Mirror is a local-first macOS workflow assistant. This policy covers the Mirror macOS app and the Mirror Local Workflow Observer browser extension.
Our privacy posture
Mirror does not collect personal data for remote processing, advertising, tracking, or resale. Current product data is processed and stored locally on the user's Mac. Mirror does not operate a remote analytics or workflow-data service.
Data handled locally
When the user enables the relevant features, Mirror may handle:
- semantic workflow events, timestamps, and application identifiers;
- sanitized website domains and route patterns;
- privacy settings, observation state, and local data receipts;
- agent simulation and execution receipts.
This information is used only to identify repeated workflow structure, present local summaries, and prepare user-reviewed automation drafts.
Data Mirror does not capture
Mirror does not capture or store screenshots, screen recordings, keystrokes, passwords, page text, form-field values, browser cookies, authentication tokens, URL query strings, URL fragments, or browsing credentials.
Browser extension
Browser observation is off by default and requires an explicit opt-in from the extension popup. When enabled, the extension sends minimized navigation, active-tab, and form-submission signals to the locally installed Mirror Native Messaging host. It does not send those signals to Mirror servers.
The extension uses local browser storage only for the user's observation-enabled preference. Its browser permissions are used to recognize top-level navigation and remove credentials, query strings, and fragments before local processing.
Storage, retention, and deletion
Workflow evidence is kept in encrypted local app storage with a bounded retention policy. Users can pause observation, exclude private apps and domains, inspect aggregate local receipts, and delete retained workflow events from Mirror.
Sharing and support
Mirror does not sell or share workflow data with advertisers, data brokers, or other third parties. Support bundles are created only after explicit user action and are redacted by design. Exporting a bundle does not upload it automatically.
Changes to this policy
This page will be updated before Mirror introduces any materially different data practice. The effective date above identifies the current version.
Contact
For privacy questions, use the public Mirror support tracker. Do not include private workflow data, credentials, or security secrets in a public issue.