Privacy Policy

Last updated: 7 August 2026

This policy explains what personal data Mirelis collects, why, and what you can do about it.

Who is responsible for your data

The data controller is Anton Kiselev-Minaev, a sole trader established in Cyprus, trading as Mirelis. Address: Ivykou 13, Apt. 101, Limassol, 3077, Cyprus. Contact: support@mirelis.app

For any question about your data, write to that address.

We do not train AI models on your images

Your uploaded garment photographs and your generated images are not used to train any AI model, ours or anyone else's. We engage image-processing providers on terms that do not permit them to use customer content for model training.

Your images are processed to produce your results, and for nothing else.

What we collect

Account data. Email address, name, country of residence, and a hashed password. You give us these when you register.

Content you upload and generate. Garment photographs you upload, and the images the service produces from them.

Billing data. Which plan you are on, your purchase and credit history, and an identifier issued by our payment provider. We never see or store your card number — it is entered directly with the payment provider.

Technical and usage data. IP address, browser and device information, pages viewed, actions taken in the app, timestamps, and error logs.

Correspondence. What you write to us at support@mirelis.app.

Why we use it, and on what legal basis

  • Creating and running your account, and generating your images — performance of a contract
  • Taking payment, issuing receipts and handling refunds — performance of a contract
  • Keeping tax and accounting records — legal obligation
  • Enforcing the restriction on users resident in Cyprus — legal obligation and our legitimate interest
  • Preventing abuse, fraud and unlawful content — our legitimate interest in a safe and lawful service
  • Diagnosing faults and improving the service — our legitimate interest in a service that works
  • Product emails you have asked for — your consent
  • Non-essential analytics — your consent

Where we rely on legitimate interest, we have considered whether it is fair to you, and you can object — see your rights below.

Who else processes your data

We use third-party providers to run the service:

  • cloud hosting and application infrastructure
  • object storage for your images
  • specialist AI image-processing providers
  • a payment provider
  • transactional email delivery
  • product analytics and error monitoring

They act on our instructions and may use your data only to provide their service to us. We are happy to tell you which providers we use in a given category — write to us and ask.

We do not sell your personal data and we do not share it for advertising.

Transfers outside the EEA

Some of these providers are located outside the European Economic Area, including in the United States. Where that is so, transfers are made under safeguards recognised by EU law — an adequacy decision or the European Commission's standard contractual clauses. You can ask us for details of the safeguards that apply.

Automated checks

Generation requests pass through automated content checks that may refuse a request or withhold a result. This is automated processing, but it decides only whether a single image is produced; it does not produce legal effects for you or similarly significantly affect you. If a check stops something wrongly, the credit is returned automatically and you can write to us and have a person look at it.

How long we keep it

  • Account data — while your account is open, then up to 90 days
  • Uploaded and generated images — until you delete them, or up to 90 days after the account is closed
  • Billing and tax records — as long as tax law requires, currently 7 years
  • Technical logs — up to 12 months
  • Correspondence — up to 2 years

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you
  • correct it if it is wrong
  • erase it, where there is no overriding reason for us to keep it
  • restrict or object to our processing, including processing based on legitimate interest
  • receive your data in a portable format
  • withdraw consent at any time, where we rely on consent

Write to support@mirelis.app. We respond within one month.

If you think we have handled your data wrongly, you can complain to a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection, or the authority in the EU country where you live.

Cookies

We set cookies that are necessary for the site to work — keeping you signed in, remembering your language, and protecting against abuse. These do not need your consent.

Anything beyond that, such as analytics, is set only if you agree, and you can change your mind at any time.

Security

Data is transmitted over encrypted connections, passwords are stored hashed, and access to production systems is limited. No service can promise perfect security, but if a breach occurs that is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.

Children

Mirelis is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

Changes to this policy

We may update this policy. If a change materially affects you, we will tell you before it takes effect.

Contact

support@mirelis.app