Privacy Policy
Effective July 23, 2026
Mirage ("we", "our", "the app") is a window and desktop streaming application developed by Ethan Lipnik in the United States. This policy describes what information Mirage processes, how it is used, the services we rely on, and the choices you have. For privacy requests, submit a private ticket through Mirage Support.
Streaming Data
Screen content, audio, and input events are streamed directly between your devices over your local network, a peer-to-peer link, or an address you control. Mirage does not route streaming media through external servers, and no screen content is stored or recorded by Mirage.
Connections through a saved address keep media encryption enabled. Mirage Pro also includes local media encryption controls. Free-tier local sessions may run without encrypted media payloads. When media encryption is enabled, video, audio, and supported clipboard payloads use per-session key derivation with AES-256-GCM.
iCloud
Mirage uses Apple's CloudKit to enable automatic device discovery and trust between devices signed in to the same iCloud account. The following data may be stored in your private iCloud container:
- Device identifiers and host names for discovery
- Identity keys for establishing trust between your devices
- Hardware metadata hints used for device icons
- A minimal support-ticket index containing the support server profile, ticket identifier, capability secret, timestamps, and cached status
Support message bodies, logs, screenshots, and other attachments are not stored in CloudKit. CloudKit data is stored in your personal iCloud account and is governed by Apple's iCloud privacy policies. You can remove it at any time from within the app or through iCloud settings.
Subscriptions
Mirage client uses RevenueCat and Apple's StoreKit infrastructure to evaluate Mirage Pro subscription state and offering metadata. Purchases, billing, cancellation, and refunds are handled by Apple under App Store terms. Mirage does not receive or store your payment details.
Mirage stores a local RevenueCat app user identifier and local entitlement cache on your device so subscription state can be restored across launches and continue during App Store or RevenueCat connectivity failures until subscription state can be verified again.
Support Requests
Mirage provides support through private Echo tickets in the app and at Mirage Support. Echo provides a ticket inbox, conversation replies, status updates, and attachments without requiring a support account. We process the ticket title, description, structured support fields, conversation messages, status history, and files you choose to attach.
When a ticket is created, the support service returns an opaque capability secret that authorizes access to that ticket. Mirage stores the capability in Keychain and may synchronize the minimal ticket index described above through your private CloudKit database. The public ticket number alone does not grant access. If iCloud is unavailable, the index remains on the device where the ticket was created.
Support reports can include app version, build, platform, device and OS details, locale, time zone, a pseudonymous Echo installation identifier, and the support details shown before submission. If you choose to attach diagnostics, logs, screenshots, or other files, those attachments are uploaded with the ticket. An exported client archive can also contain logs from the connected host or, in Oasis, every connected host. Do not include credentials, payment information, private documents, or unrelated personal information.
Tickets, attachments, diagnostics, analytics, and support operations are processed by Echo on Cloudflare-hosted infrastructure. Authorized support operators access this information through Mirage's private Echo management service, and operator actions are recorded in an audit log.
You may enable or disable notifications for each ticket. When enabled, Mirage registers an Apple Push Notification service device token with the support service and uses it only for ticket replies, status changes, and linked release updates. Notification preferences and device registrations can be revoked from the app.
When a fixing release is explicitly published, Mirage deletes uploaded logs and attachments, device and OS details, locale and time zone, Echo and RevenueCat correlation identifiers, diagnostic summaries and support fields, cached integration links, push registrations and deliveries, and read-state data from tickets linked as fixed in that release. The release is not marked published until this live-store cleanup succeeds. Mirage retains the ticket capability, conversation, resolution, product/version fields, changelog and release links, and minimized audit history so you can continue to track the resolved ticket.
Error Reporting
Mirage uses Echo for crash and error reporting. The level of diagnostic data sent is configurable:
- None: no diagnostics are sent
- Crashes Only: only crash reports are sent
- Errors: crashes and non-fatal errors are sent
Client and host apps default to "Errors." When enabled, crash reports may include device model, OS version, app version, crash stack traces, curated breadcrumbs, and technical context. Client diagnostics may include the same pseudonymous Echo identifier used by analytics. Raw iCloud record identifiers, raw stream media, message bodies, credentials, and payment details are not forwarded. Debug builds never upload diagnostics automatically; they retain a bounded local history that is included only when you explicitly export or attach logs.
Analytics
Anonymous Analytics is on by default and can be turned off in Settings, including in TestFlight builds. When enabled, Mirage sends first-party Echo events such as app launch metadata, onboarding steps, button taps, connection attempts and outcomes, stream start and stop outcomes, and session-duration signals using a pseudonymous installation identifier. Screen capture, automatic screen-view capture, and user-input recording are disabled. Debug builds never upload analytics; they retain a bounded local history for explicit log export. Analytics data is used to understand adoption, identify stuck points, and prioritize development.
Legal Bases for EU and UK Users
Where EU or UK data protection law applies, Mirage relies on contract necessity for core app functionality, subscriptions, and requested support services; legitimate interests for security, diagnostics, support operations, and first-party product analytics; consent where required for optional notifications; and legal obligation where required by law. You can change analytics, diagnostics, and ticket-notification choices in the app.
Retention
Local settings, host preferences, trust/cache metadata, ticket capabilities, bounded Debug telemetry, the local RevenueCat app user identifier, and local subscription cache entries remain on your device until you reset them or remove the app and its container data. Active subscription cache entries may be used during App Store or RevenueCat connectivity failures until subscription state can be verified again. iCloud discovery and ticket-index records remain until you remove them from Mirage or iCloud. Unresolved tickets remain available for support work. Echo records and infrastructure backups follow their configured retention schedules and may outlast deletion from Mirage's live support store. You can request earlier deletion through a support ticket.
International Transfers
Mirage is operated from the United States and uses Apple, RevenueCat, and Cloudflare infrastructure that may process data outside your country. Where transfer safeguards are required, Mirage relies on the safeguards offered by those providers, including their data processing terms and transfer mechanisms.
Data We Do Not Collect
- We do not collect or store the contents of your screen on Mirage-operated servers
- We do not track your location
- Support tickets do not require an email address
- We do not sell personal data or share it for advertising or behavioral tracking
- We do not use advertising SDKs or behavioral tracking
Third-Party Services
Mirage integrates the following third-party services, each with their own privacy policies:
Your Choices
You can control diagnostics and Anonymous Analytics in Settings, manage notifications for each support ticket, and remove local support data by deleting the app's data. You can remove iCloud discovery and ticket-index data from within the app where available or by managing your iCloud storage through System Settings. Subscription management is available through the App Store.
Your Privacy Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, objection, and withdrawal of consent for personal data that Mirage controls. EU and UK users may also lodge a complaint with their local data protection authority, including the UK Information Commissioner's Office for UK users. To make a request, submit a private ticket through Mirage Support.
Children's Privacy
Mirage is not directed at children under the age of 13. We do not knowingly collect information from children.
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated through the app or this page.
Contact
If you have questions about this privacy policy, submit a private ticket through Mirage Support.