MirrorMe — Privacy Policy
Last updated: 26 July 2026
1. Who We Are
MirrorMe (“MirrorMe”, the “App”) is a wellbeing reflection application operated by DN Consulting Software Development Company (“we”, “our”, “us”), a company registered in Bulgaria.
This Privacy Policy explains what personal data the App collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to the MirrorMe mobile application, our website at aptify.me/mirrorme.html, and our customer-support channels.
Contact: admin@aptify.me
2. What MirrorMe Is — and What It Is Not
MirrorMe generates qualitative, non-diagnostic reflection insights intended to support self-awareness about your general wellbeing.
MirrorMe does not diagnose, measure, detect, or treat any medical or psychological condition. It is not a medical device, it does not provide medical advice, and its output must not be used as a substitute for consultation with a qualified health professional. Insights are estimates based on visible cues in a photograph you submit and on information you report about yourself. They may be inaccurate. Always consult a physician before making health or lifestyle changes.
We do not perform facial recognition, face matching, identity verification, or face-based authentication, and we do not create or store biometric identifiers.
3. Data We Collect
We collect only the following:
- Account data — name, email address, and authentication identifiers from Sign in
with Apple or Google if you use them.
Purpose: creating and securing your account, verifying your identity by email. - Optional profile data — gender, date of birth, height, weight, reasons for
joining, and self-reported symptoms. All of these fields are optional. You may
skip them during onboarding, use the App fully without them, and add, edit, or clear them at any
time in Profile.
Purpose: adding optional context to the insights shown in your report. - Scan photo (face image) — a single self-captured photograph of your face,
collected only when you actively start a scan. See Section 6 for full detail.
Purpose: generating your personal reflection report and displaying your profile picture. - Self-reported check-in data — mood, energy, and sleep quality you log yourself,
and habits you mark as completed.
Purpose: producing trends and insights over time. - Bloodwork documents (optional) — a PDF you may choose to upload.
Purpose: adding optional context to your report. You may delete it at any time; deleting it removes it permanently from our systems. - Device and usage data — device identifiers, app version, crash reports, and
in-app interaction events, collected via Google Analytics for Firebase and Firebase
Crashlytics.
Purpose: diagnosing crashes, maintaining stability, and understanding which features are used. - Subscription data — subscription status and transaction identifiers received
from Apple, Google, and RevenueCat. We do not receive or store your full payment card
details.
Purpose: managing access to paid features.
We do not collect lab results, medication lists, allergy records, physician notes, or vitals. We do not collect precise location data or advertising identifiers.
4. How We Use Your Data
- To provide the App’s core features: generating your reflection report, showing your results and trends, and running the habit tracker
- To create and secure your account and verify your email address
- To send notifications you have enabled (for example, when your next scan becomes available)
- To provide customer support and respond to your requests
- To diagnose crashes, fix bugs, and improve reliability and performance
- To manage subscriptions and prevent fraudulent or abusive use
- To comply with legal obligations
We do not sell or rent your personal data. We do not use your data for advertising or cross-context behavioral advertising. We do not use your scan photos, bloodwork documents, or check-in data to train machine-learning models, and we do not permit our service providers to do so.
5. Automated Analysis and AI Processing
Your reflection report is produced by automated processing. When you run a scan, your scan photo — together with any optional profile information you have provided — is analyzed by a third-party artificial intelligence provider under contract to us, OpenAI, L.L.C., which returns a set of qualitative estimates to us. We then present those estimates to you in the App.
This processing is carried out solely to generate your own report, which is visible only to you. It produces no decision that has a legal effect on you or similarly significantly affects you. It does not identify you: the provider receives the image only, and does not receive your name, email address, or account identifier.
Under our agreement with OpenAI, L.L.C., your image is processed only to return results to us, is not used to train any model, and is retained by the provider for no longer than 30 days for abuse-monitoring purposes before deletion.
6. Face Image Data
This section describes our collection, use, disclosure, sharing, storage, and retention of face image data.
6.1 What we collect
MirrorMe collects a single self-captured photograph of your face (a “scan photo”), and only when you actively start a scan and either capture a photo with your camera or select one from your photo library. Scan photos are never collected in the background, automatically, or without an explicit action by you. Scanning is optional; you may use the App without it, though the reflection report is the App’s main feature.
We do not collect, generate, derive, or store faceprints, face templates, face geometry, facial landmarks stored as a persistent record, face embeddings, or any other biometric identifier. We do not perform facial recognition, face matching, identity verification, face-based authentication, age estimation, or emotion recognition for identification purposes. We do not use your scan photo to identify you, and we cannot use it to identify you elsewhere.
Before your photo is accepted, an automated quality check confirms that a single face is present, in focus, and fully visible in the frame. This check is used only to accept or reject the image and produces no stored record.
6.2 How we use it
Your scan photo is used for two purposes only:
- To generate your personal reflection report, which is visible only to you.
- To display as your profile picture inside the App on your own device.
Your scan photo is never used for identification, advertising, marketing, profiling, or model training. It is never made public, never shown to other users, and never sold or rented.
6.3 Sharing, storage, and third parties
Your scan photo is transmitted over an encrypted connection (TLS) and stored in a private, S3-compatible bucket on Hetzner Object Storage, located in a Nuremberg, Germany datacenter within the European Union, encrypted at rest using AES-256 server-side encryption. The bucket is not publicly accessible. Access is restricted to a limited set of authenticated backend services and named administrators.
To generate your report, we grant our AI processing provider, OpenAI, L.L.C., time-limited read access to the image through a presigned URL valid for 15 minutes, after which the link expires and can no longer be used.
The only third parties that receive your scan photo are:
- Hetzner Online GmbH — cloud storage and hosting
- OpenAI, L.L.C. — automated analysis to generate your report
Both act as processors on our behalf under written data-protection agreements. We share face image data with no other third party. We do not disclose it to advertisers, data brokers, or analytics providers, and we do not sell or rent it. We will disclose it to a legal or regulatory authority only where we are legally compelled to do so.
6.4 Retention and deletion
We retain only your most recent scan photo. When you complete a new scan, the previous photo is permanently deleted from our storage. Your most recent photo is retained so it can be displayed as your profile picture, until the earliest of: you delete it, you delete your account, or 12 months of account inactivity, after which it is deleted automatically.
You can delete your scan photo at any time from the Profile screen in the App, or by emailing admin@aptify.me. Deleting your account permanently removes your scan photo along with your other personal data.
When a scan photo is deleted, it is removed from our active systems within 24 hours and from encrypted backups within 30 days, after which it is unrecoverable.
7. Legal Bases for Processing (GDPR / UK GDPR)
- Consent (Art. 6(1)(a) and Art. 9(2)(a)) — for processing your scan photo, bloodwork documents, and self-reported wellbeing data, and for optional marketing communications. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.
- Contract (Art. 6(1)(b)) — to provide the account and subscription services you have requested.
- Legal obligation (Art. 6(1)(c)) — where applicable law requires it.
- Legitimate interests (Art. 6(1)(f)) — to maintain security, prevent fraud and abuse, and diagnose crashes, balanced against your rights.
8. Sharing and Disclosure
We do not sell or rent your personal data. We share it only with:
- Service providers acting on our behalf under written agreements, listed in Sections 5 and 6.3 and including Hetzner Online GmbH (hosting and storage), OpenAI, L.L.C. (AI analysis), Google LLC (Firebase analytics and crash reporting), RevenueCat, Inc. (subscription management), and Apple Inc. and Google LLC (app distribution and billing)
- Legal or regulatory authorities, where required by subpoena, court order, or comparable legal process
- A successor entity, in connection with a merger, acquisition, or asset sale, with notice to you
- Anyone you choose, where you initiate the sharing yourself from within the App
9. Data Retention
We retain personal data only as long as necessary for the purposes described above.
- Scan photos — most recent only; see Section 6.4
- Account data — for the life of your account, deleted within 30 days of account deletion
- Check-in and habit data — for the life of your account, deleted with your account
- Bloodwork documents — until you delete them or delete your account
- Crash and diagnostic logs — 90 days
- Records required for tax, accounting, or legal compliance — for the period required by applicable law
10. Security
We protect your data using:
- Encryption in transit (TLS) for all data exchanged with our servers
- Encryption at rest for stored images and documents
- Private, non-public storage with access limited to authorized services and personnel
- Time-limited, expiring access links for image processing
- Email-based account verification
No system is completely secure, and we cannot guarantee absolute security, but we work to protect your data using appropriate technical and organizational measures.
11. Your Rights and Choices
Wherever you live, you can:
- Access or obtain a copy of your data
- Correct inaccurate information
- Delete your scan photo, your bloodwork document, or your entire account and all associated data (account deletion is irreversible)
- Object to or restrict certain processing
- Withdraw consent at any time
- Skip or clear any optional profile field, including gender and date of birth
California residents (CCPA/CPRA): you additionally have the right to know, delete, and correct personal information, and to opt out of “sharing” for cross-context behavioral advertising. We do not sell or share personal information as those terms are defined by the CCPA. We will not discriminate against you for exercising these rights.
EU/UK residents: you additionally have the right to data portability and the right to lodge a complaint with your local Data Protection Authority.
To exercise any right, use the in-app settings or email admin@aptify.me. We respond within 30 days (45 days for CCPA requests).
12. International Transfers
We are established in Bulgaria and store data on servers located in Nuremberg, Germany, within the European Union. The one exception is the scan photo sent to OpenAI, L.L.C. for automated analysis, which is processed in the United States. Where personal data is transferred outside the EEA or the UK, we rely on approved transfer mechanisms, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
13. Children’s Privacy
MirrorMe is not directed to children and is not intended for anyone under 13. We do not knowingly collect personal data from children under that age. If we learn that we have collected such data, we will delete it promptly. If you believe a child has provided us with personal data, contact admin@aptify.me.
14. Third-Party Services
The App uses the following third-party services, each governed by its own privacy policy: Hetzner Online GmbH, OpenAI, L.L.C., Google LLC (Firebase), RevenueCat, Inc., Apple Inc., and Google Play. We are not responsible for the privacy practices of services we do not control.
15. Changes to This Policy
We may update this Policy to reflect changes in law or in our practices. When we do, we will revise the “Last updated” date and notify you by in-app alert, email, or other prominent means. Material changes take effect 30 days after notice, or sooner if required by law.
16. Contact Us
Email: admin@aptify.me
Data Protection Contact (EU/UK): admin@aptify.me
Postal: DN Consulting Software Development Company — Legal
БЪЛГАРИЯ, гр. София (1000), р-н Лозенец, жк. Градина, бул. Симеоновско шосе, 110, бл. 34, ап. 2