes your subscription status from RevenueCat. Your journal entries, stored locally and in your iCloud, must be deleted separately through iOS Settings or by deleting the app.

You may also contact us at [email protected] to request account deletion.

7. Your rights

Depending on your location, you may have certain rights regarding your personal data:

To exercise any right, contact [email protected]. We will respond within 30 days.

California residents (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioral advertising. We collect only the minimum data necessary to provide the service. You have the right to know, delete, and opt-out as described above.

European residents (GDPR)

Our legal basis for processing subscription data is contract performance (providing the service you signed up for). You have the rights described above under GDPR Articles 15–22. To lodge a complaint, contact your local Data Protection Authority.

8. Security

We take security seriously:

If you discover a security vulnerability, please report it to [email protected].

9. Children's privacy

MirrorNotes is not directed to children under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app notification and update the "Last updated" date at the top of this page. Continued use of MirrorNotes after a policy update constitutes acceptance of the updated policy.

We will never change the core architectural fact that your journal entries remain on your device without also giving you clear advance notice and the ability to export your data.

11. Contact us

Questions about your privacy?

We're a small team and we read every email.

Email: [email protected]
Developer: Lokesh Pudhari
App: MirrorNotes for iOS