Security · Privacy · Responsible AI

Trust is not built by collecting more data. It is built by needing less of it.

Mirel is an AI-powered strategic marketing platform designed for agencies, marketing teams and mid-sized companies. It helps teams think better, faster and more clearly — without encouraging unnecessary exposure of sensitive customer or business data.

Mirel’s core principle: as little risky data as possible, as much strategic clarity as necessary.

No data resale

Mirel does not sell customer data or operate an advertising or data-brokerage model.

No model training

Customer prompts and outputs are not used by Mirel to train general models for other customers.

Separated workspaces

Organisations, clients, sessions and project work are separated through authenticated access controls.

Frankfurt backend

Mirel uses Supabase infrastructure hosted in Frankfurt, Germany for core backend services.

Plain English summary

What buyers need to know first.

Mirel is operated by Mirel UG (haftungsbeschränkt), based in Hamburg, Germany. The platform is designed for strategic marketing work: diagnosis, audience understanding, positioning, campaign strategy and related strategic workflows.

What happens to your input?

User inputs are processed by Mirel to generate strategic outputs. Depending on the workflow, relevant context is sent to a selected AI provider through commercial API access.

Where is work stored?

Mirel uses Supabase as its core backend, authentication and persistence layer. The Supabase server is hosted in Frankfurt, Germany.

Who can access work?

Users access Mirel through authenticated accounts. Human access by Mirel personnel is limited to operational support, debugging, maintenance or user-requested assistance.

Should sensitive data be uploaded?

No. Mirel is designed so good strategy normally works with abstraction, anonymised context and patterns — not raw CRM exports, health data, claims data or customer records.

Our philosophy

Why Mirel needs less data than most AI.

Many AI tools imply that better output requires more input. Mirel takes the opposite view for strategic work.

Most high-quality marketing strategy does not require personally identifiable information, individual customer records or highly sensitive operational datasets. It requires clear context, sharp hypotheses, category understanding, audience psychology, competitive awareness and good strategic judgement.

That is why Mirel encourages users to work with anonymised, aggregated or abstracted information wherever possible. This reduces organisational risk and often improves strategic clarity by focusing attention on patterns rather than isolated details.

Recommended
Audience descriptions, category patterns, anonymised observations, strategic challenges, campaign context and non-sensitive business framing.
Not recommended
Personal data, CRM exports, customer records, health information, claims data, contracts, passwords, API keys, confidential financial data or regulated case-level records.
Simple rule
If you would not write the information on a workshop whiteboard with external strategic partners in the room, abstract it before putting it into Mirel.

Security by design

Controlled access. Separated work. Clear boundaries.

Mirel is designed as a controlled B2B environment, not as an open consumer tool.

AreaCurrent approach
AuthenticationAuthentication is handled through Supabase Auth. Mirel does not store user passwords in the frontend.
AuthorisationAccess is restricted through authenticated user accounts and access-control rules for users, sessions, organisations and client-related work.
Workspace separationClient and organisation workspaces are separated so users only see work they are authorised to access.
Backend logicWorkflow instructions, provider keys and model settings are handled server-side, not exposed in the browser.
Encryption in transitData transmitted between users, Mirel, infrastructure providers and AI providers is encrypted via HTTPS/TLS.
Encryption at restStored data benefits from provider-managed encryption standards within Supabase and related infrastructure.
Human accessHuman access to customer content is exceptional and limited to support, debugging, security, maintenance or user-requested assistance.

Mirel’s security controls evolve with the platform. The aim is to communicate current capabilities clearly rather than overstate maturity.

Data handling

Temporary work when possible. Persistent work when useful.

Mirel uses different data modes depending on how users work.

Temporary usage

In standard usage, session context is retained for a limited period, typically up to 72 hours, to support active work without turning every interaction into permanent memory.

Client Brains

Persistent project workspaces, called Client Brains, allow users to save and reuse strategic outputs across future workflows for the same client context.

Deletion

When a Client Brain or saved client context is cancelled or deactivated, associated data can be deleted through structured deletion workflows. A short recovery period may apply.

Operational logging

Operational logs may be retained for security, troubleshooting, monitoring and platform stability. Logging exists to operate the product, not to monetise customer content.

Data flow

How a Mirel interaction works.

Mirel keeps the architecture intentionally simple from the buyer’s perspective.

  1. User submits strategic inputA brief, question, challenge, audience context or campaign problem.
  2. Mirel authenticates and routes the requestSupabase Auth and backend logic control access and workflow execution.
  3. Relevant context is sent to the selected AI providerThe provider is assigned by Mirel admins per task or workflow based on model strengths.
  4. The strategic response is returnedThe output is shown to the user and may be saved temporarily or into a Client Brain.
  5. The user decides what becomes persistentTemporary outputs expire; saved client outputs become reusable project memory.

Responsible AI

Different strategic tasks need different model strengths.

Mirel does not use consumer chat accounts to process customer work. AI providers are accessed through commercial API offerings.

Mirel administrators assign the appropriate LLM to each task or workflow. This allows the system to benefit from different model strengths and adapt as models evolve, without exposing workflow instructions, provider keys or model configuration in the browser.

ProviderCurrent roleBuyer note
Google GeminiSelected strategic and general workflowsAccessed through commercial API usage.
OpenAISelected strategic and reasoning workflowsAccessed through commercial API usage.
Anthropic ClaudeSelected reasoning and strategy workflowsAccessed through commercial API usage.
PerplexityInternet-augmented research workflowsUsed where current web-informed research is part of the task.
No Mirel training
Mirel does not use customer prompts, outputs or saved work to train general-purpose models for other customers.
Provider terms
AI providers operate under their own commercial API terms, data-processing terms and retention policies. These should be reviewed by buyers where required.
Human responsibility
Mirel outputs are strategic working material. Important claims, legal statements, regulatory implications and public-facing outputs should be reviewed by qualified humans before use.

What Mirel is not

Clear boundaries reduce risk.

Not a customer database

Mirel is not designed to store raw CRM exports, customer-level records, claims data, employee files or operational archives.

Not a legal approval system

Mirel can support strategic thinking, but it does not replace legal, privacy, regulatory or brand approval processes.

Not an advertising tracker

Mirel does not operate advertising networks, behavioural ad tracking or data brokerage mechanisms inside the platform.

Not a decision-maker

Mirel supports decisions. Final responsibility for using, adapting, publishing or implementing outputs remains with the customer organisation.

Shared responsibility

We protect the system. You choose the input.

Responsible use of AI is not only a technical matter. It is also an input discipline.

Mirel is designed to minimise the need for risky data, but users still decide what information they enter. Customer organisations should define internal rules for what may be entered, what must be anonymised and what must stay outside the system entirely.

The practical rule

If the information is unnecessary for strategic reasoning, do not put it into Mirel. If the strategic meaning can be expressed through abstraction, use the abstraction.

Questions we hope you ask

The uncomfortable questions are usually the useful ones.

Can another agency or client see our work?

No. Mirel separates organisations, users, sessions, clients and saved work through authenticated access controls. Users only see work they are authorised to access.

Do you use our work to train Mirel?

No. Customer prompts, outputs and Client Brain content are not used by Mirel to train general-purpose models or create strategic shortcuts for other customers.

Can Mirel employees read everything?

No. Human access to customer content is not routine. It is limited to operationally necessary situations such as debugging, support, security, maintenance or assistance requested by the user.

Where is Mirel hosted?

Mirel uses Supabase as its core backend, authentication and persistence layer. The Supabase server used by Mirel is hosted in Frankfurt, Germany.

Which AI model processes our data?

Mirel administrators assign AI providers per task or workflow. Current and potential providers include Google Gemini, OpenAI, Anthropic Claude and Perplexity, accessed through commercial API offerings.

Should we upload full customer databases?

No. Mirel is not designed for raw customer databases. Most strategic work is better handled with anonymised, aggregated or abstracted context.

What happens to temporary outputs?

Temporary usage is designed around limited persistence, typically up to 72 hours. Outputs saved into a Client Brain persist so users can continue strategic work over time.

What is Mirel’s business model?

Mirel is subscription software. Mirel has no commercial incentive to collect more customer data than necessary to deliver the service. It does not operate an advertising, data brokerage or model-training business model.

Is Mirel suitable for banking or insurance work?

Mirel can support agency and marketing strategy work involving regulated clients, but it should not be used for raw regulated records, individual claims, customer files or sensitive case-level data unless appropriate client, legal and compliance approvals are in place.

Does Mirel guarantee AI outputs are correct?

No. AI systems can produce incomplete, outdated or contextually inappropriate outputs. Mirel outputs should be treated as strategic working material and reviewed before important use.

Security & privacy contact

Have a due-diligence question?

For security, privacy, procurement or compliance questions, contact Mirel UG (haftungsbeschränkt), Hamburg, Germany, through your Mirel representative or via johanna@usemirel.com.

Email Mirel