Legal
Privacy Policy
Last updated: July 11, 2026
This Privacy Policy explains how Miaru collects, uses, and shares your personal information across our websites, apps, and related services — and names the specific services we rely on, so there are no surprises.
1. General
At Miaru, we care about your personal information, so we have prepared this Privacy Policy to explain how we collect, use, and share it. This Privacy Policy applies to the Miaru websites (miaru.co and app.miaru.co), apps, and related services (together, the “Service”). By using the Service, you agree to the collection, use, and sharing of your personal information as described in this Privacy Policy.
Miaru is a young product that is improving quickly. Features described in this Privacy Policy may change, and we will update this policy as our practices evolve.
2. Information We Collect
a. Account Registration
To create a Miaru account you provide us with your email address. We sign you in with one-time codes sent to that email — Miaru does not use or store passwords, and we do not offer social logins or collect phone numbers. Your account is managed for us by Amazon Cognito, an authentication service operated by Amazon Web Services.
b. Profile & Learning Activity
After you register, you can set a display name and a username (handle), and answer optional onboarding questions such as what you want to learn, why you are learning, your interests, how you heard about Miaru, and your daily practice goal. As you learn, we record your progress: lessons started and completed, answers and scores, experience points (XP), streaks, and spaced-repetition review schedules.
Your display name, XP, and streak may be visible to other Miaru learners in features such as leaderboards. Your email address is never shown to other learners.
c. Payments
If you subscribe to a paid plan, checkout is handled by Stripe, our payment processor. Your card number and full payment details go directly to Stripe and never touch Miaru’s servers. We receive and store only what we need to run your subscription: your subscription status, plan and billing interval, and renewal date, together with a Stripe customer reference. Stripe’s handling of your data is described in Stripe’s own privacy policy at stripe.com/privacy.
d. Activity & Device Data
When you use the Service we automatically generate technical data such as your IP address, browser and device type, the pages you visit, and product events such as opening the app, viewing onboarding steps, completing lessons, clicking links from our marketing site into the app, and completing a purchase.
e. Cookies & Local Storage
We use cookies and browser storage to run the Service: browser local storage that keeps you signed in, remembers your language preference, and remembers your analytics choice; and — only if you allow analytics — Google Analytics cookies (for example “_ga”) to measure usage and an attribution cookie (“miaru_utm”, kept for up to 90 days) that remembers which campaign first and most recently brought you to Miaru. The attribution cookie stores only standard campaign parameters (such as utm_source) and is shared between miaru.co and app.miaru.co. Most browsers let you block or delete cookies; parts of the Service (such as staying signed in) may not work without them.
f. Analytics — Google & Amplitude (optional, with your consent)
We use two analytics providers to understand how Miaru is used and where learners get stuck: Google Analytics (loaded through Google Tag Manager) and Amplitude. Analytics are optional: nothing is loaded and no analytics data is collected until you choose “Allow analytics” in the consent banner, and declining does not change how the Service works. When you allow analytics, the providers receive the activity and device data described above tied to a pseudonymous identifier and, when you are signed in, to a random account identifier generated by Miaru — never your email address, name, or payment identifiers.
Amplitude also provides session replay, which records how a small sample of visits interact with our pages — clicks, scrolls, and page structure — so we can find and fix confusing screens. Replay is sampled (roughly 1 in 10 marketing-site visits and at most 1 in 20 app sessions), masks text conservatively, and blocks everything you type (inputs and other sensitive areas such as sign-in, profile, billing, and issue-report screens are excluded). Session replay does not capture your payment details (payment happens on Stripe’s pages, outside our app).
You can change your analytics choice at any time via “Analytics preferences” in the website footer or on your profile page in the app; declining stops all analytics collection immediately. You can additionally opt out of Google Analytics with Google’s browser add-on (tools.google.com/dlpage/gaoptout). We use analytics only to improve Miaru — we do not run third-party advertising on the Service and we do not sell your personal information.
3. How We Use Your Information
Miaru processes your personal information to provide products and services you request, to pursue our legitimate interest in improving the Service, to comply with legal obligations, and with your consent where required. In particular, we use your information to:
- Operate your account and sign you in with one-time email codes.
- Save and sync your learning progress, streaks, XP, and review schedules across devices.
- Personalize your experience, such as resuming where you left off and scheduling reviews of the characters and words you found hardest.
- Start, renew, and manage your subscription through Stripe.
- Send you transactional email, such as login codes and replies to issue reports you submit.
- Measure and improve the Service through the analytics described above.
- Keep the Service secure, prevent abuse, and comply with the law.
We may also create aggregated, de-identified, or otherwise anonymous information (for example, overall lesson completion rates) and use it for any purpose. Such information is not personal information.
4. How We Share Your Information
We do not sell your personal information, and we do not share it with advertising networks. We share personal information only with the service providers that run Miaru, and only for the purposes described in this policy:
- Amazon Web Services — hosting, storage, authentication (Amazon Cognito), and email delivery (Amazon SES) for login codes and notifications. Our infrastructure runs in the United States.
- Stripe — payment processing and subscription billing.
- Google — analytics via Google Analytics and Google Tag Manager.
- Amplitude — product analytics and session replay.
We may also share personal information if required by law or legal process, to protect the rights, property, or safety of Miaru, our users, or others, or as part of a merger, acquisition, or sale of assets — in which case this Privacy Policy will continue to apply to your information.
5. Your Data Subject Rights
In addition to any rights granted by the law that applies to you, you can always ask us to:
- Tell you what personal information we hold about you.
- Give you a copy of your personal information in a portable format.
- Correct inaccurate personal information.
- Delete your account and the personal information we have collected about you.
- Object to, or ask us to restrict, certain processing of your information.
- Withdraw consent you previously gave us.
To exercise any of these rights, email us at privacy@miaru.co from the address on your account. Account and data deletion is described step by step on our Data Deletion page at miaru.co/data-deletion. We may need to verify your identity before acting on a request, and we may decline requests where we have a legitimate reason, such as when the request would violate the law or the rights of another person. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority.
6. Data Retention
We keep your personal information for as long as your account exists. If you ask us to delete your account, we will delete or anonymize your personal information, except where we must keep it longer — for example billing records we are legally required to retain, information needed to resolve disputes or enforce agreements, or data needed to investigate misuse of the Service. We may retain anonymous data indefinitely.
7. Children
Miaru is not directed to children, and we do not knowingly collect personal information from children under 13 (or under the age of digital consent where you live, such as 16 in parts of the European Union). Miaru does not currently offer child accounts or parental controls. If you believe a child has created a Miaru account, please contact us at privacy@miaru.co and we will delete the account and its information.
8. Security
We protect your information with encryption in transit, one-time login codes instead of stored passwords, access controls on our infrastructure, and payment processing that keeps card details entirely with Stripe. No method of transmission or storage is completely secure, so we cannot guarantee absolute security — if we learn of a breach affecting your personal information, we will notify you as required by law.
9. Do Not Track
The Service does not currently respond to “Do Not Track” signals sent by some browsers. Analytics only run if you allow them in the consent banner, and the “Analytics preferences” controls described in Section 2(f) are the most reliable way to limit analytics collection.
10. Links to Third-Party Websites
The Service may link to websites we do not operate, and checkout takes place on pages operated by Stripe. We are not responsible for the content or privacy practices of third-party websites. Any information you submit to a third party is governed by that third party’s privacy policy.
11. International Data Transfer
Miaru is based in the United States and processes data on servers located in the United States, which may not provide the same level of data protection as your home jurisdiction. By using the Service, you understand that your information will be transferred to and processed in the United States as described in this Privacy Policy.
12. Privacy Policy Updates
We may update this Privacy Policy as our practices change. If the changes are material, we will post a notice on the website at least seven (7) days before they take effect, and we will always show the date this policy was last revised. Your continued use of the Service after changes take effect means you accept the updated policy.
13. Contact Us
Miaru, LLC is the data controller of your personal information for the purposes of the General Data Protection Regulation (GDPR) and equivalent local laws. Miaru’s headquarters are located in the United States at:
Miaru, LLC., Austin, TX 78735, United States of America.
For privacy inquiries, data subject requests, or any questions about this Privacy Policy, email us at privacy@miaru.co. For anything else, hello@miaru.co reaches us too.
