← Back to Home

Privacy Policy

Effective date: 22 August 2026

1. Controller and contact

The controller responsible for DeepMirror is DeepMirror service operator.

Privacy and data-rights requests: privacy@deepmirror.me.

Notice: The controller's postal address is being added to this notice. You may use the email address above in the meantime.

2. Data processed, purposes, and legal bases

Free-form reflection content may reveal sensitive information. DeepMirror does not require health, religious, political, sexual-orientation, trade-union, genetic, or biometric information. Do not enter this information unless you choose to include it as part of a requested private reflection. DeepMirror does not use reflection content for advertising.

3. AI processing and profiling

When you request an AI feature, the content needed for that request is sent to the configured AI provider to generate questions, feedback, summaries, images, career results, or other requested output. This may identify patterns, preferences, values, or possible goals and therefore may constitute profiling. These outputs support self-reflection only. DeepMirror does not make decisions producing legal or similarly significant effects about you.

4. Recipients and processors

Depending on the feature used, personal data may be processed by Google Cloud and Firebase (hosting, database, authentication, storage, task scheduling, text-to-speech, and AI services), OpenAI (AI generation and optional image generation), Stripe (payments), Google Analytics (consent-only analytics), Meta/WhatsApp (consent-only reminders), and Namecheap Private Email (requested email reminder delivery). Career Mirror may also retrieve public job and company information from public websites.

DeepMirror does not sell personal data or share reflection content for third-party advertising. Service providers process data under their applicable contractual and privacy terms.

5. International transfers

Some providers may process data outside Germany or the European Economic Area. Where required, transfers must rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You may request information about the safeguard applicable to a particular provider at privacy@deepmirror.me.

6. Retention

7. Security

DeepMirror uses encrypted transport, access controls, Google Cloud security controls, and application-level encryption for stored reflection content in supported cloud-storage paths. New encrypted records use envelope encryption with random data-encryption keys protected by Google Cloud KMS; older encrypted records remain readable in their previous format until migration is completed. The service decrypts content when necessary to display it to you or provide a feature you request, including requested AI features. Device-only mode avoids cloud persistence of the check-in but does not prevent this requested server and AI processing. No online service can guarantee absolute security.

8. Cookies and browser storage

Necessary cookies and browser storage support sign-in, session security, language, device-only storage, theme, and your cookie choice. Optional Google Analytics is loaded only after you accept it. Declining analytics does not prevent use of the core service.

9. Your rights

Subject to the GDPR's conditions and exceptions, you may request access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests. You may withdraw consent at any time without affecting processing that occurred before withdrawal.

Signed-in users can view and delete check-ins, download a machine-readable export from Profile, and delete their account. Other requests can be sent to privacy@deepmirror.me. Requests are normally answered within one month, and identity verification may be required.

You may lodge a complaint with the competent data-protection supervisory authority, including the authority for your habitual residence, workplace, or the place of an alleged infringement.

10. Required and optional data

An email-based sign-in identifier is required for a cloud account. Content entered into reflection features is optional, but the requested feature cannot generate personalised output without the relevant input. Analytics, WhatsApp reminders, and email reminders are optional.

11. Children

DeepMirror is not intended for children under 16. If DeepMirror learns that it has collected a child's data contrary to applicable requirements, it will delete that data.

12. Changes

This notice may be updated when processing or providers change. Material changes will be communicated through the service where appropriate, and the effective date above will be updated.