Privacy Policy for Mira

Effective date: 20th August 2026
Last updated: 20th August 2026

Consensus Gentium Limited, doing business as Consensus Gentium (“Company,” “we,” “us,” or “our”), provides the Mira mobile application, related websites, and associated services collectively referred to in this Privacy Policy as the “Service.”

Mira is a personal AI secretary designed to help users manage schedules, contacts, communications, documents, voice instructions, and related administrative tasks.

This Privacy Policy explains how we access, collect, use, disclose, retain, and protect information when you use the Service. It also explains the choices and rights available to you.

Our contact information is:

Legal entity: Consensus Gentium Limited
Registered or business address: Unit 04, 12/F, 33 Hung To Road, Kwun Tong, Kowloon, Hong Kong
Privacy email: privacy@cgentium.com
Support email: support@cgentium.com
Privacy request page: https://www.cgentium.com/privacy-request
Account deletion page: https://www.cgentium.com/account-deletion

1. Summary of our privacy practices

We follow these principles:

2. Information covered by this Privacy Policy

“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household.

The information handled by the Service may include information about you and information about other people contained in your contacts, calendars, communications, documents, recordings, or instructions.

When you ask the Service to process information concerning another person, such as a contact’s name, email address, phone number, or calendar invitation, we process that information only to carry out the task you request and as otherwise described in this Privacy Policy.

3. Information we access, collect, or generate

Some information may be accessed and processed only on your device. Other information may be transmitted to our servers or contracted service providers. We identify those distinctions below where applicable.

3.1 Account and profile information

When you register, sign in, connect an account, or manage your profile, we may process:

When you use Google Sign-In, we receive only the profile information covered by the permissions shown on the Google authorization screen, such as your Google Account identifier, name, primary email address, and profile image.

We use this information to authenticate you, operate your account, display your profile, secure the Service, communicate with you, and associate connected services with the correct account.

3.2 Device time and time zone

The Service may access your device’s current time, time-zone setting, locale, and related date and time information.

We use this information to:

The time-zone information may be transmitted to our servers for processing and providing time-related services for you.

We do not treat device time-zone information as precise physical location data, and we do not use it to track your movements. We may infer a broad region from a time zone only when needed to interpret scheduling instructions or comply with regional requirements.

3.3 Device contacts

When you choose a feature involving recipients, attendees, or contact lookup, the Service may access contacts you select through the device’s system contact picker. Contact information may include:

We use contact information to identify recipients, suggest meeting attendees, address communications, create contact-related reminders, and perform other actions you request.

We do not use contact information to send unsolicited marketing, build advertising profiles, publish non-public contacts, or independently contact people without your instruction.

If you enable full device-contact synchronization, the Service may access your device contact list after displaying a separate prominent disclosure and obtaining permission. Full contact access is used only to resolve natural-language requests such as “email Alex,” “schedule a meeting with my accountant,” or “find Jordan’s phone number.” You can disable contact access in the app or device settings.

3.4 Device calendar information

When you connect or authorize a device calendar, the Service may access calendar names, event titles, dates, times, recurrence information, attendees, availability, meeting links, locations, reminders, descriptions, notes, and related event information.

Depending on the permission you grant, the Service may:

Where the feature can be provided using a system calendar interface without direct calendar access, we may open your calendar app with a pre-filled event and allow you to review and save it there.

3.5 Mail-app integration

When you choose to compose an email using an installed mail application, the Service may provide the mail app with information you approved, such as:

The selected mail application then controls the sending process under its own terms and privacy practices.

Opening a compose screen in another mail app does not give us access to your inbox, sent messages, stored drafts, or other mailbox content.

3.6 Gmail send-only integration

Under the customized sending configuration described in this Privacy Policy, Gmail access is strictly limited to sending messages that you instruct or approve the Service to send.

We may process:

We do not use this integration to:

The Service may generate a proposed message inside Mira. You will be shown the proposed recipient and content before sending unless you have expressly configured a specific automation that permits sending under defined conditions.

3.7 Google Calendar

If you connect Google Calendar, we may access the minimum calendar information needed for the features you enable. Depending on the scopes you authorize, this may include:

We use Google Calendar information to show your schedule, prevent conflicts, suggest meeting times, and carry out scheduling actions you request.

3.8 Google Contacts

If you connect Google Contacts, we may access the contact fields covered by the permissions you authorize, such as names, email addresses, phone numbers, organizations, and profile images.

We use Google Contacts information to identify recipients and attendees, help you find contact details, and carry out communications or scheduling actions you request.

3.9 Google Drive

The Service uses limited, per-file Google Drive access.

We may access a Drive file only when:

Depending on the task you request, we may process file names, file metadata, file content, comments, or generated output. We may download a temporary copy to process your request or upload a resulting file to the location you choose.

We do not broadly search, scan, index, or read other files in your Google Drive.

The intended Drive scope is:

https://www.googleapis.com/auth/drive.file

3.10 Photos and videos

When you choose to attach, analyze, upload, or reference a photo or video, the Service may access only the items you select through the Android Photo Picker or another system file picker.

Selected content and related metadata may be used to:

We do not continuously scan your photo library or upload unselected photos and videos.

3.11 Camera

The Service may request camera access when you choose to capture an image or video for a specific task.

Camera access begins only after you activate the camera feature. We do not secretly activate the camera or continuously record in the background.

Images or videos captured through the Service may be stored on your device or transmitted to our servers and contracted processors when needed to perform the task you request.

3.12 Microphone, voice messages, and transcriptions

When you activate a voice feature, the Service may record:

We use this information to transcribe your instruction, understand the requested task, generate a response, create content, or carry out an action you authorize.

Recording begins only after you activate the microphone or voice-message feature. The Service does not continuously listen or record in the background when the feature is not active.

Audio may be transmitted to NLP and AI Providers to provide transcription and AI-processing functions.

Audio recordings are retained for 14 days, or processed ephemerally and deleted after transcription if that is your actual implementation. Transcripts may remain in your assistant history until you delete them or for the period stated in Section 11.

3.13 Files and documents

When you select, upload, scan, create, or share a file with the Service, we may process:

We process files only to perform the task you request, such as summarizing a selected document, extracting deadlines, creating a calendar event, preparing a reply, or attaching the file to a user-directed communication.

3.14 Assistant instructions, tasks, and generated content

We process the content you submit to the assistant, including:

We use this information to understand your request, provide the assistant’s response, personalize your experience, maintain task history, and carry out authorized actions.

We keep user-specific memory to personalize your experience better, it is associated only with your account, can be viewed or deleted through [[SETTINGS > DELETE USER MEMORY]], and is not used to train any model.

3.15 Usage, device, and diagnostic information

We and our contracted technical providers may collect:

We use this information to operate the Service, detect abuse, troubleshoot errors, monitor reliability, understand aggregate feature usage, and improve security and performance.

We do not include the content of your contacts, emails, calendar events, selected files, photographs, or voice messages in analytics or advertising profiles.

3.16 Purchases and subscriptions

If the Service offers paid subscriptions or purchases, Google Play may process payment-card or billing information.

We may receive transaction identifiers, subscription status, purchase history, renewal information, country, currency, and limited billing details. We generally do not receive complete payment-card numbers from the payment processor.

3.17 Support and communications

When you contact support, participate in a survey, or communicate with us, we may collect your contact details, message content, attachments, diagnostic information you submit, and records of our response.

Support personnel will not access the contents of Google Workspace messages, files, calendars, or contacts unless you provide explicit permission to access specific information for support purposes or access is necessary for security or legal reasons.

4. How we use information

We use information to:

  1. Provide, maintain, and operate the personal AI secretary;
  2. Authenticate users and manage accounts;
  3. Interpret text and voice instructions;
  4. Show calendars, schedules, reminders, and availability;
  5. Suggest recipients, attendees, and meeting times;
  6. Generate proposed messages, notes, tasks, and documents;
  7. Send communications approved or configured by the user;
  8. Create, update, or delete calendar events at the user’s direction;
  9. Process selected files, photographs, recordings, and documents;
  10. Provide user-specific preferences and optional personalization;
  11. Synchronize connected services;
  12. Provide customer support;
  13. Protect users, prevent fraud, and secure the Service;
  14. Diagnose technical problems;
  15. Maintain aggregate service analytics;
  16. Comply with legal obligations; and
  17. Enforce our terms and protect our legal rights.

We do not use Google Workspace data or other sensitive integration data for unrelated advertising, data brokerage, credit decisions, or generalized AI-model training.

5. Artificial intelligence processing

The Service uses artificial intelligence to interpret instructions, generate content, extract information, and recommend or perform administrative actions.

To provide these functions, we may transmit the minimum relevant portion of your instruction and connected data to contracted AI-processing providers, including:

These providers process information on our behalf and under our instructions.

We require our AI providers to apply contractual and technical restrictions appropriate to the information they receive.

We do not:

AI-generated content may be inaccurate or incomplete. You should review important communications, dates, recipients, instructions, and actions before approving them.

6. External actions and automations

By default, the Service presents external actions for your review or obtains your instruction before performing them. External actions may include:

Where the Service permits automations, we disclose the automation’s purpose, data access, permitted actions, trigger conditions, frequency, and recipients before activation. You can review, pause, modify, or disable an automation through [[SETTINGS > AUTOMATION ON/OFF]].

7. Google Workspace data and Limited Use

Mira's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

8. When we disclose information

8.1 Service providers

We may provide information to companies that process it on our behalf, such as:

Our current providers are listed below:

Service providers are authorized to process information only for contracted purposes and are required to apply appropriate confidentiality, security, and data-protection measures.

8.2 Connected services and user-directed recipients

We disclose information when needed to perform an action you request. For example, we may send an approved message to its recipients, add attendees to an event, upload a file to a location you select, or open another app with information you choose to transfer.

Recipients and independently controlled connected services may process that information under their own privacy policies.

8.3 Legal, safety, and security reasons

We may disclose information when we reasonably believe disclosure is necessary to:

8.4 Corporate transactions

Information may be disclosed in connection with a proposed or completed merger, financing, acquisition, restructuring, sale of assets, or similar transaction.

Where Google Workspace data is involved, we will obtain prior consent when required by Google’s Limited Use requirements and applicable law.

8.5 No sale or behavioral-advertising sharing

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising or use contacts, calendar content, email content, files, photographs, recordings, or assistant instructions to target third-party advertisements.

9. Your permissions and choices

You can decline or revoke device permissions and connected-service authorizations. Depending on the permission, you can manage access through:

Revoking a permission prevents future access but may not automatically delete information previously stored in your Mira account. You can delete stored information through the Service or request deletion as described below.

Declining one permission does not prevent you from using unrelated features. Features that genuinely depend on the declined permission may be unavailable or operate in a limited manner.

10. Google account disconnection

You can disconnect your Google Account through [[SETTINGS > GOOGLE CONNECTION ON/OFF]].

After disconnection:

You may also revoke access through your Google Account. Revocation prevents future API access but does not necessarily delete your separate Mira account. To delete the entire account and associated information, use the account-deletion process below.

11. Data retention

We retain information only for as long as reasonably necessary to provide the Service, fulfill the purposes described in this policy, comply with law, resolve disputes, and enforce agreements.

Information

Retention Period

Account and profile data

While the account is active and for 60 days after deletion is requested

OAuth access and refresh tokens

Until the integration is disconnected or the account is deleted, then deleted within 24 hours

Contacts and calendar data cached by the Service

60 days

Selected Gmail outgoing-message content

60 days

Selected Drive files and extracted content

60 days

Voice recordings

14 days

Voice transcripts, prompts, tasks, and assistant history

Until deleted by the user or for 60 days

Photos, camera images, and uploaded files

60 days

Crash logs and security logs

60 days

Backups

Removed through the backup cycle within 90 days

Billing and transaction records

2 years or the period required by applicable law

Support records

2 years after the support matter closes

Information may be retained longer where necessary to comply with law, prevent fraud or abuse, resolve a dispute, or establish or defend legal claims. Where possible, information retained for these reasons will be isolated from ordinary product use.

12. Account and data deletion

You can initiate account deletion:

In the app: [[SETTINGS > ACCOUNT > DELETE ACCOUNT]]
On the web: https://www.cgentium.com/account-deletion
By email: support@cgentium.com

We may verify your identity before completing a request.

Users may request the deletion of their account and all associated data at any time via the web link provided above, even if they no longer have the application installed on their device.

Deleting your account results in deletion of the personal information associated with the account, including stored assistant content, connected-service tokens, and cached integration data, except information we are legally required or permitted to retain.

We complete deletion from active systems within 2 days. Residual encrypted backup copies are removed through our normal backup cycle within 90 days and are not restored to active use except for disaster recovery or security purposes.

Temporary account deactivation or suspension is not treated as account deletion.

You may also delete individual tasks, messages, recordings, uploaded files, memories, or integrations through [[SETTINGS > DELETE ALL HISTORY]].

13. Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, acquisition, loss, alteration, disclosure, or destruction.

These safeguards include, as applicable:

No security measure is perfect, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed despite our safeguards.

14. International data transfers

We and our service providers may process information in countries other than the country where you live. Data is usually stored and processed in Singapore but AI providers have different locations.

Where required, we use appropriate safeguards for international transfers, which may include contractual protections, data-processing agreements, standard contractual clauses, adequacy decisions, or another legally recognized transfer mechanism.

15. Legal bases for processing

Where applicable law requires a legal basis, we process personal information on one or more of the following grounds:

You may withdraw consent at any time. Withdrawal does not affect processing that occurred lawfully before withdrawal.

16. Your privacy rights

Depending on where you live, you may have the right to:

Because we do not sell personal information or use it for cross-context behavioral advertising, there is no sale or behavioral-advertising sharing from which you need to opt out under this policy.

Submit a request by contacting support@cgentium.com.

We may request information necessary to verify your identity and protect your account. Authorized agents may submit requests where permitted by law, subject to appropriate proof of authorization.

17. Children’s privacy

The Service is not directed to children under 15, and we do not knowingly collect personal information from children below that age.

If we learn that a child has provided personal information contrary to this section, we will take reasonable steps to delete it.

18. Third-party services

The Service may link to or interact with third-party services, including Google, device applications, payment processors, and services selected by you.

This Privacy Policy governs our processing. A third party’s own processing is governed by its privacy policy and terms. We encourage you to review the permissions and privacy practices of every connected service.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in the Service, our practices, technology, legal requirements, or Google platform rules.

We will update the “Last updated” date when changes are made. Where required or appropriate, we will provide additional notice through the Service or by email and obtain consent for materially different data uses.

20. Contact us

Questions, complaints, and privacy requests may be directed to:

Consensus Gentium Limited
Unit 04, 12/F, 33 Hung To Road, Kwun Tong, Kowloon, Hong Kong
Support Email: support@cgentium.com
Privacy Request Email: privacy@cgentium.com
Privacy request page: https://www.cgentium.com/privacy-request

Data Protection Officer or privacy representative, if applicable:
Ms. Leung
privacy@cgentium.com