MIORA

Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how Miora collects, uses, stores, and shares information when you use the Miora mobile application and related Event and Journal services.

1. What Miora does

Miora helps you keep personal photo journals and collect photos from shared events. Journals are private by default. An Event can be shared with guests by an invite link or QR code.

2. Information we process

Account and authentication information

When you create or sign in to an account, we process your Firebase user ID, email address, display name, email-verification state, and authentication provider information. You may sign in with email/password, Google, or Apple. Anonymous guest sessions may be created only for Event participation and are not eligible for personal Journals or paid purchases.

Content you choose to provide

Depending on the feature you use, Miora processes photos, optional videos, captions, notes, dates, Journal titles, Event titles, cover images, invite links, and QR codes. Event uploads may also include uploader display name, uploader ID, file type, file size, and upload status.

Camera and photo-library information

Quick Capture requests camera access only when you start capture. A captured photo is saved locally first and is uploaded or assigned to a Journal only as part of the flow you choose.

If you enable Auto Journal, Miora may read photo dates, dimensions, favorite and screenshot flags, local availability, location metadata, and small thumbnails from the device photo library. This analysis is performed on the device. GPS coordinates used for temporary grouping remain in memory and are not sent to Miora’s servers as part of a suggestion. No Journal is created until you review and confirm a suggestion.

When you explicitly import or upload a selected photo, the selected media is sent to Firebase Storage so it can be displayed on your account or Event.

Device, diagnostic, and usage information

Miora and its service providers may process app version, operating system, device model, language, approximate technical region, crash information, route name, and coarse feature events. Crash reports and logs are designed not to contain photo bytes, file paths, file names, notes, Journal titles, GPS coordinates, invite tokens, or photo-library asset IDs.

Purchases and entitlements

When paid Event Passes or other RevenueCat-managed purchases are enabled, Miora and RevenueCat process a Firebase user ID, product or package identifiers, purchase state, entitlement state, and transaction or receipt information. Apple App Store and Google Play process payment details; Miora does not receive your full card number.

3. Why we use information

We use information to authenticate and protect access; save, sync, display, and organize the content you request; enforce Event membership and upload limits; provide local-first drafts and offline recovery; diagnose reliability issues; improve the service; and comply with legal obligations. Miora does not sell personal information or use photos or Journal notes for advertising profiles.

4. Service providers and sharing

We share information only as needed to provide the requested service. Google Firebase provides Authentication, Firestore, Cloud Functions, Cloud Storage, Crashlytics, and Analytics. RevenueCat provides purchase and entitlement management when paid products are enabled. Apple and Google Play process purchases. Private Journals are not shared unless you explicitly use an Event or sharing feature.

5. Local storage, security, and retention

Miora stores local drafts, encrypted Drift database records, upload retry data, preferences, and media cache files on your device. Content stored in Firebase is retained while your account, Journal, or Event requires it. A soft-deleted Event is hidden immediately and is scheduled for permanent purge no earlier than seven days later. We use encrypted local storage where supported, access controls, Firebase security rules, and encrypted transport.

6. Your choices and rights

You can grant, deny, or revoke camera and photo-library permissions; opt out of Auto Journal suggestions; review or delete content through product controls; clear eligible disk cache; and request access, correction, or deletion of personal information by contacting us.

You can permanently delete your account in the app at Account → Security → Delete account. We then remove your account, private Journals, hosted Events, uploaded media, and device-local app data. Media you uploaded to another person’s shared Event is also removed. This action cannot be undone. For a web deletion request, use the Support page below.

7. Children

Miora is not directed to children under the minimum age required in the applicable country. We do not knowingly collect personal information from children without appropriate authorization.

8. International transfers

Our service providers may process information in countries different from your country of residence. We use contractual, technical, and organizational safeguards required by applicable law.

9. Changes to this policy

We may update this policy when Miora’s features, providers, or legal requirements change. We will update the effective date and provide additional notice in the app when a change is material.

10. Contact

For privacy questions or requests, contact tuanho.dev@gmail.com or visit https://moments.iseed.space/support.