Mmirrorsite.ai

Privacy

Privacy Policy

This Privacy Policy explains how MirrorSite AI collects, uses, stores, protects and shares information when you use our services.

Last Updated: September 1, 2026

Privacy at a Glance

MirrorSite AI collects information needed to provide your account, process your projects, operate AI-powered application development features, process payments, maintain security, provide support, and improve the service.

  • We collect information you provide directly.
  • We collect some information automatically when you use the service.
  • We process project and prompt information to provide the requested functionality.
  • Third-party providers may process information when required to operate specific services.
  • We do not sell your personal information.
  • You remain responsible for ensuring you do not submit information you are not authorized to provide.
  • You should review this Policy together with the Terms of Service.
Table of Contents

1. About This Privacy Policy

This Privacy Policy describes how MirrorSite AI handles information when users visit the website, create an account, use the platform, create projects, submit prompts, provide URLs, use AI features, purchase credits, participate in referrals, or contact support.

The exact information processed depends on how you interact with the platform. Separate notices may apply to specific features where required.

By using MirrorSite AI, you acknowledge that you have read and understood this Privacy Policy. We encourage you to review this Policy and the Terms of Service regularly.

2. Who We Are

MirrorSite AI is a product created and operated by ATAI — Advanced Technologies and AI Enterprises. ATAI focuses on building practical AI-powered technology that transforms complex technical workflows into accessible, automated experiences.

[LEGAL ENTITY DETAILS TO BE CONFIRMED BY ATAI/LEGAL COUNSEL]

3. Information We Collect

MirrorSite AI processes different categories of information depending on how you use the service:

Account Information

  • Email address
  • Name
  • Authentication provider (password or Google)
  • Google ID (if using Google sign-in)
  • Profile image URL (if using Google sign-in)
  • Email verification status
  • Account status
  • Referral code

Project Information

  • Project name and description
  • Project mode (website or idea)
  • Source URLs
  • Ideas and prompts
  • Project preferences
  • Generated specifications
  • Application code
  • Build history

AI and Processing Data

  • Prompts and instructions
  • Website analysis results
  • Generated application plans
  • Project understanding
  • Conversation history
  • Build summaries

Transaction Information

  • Credit balance and history
  • Top-up records
  • Payment references
  • Transaction status
  • Package selections

Website Analysis Data

  • Submitted URLs
  • Crawled page content
  • Page structure and navigation
  • Screenshots
  • Visual patterns
  • Content structure

Technical Information

  • IP address
  • Browser type and version
  • Device type
  • Operating system
  • Session identifiers
  • Timestamps

4. Information You Provide

You voluntarily provide information when you:

  • Create an account (email, name, password)
  • Complete your profile
  • Submit prompts, ideas, or application requirements
  • Provide website URLs for analysis
  • Create and configure projects
  • Upload files or assets
  • Submit support requests or feedback
  • Participate in the referral program
  • Purchase credits

Please do not submit sensitive personal information into prompts, projects or uploads unless it is necessary and you are authorized to provide it.

5. Project, Prompt and AI Processing

Users may submit product ideas, prompts, application requirements, project information, website references, code, configuration, and other development-related content to MirrorSite AI.

MirrorSite may process this information to:

  • Understand the requested application
  • Create structured project context
  • Generate project plans and specifications
  • Generate application code
  • Create application components
  • Provide development previews
  • Configure supported infrastructure
  • Perform requested AI functions
  • Maintain project state and history

Your prompts and project inputs may be transmitted to third-party AI infrastructure providers when necessary to provide the requested functionality. The specific providers and processing arrangements may change as the service evolves.

AI Training

MirrorSite may rely on third-party AI providers to process information necessary to provide requested functionality. Whether those providers retain or use submitted information for model improvement may depend on the applicable provider's terms and configuration. MirrorSite does not independently use your data to train AI models.

6. Website URLs and Website Analysis

When you submit a website URL, the following may occur:

  1. MirrorSite receives the URL you submitted.
  2. The system requests and analyzes publicly accessible website information as required by the requested feature.
  3. Relevant information may be processed to understand the website's structure, layout, navigation, content, and functionality.
  4. Structured information may be generated from the analysis.
  5. That information may be used to produce project context or application output.

Important

Submitting a URL does not transfer ownership of the referenced website to MirrorSite or the user. Users should not submit URLs to private areas they are not authorized to access.

Website analysis may encounter information that appears on publicly accessible webpages. Users should avoid using the platform to intentionally collect personal information from third-party websites without an appropriate legal basis or authorization.

7. Payment and Billing Information

MirrorSite AI uses mobile money payment processing (MTN and Airtel) for credit purchases. Payment information is processed as follows:

  • You submit a payment confirmation screenshot for verification.
  • An AI-powered analysis system extracts transaction details from the screenshot for verification purposes.
  • MirrorSite receives transaction confirmation data including: transaction ID, amount, currency, payment status, payment reference, and timestamps.
  • MirrorSite does not directly collect or store credit card numbers.

Credit balances, usage information, and transaction history are associated with your account in order to provide the service and enforce applicable usage limits.

8. Referral Information

If you participate in the referral program, the following information may be processed:

  • Referral code and referral relationships
  • Referring account and referred account identifiers
  • Qualifying events and verification status
  • Reward credit issuance
  • Anti-fraud signals and fraud detection flags

Referral information is processed to attribute referrals, issue qualifying rewards, prevent fraud, and enforce referral program rules. We use the minimum data necessary for these purposes.

9. Automatically Collected Information

When you use MirrorSite AI, certain information may be collected automatically, including:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Language and timezone settings
  • Pages visited and navigation patterns
  • Referrer information
  • Timestamps of activity
  • Session data
  • Error and performance information

This information is used for security, authentication, abuse prevention, analytics, debugging, performance monitoring, and service improvement.

10. Cookies and Similar Technologies

MirrorSite AI uses the following types of cookies:

TypePurposeDuration
Session CookieAuthentication and security. Named mirrorsite_session. HttpOnly, secure, SameSite: lax.30 days
AnalyticsVercel Analytics (production only). Used to understand usage patterns in aggregate.Varies

The session cookie is essential for authentication and cannot be disabled while logged in. MirrorSite does not use marketing or advertising cookies.

11. How We Use Information

MirrorSite may use information to:

Provide the service

  • Authenticate accounts
  • Create and manage projects
  • Generate applications
  • Process AI requests
  • Provide infrastructure
  • Process payments

Improve the service

  • Understand product usage
  • Improve workflows
  • Identify bugs
  • Improve performance
  • Develop new features

Maintain security

  • Detect abuse
  • Prevent fraud
  • Secure accounts
  • Investigate suspicious activity
  • Enforce rate limits

Support users

  • Respond to requests
  • Troubleshoot issues
  • Communicate about service changes
  • Send transactional emails

12. AI Processing

MirrorSite AI uses artificial intelligence capabilities across multiple stages of the application-building process. AI processing may involve:

  • Analyzing submitted prompts and ideas to understand requirements
  • Interpreting website structure and content from submitted URLs
  • Creating structured project context from analysis results
  • Planning application architecture and components
  • Generating application code and configuration
  • Reasoning about dependencies and technical requirements
  • Verifying payment screenshots for transaction confirmation

MirrorSite may transmit certain project inputs to third-party AI infrastructure providers when necessary to provide requested functionality. The specific providers and processing arrangements may change as the service evolves.

13. How Information Is Shared

Information may be shared with:

Service Providers

Providers needed to operate the service, including hosting, databases, authentication, AI processing, email delivery, payments, file storage, analytics, and monitoring.

Legal and Safety Reasons

Information may be disclosed when reasonably necessary to comply with law, respond to lawful requests, enforce our Terms of Service, prevent fraud, protect users, or protect the service.

Business Transfers

If the business undergoes merger, acquisition, restructuring, or asset transfer, data may be transferred as part of the relevant transaction, subject to applicable law.

MirrorSite does not sell personal information to third parties.

14. Third-Party Services

MirrorSite uses the following categories of third-party service providers:

CategoryPurposeData Potentially Processed
DatabaseData storageAccount, project, and application data
Website AnalysisWebsite crawling and analysisSubmitted URLs, page content, screenshots
Application GenerationCode generation and buildingPrompts, project context, specifications
AI ProcessingAI reasoning and generationPrompts, project inputs, payment screenshots
HostingApplication hosting and deploymentTechnical and service data
EmailTransactional email deliveryEmail address, account data
File StorageAsset and file managementUploaded files, project assets
AnalyticsUsage measurementAggregate usage data
AuthenticationGoogle sign-in (optional)Email, name, profile image

MirrorSite may link to third-party websites or services. Their privacy practices are governed by their own policies. We do not assume responsibility for third-party privacy practices.

15. How We Protect Information

MirrorSite implements security measures designed to protect information, including:

  • Password hashing using bcrypt with a cost factor of 12
  • Session tokens stored as SHA-256 hashes (raw tokens are never stored server-side)
  • HttpOnly, secure session cookies with SameSite protection
  • Authentication-based access controls on all project and account data
  • Rate limiting on sensitive endpoints (registration, login, etc.)
  • Structured logging with automatic secret redaction
  • Server-side session management with automatic expiration

No method of transmission or storage can be guaranteed to be completely secure. While we take reasonable measures to protect information, we cannot guarantee absolute security.

16. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal requirements and operational needs.

Specific retention details:

  • Session tokens: Expire after 30 days and are deleted on logout.
  • Account data: Retained while the account is active. Soft-deleted accounts have PII stripped but records may be retained for legitimate business purposes.
  • Project data: Retained while the project exists and as needed for service operation.
  • Transaction records: Retained for billing, accounting, and fraud prevention purposes.
  • Server logs: Retained for operational and debugging purposes.

Specific retention periods for jurisdictions requiring formal schedules should be finalized by legal counsel.

17. Account and Data Deletion

You may request account deletion through your account settings or by contacting support. Account deletion performs a soft-delete that:

  • Removes your ability to log in
  • Strips personally identifiable information from your account record (email replaced, name anonymized)
  • Revokes all active sessions

Some information may need to be retained where required by law, fraud prevention, security, accounting, dispute resolution, or legitimate business records.

You may also contact MirrorSite support to request access to, correction of, or deletion of your personal information. We will respond to reasonable requests in accordance with applicable law.

18. Your Privacy Rights

Depending on where you live and applicable law, you may have certain rights regarding your personal information, which could include:

  • Access to your personal information
  • Correction of inaccurate information
  • Deletion of your personal information
  • Data portability
  • Restriction of processing
  • Objection to processing
  • Withdrawal of consent
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, please contact MirrorSite support. We will respond to reasonable requests in accordance with applicable law.

19. Children's Privacy

MirrorSite is not intentionally designed to collect personal information from children in circumstances where doing so would violate applicable law. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete that information.

20. International Data Processing

MirrorSite and its service providers may process information in countries other than the country where you live. These countries may have data protection laws that differ from the laws of your country.

By using MirrorSite AI, you acknowledge that your information may be transferred to and processed in other countries. We take reasonable measures to ensure that adequate protections are in place.

21. Changes to This Privacy Policy

We may update this Privacy Policy as the service evolves, features are added, providers change, legal requirements change, or privacy practices change.

When we make material changes to this policy, we will update the "Last Updated" date at the top of this page and, where appropriate, notify users through reasonable means.

We encourage you to review this Policy periodically. Your continued use of MirrorSite AI after changes are posted constitutes acceptance of the updated policy.

22. Contact

If you have questions about this Privacy Policy or MirrorSite AI's privacy practices, please contact us through the MirrorSite AI platform or reach out to ATAI — Advanced Technologies and AI Enterprises.

[OFFICIAL PRIVACY CONTACT TO BE CONFIRMED BY ATAI]

23. Privacy FAQ

What information does MirrorSite AI collect?
MirrorSite AI collects account information (name, email, authentication details), project information (ideas, prompts, URLs, generated code), payment information (transaction records via mobile money providers), technical information (IP address, browser type, device information), and usage data necessary to operate the service.
Does MirrorSite store my projects?
Yes. MirrorSite stores project information including your ideas, prompts, website references, generated specifications, application code, and project metadata. This information is stored to provide the service and maintain your project history.
Does MirrorSite process my prompts?
Yes. Prompts and ideas you submit are processed to generate application plans, code, and project context. They may be transmitted to third-party AI providers for processing as described in this policy.
Does MirrorSite send my project information to AI providers?
Yes. MirrorSite may transmit project inputs (prompts, ideas, website analysis data, and project context) to third-party AI infrastructure providers when necessary to provide requested functionality such as application generation and analysis.
Is my data used to train AI models?
MirrorSite may rely on third-party AI providers to process information necessary to provide requested functionality. Whether those providers retain or use submitted information for model improvement may depend on the applicable provider's terms and configuration. MirrorSite does not independently use your data to train AI models.
Does MirrorSite collect payment card information?
No. MirrorSite does not directly collect or store credit card numbers. Payments are processed via mobile money providers (MTN and Airtel). MirrorSite receives transaction confirmation data from the payment verification process but not raw card details.
What information does MirrorSite receive from payment providers?
MirrorSite receives transaction confirmation data including transaction ID, amount, currency, payment status, payment reference, and timestamps. This information is used to verify payments and credit your account.
What happens when I submit a website URL?
When you submit a website URL, MirrorSite uses a third-party website analysis service to crawl and analyze publicly accessible content. The system extracts page structure, layout, navigation, content, and visual patterns to create structured development context for building an application.
Can MirrorSite analyze private websites?
No. MirrorSite analyzes publicly accessible website content. You should not submit URLs to private areas you are not authorized to access. Users are responsible for ensuring they have authorization to analyze the websites they submit.
Who owns my project?
You retain ownership of the content you submit and the applications you create. MirrorSite processes your project information to provide the service but does not claim ownership of your personal information or project content.
How long does MirrorSite retain my information?
MirrorSite retains information for as long as reasonably necessary to provide the service, maintain legitimate business records, comply with applicable legal requirements, resolve disputes, prevent abuse and enforce agreements. Session tokens expire after 30 days.
Can I delete my account?
Yes. You can request account deletion through your account settings or by contacting support. Account deletion performs a soft-delete that removes your ability to log in and strips personally identifiable information from your account record.
Can I request deletion of my data?
Yes. You may request access to, correction of, or deletion of your personal information by contacting MirrorSite support. Some information may be retained where required by law, fraud prevention, security, accounting, dispute resolution, or legitimate business records.
Does MirrorSite use cookies?
Yes. MirrorSite uses essential cookies for authentication (session cookies) and security. The session cookie is httpOnly, secure, and has a 30-day expiry. MirrorSite also uses Vercel Analytics in production.
Does MirrorSite use analytics?
Yes. MirrorSite uses Vercel Analytics in production to understand usage patterns and improve the service. Analytics data is collected in aggregate and does not personally identify individual users.
Is my information shared with third parties?
MirrorSite shares information with service providers necessary to operate the service, including hosting, database, AI processing, website analysis, email, payment, and analytics providers. Information may also be disclosed for legal compliance, safety, or to enforce terms of service.
Does MirrorSite sell personal information?
No. MirrorSite does not sell personal information to third parties. Information is shared only with service providers necessary to operate the service or as described in this Privacy Policy.