Privacy
This describes how Mirrorstone AI uses personal and business data. It is written for the product as it ships today — not a generic template.
Controller. Mirrorstone AI is operated by Mirrorstone Group. Contact hello@mirrorstone.co.uk for privacy requests.
What we collect
- Account data — name, email, username, organisation name, optional profile or logo images, authentication records (including 2FA secrets if you enable them).
- Billing data — plan, trial status, and Stripe customer/subscription identifiers. Card details are handled by Stripe, not stored in Mirrorstone.
- Connector credentials — OAuth tokens and API keys, stored encrypted, used only to sync the sources you connect.
- Warehouse data — records synced from those sources (orders, invoices, campaigns, and so on) into your organisation’s warehouse schema.
- Chat and product usage — questions, answers, Evidence, reports, dashboards, schema notes, named metrics, and usage needed to run credits and limits.
How we use it
We use this data to provide the service: sign you in, sync connectors, run read-only SQL for Chat, render reports and dashboards, bill the organisation, send transactional email (invites, password reset, data-ready notices), and keep the platform secure.
Chat sends your question plus warehouse schema context to the large-language-model provider configured for that organisation (Mirrorstone’s shared default, an organisation key, or a personal key). We do not sell your warehouse data.
Sharing
We share data with subprocessors required to run the product (hosting, email delivery, Stripe, and the LLM provider you or Mirrorstone configure). Password-protected report links expose only the report you chose to share. Organisation admins control who is a member.
Retention
Account and warehouse data last for the life of the organisation, subject to plan limits and any freeze/purge after an unpaid trial. You can disconnect a connector; synced tables follow the product’s disconnect and retention behaviour. You may request deletion via the contact address above.
Your rights
If UK GDPR applies, you may request access, correction, deletion, or restriction, and you may complain to the ICO. Some rights are limited where we must keep records for security, billing, or legal obligation.
Last updated 25 August 2026.