Privacy Policy
See what stays on your device, what may sync when you choose cloud sync, and how Mirsah handles account, billing, support, and Privacy Lock data.
Local data
Workspaces, bookmark titles and URLs, settings, sync preferences, optional Focus timer state, local link-open counters, and Privacy Lock configuration are stored in extension storage on your device. Custom image and video wallpaper files are stored locally in IndexedDB.
Privacy Lock and PIN data
If you enable the Pro Privacy Lock, the raw PIN is never stored or synced. Mirsah derives local verification data using PBKDF2 with SHA-256 and a random salt, and stores only that derived verification data plus local lock settings such as auto-lock preference and lock state. This data remains on the local Mirsah profile and is not included in cloud sync.
Account, trial eligibility, and cloud sync
An account is required to use the Mirsah workspace. Eligible verified accounts may receive one 30-day Pro trial. To prevent a new Firebase account from receiving another trial after deletion and recreation with the same verified email, Mirsah retains a server-side pseudonymous eligibility marker derived with SHA-256 from the normalized verified email. The marker record does not contain the raw email address or Firebase UID and is used only for trial eligibility and abuse prevention. It is retained after account deletion so the one-trial rule remains enforceable. For eligible Pro accounts, cloud sync is optional and may store supported workspace and setting copies in Firebase Firestore for synchronization and recovery. Custom wallpaper files, Focus timer state, local link-open counters, and Privacy Lock PIN verification data are not uploaded by cloud sync.
Authentication and optional bookmark import
Firebase Authentication handles email-and-password accounts and Google sign-in. Google sign-in uses OpenID, email, and basic profile scopes only. Mirsah does not access Gmail, Drive, contacts, calendars, or browsing history. The optional Chrome bookmarks permission is requested only when you choose to import bookmarks.
Payments
Lemon Squeezy handles payments, invoices, and subscription management. Mirsah does not receive or store card numbers. It stores subscription and entitlement information needed to unlock paid features and provide account management.
Contact and support requests
When you submit the contact form, Mirsah stores the name, email, request type, subject, message, optional extension version, language, ticket number, and processing status. This information is used to respond to and manage the request. Do not include passwords, PINs, card details, API keys, verification links, or unnecessary sensitive data.
Service providers and sharing
Data is processed only with providers needed for the disclosed features: Google OAuth and Firebase for authentication, hosting, optional sync, and support requests; and Lemon Squeezy for payments and subscriptions. Mirsah does not sell user data, use it for personalized advertising, or share it with data brokers.
Your controls and retention
You can export local backups, pause eligible Pro sync, change or remove a configured Privacy Lock PIN, sign out, and delete your account and cloud workspace data. Local device data remains until you remove it, reset Mirsah, or uninstall and clear extension data. The pseudonymous trial-eligibility marker is retained after account deletion to enforce the one-trial rule. De-identified billing/security records and support requests may also be retained only as reasonably needed for abuse prevention, accounting or legal duties, and support operations.
Chrome Web Store Limited Use
Mirsah’s use of information received from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Contact
Questions about privacy can be submitted through the contact form.