Skip to content

Miramiru is now live!-There are still many bugs and missing features. Feel free to send us your feedback and requests.Contact

EN/KO supported! AI-translated — feedback welcome on Discord.Discord

Privacy Policy

Note: This is an unofficial English translation provided for convenience. The Japanese version is the only legally binding version.

Effective date: March 29, 2026

Miramiru (hereinafter "the Service") values user privacy. This policy explains what information we collect and how we use it as clearly as possible. The Service does not display advertisements, and collected information is never used for ad delivery or sold to third parties.

1. Information We Collect

The Service collects the following information:

Account Information

  • Email registration: Email address (used for identity verification via authentication code)
  • Discord integration: Display name, avatar image, email address (minimal information obtained by the authentication platform; we do not access DMs)
  • X (Twitter) integration: Display name, avatar image (read-only permissions only; we do not post or perform any actions)
  • User-configured information: Username, display name, bio, profile image (all freely editable)

Character Information (Optional)

  • If you use Lodestone integration: character name, world, race, gender, title, and avatar image. These are used for profile display and contest participation.

Post Data

  • Glamour images, titles, descriptions, equipment information, tags, and comments

Usage Data

  • Interaction data such as likes, favorites, follows, and album saves
  • Post page view counts (used for view count aggregation)

Technical Information

  • IP address, browser information, access timestamps (used for preventing unauthorized access and rate limiting)

2. Purpose of Information Use

Collected information is used solely for the following purposes:

  • Providing and operating the Service (post display, search, notifications, albums, and other features)
  • User authentication and account management
  • Usage analysis for service improvement and new feature development
  • Prevention and detection of misuse (spam, impersonation, etc.)
  • Sending important notices and notifications (service-related only; no promotional emails)
  • Aggregation and publication of anonymized statistical data (e.g., popularity rankings by race or job)

3. Integration with External Services

The Service uses the following external services, and data may be processed in accordance with their respective privacy policies:

  • Supabase: Used as the foundation for user authentication, database, and image storage
  • Vercel: Used for hosting and access analytics (Vercel Analytics & Speed Insights)
  • XIVAPI: Used to retrieve equipment item information (no personal user data is transmitted)

Servers for these services may be located outside Japan (e.g., the United States), and data may be transferred internationally. We select services that meet appropriate security standards.

4. Cookies and Local Storage

The Service uses cookies and browser local storage for the following purposes:

  • Authentication cookies: Storing session information necessary to maintain login status
  • Local storage: Recording like status for users who are not logged in (stored only on the device and not sent to the server)
  • Analytics: Access analytics to understand usage patterns and improve the Service (Vercel Analytics)

You can disable cookies through your browser settings, but login functionality will become unavailable.

5. Disclosure of Information to Third Parties

Collected personal information is not, in principle, provided to third parties. However, exceptions include:

  • When user consent is obtained
  • When required by law
  • When necessary to protect a person's life, body, or property, and obtaining user consent is difficult
  • When delegating to the service providers listed in "3. Integration with External Services" above, within the scope necessary for operating the Service

Note that anonymized statistical data that cannot identify individuals (e.g., equipment popularity rankings) may be published within the Service.

6. Data Storage and Security

  • Communications are encrypted using SSL/TLS.
  • Email authentication uses an authentication code (OTP) method; no passwords are stored.
  • Uploaded images are stored in access-controlled cloud storage.
  • However, complete security cannot be guaranteed for communications over the internet.

7. Data Retention Period

  • Account information and post data are retained as long as the account exists.
  • Upon account deletion, associated personal data (profile, posts, comments, likes, etc.) is deleted.
  • Access logs are retained for the period necessary for investigating misuse (up to 90 days) and then automatically deleted.
  • Service-wide usage statistics (anonymized) are retained for service improvement.

8. Guest Posts

The Service allows posting glamours (guest posts) without account registration. Data handling for guest posts is as follows:

  • An anonymous account (guest account) is automatically created when making a guest post. No email address or personal information is associated with guest accounts.
  • Post editing is only possible while the browser session used to create the post is active. Editing becomes unavailable if browser data is cleared.
  • Post deletion is possible regardless of session status by using the "deletion key" issued at the time of posting. The deletion key is displayed only once immediately after posting and cannot be shown again.
  • If you register an account from a guest account, post data is transferred to the account. Transfer is only possible within the same browser session.
  • Data from guest accounts without posts may be automatically deleted after a certain period.
  • If you lose the deletion key and your browser session has also expired, you can request deletion via the contact form.

9. User Rights

Users have the following rights:

  • Review and change information: You can change your profile information and email address at any time from the settings page.
  • Delete your account: You can delete your account at any time from the settings page. Deletion also removes associated personal data.
  • Remove external integrations: You can disconnect external account integrations (Discord, X, etc.) at any time from the settings page.
  • Personal information requests: To request disclosure, correction, or cessation of use of personal information, please contact us via the contact form.

10. Use by Children

The Service is not intended for children under the age of 13. We do not intentionally collect personal information from children under 13. If we become aware that such information has been collected, we will promptly delete it.

11. Changes to This Policy

This policy may be updated in response to changes in laws or the Service. Significant changes will be announced within the Service. The updated policy takes effect upon publication on this page.

12. Contact Us

For questions or requests regarding privacy, please contact us via the contact form.