Your inner world is sacred. This policy explains exactly what we collect, what leaves your device and where it goes, and what we will never do with it. It uses the same defined terms as the Terms & Conditions and the Refund & Returns Policy.
Who We Are
White Mirror Labs is a technology company. We build AI-enabled tools for human wellbeing, designed around simplicity and minimalism — which is also how we approach data: we collect what the product actually needs, and nothing because it might be useful later.
White Mirror Labs is the controller of your personal data. We are established in the Arab Republic of Egypt at 128 Degla Gardens, October Gardens, Giza, Egypt, and we handle personal data under Egyptian law, including the Personal Data Protection Law.
For anything in this policy, write to hello@whitemirrorlabs.com.
Scope & Terms Used
This policy covers the Site, the App and the sale of the Journal. The definitions are the ones set out in section 02 of the Terms; the ones that matter most here are:
What We Collect
Almost nothing. The Site sets no cookies, runs no analytics and carries no advertising or social trackers. Our hosting provider keeps standard server logs, which include your IP address and the page requested, for security and reliability.
When you order the Journal- Your name, email address and phone number
- Your delivery address: street, city and governorate
- The order itself — product, quantity, amount, payment status, and delivery status once it ships
We never receive your card number. Payment happens on XPay's hosted checkout; we are told only whether it succeeded.
When you use the App- Account details: email address, and a password or a sign-in via Apple or Google
- Profile details you enter: name, phone, delivery address for a future order, and your onboarding answers
- Your Entries, and the mood recorded with them
- Your practice history: meditation sessions, streaks and progress through the 90 days
- Whether you rated an Insight useful, so the next one lands better
- If you use the social features, the connections you make and the groups you join
The App can read sleep, steps, active energy, heart rate and mindfulness minutes from Apple Health or Health Connect. This is off unless you grant permission, and you can withdraw it at any time in your phone's settings. Section 06 explains the strict limit on what any of it can do.
When you contact us- Whatever you write to us, and the address you write from
- Waitlist submissions: your name, email and, if you give it, your phone number
What We Do Not Do
These are commitments, not aspirations. If any of them changes, we will say so before it does.
- We do not sell, rent or trade your personal data — ever, to anyone
- We do not use your Entries to train machine learning models, our own or anyone else's
- We do not use your Entries for advertising, targeting or profiling
- We do not run advertising or marketing trackers on the Site
- We do not store your card details
- We do not read your Entries to improve the product; we read the numbers, not the writing
How Your Entries Are Protected
Your Entries are encrypted before they are stored. Each account has its own data key, which is itself held encrypted under a master secret kept in a separate secure store. A copy of the database on its own does not reveal anyone's writing.
The practical limit of this, stated plainly: the key is escrowed on our side rather than held only on your device, so this is strong protection against a database leak — it is not end-to-end encryption, and we could be compelled by a lawful order to produce data. Section 06 describes the one routine case in which entry text leaves our systems.
AI Features: What Leaves Your Device
Three features in the App send data to an AI provider. Each one runs only when you ask for it.
Health data is treated far more narrowly. Exact figures never leave your phone. Heart rate variability, resting heart rate and active energy are never sent anywhere. What can accompany an Insight request is a coarse band and nothing else — for example "sleep: short, activity: typical" — used only to keep the tone of the reflection honest on an unusual week. The model is instructed never to quote, discuss or give advice about it.
These features are optional. Not using them means nothing is sent.
How We Use Your Information
- To take your order, deliver the Journal, and handle returns and refunds
- To create and run your account, and to unlock it when you redeem a Serial
- To store your Entries and show them back to you
- To produce an Insight, transcribe a scanned page, or generate a meditation when you ask for one
- To send you order confirmations, delivery updates and account notices
- To send you marketing email only if you have opted in, with an unsubscribe link every time
- To answer your questions and support requests
- To keep the Services secure and to investigate fraud or abuse
- To meet our legal, tax and accounting obligations in Egypt
Our Legal Basis
Where the GDPR applies to you as well, these are the Article 6 bases we rely on, and health data is processed only on your explicit consent.
Who Else Sees Your Data
We do not sell your data. These are the processors we rely on to operate, and precisely what each receives:
International Transfers
Our providers operate outside Egypt, so your data is processed abroad — chiefly in the European Union and the United States. Every provider in section 09 is bound by a data processing agreement, and where a transfer leaves the EEA we rely on Standard Contractual Clauses. Where Egyptian law requires an approval or licence for a cross-border transfer, we obtain it before relying on the transfer.
Cookies & Similar Technologies
The Site sets no cookies. There is no analytics cookie, no advertising cookie and no consent banner, because there is nothing to consent to.
The App stores a sign-in token and your local preferences on your own device so you are not signed out between visits. This is strictly necessary to keep you logged in, and clearing the App's data or signing out removes it.
How Long We Keep It
- Your Entries and profile: for as long as your account exists. Deleting your account deletes them.
- Order and payment records: 5 years from the transaction, to meet Egyptian commercial and tax record-keeping requirements. These survive account deletion because the law requires it.
- Support email: 2 years from the last message in the thread.
- Marketing preferences: kept indefinitely, so that an opt-out stays honoured.
- Server and security logs: up to 12 months.
- Data sent to an AI provider: retained by that provider under its own policy for abuse monitoring, then deleted. It is not retained by us beyond the result shown to you.
When a period ends, we delete the data or irreversibly anonymise it.
Your Rights
Under the Egyptian Personal Data Protection Law — and under the GDPR where it applies to you — you have the right to:
Write to hello@whitemirrorlabs.com. We acknowledge within 5 business days and answer within 30 days. Exercising a right is free, and we will not treat you differently for it.
Deleting Your Account
You can delete your account from within the App, without asking us. Deletion removes your Entries, your profile and your social connections. It does not remove order records we are required to keep, and it does not un-redeem a Serial — a Serial is spent once and cannot be reused on a new account.
Children's Privacy
The Services are for people aged 16 and over. We do not knowingly collect data from anyone younger. If you believe a child has given us their data, write to hello@whitemirrorlabs.com and we will delete it promptly.
Security
Your Entries are encrypted at rest as described in section 05. Data in transit is encrypted with TLS. Access to production data is restricted, and database access rules are enforced per account so one person cannot reach another's records. Payment card data never touches our systems.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authority as the law requires. If you suspect your account has been accessed, contact us at once.
Changes to This Policy
We will update the "Last updated" date above whenever this policy changes. For a material change — particularly a new processor receiving your Entries, or a new use of your data — we will email account holders before it takes effect, and where the change relies on consent we will ask for it rather than assume it.
Contact Us
Any question about your data, or any request to exercise a right, goes to one address.
White Mirror Labs
128 Degla Gardens, October Gardens
Giza, Egypt
Email: hello@whitemirrorlabs.com
We reply to privacy requests within 5 business days.
This Privacy Policy was written to be read — not just to comply.
If any part of it is unclear, please reach out. Your trust is the foundation of everything we build.