01Introduction
This Privacy Policy describes how Miraa Health (“Miraa”, “we”, “us”) handles personal information when you use our websites, applications, and related services (the “Service”). It applies to clinicians and organisations who use Miraa, and to visitors of our website.
Where Miraa processes patient health information on behalf of a clinician or clinic, we act as a processor / business associate, and that clinician or clinic is the controller responsible for that information. See Patient health information below.
02Information we collect
Information you provide
- Account and profile details (name, email, role, practice, billing information).
- Communications you send us (support requests, feedback).
- Content you submit through the Service, including consultation audio, transcripts, drafted notes, and patient information you choose to process.
Information we collect automatically
- Usage and device information (pages viewed, features used, browser, approximate location, log data).
- Cookies and similar technologies, see Cookies and analytics.
03How we use information
- To provide, maintain, and improve the Service and generate your drafts;
- to authenticate users, secure accounts, and prevent abuse;
- to process payments and manage subscriptions;
- to provide support and respond to your requests;
- to comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not use patient content to train our models.
04Patient health information and HIPAA
Patient information you process through Miraa is handled on your behalf. Where applicable, we enter into a Business Associate Agreement (BAA) or equivalent data processing agreement that governs how we may use and protect that information. Patient audio and transcripts are processed only to produce your drafts and are ephemeral by default, see retention below. We align our handling of health information with HIPAA and applicable local health-privacy requirements.
05How long we keep information
Consultation audio and transcripts are ephemeral by default and are removed on our zero-retention layer once the encounter is closed. Account, billing, and limited operational records are retained for as long as your account is active and as required to meet legal, accounting, and security obligations, after which they are deleted or de-identified.
07Security
We protect information with encryption in transit and at rest (AES-256), access controls, and audit logging, and we maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data. No system is perfectly secure, but security is a baseline of how Miraa is built, not a premium add-on.
08Data residency and international transfers
Data is hosted in the Australian (AU) region by default. Where information is transferred across borders, we use appropriate safeguards as required by applicable law. Institution and enterprise customers may elect specific residency or private-cloud arrangements.
09Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Where Miraa processes patient information on a clinician’s behalf, requests from patients should be directed to that clinician or clinic as the controller. To exercise your rights, contact us at [email protected].
11Children’s privacy
The Service is intended for use by healthcare professionals and is not directed to children. We do not knowingly collect personal information directly from children through the Service.
12Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide reasonable notice and update the “Last updated” date above.
13Contact us
For privacy questions or to reach our privacy contact, email [email protected], Miraa Health, 3 Broadway, Ultimo NSW 2007, Australia.





