Privacy Policy

Last updated: April 2026

Miro Fertility ("Miro", "we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, and your rights. If you have questions, contact us at privacy@mirofertility.com.

1. Who we are

Miro Fertility is a reproductive health tracking platform operated from India. We are not a medical device, clinic, or healthcare provider. Our platform helps individuals track their fertility journey for personal use only.

We comply with India's Digital Personal Data Protection (DPDP) Act 2023, the EU's General Data Protection Regulation (GDPR), and follow HIPAA-aligned practices for the handling of health data. We also comply with the PCPNDT Act 1994 — we never disclose or facilitate determination of fetal sex.

2. Data we collect

Account data: Your name, email address, and password (hashed) when you create an account.

Health data you voluntarily enter: Cycle information, IVF protocol details, lab results, medication logs, scan results, embryo data, symptom logs, mood entries, and journal entries. This data is entered by you and belongs to you.

Clinic data (if applicable): If your fertility clinic uses Miro, they may add appointment records or treatment cycle data to your account. You can see everything they add.

Usage data: Standard server logs including IP address, browser type, pages visited, and timestamps. We use this to keep the service running securely.

We do not collect: Payment information (we use third-party processors), government IDs, or location data beyond what you voluntarily provide.

3. How we use your data

To provide the service: Storing and displaying your health records, powering the dashboard, community, and clinic features.

To improve the platform: Analysing aggregated, anonymised usage patterns to understand which features are most useful. We do not use your identifiable health data for this purpose.

To send you notifications: Medication reminders and appointment alerts you configure. You can turn these off at any time in Settings.

We will never: Sell your data to advertisers or data brokers; use your identifiable health data to train AI models without your explicit opt-in consent; share your data with your employer, insurer, or government without a lawful order.

4. Data storage and security

Your data is stored on encrypted servers (Neon PostgreSQL, hosted on AWS). All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

Health data is stored in India and/or the EU in accordance with applicable data localisation requirements.

We conduct regular security reviews and follow OWASP security best practices. In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by applicable law.

5. Your rights

Under the DPDP Act 2023 and GDPR, you have the right to:

  • Access all personal data we hold about you
  • Correct inaccurate data
  • Delete your account and all associated data permanently
  • Export your health data in a portable format (JSON or PDF)
  • Withdraw consent for any optional data processing
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, go to Settings → Privacy in the app, or email privacy@mirofertility.com. We will respond within 30 days.

6. Data sharing

We share your data only in the following limited circumstances:

  • Your clinic: If you connect a clinic account, they can see the health records you share with them. You control what is shared.
  • Service providers: We use a small number of trusted vendors (database hosting, email delivery, authentication) who are contractually bound to process data only on our instructions.
  • Legal requirements: If required by a valid court order or law enforcement request. We will notify you if permitted by law.

We never sell data. We have no advertising relationships.

7. Cookies

We use only essential cookies required for authentication (your session token) and security (CSRF protection). We do not use advertising, tracking, or analytics cookies from third parties.

8. Children

Miro is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, please contact us at privacy@mirofertility.com.

9. Changes to this policy

We will notify you by email and in-app notification if we make material changes to this policy. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

For privacy questions or data requests: privacy@mirofertility.com

General enquiries: hello@mirofertility.com