Privacy Policy

Miraa Team·Last updated 21 June 2026

This policy explains what information Miraa collects, how we use it, and the choices and rights you have. Privacy is built into how Miraa is designed.

01Introduction

This Privacy Policy describes how Miraa Health (“Miraa”, “we”, “us”) handles personal information when you use our websites, applications, and related services (the “Service”). It applies to clinicians and organisations who use Miraa, and to visitors of our website.

Where Miraa processes patient health information on behalf of a clinician or clinic, we act as a processor / business associate, and that clinician or clinic is the controller responsible for that information. See Patient health information below.

02Information we collect

Information you provide

  • Account and profile details (name, email, role, practice, billing information).
  • Communications you send us (support requests, feedback).
  • Content you submit through the Service, including consultation audio, transcripts, drafted notes, and patient information you choose to process.

Information we collect automatically

  • Usage and device information (pages viewed, features used, browser, approximate location, log data).
  • Cookies and similar technologies, see Cookies and analytics.

03How we use information

  • To provide, maintain, and improve the Service and generate your drafts;
  • to authenticate users, secure accounts, and prevent abuse;
  • to process payments and manage subscriptions;
  • to provide support and respond to your requests;
  • to comply with legal obligations and enforce our terms.

We do not sell personal information, and we do not use patient content to train our models.

04Patient health information and HIPAA

Patient information you process through Miraa is handled on your behalf. Where applicable, we enter into a Business Associate Agreement (BAA) or equivalent data processing agreement that governs how we may use and protect that information. Patient audio and transcripts are processed only to produce your drafts and are ephemeral by default, see retention below. We align our handling of health information with HIPAA and applicable local health-privacy requirements.

05How long we keep information

Consultation audio and transcripts are ephemeral by default and are removed on our zero-retention layer once the encounter is closed. Account, billing, and limited operational records are retained for as long as your account is active and as required to meet legal, accounting, and security obligations, after which they are deleted or de-identified.

06How we share information

We share information only as needed to run the Service:

  • with sub-processors who provide infrastructure, hosting, and processing under contractual confidentiality and security obligations;
  • with your organisation’s administrators, where you use Miraa under a clinic or group account;
  • when required by law, legal process, or to protect rights, safety, and the integrity of the Service;
  • in connection with a merger, acquisition, or sale of assets, subject to this policy.

A current list of sub-processors is available on request at [email protected].

07Security

We protect information with encryption in transit and at rest (AES-256), access controls, and audit logging, and we maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data. No system is perfectly secure, but security is a baseline of how Miraa is built, not a premium add-on.

08Data residency and international transfers

Data is hosted in the Australian (AU) region by default. Where information is transferred across borders, we use appropriate safeguards as required by applicable law. Institution and enterprise customers may elect specific residency or private-cloud arrangements.

09Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Where Miraa processes patient information on a clinician’s behalf, requests from patients should be directed to that clinician or clinic as the controller. To exercise your rights, contact us at [email protected].

10Cookies and analytics

We use necessary cookies to operate the Service and may use limited analytics to understand and improve usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.

11Children’s privacy

The Service is intended for use by healthcare professionals and is not directed to children. We do not knowingly collect personal information directly from children through the Service.

12Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide reasonable notice and update the “Last updated” date above.

13Contact us

For privacy questions or to reach our privacy contact, email [email protected], Miraa Health, 3 Broadway, Ultimo NSW 2007, Australia.

Privacy Policy | Miraa Health