Trust
Security
This page is maintained by the MirrorMind team to describe the protections we have enabled. It reflects our current practices and is not an independent security certification.
Protecting your account
- Sign-in is handled by a managed authentication service — we never see or store your password in readable form.
- Passwords are hashed by that service, and sign-in with Google is available if you'd rather not manage another password.
- Each session uses a short-lived token that is refreshed automatically and cleared when you sign out.
- Signing out from Settings → Security ends the session on your device.
Password recommendations
- Use at least 12 characters, and prefer a memorable passphrase over a short complex string.
- Use a password you have never used on another site.
- Store it in a password manager rather than a note or your browser's autofill alone.
- Change it immediately from Settings → Account if you suspect anyone else has it.
- Never share your password with anyone — MirrorMind will never ask you for it.
Login activity
Sign in to see your most recent login. You'll also find this in your account under Settings → Security.
If a sign-in looks unfamiliar, change your password straight away and contact us.
Data encryption
- Every connection between your device and MirrorMind is encrypted in transit with HTTPS/TLS.
- Data stored in our managed database and file storage is encrypted at rest by our hosting provider.
- Profile photos are kept in a private bucket and served only through short-lived signed links created for your account.
We describe the controls that are enabled rather than making absolute guarantees — no online service can promise perfect security.
How your data is separated
Every table that holds your information uses row-level security rules tied to your account identifier. In practice this means a request made with your session can only ever read or change your own profile, assessments, reports and preferences.
Reporting a problem
If you believe you've found a security issue, please email security@mirrormind.app with the details before sharing it publicly. We read every report and will respond as quickly as we can.