Privacy Policy
Zuletzt aktualisiert am 8. September 2026
Unsere Rechtstexte erscheinen nur auf Englisch. Eine Übersetzung könnte ihre Bedeutung verändern, deshalb übersetzen wir sie nicht maschinell.
Who is responsible for your data
The data controller is HESTI BILI TECH LTD, a company registered in England and Wales under number 17079558, registered office 8/A Greenwood Grove, Hesti Bili Tech Office, Marcham, Abingdon, OX13 6FR, England.
For any question about your data, or to exercise the rights below, write to support@mirro.tech.
What this policy covers
This policy explains what mirro collects, why, and what we never collect. It covers both the Site and the macOS application.
We process your data under UK GDPR and the Data Protection Act 2018.
What the app never sends
mirro never transmits the contents of your screen. Mirroring, recording and screenshots happen entirely on your Mac; no video, audio or image data leaves your machine.
The Software has no analytics SDK and no crash reporter that uploads screen contents.
Device identification
To enforce the two-device limit, the app derives a device fingerprint locally by hashing your Mac's hardware identifiers together with a build-specific value. The raw hardware identifiers never leave your Mac.
Our servers store only a further keyed hash of that fingerprint. It cannot be reversed into a hardware identifier, and it is used solely to count and manage device activations.
What we store
Account: your email address, and a Firebase authentication identifier.
Licence: your licence key, its status, subscription period, and the Stripe customer and subscription identifiers.
Activations: device name (as reported by your Mac), Mac model identifier, macOS version, mirro version, activation time, last-seen time, and a keyed hash of the IP address of the last request.
Trials: the device fingerprint hash, trial start and end times, and the app and macOS versions seen at first launch.
Audit events: a record of licence issuance, activation, deactivation and revocation, retained for up to 400 days.
Payments
Payments are processed by Stripe. We never see or store your card details. Stripe acts as an independent controller for payment data; see stripe.com/privacy.
Transactional email (licence keys, payment notices, renewal reminders) is sent through Resend. We do not send marketing email unless you opt in.
Why we are allowed to process it
Account, licence and activation data: performance of our contract with you. Without it we cannot issue or enforce a licence.
Device fingerprint hashes, IP address hashes and audit events: our legitimate interest in preventing licence sharing and fraud, balanced against your privacy by storing only irreversible keyed hashes.
Tax and accounting records: compliance with a legal obligation.
Where data is held
Account, licence and activation data is stored in Google Cloud Firestore in the European Union (eur3 multi-region). Release files are served from Cloudflare R2.
Transfers from the UK to the EEA are covered by the UK adequacy regulations. Where a processor operates outside the UK or EEA, we rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses.
Retention
Licence and account records are kept while your subscription is active and for as long as needed for tax and accounting obligations. Audit events expire after 400 days; webhook records after 90 days.
Your rights
You have the right to access, correct, erase, restrict or object to our processing of your data, and to receive it in a portable form. Email support@mirro.tech and we will respond within one month.
Deleting your account cancels any active subscription and revokes the associated licence.
If you believe we have handled your data improperly you can complain to the Information Commissioner's Office (ico.org.uk), the UK supervisory authority. We would rather you told us first so we can put it right.