| Anything inside a connection to your twin: messages, the screen, approvals, cookies, memory, voice | TLS ends on your machine, with a key only your machine holds. The relay reads the name on the envelope (the SNI) and passes the still-encrypted bytes through; it has no code path that loads a certificate for your name, and a test proves it sees only ciphertext | mirrin reach verify, mirrin reach fingerprint, and the openssl check below |
| A certificate for your address, obtained quietly | Your address's CAA record names your machine's own Let's Encrypt account and the TLS-ALPN-01 method, so a relay, a stolen signing key or a hijacked route can't get one. We can rewrite that record, so on the shared zone a certificate we (or our DNS provider) caused would be detected, not prevented: every certificate lands in public logs, and your twin checks them every 6 hours | mirrin reach verify, mirrin reach alarm, and your address on crt.sh |
| What's in your backups, or the names of the files inside them | Each backup is encrypted on your machine with age, to a key made from your 12 words. The words are never stored, not even on your machine. Objects are named by time and a random tag only | mirrin backup key --age, then stock age -d; mirrin backup verify |
| Your 12 words | They are shown once, on your screen, for you to write down. Only public keys made from them are kept | mirrin backup status shows only a Kit ID; mirrin backup verify asks you to type the words, because they appear nowhere on disk (a test scans for them) |
| Your passwords, API keys and signed-in browser | They never leave your machine. Backups leave out the browser profile altogether, and the rest travels only inside the encrypted backup | Decrypt a backup with mirrin backup key --age and age -d, then list it with tar -tz: there is no browser profile. The Trust page lists everything that leaves |
| Your notifications | Your machine encrypts them and sends them straight to Apple's, Google's, Mozilla's or Microsoft's push service. No server of ours is in the path | mirrin cloud egress shows no notification ever sent to Cloud; the Trust page names the push service as their only destination |
| Your email address | The control plane has no email column. It fetches the address from the payment provider for one mirrin cloud me answer and doesn't keep it | mirrin cloud me (its schema-coverage test fails if a stored field is missing) |
| Your IP address, in our database | No table has an address column. Rate limits hold addresses in memory only | mirrin cloud me |
| What your twin does, or which model you use | None of it goes through us. The only requests your machine sends to Cloud are signed calls carrying public keys, your handle and backup sizes | mirrin cloud egress lists every request sent: method, path and size, never the body |
| Anything at all from a twin that never linked | The Cloud client is inert until mirrin cloud link. Only three packages may import it (a test enforces that), and a test runs a default twin for two days of simulated time and sees no request to a Cloud or relay host | mirrin cloud status ("sends nothing") and mirrin cloud egress (empty) |