LegalDrafts · not in force
Mirrin Cloud: terms and privacy, in draft
The free, open-source twin needs none of these. It sends us nothing and needs no account, and it comes under its licence: the source is MIT, the default downloads (with WhatsApp) are GPL-3.0, and an MIT build comes without WhatsApp. The licences, in plain words.
Terms of service
1. Who we are, and what these terms cover
These terms are between you and [MavrkAI legal entity name, ABN, registered address] (“we”, “us”). They cover Mirrin Cloud (“Cloud”): an optional subscription that gives you
- an address (a “handle”) that routes encrypted connections from your devices to the software running on your own computer, and
- storage for encrypted backups made by that software.
They don't cover the free software itself, which you get under its own licence and can use fully without Cloud. We don't host, run or have access to your twin.
2. No account; your keys
There is no sign-up, login or password. You link a computer with mirrin cloud link, and your subscription is identified by public keys that your computer creates. You are responsible for your computer, its keys and your 12 recovery words. We never hold your words, so we can't recover your backups if you lose them, and we can't reset anything for you that depends on them.
3. Buying, prices and refunds
- Cloud is sold by our reseller and merchant of record, [Paddle.com Market Ltd], which takes payment, handles tax and invoices, and holds your email and card details under its own terms and privacy policy.
- The price is the one shown at checkout. A founding price is kept for as long as your subscription continues without a break. We'll give you at least [30] days' notice of any price change, which then applies from your next renewal.
- There is no free trial. You can have a full refund within 30 days of your first payment, through the billing page (
mirrin cloud billing). - Nothing in these terms limits rights you have under the Australian Consumer Law or other consumer law that can't be excluded.
4. What we provide
- Reach. A handle under our domain, the DNS records for it (including a CAA record naming your computer's own certificate account), and two relays that pass your encrypted connections through to your computer. The relays can't read them.
- Backup. Up to 20 GB of storage for encrypted backup files. Retention (7 daily, 4 weekly and 6 monthly) is applied as described in the documentation.
- Support. By email, aiming to answer within two business days (next business day, best effort, on the Supporter plan).
We provide Cloud with reasonable care and skill, but we don't promise it will always be available. Your twin keeps working on your computer whether or not Cloud is up, and your free routes keep working too. [Counsel: whether to offer a service level or credits.]
5. Your content
Connections through the relays are encrypted end to end between your devices and your computer, and backups are encrypted on your computer before they reach us, with keys we don't hold. You keep every right in your content. We don't claim any licence to it, and we can't read it.
6. Fair use and limits
Cloud is for reaching your own twin. Fair use is about 100 GB relayed a month, and up to 20 Mbit/s for your address, shared by all its connections. If you go over 100 GB, we'll warn you first; if it carries on, we may stop serving your address until the next month. The acceptable use policy is part of these terms.
7. Suspension
We may suspend your handle (by adding it to the deny list the relays check) if you breach the acceptable use policy, if your address is opened from more than 200 different networks in one day (which pauses it automatically for seven days), if payment fails, or if the law requires it. Where the law lets us, we'll tell you why and how to fix it. Suspension doesn't affect your twin or your backups.
8. Cancelling and ending
- You can cancel at any time from the billing page. Cloud keeps working until the end of the period you paid for, and your handle keeps routing for up to 7 days after it.
- From the end of the paid period no new backups are stored. For 90 days after it you can still list and download every backup already stored.
- After those 7 days the relays stop routing your handle. It is never given to anyone else.
mirrin cloud delete-accountdeletes your Cloud record. You have 7 days to undo it (--undo); then the records, DNS entries and stored backups are removed.
9. Changes, and if we shut Cloud down
We'll give at least [30] days' notice of a material change to these terms, in the CHANGELOG and on this site. If we ever discontinue Cloud, we'll give at least 90 days' notice, and your backups stay downloadable for that time.
10. Open source
The source code of the relay and of the service that manages subscriptions is published under the MIT licence (the relay program also contains one library under MPL-2.0, yamux). Nothing in these terms limits what those licences let you do, including running them yourself.
11. Liability
To the extent the law allows, Cloud is provided as described here and without other warranties, and our total liability to you is limited to [the fees you paid us in the 12 months before the claim]. We aren't liable for losses caused by keys or words you lost, or by your use of the free software. [Counsel: consumer-law carve-outs; indirect loss; indemnity from business customers.]
12. Law and contact
These terms are governed by the law of [New South Wales], Australia, without taking away the protection of the consumer law where you live. Contact: [support address].
Acceptable use policy
1. What this covers
Handles on our domain, the relays that carry them, and backup storage. A handle is for reaching your own Mirrin twin, from your own devices.
2. Not allowed
- Phishing, or pretending to be another person, company or government body.
- Distributing malware, or running command-and-control for it.
- Child sexual abuse material. We report it to the authorities.
- Anything else illegal where you are or where we are, including infringing others' rights.
- Spam or bulk unsolicited messages sent through the handle.
- Running a public website, proxy, VPN exit or file-sharing service on the handle, or sharing one handle among many people.
- Scanning, attacking or overloading other systems, or trying to get round the relays' limits, the deny list or another customer's isolation.
3. How we find out
We can't see inside connections or backups. We act on reports, and on the connection details a relay does see: how many different networks open an address in a day, how much it carries, and public certificate and blocklist data.
4. What we do
Depending on how serious it is: a warning, suspending the handle, or ending the subscription. Urgent cases (phishing, malware, abuse material) are suspended at once. Where the law lets us, we'll say why and how to appeal. A refund on ending is at our discretion, except where the law requires one.
5. Reporting abuse
Write to [abuse address] with the address, the time and what you saw. We'll acknowledge it within [two business days].
6. Requests from authorities
We need valid legal process [counsel: Australian and foreign process]. We hold little (the privacy policy lists it) and we can't decrypt your connections or backups. [Counsel: whether to publish a transparency report.]
Privacy policy
1. Who we are
[MavrkAI legal entity name, ABN, address] is responsible for the personal information described here. Contact: [privacy address].
2. This website
This site sets no cookies, runs no analytics and loads nothing from another server. Your theme choice is kept in your own browser. The host that serves the pages keeps its own access logs [GitHub Pages: confirm what it logs, and for how long].
3. The free software
The Mirrin software runs on your computer and sends us nothing. With default settings it asks Open-Meteo for the weather (turn this off with ui.weather: false) and talks to the model provider you choose. It contacts GitHub only when you install or update a pack, or run mirrin update; installing or updating a pack fetches it from where it is published. Voice setup, when you run it, downloads its models from Hugging Face and GitHub, and its helper from the Python package index. The Chrome window it browses with makes Chrome's own background requests to Google. It contacts other services only when you connect them. Every kind of connection it can make is listed in the threat model; its Trust page shows the main ones, and whether each is on.
4. Cloud: what we collect
| Information | Why | How long |
|---|---|---|
| An account number, the payment provider's customer number, plan, billing status and paid-through date | To provide what you paid for | While you subscribe, then until deletion |
| Your handle | It is your address; it is also published in DNS and in public certificate logs | Never reassigned: a record of the name is kept, even after deletion, so it is never given to anyone else |
| Your computer's public keys, the certificate account its address is pinned to, and the day it last checked in | To know it's your computer, and to write your DNS records | While you subscribe, then until deletion |
| Your backup folder's name (made from a public key), and each backup file's name, size and time | To store your backups within your quota | Until the backup is pruned or deleted |
| What happened to your subscription (a kind and a time, never content) | Support and security | Until deletion |
| Relay connection records: the time, your handle, the network a connection came from (only the first three parts of an IPv4 address, or its /48 for IPv6), bytes and duration | To run the relays and spot abuse | 72 hours in memory, then hourly totals for 30 days |
| IP addresses, in memory only, for rate limits and while a connection is open | Security | Not written down |
We don't store your email address, IP address, name or card. The payment provider holds your email and card as a separate controller, under its own privacy policy. When you run mirrin cloud me, we fetch your email from it for that answer and don't keep it.
We can't see what's inside your connections or backups: they are encrypted with keys only your computer and your 12 words hold. What we would and couldn't see has the full list, with a command to check each line.
5. Legal bases
Providing the service you asked for (contract); keeping it secure and free of abuse (legitimate interests); and keeping tax and payment records, through the payment provider (legal obligation).
6. Who else is involved
| Provider | For | What they receive |
|---|---|---|
| [Paddle] | Checkout, billing, tax | Your email, card and billing details (as a separate controller) |
| [Amazon Web Services, Route 53] | DNS for handles | Your handle and the relays' addresses |
| [Cloudflare, R2] | Backup storage, and our own database replica | Encrypted backup files; our records above |
| [Relay hosts: two providers to be chosen] | Running the relays | Encrypted connections passing through |
Your computer also talks to Let's Encrypt, under its own account, and to your phone's push service. Those are between your computer and them, not us. We don't sell or rent personal information, and we don't use it for advertising.
7. Where it's kept
[Regions for the relays, database and storage; cross-border transfer safeguards such as the EU standard contractual clauses and the UK addendum.]
8. Your choices and rights
- See everything we store about you:
mirrin cloud me. - See every request your computer has sent us:
mirrin cloud egress. - Delete it:
mirrin cloud delete-account(7 days to undo). - Ask us to correct or explain anything, or object: [privacy address].
- Complain to the Office of the Australian Information Commissioner, or to the data protection authority where you live.
9. Security
Encryption ends on your computer; the relays hold no key for your address; backups are encrypted before they leave; signing keys are kept apart by purpose and rotated yearly; and there is no administration website, only command-line access over SSH. An independent security review will be done before checkout opens.
10. Children
Cloud is not for anyone under [18].
11. Changes
We'll post changes here and in the CHANGELOG, at least [30] days before they take effect when they matter.
Data processing agreement
1. Roles
For personal information carried through the relays or held in encrypted backups, you are the controller and we are your processor. For the account information in the privacy policy, we are the controller. Mirrin Cloud is designed so that we can't read the content we process: it is encrypted with keys only you hold.
2. The processing
- Subject matter and purpose: passing encrypted connections to your computer, and storing encrypted backups.
- Duration: the subscription, plus 90 days after the paid period ends to download backups, plus the deletion period.
- Personal information: whatever you and your devices put inside encrypted connections and backups (which we can't see), and connection details: the network a connection came from, the time, bytes and duration.
- People it concerns: you, the people who use your devices, and anyone whose information is in your twin.
3. Our commitments
- We process only on your instructions: these terms, and what your computer asks the service to do.
- Everyone who can reach the service's systems is bound to confidentiality.
- We keep the security measures in Annex A.
- We use only the subprocessors in Annex B, give you [30] days' notice of a new one, and you may object and cancel with a refund of the unused period.
- We help you answer requests from the people the information is about, as far as we can without the keys.
- We tell you of a personal data breach affecting you without undue delay, and within [48] hours of becoming aware of it.
- At the end, you can download your backups for 90 days after the paid period ends; then we delete them and our records of you, except where the law makes us keep them (and the record that keeps your handle from being reassigned).
- We make available what you need to check we keep these commitments. The relay and the service are open source; audits beyond that are by agreement, at your cost [counsel].
- International transfers are covered by [the EU standard contractual clauses, module 2 and 3, and the UK addendum].
Annex A: security measures
- TLS ends on your computer. The relays pass connections through by name and have no code path that loads a certificate for your address.
- Your address's certificate is pinned by CAA to your computer's own certificate account, and your computer watches the public certificate logs.
- Backups are encrypted on your computer with age, to a key made from words we never see.
- Only minimal records are kept: no email or IP address columns; relay records reduced to a network, and to hourly totals after 72 hours.
- Requests from your computer are signed, with replay protection.
- Signing keys are separate by purpose, held in encrypted credentials, and rotated yearly.
- No administration website; access by command line over SSH, reviewed weekly.
- An independent security review before launch.
Annex B: subprocessors
The providers in the privacy policy, section 6, except the payment provider, which is a separate controller. [Final list, with locations, before checkout.]