Legal
Last updated: September 2026
Miro Fertility ("Miro", "we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, and your rights. If you have questions, contact us at hello@mirofertility.com.
Miro Fertility is a reproductive health tracking platform operated from India. We are not a medical device, clinic, or healthcare provider. Our platform helps individuals track their fertility journey for personal use only.
We comply with India's Digital Personal Data Protection (DPDP) Act 2023and the PCPNDT Act 1994 — we never disclose or facilitate determination of fetal sex. You can export your data or delete your account at any time from Settings.
Miro is open to people outside India, including NRIs and international patients planning treatment at Indian clinics. If you live in the European Union, the UK, or another country with its own data protection law (such as the GDPR or UK GDPR), that law also protects you. For the purposes of the GDPR, Miro Fertility is the controller of your personal data.
Account data: Your name, email address, and password (hashed) when you create an account.
Health data you voluntarily enter: Cycle information, IVF protocol details, lab results, medication logs, scan results, embryo data, symptom logs, mood entries, and journal entries. This data is entered by you and belongs to you.
Clinic data (if applicable): If your fertility clinic uses Miro, they may add appointment records or treatment cycle data to your account. You can see everything they add.
Community content (if you choose): Posts, replies, and reactions you share in the community. These appear under an automatically generated anonymous handle — never your real name — and you can delete them at any time.
Usage data: Standard server logs including IP address, browser type, pages visited, and timestamps. We use this to keep the service running securely.
We do not collect: Payment information (we use third-party processors), government IDs, or location data beyond what you voluntarily provide.
To provide the service: Storing and displaying your health records, powering the dashboard, community, and clinic features.
To improve the platform: Analysing aggregated, anonymised usage patterns to understand which features are most useful. We do not use your identifiable health data for this purpose.
To send you notifications: Medication reminders and appointment alerts you configure. You can turn these off at any time in Settings.
We will never: Sell your data to advertisers or data brokers; share your data with your employer, insurer, or government without a lawful order.
If the GDPR or UK GDPR applies to you, we rely on the following legal bases:
Your data is stored on managed PostgreSQL provided by Railway, with the web application also hosted on Railway. Railway encrypts data at rest with AES-256 and enforces TLS for data in transit. Miro does not configure or manage the encryption layer directly — we rely on the defaults provided by Railway.
Your account and health records are stored in India (with a Singapore fall-back region). Files you upload, such as lab reports, are stored in India (AWS Mumbai). Some service providers process limited data elsewhere: transactional emails are sent through a provider in the EU, and if you use the AI Companion, your questions are processed by an AI provider in the United States with your name, email and date of birth removed.
If you use Miro from outside India, your personal data is transferred to India, and some of it to the service providers described above. India and the United States do not have an adequacy decision from the European Commission or the UK government. Where our service providers offer them, we rely on the Standard Contractual Clauses (GDPR Art. 46) in our data processing agreements with them. Otherwise, the transfer is based on the explicit consent you give when you create your account (GDPR Art. 49(1)(a)), after being told about these risks: your data may not have the same legal protection as in your home country, and authorities in the destination country may be able to request access to it.
You can ask us for more information about these safeguards at the contact address below.
We conduct regular security reviews and follow OWASP security best practices. In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by applicable law.
Under the DPDP Act 2023 and, where it applies to you, the GDPR / UK GDPR, you have the right to:
To exercise any of these rights, go to Settings → Privacy in the app, or email hello@mirofertility.com. We will respond within 30 days.
We share your data only in the following limited circumstances:
Advertising partners: Third-party advertising may appear on our public informational and directory pages (see Section 11). These partners never receive your health records, fertility passport data, lab reports, messages, or any logged-in clinical information.
We never sell data.
Essential cookies keep you signed in (your session token) and protect against CSRF. To understand aggregate usage and improve the product, we also use Google Analytics and Ahrefs Web Analytics; a cookie notice appears on your first visit to let you know. Analytics is never tied to the health records you enter, and we never use cookies to profile your health or to sell your data.
Separately, our public informational and directory pages may serve third-party advertising, and those advertising partners may set their own cookies or use similar technologies (such as device identifiers). See Section 11 for details and how to manage advertising consent. Within the logged-in app — your dashboard, fertility passport, and any clinical area — we do not run advertising and do not use cookies to advertise to you.
Where ads appear: To help keep Miro free, third-party advertising (including Google AdSense) may be displayed on our public informational and directory pages — for example, blog articles, guides, and the public clinic directory. Advertising does not appear inside the logged-in app: your dashboard, fertility passport, cycle and lab data, messages, and clinical records are ad-free.
Cookies and similar technologies: Our advertising partners, including Google and its ad-technology partners, may use cookies, device identifiers, and similar technologies to serve and measure ads and, where permitted, to personalise the ads you see based on your visits to this and other sites. This processing is carried out by those partners under their own privacy policies. You can review how Google uses information from sites that use its services at policies.google.com/technologies/partner-sites.
Managing advertising consent: Where required by law, we ask for your consent before advertising cookies are set, and you can change or withdraw that choice at any time through the cookie/consent banner on our public pages. You can also manage or opt out of personalised advertising through Google Ads Settings (adssettings.google.com), the industry tools at aboutads.info/choices and youronlinechoices.eu, or by adjusting your browser and device privacy settings.
Your health data is never used for advertising: We never share your health records, fertility passport data, lab reports, scan results, medication logs, community messages, or any logged-in clinical information with advertisers, and none of it is ever used to target or personalise advertising to you.
Miro is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, please contact us at hello@mirofertility.com.
We will notify you by email and in-app notification if we make material changes to this policy. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the service after changes constitutes acceptance of the updated policy.
For privacy questions or data requests: hello@mirofertility.com
General enquiries: hello@mirofertility.com