Legal · Data Protection
Privacy Policy
Last updated: 10 September 2026
Mirai Talent Inc., a Delaware corporation (File Number 10680377) with its registered office at 2810 North Church Street, Wilmington, DE 19802, USA, trading as Mirai (“Mirai,” “we,” “us”), provides an AI licensing platform at mirai.inc and miraitalent.ai (the “Platform”). This Privacy Policy explains what information we collect, why we collect it, with whom we share it, how long we keep it, and the rights you have over it. It is written to comply with the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA).
1. What We Collect
- Account data. Full name, email address, password hash, role (brand, model, or admin), and, for brands, company name.
- Model application & profile data. Date of birth, gender, location, social handle (e.g. Instagram), height and size, model categories, agency representation and territories, and the category restrictions (exclusions) you set.
- Talent photographs. Photos you upload during application and portfolio updates. Depending on the processing performed and the applicable jurisdiction, these may constitute biometric or otherwise sensitive data; Mirai applies heightened safeguards to all likeness materials.
- Voice & movement recordings. Your optional voice intro and movement clips, a text transcript of the intro, and, only where you separately consent, a voice model derived from that recording.
- Model profile & character data. Your public roster profile, and an internal character profile generated from your reference kit to keep generations of you consistent.
- Generated imagery. AI-generated images, the prompts used to create them, approval decisions, and licensing metadata.
- Brand content. Product images, reference images, and brand-kit materials that brands upload to brief and generate campaigns.
- Licence records. For each licence, the asset, brand, model, fee, model payout, format, territory, start and end dates, exclusivity, and any restrictions.
- API data. For accounts using the API, API keys (stored only as a hash) and request and usage logs.
- Payment data. Billing address and a tokenised reference to your card or bank account. Card numbers, bank accounts, and verification details are handled directly by Stripe; we do not store them.
- Communication data. Emails you send us, chat-message content, and, with consent, call recordings from support interactions.
- Analytics events. Page views, button clicks, session duration, device type, and IP address. Used to diagnose issues and improve the product.
- Cookies and preferences. Essential cookies for authentication and session state, and an optional first-party analytics identifier after you accept analytics. We do not use advertising or cross-site tracking cookies. See the cookie notice below for more detail.
2. Why We Collect It
- Service provision. To create and run your account, create your AI likeness from your reference kit, generate images, process approvals, and deliver licences.
- Payments. To bill brands, calculate payouts, and transfer funds to talent.
- Communication. To send transactional email (applications, approvals, payouts, security alerts) and, with opt-in consent, product updates.
- Safety. To enforce our Terms and Acceptable Use Policy, detect fraud and abuse, and respond to legal process.
- Product improvement. To debug, understand usage patterns, and roll out improvements.
2a. What We Never Do With Your Likeness
Talent photographs and likenesses are used exclusively for AI image generation and platform operation as described in Section 2. We explicitly do not, and will not, use Talent likeness data for:
- Facial recognition or biometric identification. We do not use reference photographs to identify, match, track, or authenticate individuals against other images, databases, or identity systems.
- Surveillance or monitoring. We do not use likeness data to monitor, profile, or track any individual’s movements, behaviour, or activity, online or offline.
- Identity verification or authentication. Mirai is not an identity-verification platform. We do not supply likeness data to KYC, AML, border control, or any law-enforcement system.
- Foundation model training. Mirai does not contribute reference photographs to general-purpose AI training datasets and does not use them to fine-tune or train foundation models. Mirai uses AI provider APIs under terms that state customer inputs are not used to train general models, subject to each provider's documented retention, safety and legal-obligation practices.
3. Legal Bases (GDPR)
- Contract. To provide the Platform you signed up for.
- Consent. For processing of biometric photographs, the creation of your personal AI likeness, and marketing emails.
- Legitimate interest. For fraud prevention, security, analytics, and improving the product, balanced against your rights.
- Legal obligation. Tax, accounting, anti-money laundering, and rights-enforcement obligations.
4. Who We Share It With
We do not sell your personal information and we do not share it for cross-contextual behavioural advertising (within the meaning of the CCPA). We share data with a small set of vendors strictly as needed to operate the Platform. The applicable provider agreements and processing roles depend on the service. For a processor engagement, request the current provider list, processing locations and executed data-protection terms before sending covered data.
- Stripe (United States). Payment processing, Connect payouts, subscription management, fraud screening.
- Supabase (Japan / Tokyo region). Database hosting, authentication and file storage for application uploads. Regional database hosting does not mean all support access or onward processing stays in that region.
- Cloudinary (United States). Image storage, transformation, watermarking, and delivery.
- fal.ai (United States). Image generation routing layer. Your reference photographs and the resulting generated images pass through fal.ai at the moment of each generation. Generation delivery and retention depend on the selected endpoint and provider terms. Mirai does not authorize general-model training on talent references through this workflow.
- Resend (United States). Transactional email delivery.
- OpenAI (United States). Operator of GPT-Image-2, the primary image generation model, and OpenAI vision models used to classify reference photos and select a compact identity reference set when your portfolio changes. Reference photographs are transmitted directly to OpenAI for that selection and via fal.ai at generation time. Mirai disables response storage for reference selection. OpenAI’s API policy states it does not train on API inputs.
- Google (United States). Operator of Nano Banana 2, used as a fallback image generation model. Also provides Google OAuth sign-in where you choose to use it. Google’s API policy states they do not train on API inputs.
- Anthropic (United States). Operator of Claude, used to enhance brand-typed prompts into production photography briefs and to classify brand-uploaded reference images. Brand prompts and, where classification runs, the uploaded reference image are sent to Anthropic. Anthropic’s API policy states they do not train on API inputs.
- ByteDance (China). Operator of the Seedream image edit and Seedance video engines, reached via fal.ai at generation time. Reference photographs may be transmitted for the requested generation. Processing must remain within the applicable consent and renderer requirements; this policy does not promise zero retention by every endpoint.
- Kuaishou (China). Operator of the Kling video engine, reached via fal.ai for face-reveal video renders. The start frame and a reference photograph may be transmitted for that render, subject to applicable consent and provider processing terms.
- MiniMax (China). Operator of the Hailuo video engine, reached via fal.ai for film renders from a composed start frame, subject to applicable consent and provider processing terms.
- Black Forest Labs (Germany). Operator of the FLUX.2 [pro] Edit engine where enabled for a permitted workflow. The canonical-kit generation chain does not use this engine. Any processing must meet the applicable consent and provider terms.
- Railway (application hosting). Runs the Mirai application and processes operational logs and metrics.
- Sentry. Error monitoring and technical diagnostics, which may include request context and account identifiers. Do not include sensitive personal information in free-text error reports.
- Upstash. Rate limiting and abuse prevention using request or account identifiers.
We may also disclose information if required by a court order, lawful governmental request, or to protect the safety of users or the public.
5. Data Transfers
Your data may be processed in the United States, the European Union, and other regions where our vendors operate. Restricted transfers require an applicable lawful mechanism, such as an adequacy decision or executed contractual safeguards, and any necessary assessment. A provider’s location alone does not establish that mechanism. Contact legal@mirai.inc for the documentation relevant to your workflow; a processor engagement must agree its transfer arrangements before processing begins.
6. How Long We Keep It
- Consent, approval and licence records. Retained for the longer of the applicable licence term, seven years after its expiry or termination, and any period reasonably required for an active claim, legal hold, regulatory requirement or limitation period. Records are then deleted or irreversibly minimised.
- Reference photographs. Kept while your account is active. Deleted within thirty (30) days of account closure or a withdrawal of consent, subject to legal holds. Mirai does not store derivative AI model weights of your likeness, reference photographs are passed to third-party generators at each generation moment, not used for training.
- Generated images. Delivered images kept while the associated licence is active. Undelivered drafts deleted with your account.
- Analytics events. Retained for up to fourteen (14) months and then aggregated or deleted.
- Payment records. Retained for seven (7) years to meet tax and accounting obligations.
7. Your Rights
Subject to the laws of your jurisdiction, you have the following rights:
- Access. Receive a copy of the personal data we hold about you.
- Rectification. Correct inaccurate or incomplete data.
- Deletion. Ask us to delete your account, your reference photographs, and your generated images.
- Portability. Export your data in a machine-readable format.
- Restriction and objection. Ask us to stop or limit specific processing, including direct marketing.
- Withdraw consent. Withdraw consent for processing that is based on consent, without affecting the lawfulness of past processing.
- Non-discrimination. We will not penalise you for exercising your CCPA rights.
- Lodge a complaint. With your local data protection authority, for example the UK ICO, the Irish DPC, or the California Privacy Protection Agency.
8. Data Subject Access Requests
To exercise any of the rights above, email legal@mirai.inc from the address associated with your Mirai account. Include the nature of your request. We will verify your identity, typically by asking you to confirm account details or a recent transaction, and respond within thirty (30) days. For complex requests we may extend this by up to sixty (60) days, notifying you in advance.
9. Children
The Platform is not intended for anyone under the age of eighteen. We do not knowingly collect personal information from minors. If you believe a minor has submitted information, email legal@mirai.inc and we will promptly delete the data.
10. Security
We use encryption in transit (TLS 1.2 or higher), encryption at rest for files and databases, role-based access control, least-privilege service accounts, webhook signature verification, and continuous monitoring. No system is perfectly secure. If we learn of a breach affecting your data we will notify you and the relevant authorities within the time frames required by law.
12. Changes
Material changes to this Privacy Policy will be notified by email and by an in-product banner at least thirty (30) days before they take effect, except where immediate changes are required to comply with law.
Contact
Privacy enquiries: legal@mirai.inc
General enquiries: info@mirai.inc
Mirai Talent Inc. (trading as Mirai)
Delaware File Number 10680377
2810 North Church Street
Wilmington, DE 19802, USA
Data controller for the purposes of UK GDPR, EU GDPR, and California CCPA/CPRA.