miracle.fyi Start →

Privacy Policy

The short version: we collect only what the product needs to work: account information; the text, images, documents, audio, messages, and settings you submit; guest checklist snapshots and progress you intentionally share; the community profile and automatic activity created under the defaults below; limited technical records; and Stripe or App Store membership payment records. Apple processes native iPhone membership payments. Miracle receives only bounded verified purchase history and entitlement facts, not your Apple payment method. Anyone with a private guest checklist link can view and complete its shared items, so treat the link like a secret. The fixed Right Now Habit, its current answer, the active daily completion date, and its dated completion snapshots are private and create no Community post. Other automatic activity can include a controlled non-Right-Now habit or pact completion, journal-session count, or structured exercise progress under your named community profile, but not journal writing or private habit and pact details in the published card. We use OpenAI and Anthropic only for the specific web, consented native Voice To-Do and document, connected-capture, North Star, and automatic numeric exercise-classification features described below. Native iPhone Voice To-Do keeps recording and Apple speech recognition on-device; after you review the disclosure and turn on native AI processing, it sends only the finished transcript to Anthropic, never voice audio. Existing native AI permissions must be reviewed again before this transcript-only use can run. Selected-photo capture is not sent to either AI provider. When you explicitly choose a native PDF or one-page camera scan after allowing AI processing, only that selected document is sent. Deliberate Feed posts and replies are never sent to AI. Only strictly necessary first-party cookies. No ad trackers, no analytics scripts, no selling data, and no opting your content into AI model training.

1. Who we are

miracle.fyi is operated by Highway 86 LLC, a Delaware limited liability company. This policy covers the miracle.fyi website, app, Chrome extension, API, MCP server, and messaging integrations. Privacy questions: claycollins@gmail.com.

2. What we collect

  • Account information. When you sign in, our authentication provider (WorkOS) gives us your email address and name and may provide the profile-picture URL supplied by your sign-in provider. That's the account.
  • Complimentary account access. When a Miracle super administrator invites someone to receive access at no charge, we store the normalized recipient email, inviting administrator, seven-day expiration, fixed delivery template, delivery state and attempt times, bounded delivery error code, Resend message and idempotency identifiers, and later acceptance or revocation account identifiers and times. The invitation is single-use and only a WorkOS identity with the verified exact invited email can accept it. The raw capability appears in the email URL fragment and, after opening, only in a short-lived invitation cookie or the installed iPhone app's in-memory sign-in handoff; it is never stored in PostgreSQL, and Miracle stores only its SHA-256 hash. The browser exchanges the capability through an exact-origin request, or the installed iPhone app submits it with its PKCE-bound native sign-in exchange. The fragment is omitted from the initial page request and ordinary URL access logs. A super administrator can instead directly create an active complimentary account by supplying an email address and password and asserting that the address belongs to the intended person. WorkOS receives the email and password and creates the verified sign-in identity. Miracle never stores the password. We retain a password-free provision receipt containing the normalized email, WorkOS identity and deterministic external identifiers, creating administrator, onboarding choice, optional account-ready-email choice and delivery state, and grant or revocation times. If the optional account-ready email is selected, it includes the email address and sign-in link but never the password.
  • The content you create. Goals, including the current Right Now answer, its active account-local completion-instance date, and its private dated completion snapshots, journal entries, mantras, North Star text and builder answers, to-dos and notes, pact check-ins, Vision images, screenshots and files attached to tasks, vocabulary, and settings. This is the heart of the Service and it exists so you can use it, not so we can mine it.
  • Google Photos Picker. Miracle requests Google Photos access only after you choose Google Photos in an image picker. Google shows its own picker. Miracle cannot browse your Google Photos library and receives only the one photo you select. Miracle validates and resizes that photo, then stores one private, normalized, display-ready copy as product content. Miracle does not sell the selected photo, use it for advertising, or use it to train generalized AI models. Temporary Google access and refresh credentials are encrypted while the picker is active and removed after the import completes, you cancel it, or the flow expires. The saved copy then follows the Screenshots and images retention rule below. Miracle uses Google Photos data only to provide this import and follows the Google API Services User Data Policy, including its Limited Use requirements.
  • Guest checklist assignments. When you share a task checklist, we store a separate snapshot of the title and checklist item text, the assignee label you enter or the default Guest label, each item's starting and current completion state, completion attribution supplied through the link, activity times, revocation state, and assignment completion state. Miracle's server stores no raw capability token. The token is returned in the private link fragment, which the browser omits from the initial page request and ordinary URL access logs. The guest page keeps it in assignment-scoped session storage for that browser tab so a reload still works. When someone uses the assignment, the guest page sends the token only in an authorization header to authorize that assignment request; Miracle keeps it out of paths, query strings, request bodies, database rows, application logs, and account exports. The database keeps only a non-secret rotation version used with the server's private pepper to validate the link.
  • Pact Community information. Miracle creates an active community profile for each account. Miracle creates one fixed private Right Now Habit without requiring Annual, Month, Week, or Today planning. It does not activate official One Thing membership, and there is no Pact or Habit choice. By default, the public display name is the sign-in first name and last initial, the handle is a unique generated value, and the avatar is the provider profile picture when WorkOS supplies an approved Google or WorkOS-hosted image URL or generated initials otherwise. The stored provider image URL can refresh when you sign in after the source picture changes. Public pages for group pacts you own reuse the active Community display name, handle, and current avatar. The group commitment and description are public as the page's headline and story. A public pact share page can also show anonymous activity type, time, reply count, and Cheer count. It never shows a member name, avatar, handle, post text, reply text, or source record in that anonymous preview. Miracle does not collect separate pact marketing, identity, photo-upload, or arbitrary pact-photo URL fields. Legacy pact marketing copy saved before this change may remain stored and appear under a legacy label in your account export until account deletion, but current product and public pages do not use it. We store the handle, display name, generated avatar seed, optional provider image URL, automatic-sharing and audience choices, Community Guidelines acknowledgement records if provided, and moderation status. Right Now stores the fixed current Habit state, the active completion instance's account-local date, and a private answer and kind snapshot for each completed action, dated in the saved account time zone. The current answer carries across local dates until it is explicitly changed or cleared, while each new date resets only completion. New snapshots say Habit; an earlier Pact kind snapshot remains historical and is not rewritten. Choosing a new #1 after completion preserves the previous action's exact receipt and proof source in private read-only history. Only the current action's completion can be undone on the same account-local day. The Goal Grid Archive shows up to 365 daily receipts and 365 earlier same-day actions as read-only entries. The account export includes the complete history. Right Now creates no new Community activity. Earlier fixed Right Now posts can remain until their ordinary retention or deletion rule applies. Automatic community activity can still store fixed non-Right-Now practice completions, fixed journal-session counts, and structured exercise amounts, types or units, and daily targets. We do not ask for or store a separate date of birth for community access because the Service is limited to adults under the Terms. Community use can add deliberate manual posts and replies. Miracle applies reject-only validation, stores accepted text exactly as submitted, rejects disallowed text instead of rewriting it, and never sends manual Feed text to AI. Community use can also add Cheers, follows, blocks, reports, notifications, and short-lived rate-limit records. Your email address and full last name are not displayed by default, and you may change the public community name and handle.
  • Membership payment and consent records. If you start a web membership trial, Stripe processes your card. We store membership status, Stripe customer and subscription references, renewal dates, card brand and last four digits, charge attempts, receipts, refunds, disputes, and delivery status for required membership messages. We never store your full card number, which stays with Stripe. If you buy a membership in the native iPhone app, Apple processes the payment. Miracle sends Apple a stable random account token that links the purchase to your signed-in Miracle account without containing your name or email. Miracle receives the signed StoreKit transaction from the app and signed subscription notifications from Apple for verification, but does not retain those signed payloads. We store only one-way payload hashes and bounded verified facts: product, transaction and original-transaction identifiers, production or sandbox environment, purchase and expiration dates, revocation and offer facts, ownership type, current entitlement and grace-period state, and verification times. We never receive or store your Apple payment method.
  • Messages and attachments you send to connected capture services. If you connect Telegram, WhatsApp, Slack, Discord, or iMessage to Miracle, we receive the messages, voice clips, and screenshots you intentionally send, plus the account, channel, conversation, event, or phone identifier the service attaches. Sendblue carries the iMessage connection. We do not read unrelated conversations. When a connected-chat capture needs your choice, Miracle keeps an expiring routing draft containing the normalized message or transcript, the paired sender and conversation, constrained classifier result, prompt state, account-local date fixed when the message arrived, and resulting to-do or note identifier if saved. Telegram and Discord can display native buttons. WhatsApp, Slack, and iMessage receive numbered choices.
  • Chrome extension captures. Miracle Capture sends data only after you choose a capture action. Browser tab and Area of browser tab send the screenshot and the source page URL. Screen or app window opens Chrome's own source picker, takes one still frame from the source you select, immediately stops the stream, and sends that frame with no page URL. Area of screen asks Chrome for one monitor, hides Miracle's controller, copies one still locally, stops the stream, restores the controller, and lets you select a rectangle. Nothing uploads until you click Send selected area. Only the selected pixels are encoded and sent with no page URL; the full still remains in memory on your device and is cleared when it is no longer needed. If you separately enable the optional Gmail integration, Chrome grants the extension persistent host access on mail.google.com so its message-level controls remain available while you navigate Gmail. Before a capture click, the extension checks only whether the active tab is on the Gmail origin and reads no message fields. It reads and sends only the exact expanded message whose Miracle button or popup Send this email button you click, including its subject, sender, recipients, displayed sent time, plain-text body, stable message hint, and Gmail permalink. Miracle Capture does not scan your inbox, read collapsed messages, capture in the background, or send a page, screen, or message before an explicit click. The selected list destination is a separate setting and is never inferred from screenshot or email content.
  • Chrome extension credentials and settings. The extension stores your default destination and limited account label in its local extension storage. It stores a short-lived OAuth access token in session storage and a rotating refresh token in local extension storage restricted to trusted extension contexts. Gmail and page-selection scripts never receive either token. Disconnect confirms that Miracle revoked the complete token family before removing local credentials. If confirmation fails, the extension keeps the connection active and offers retry instead of falsely claiming that sign-out succeeded. Anyone with access to your unlocked Chrome profile may still be able to operate installed extensions, so protect the device and Chrome profile.
  • Chrome Web Store Limited Use. Miracle Capture's use of information received from Chrome and Gmail complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide or improve the extension's single disclosed purpose, related security and reliability, or as otherwise permitted by those requirements.
  • Voice recordings, transcripts, and vocabulary. Server-backed web and connected-service voice capture processes the audio you submit. Voice-to-do capture on those surfaces can also use your saved preferred spellings as recognition context. Miracle does not retain the audio as product storage. Duration checks and format conversion can stage it in a private temporary file that is deleted after processing; otherwise it remains in request memory only. A server-backed voice-to-do transcript and organized draft stop accepting review or save actions at a fixed deadline no later than 24 hours after intake, then remain inactive until scheduled cleanup deletes the row. A Telegram, WhatsApp, Slack, Discord, or iMessage transcript can likewise remain in an inactive routing row after its action deadline while awaiting scheduled cleanup. The final reviewed or routed to-do or note is saved as product content. In the web North Star room, ordinary browser speech recognition can also paint live words while you speak. The browser or its speech-service provider may process that audio remotely under its own terms. Miracle does not receive, save, or log the helper transcript, and it cannot validate or save a repetition; the separately recorded clip sent through Miracle to OpenAI remains authoritative. In the native iPhone app, voice-to-do recognition stays on-device: Voice To-Do recording, Apple speech recognition, and preferred terms stay on the iPhone. When you turn on current native AI processing and stop a recording, Miracle sends only the finished transcript to Anthropic to prepare an editable title, checklist, due date, and notes; it does not send that voice audio to Miracle, OpenAI, or Anthropic. This transcript-only use requires a fresh current permission rather than an older native AI grant. If AI processing is off, the transcript stays on the iPhone until you review task fields and choose to add them. Native North Star recitation prefers on-device Apple recognition but may use Apple's network speech service when on-device recognition is unavailable; Apple can then receive the recitation audio and contextual terms under Apple's terms. Native North Star recognition does not use Miracle's server recorder, OpenAI, or Anthropic. Only the task fields or canonical journal text you review and save are sent to Miracle as product content.
  • PDF source documents. On the web, when you choose a PDF through task capture, Miracle validates the real file, records its filename, byte and page counts, and stores an application-encrypted copy in private object storage. Anthropic processes the complete PDF to propose editable tasks and a bounded private search index. Nothing becomes a to-do until you approve it. In the native iPhone app, both document actions are available only after you explicitly allow native AI processing. Choose PDF from Files uploads only the PDF you select. Scan one page with camera converts only that chosen page into a one-page PDF. Miracle validates and stores the selected source in encrypted private document storage and sends it to Anthropic for editable task proposals and a bounded private search index. Nothing becomes a to-do until you approve it.
  • Forwarded-email attachments. When you deliberately forward an email to your Miracle inbox, Miracle receives every user-visible attachment contained in that signed message. It excludes inline signature graphics and other related body resources unless they are explicit attachments. Miracle records bounded filename, type, size, order, processing status, and page count where applicable, then application-encrypts each accepted file in private object storage and attaches it to the resulting task. Safely readable PDFs, validated raster images, and bounded text-family files are sent to Anthropic with the subject, body, and your forwarding note to identify the requested action and relevant facts. Unsupported, corrupt, encrypted, archived, executable, macro-enabled, SVG, and other opaque files remain private forced downloads but are not sent to Anthropic, executed, unpacked, or rendered inline. The Gmail feature in Miracle Capture does not import Gmail attachments.
  • Email capture receipts. After a forwarded email creates a task, Miracle sends an automatic acknowledgement to the authenticated sender in the same email thread. The acknowledgement contains the final task title, list, checklist items, due date if one was created, and a link to that exact task. If the sender did not name a list, it can also contain confirmation links for the lists where the task can actually appear. Those links expire after 31 days. The raw confirmation capability appears in the delivered email and the temporary delivery snapshot, while Miracle stores only its SHA-256 digest in the action table. Automated scanners, previews, and the initial HTTP request are read-only. For a signed-in member, selecting the email link confirms and applies that exact list choice. A signed-out member first sees the exact change and must confirm it in Miracle. Miracle stores a fixed delivery snapshot while the acknowledgement is pending or retrying, then removes the address, raw confirmation links, and message content from that delivery row as soon as Resend accepts it or delivery permanently stops.
  • AI-derived content. When you choose an AI-assisted feature, or when an eligible numeric goal reaches the automatic exercise classifier described below, we receive and save the useful result, such as a screenshot transcription, a structured title and checklist, a cleaned capture, a constrained connected-channel content type and confidence, a General Note title, a North Star sentence or field, or a validated exercise decision and neutral labels. A long typed to-do submitted for organization, including its full source text and organized preview, remains actionable for no more than 24 hours; its inactive preview row is removed by scheduled cleanup afterward. It does not become a to-do until you approve it. A connected-channel classifier can return only To-do, today's Daily Note, or General Note. Only deterministic wording authored by you can choose In Progress, Today, Priority, or Inbox; otherwise Miracle asks where to put a To-do. Unknown, malformed, or uncertain content-type results likewise ask you rather than silently choosing. Captured content is untrusted data and cannot make Miracle execute instructions, invoke tools, fetch URLs, send arbitrary messages, change account settings, or widen Notes access. The provider inputs and the different retention rules are detailed below.
  • Automatic sync recovery copies. If two devices change the same field before they have synchronized, Miracle applies the changes in server order and briefly keeps the displaced prior value so an overwritten edit can be recovered. The copy contains only the affected field value and limited operational metadata needed to identify the account, target, and change.
  • Device recovery drafts. If an older whole-account sync candidate or a locally invalid target cannot be replayed safely, Miracle can quarantine that exact unsent draft in this browser's IndexedDB instead of sending it or blocking later changes. Eligible drafts remain copyable from Sync recovery for up to 30 days. Drafts that cannot be tied to the current immutable account stay hidden and are never replayed.
  • Browser reminder subscriptions. If you turn on browser alerts for task reminders and generic guest-checklist completion notices, we store a private per-device push endpoint, the public encryption key and authentication secret issued by that browser, a random installation identifier, limited browser information, and delivery status. Scheduled task reminders also use job records needed to retry or deduplicate their delivery. Guest-checklist notices are best-effort and do not include the shared task title, checklist item text, assignee label, or share link. We do not create a browser push subscription or request notification permission on page load.
  • Technical basics. Standard server logs (IP address, request path, timestamp) kept briefly for security and debugging; one first-party session cookie that keeps you signed in; and strictly necessary, short-lived first-party cookies for an invitation exchange, temporary onboarding test account, administrative support view, or contact-form spam prevention when one of those features is active. The contact-form cookie contains a random value, not your identity, and expires after two hours. We retain submitted contact messages, including messages flagged as possible spam, but may suppress notifications for suspicious or repeated submissions.

3. What we don't do

  • No advertising, and no third-party ad or analytics trackers anywhere on the site.
  • We never sell or rent your personal information.
  • We do not use your content to train AI models, and we do not opt it into model-training programs offered by OpenAI or Anthropic.
  • No advertising or analytics cookies. Miracle uses only the sign-in cookie and strictly necessary, short-lived first-party cookies for the limited features named above.

4. How we use your information

We use information only to operate the features you request and the account defaults disclosed in this policy:

  • Store, display, sync, export, and delete your product content.
  • Let the platform owner open a time-limited, visibly labeled support session when needed to diagnose and correct the product state and screens you report. During that session, the owner can view and change product content as your account. The session does not give your account administrative authority and cannot change billing, membership, login identity, account deletion, note share links, guest assignments, Community publishing, connected capture services, or admin controls. Miracle records the owner account, customer account, start, stop, and expiry for security and accountability.
  • Send a recipient-bound complimentary invitation when a super administrator requests it, verify that the accepting WorkOS identity owns the exact invited email, or directly create a verified email-and-password identity when the administrator chooses that separate mode; grant access without fabricating billing state; apply the administrator's first-login onboarding choice; and let a super administrator revoke the pending invitation or complimentary access.
  • Create the guest-checklist snapshot you request, let anyone holding its private capability link mark snapshot items complete, show that progress to you, let you revoke access, and keep completion of the source task under your signed-in control.
  • Keep a short-lived recovery copy when one synchronized edit displaces another edit to the same field.
  • Transcribe server-backed audio; turn voice transcripts, longer typed entries, screenshots, PDFs, forwarded emails and their safely readable attachments, and a Gmail message explicitly captured through Miracle Capture into reviewable to-dos; classify and route messages sent through Telegram, WhatsApp, Slack, Discord, or iMessage to a to-do, today's Daily Note, or a General Note; create a bounded title for a routed General Note; clean and file other supported connected captures; and compose, polish, or rebuild North Star text.
  • Authenticate Miracle Capture with a capture-only OAuth permission, remember the extension's default destination, process only the browser view, selected page area, selected screen or window, or open Gmail message you explicitly capture, and open your Miracle account when you use its shortcut.
  • Return requested information to an AI assistant or other MCP client you connect, limited by the access scopes you approve, and apply changes that client asks Miracle to make on your behalf.
  • Resurface tasks in the app and, when you explicitly enable a channel, send task reminders through browser push or a connected Telegram account. A reminder does not change the task's due date, active section, or deferred lifecycle.
  • Verify membership access and process and reconcile authorized membership charges, refunds, and disputes.
  • Evaluate habit and pact days and show shared-pact activity to that pact's members.
  • Operate Pact Community under the account defaults: create the first-name-and-last-initial identity, unique handle, and available provider avatar for every account; keep the fixed Right Now Habit and its completions private; carry the current Right Now answer across account-local dates until you change or clear it, reset only the daily completion, and preserve completed prior-date snapshots without creating new official membership or posts; publish fixed controlled completions for supported non-Right-Now practices; reuse the active Community display name, handle, and avatar on public pages for group pacts you own; publish the group commitment and description there as the headline and story; publish detached fixed journal-session counts and structured exercise progress to the followers or global account audience unless you turn sharing off or select pact-only; classify eligible numeric goal definitions for safe exercise; apply reject-only validation to deliberate Feed posts and replies, then store accepted text exactly as submitted without AI processing; keep the source habit or pact and private-pact relationship out of detached activity; narrow other private-pact activity to that pact; support follows, Cheers, and flat replies; enforce rate limits; honor blocks; review reports; and apply the Community Guidelines.
  • Send required transactional messages, send product updates only if you separately subscribed, secure and debug the Service, prevent abuse, and comply with law.

5. Who we share it with

Only service providers that operate the product, only with what they need:

  • WorkOS and an available profile-image host: WorkOS handles sign-in and may supply the name and profile-picture URL provided by Google or another identity provider. When a super administrator directly creates a complimentary account, WorkOS receives the supplied email address and initial password and stores the resulting verified sign-in identity; Miracle does not retain that password. Community and public group-pact pages may show the same current provider avatar. The viewer's browser requests it directly only from an approved Google or WorkOS content-delivery host. The image request suppresses the Miracle page address, but the image host receives ordinary connection information such as the viewer's IP address, browser information, and request time. Miracle does not derive a Gravatar hash from your email address or query Gravatar.
  • Stripe: web membership payments.
  • Apple: native iPhone membership payment processing, auto-renewing subscription management, purchase restoration, cancellation, refunds, and signed StoreKit subscription status. Apple receives the stable random Miracle account token used to bind the purchase, plus the purchase information and ordinary technical data its App Store services process under Apple's own privacy terms. The account token contains no Miracle name or email address.
  • Railway: hosting, object storage, and our database.
  • Resend: email delivery. For a complimentary invitation, Resend receives the recipient address, inviter display name, fixed invitation message and recipient-bound link, plus the provider idempotency and delivery metadata needed to send and troubleshoot that email. If a super administrator chooses the optional account-ready email for a directly created complimentary account, Resend receives the recipient address, fixed account-ready message and sign-in link, and delivery metadata; it never receives the account password. For an Email to Inbox acknowledgement, Resend receives the authenticated sender address, original subject, final task title, list, checklist items, due date if present, exact task link, available 31-day list-confirmation links when no list was named, and limited message-thread and delivery metadata.
  • Telegram, Meta (WhatsApp), Slack, Discord, and Sendblue (iMessage relay): only if you connect that capture service. The service handles messages, account or phone identifiers, and attachments you route through it under its own privacy terms. Telegram and Discord also carry the routing buttons Miracle displays, while Sendblue carries the equivalent numbered iMessage prompt and reply.
  • Cloudflare: an email you forward to Miracle transits Cloudflare's email routing before it reaches us.
  • Your browser's push service: if you enable browser alerts, Miracle sends an end-to-end encrypted notification to the private endpoint issued by Safari or an installed iOS web app (Apple Push Notification service), Chrome (Google Firebase Cloud Messaging), Firefox (Mozilla Push Service), or the equivalent service selected by your browser. That provider receives the routing endpoint and delivery metadata under its own privacy terms. Task-reminder text is encrypted in transit for the subscribed browser. A guest-checklist completion alert is generic and omits the shared title, checklist item text, assignee label, and share link so those details do not appear on a lock screen.
  • OpenAI: server-backed voice capture sends the full audio recording to OpenAI for transcription. Voice-to-do capture also sends your saved preferred spellings as recognition context; common-error spellings are applied by Miracle afterward and are not sent. Journal or mantra audio is sent without vocabulary context. A full typed message, or a transcript produced from a voice message, sent through Telegram, WhatsApp, Slack, Discord, or iMessage can be sent to OpenAI to remove capture-command framing and return constrained routing fields. Those fields can identify To-do, today's Daily Note, or General Note. Only deterministic wording from the authenticated member can choose Inbox, Priority, Today, or In Progress for a to-do; otherwise Miracle asks. After Miracle confirms that Notes is enabled for the member, a General Note's full cleaned text can also be sent to OpenAI to produce one bounded factual title. The title model cannot choose the note type, date, recipient, or an action. Provider failure, invalid output, or missing configuration uses the first meaningful line as a deterministic title instead of blocking the save. The model cannot supply an account, provider recipient, callback action, command, or tool call. Unknown, malformed, or uncertain routing output fails closed and asks you to choose. Ordinary typed to-dos entered in the Miracle web app are not sent to OpenAI.
  • Forwarded connected captures: when Telegram, WhatsApp, Slack, or Discord reliably identifies a forwarded message, Miracle treats the forwarded text, transcript, and files as content rather than routing authority. Only your separate forwarding comment, when the provider supplies one, can be sent for routing classification; without one, Miracle asks you where to save it. Forwarded audio can still be sent to OpenAI for transcription, and content you choose to save can be sent for the General Note title or task organization described here. The current Sendblue iMessage payload does not identify forwarded or quoted content, so Miracle cannot distinguish it from text or media you authored directly.
  • Anthropic: server-backed web and connected-channel voice-to-do capture sends the corrected transcript, but not the audio, to Anthropic's Claude to create a title, checklist, notes, and due date. When you turn on native iPhone AI processing, native Voice To-Do sends only its finished on-device transcript to Anthropic for the same editable draft; its recording audio and Apple speech recognition stay on the iPhone. Connected-channel voice transcripts are likewise sent to Anthropic for this organization before routing, including when Miracle later saves the corrected transcript as a Daily Note or General Note. For a note, Miracle saves the normalized transcript rather than Claude's organized task prose. When a typed web to-do is at least 24 words, at least 160 characters, or contains multiple nonempty lines, Miracle sends the full typed text to Anthropic to propose a title, up to 20 checklist items, and a due date. Shorter one-line typed tasks are saved without AI organization. Forwarded-email capture sends the subject, email body, any note you add, sanitized filenames, and the complete contents of every safely readable user-visible attachment. Miracle validates PDFs, normalizes supported raster images, and bounds decoded text before sending it. It does not send unsupported, corrupt, encrypted, archived, executable, macro-enabled, SVG, or other opaque attachments. Claude can return only a bounded title, checklist, due date, and factual attachment summaries. It receives no routing, messaging, URL-fetching, storage, command, or other execution tool, and Miracle treats every instruction found inside an email or file as untrusted content rather than authority. A Gmail message you explicitly capture through Miracle Capture sends its subject and body, plus any available sender, recipient, sent-time, and source-link context, but that extension path does not import Gmail attachments. Screenshot-to-do capture sends the full screenshot image, including a browser, window, screen, or cropped area you explicitly choose through Miracle Capture, to transcribe visible text and extract a task; ordinary Vision board uploads are not sent. The native iPhone selected-photo flow stores the selected private image and reviewed task fields without sending the image to Anthropic. Web PDF capture and the consented native Choose PDF from Files and Scan one page with camera actions send only the complete document the member selected and its filename to propose up to 20 editable tasks and produce a private search index; the selected list destination is controlled by Miracle and is not taken from the email, screenshot, document, or model. Both native document actions require explicit AI processing permission before upload. North Star tools can send your net-worth or identity answer, money manner, place, relationships, health or longevity, feelings, purpose, selected people or feeling values, and the saved North Star sentence to compose alternate wording, polish a list, or rebuild editable fields. Miracle does not send deliberate Feed posts or replies to Anthropic or another AI provider. Those manual submissions use reject-only validation and, when accepted, are stored exactly as submitted. For a numeric goal eligible for followers or global automatic sharing, Miracle automatically sends only the NFKC-normalized goal title, capped at 240 characters, and unit, capped at 40 characters, when an eligible definition is new or changes so Anthropic can decide whether it is safe physical exercise and return neutral singular and plural labels. Progress sets reuse that saved decision and never invoke the classifier; a transient provider or delivery failure may retry the same definition. The title can come from a private habit or pact, but the raw title never publishes. Local filters reject profanity, sexual anatomy, obvious personal information such as contact details, threats, self-harm, and bidirectional or hidden formatting before the call. Miracle never sends this classifier a member identity; pact id, type, visibility, description, or membership; target, progress, history, schedule, notes, rules, or journal content. Miracle claims a new provider call only while at least one member of the goal is eligible for followers or global automatic sharing. Choosing Off or pact-only removes that member's eligibility and prevents a detached card for that member. A shared pact may still be classified for another eligible member, and an already in-flight provider request may finish. Unsafe or uncertain input or output, provider failure, or a missing Anthropic key fails closed without blocking the goal or progress. Miracle retains only the current validated decision and neutral labels with the pact until its definition changes or the pact is deleted, not the raw model response. Per-day Feed-safe label, term, and action snapshots expire with the 180-day automatic-activity window. Fixed automatic completions and journal-session counts still do not use AI, task text, or journal writing.
  • An AI assistant or other MCP client you connect: after you authorize ChatGPT, Claude, or another compatible client, Miracle returns only the information requested under the access scopes you approved. Depending on that request, this can include to-dos and notes, pacts, Goal Grid data, journal entries, Vision data, North Star fields, birth-date or Time on Earth data, and other scoped product content. The client can also send authorized changes back to Miracle. The assistant's provider processes that data under its own privacy terms; Miracle does not send MCP data until an authenticated client requests it.

Native iPhone speech and capture. Voice To-Do requires on-device Apple speech recognition, and that audio and its preferred terms stay on the iPhone. They are not sent to Miracle, OpenAI, Anthropic, or Apple's network speech service; if on-device recognition is unavailable, that flow asks you to type instead. When you turn on native AI processing and stop a Voice To-Do recording, Miracle sends only the finished on-device transcript to Anthropic to prepare an editable title, checklist, due date, and notes. Nothing is saved until you review and add it; with AI processing off, the transcript stays on the iPhone and you can use the basic editable draft. North Star recitation prefers on-device Apple recognition but may use Apple's network speech service when on-device recognition is unavailable. Apple can then receive the recitation audio and contextual terms under Apple's terms. Native North Star recognition does not switch to Miracle's server recorder, OpenAI, or Anthropic. Selected-photo capture uploads the private image and the task fields you approve to Miracle but does not send the image to an AI provider. Native document capture is not on-device extraction: after you explicitly turn on native AI processing, Choose PDF from Files uploads only the selected PDF, and Scan one page with camera uploads only the selected page as an encrypted one-page PDF. Miracle sends that chosen document to Anthropic for editable proposals.

How the AI providers handle content. Miracle uses commercial APIs and does not opt submitted content into provider model training. Under the providers' published defaults as of this policy's effective date, OpenAI says API data is not used to train its models unless the customer explicitly opts in. OpenAI lists no abuse-monitoring or application-state retention for its audio-transcription endpoint, while its text Chat Completions endpoint can retain customer content in abuse-monitoring logs for up to 30 days. Anthropic says commercial API inputs and outputs are not used to train its models by default and are automatically deleted from its backend within 30 days. Both providers describe exceptions for legal requirements and misuse or policy enforcement, and an account-specific agreement can change retention. Provider retention is separate from Miracle's own retention below.

What other members can see. Automatic completion sharing and the global feed are the account defaults for supported Community activity, but the fixed Right Now Habit is excluded. Its current answer, Done today occurrence, and Goal Grid Archive receipts are private and never shown to other members. A historical fixed "Completed one thing today." post can remain visible under its original audience until its ordinary retention or deletion rule applies. A private pact post is visible only to active members of that pact. A followers post is visible to accounts that follow the community profile. A global post can appear in the global feed. The audience for a deliberate post or reply sees the exact text you submitted. Detached journal and exercise cards use the followers or global account audience and are not published when the account audience is pact-only. Their audience can see the community handle, display name, provider picture or generated initials, fixed journal-session count, or structured exercise amount, exercise type or unit, and daily target, plus replies and Cheer count. A detached exercise card never identifies the source habit or pact, even when progress originated inside a private pact. Blocks remove visibility and interaction between the two profiles. Miracle does not place private task text, journal writing, North Star language, habit or pact titles, pact identity or membership, notes, or attachments into an automatic card.

What visitors to a pact share page can see. Anyone with a group pact's public link can see its public title, description, leader identity, terms, member and check-in totals, and an anonymous recent-activity preview when the owner has enabled a public community. Each preview row can state only the activity category, relative time, reply count, and Cheer count. It does not include a member name, avatar, handle, post text, reply text, or source record. Members-only and disabled communities do not expose activity rows. Joining and signing in are required to see the full Feed, names, post and reply text, or to interact.

What a guest checklist recipient can see and do. Anyone with the private link can see the assignment's copied title, assignee label, checklist item text, and current progress and can check or uncheck delegated snapshot items. Items already completed before sharing stay locked. The link does not expose task notes, attachments, later edits to the source task, the rest of the owner's account, or the owner's sign-in identity. Miracle does not authenticate the recipient or guarantee that the named assignee is the person using the link. Guest progress is private link activity, not Community activity, and cannot complete the owner's source task.

An eligible committed exercise action can create a separate automatic post. Other members can therefore see the amount just completed and the resulting running total for each shared set, such as "Did 10 more push-ups. 20 of 100 done today." Individually completed circles can post separately, while one bulk action that finishes several circles creates one combined post. A retry does not create another post for the same event. Undo removes that event's post, and later visible totals reconcile to the remaining progress. These progress writes reuse the saved exercise classification and do not send the target, progress, or set to Anthropic.

We will also disclose information if the law genuinely requires it. We do not otherwise disclose your information.

6. Where your data lives and how long

Our primary servers, object storage, and database are hosted in the United States. The service providers above may process data in the United States or other locations described in their terms. If you use the Service from elsewhere, you consent to that processing.

  • Product content. We keep it while your account is active or until you delete it. Ask us to delete your account at claycollins@gmail.com and we will remove deletable personal data within 30 days, with copies in encrypted backups aging out on the backup cycle.
  • Administrative support records. We retain the administrator account, viewed account, support-session identifier, start, stop, expiry, and limited request metadata as reasonably needed for security, abuse prevention, troubleshooting accountability, legal obligations, and defense of claims. The record does not copy the product content viewed during the session.
  • Right Now practice. We keep the fixed current Habit state, its current answer, its active completion-instance date, and private dated answer and historical kind snapshots while your account is active or until you delete product data. The current answer carries across days in your saved account time zone until you explicitly replace or clear it. Each new day resets only completion and does not create a historical snapshot. An accepted completion creates one private receipt for that action; a retry returns the same receipt instead of rewriting it. Choosing a new #1 preserves the previous receipt's answer, kind, timestamps, and proof source in immutable private history. You may Undo only the current action's receipt on the same account-local day. The Goal Grid Archive shows up to 365 daily receipts and 365 earlier same-day actions as read-only entries. The account export retains the complete history, including all earlier same-day actions. Changing the saved time zone does not rewrite a receipt's original civil date. New snapshots say Habit; an earlier Pact snapshot stays unchanged. The account export includes the current Habit state, its current answer, its active completion-instance date, and the complete account-scoped receipt rows. A product-data wipe deletes them and keeps any legacy official One Thing membership in left status.
  • Complimentary invitations, provisions, and grants. A pending invitation link expires after seven days, and its short-lived exchange cookie expires after 15 minutes. We retain the recipient email, inviting, creating, accepting, or revoking account identifiers, onboarding choice, fixed email template when delivery is requested, Resend delivery metadata, WorkOS identity and deterministic external identifiers for a direct provision, and invitation, provision, grant, or revocation audit times while delivery recovery or complimentary access is active and afterward as reasonably needed for security, abuse prevention, delivery troubleshooting, audit, legal obligations, and defense of claims. We do not retain a directly supplied password, and the raw invitation capability is never part of those retained records. A super administrator can immediately revoke a pending invitation or complimentary access without changing an independent Stripe subscription.
  • Voice. Miracle does not retain voice audio as product storage after processing. Voice-to-do transcripts and drafts stop accepting review or save actions at a fixed deadline no later than 24 hours after intake. Scheduled bounded cleanup deletes the inactive rows afterward, so physical database removal can occur later than the action deadline. The saved to-do follows the product-content rule.
  • Typed to-do previews. A long typed entry and its organized preview stop accepting approval after 24 hours. Scheduled cleanup deletes the inactive preview row afterward. If you approve the preview in time, the resulting to-do follows the product-content rule.
  • Connected capture routing drafts. A Telegram, WhatsApp, Slack, Discord, or iMessage routing draft has an absolute action deadline no later than 24 hours after intake. After that deadline it cannot authenticate a choice or create a result. The deadline is not a promise of physical deletion at that instant: scheduled bounded cleanup deletes inactive rows afterward and may complete later. Account deletion removes them. They are excluded from account exports because they are temporary provider callback and idempotency state; the resulting to-do or note follows the product-content rule and appears in its normal export collection.
  • Connected capture replay receipts. For direct Telegram text, Discord, and iMessage intake, Miracle stores a one-way event fingerprint, the account revision boundary, and a processing status before capture content is sent to AI. A failed first attempt can continue only for that same account revision; draft creation activates the receipt atomically, and a later retry replays the existing result without processing the content again. A routing-choice receipt temporarily also holds the provider response identity, prompt stage and choice, and a bounded result so a retry cannot apply the same answer twice. A product-data wipe marks each receipt account-data-deleted and clears every linked draft, prompt, choice, and result while retaining the event identity so a delayed provider retry cannot recreate wiped work. Full account deletion removes these receipts. They contain no captured message after the wipe and are excluded from account exports.
  • Telegram, WhatsApp, and Slack intake receipts. Miracle keeps the authenticated provider payload only while its capture is queued, processing, or retrying. A queued Telegram voice payload includes Telegram's file_id, a private audio-retrieval capability that Miracle uses only to fetch that voice memo for processing. A queued Telegram voice capture, or queued WhatsApp or Slack text or voice capture, stops content processing 24 hours after intake: Miracle no longer classifies, transcribes, organizes, routes, or saves the old event and retries only the terminal notice, so anything already saved stays saved and the old event cannot create a new result. Telegram also stops downloading the expired voice memo. After capture or terminal-notice delivery finishes, Miracle clears the provider payload, including any Telegram file_id, and retains one-way event and payload fingerprints plus a bounded result. A full product-data wipe immediately clears any remaining provider payload, task reference, and saved destination while keeping the content-free fingerprints as a no-resurrection receipt; deleting the full account deletes the receipt. Deleting one saved item does not itself promise immediate deletion of an otherwise active provider receipt. These internal callback and idempotency receipts are excluded from account exports; the resulting to-do or note follows the product-content rule and appears in its normal export collection.
  • Screenshots and images. An image attached to saved content remains private product content until that content or your account is deleted. An unreferenced image is deleted after a seven-day recovery grace period. Extracted screenshot text saved in a to-do follows the product-content rule.
  • PDF documents. For web PDF capture and consented native Choose PDF from Files or Scan one page with camera, an unsaved preview, its proposed tasks, and its private search index expire within 24 hours. An approved PDF is attached to the resulting tasks and follows the product-content rule. If its last task attachment is removed, Miracle keeps the encrypted document for a seven-day recovery grace period and then deletes it. Raw PDF bytes are encrypted with AES-256-GCM inside the application before private object storage; the service must decrypt them temporarily to send the requested PDF to Anthropic or return it to your authenticated download. A non-content processing meter containing the account, an opaque capture reference, page count, new-or-retry type, and timestamp remains for up to 72 hours so deleting a preview cannot reset the AI processing limit. Native document capture uploads only the PDF or camera page you explicitly select after allowing AI processing; both follow this encrypted PDF rule.
  • Forwarded and captured email. Miracle keeps the original email body in a separate, read-only source field. For Gmail, this is the message explicitly sent through Miracle Capture. Miracle automatically removes it after 90 days. Removing it does not erase notes you added or edited. Files from forwarded email are task attachments and follow the product-content rule independently of the temporary source email. Completed inbound-delivery and extension-capture records follow the same 90-day policy. If an accepted message is still retrying at that age, Miracle removes its body and addressing details, retains only a bounded subject and, for an extension capture, its selected list destination, and continues trying to create the task. An Email to Inbox acknowledgement keeps its exact delivery snapshot only while pending or retrying. That temporary snapshot can include raw list-confirmation links. After Resend accepts it or delivery permanently stops, Miracle immediately removes the recipient address and message content from the delivery row. Miracle stores only a domain-separated SHA-256 digest for each list choice, expires the choice after 31 days, and removes the expired action row through bounded cleanup. Account deletion removes those rows immediately. Miracle also permanently stops and clears a delivery snapshot that remains undeliverable for seven days, including while an email-provider credential is unavailable, then deletes the remaining delivery evidence after 90 days. The extracted to-do fields and attached files remain until you delete them.
  • Sync recovery. A prior field value retained because a later synchronized edit displaced it is used only to recover overwritten work and is automatically deleted after 30 days. Deleting your account data removes these recovery copies as part of that deletion workflow.
  • Device recovery drafts. A quarantined unsent draft remains only in browser storage for up to 30 days and is never sent automatically. Discarding the draft or deleting app content removes drafts tied to that account from the current device.
  • Guest checklist assignments. A shared snapshot and its item progress remain with the source task until you delete the source task or delete your account data. Stopping sharing immediately invalidates the existing capability link but retains the private revoked snapshot and progress for your account; sharing that task again replaces the snapshot and issues a new capability. The account export includes active and revoked snapshots and progress but never includes the link token, server pepper, token rotation version, or other capability-signing material.
  • Browser reminders. An active browser push subscription remains until you turn it off on that device, the browser expires it, or you delete your account data. Expired or disabled subscription records are deleted after 30 days. Terminal task-reminder delivery jobs and their per-channel results are deleted after 90 days; this window prevents duplicate delivery across retries and deployments.
  • Pact Community. Your public display name, handle, avatar seed, optional provider image URL, sharing choices, manual posts, replies, Cheers, follows, and blocks remain until you change or delete the relevant item or delete the account, subject to safety and legal exceptions. Accepted manual posts and replies are stored exactly as submitted. Automatic completion, journal-session, and exercise-progress posts expire after 180 days. Per-day Feed-safe exercise labels, numeric terms, and action records expire with that same automatic-activity window. Miracle no longer creates generalized-result receipts; any legacy single-use receipt expires after 15 minutes. A current validated exercise-classification decision and its neutral labels remain with the pact until the title or unit changes or the pact is deleted; Miracle does not retain the raw model response. Hashed classifier quota buckets and other Community rate-limit buckets are deleted after seven days, and notifications after 90 days. Reports and moderation decisions may remain as long as reasonably needed for safety, appeals, abuse prevention, legal obligations, and defense of claims. Turning automatic sharing off prevents new automatic cards and removes your visible automatic cards. Deleting community activity removes your authored posts, replies, Cheers, any unexpired legacy generalized-result receipts, and retained exercise Feed action and label records. It preserves the profile, follows, and blocks so identity and safety choices do not disappear unexpectedly. Deleting the account removes that remaining community data through relational deletion; reports and safety records may remain with account identifiers minimized where practical.
  • Membership payment and safety records. Membership payment, consent, refund, dispute, fraud-prevention, and required-message delivery records are kept as long as reasonably needed for reconciliation, legal obligations, and defense of claims. Deleting product content does not erase records that must be retained for those purposes.
  • App Store billing records. Verified App Store transaction, entitlement, account-binding, and notification evidence remains linked to the Miracle account while that account exists. Full account deletion removes those linked StoreKit records from Miracle. Apple independently retains and handles App Store purchase and refund records under its own terms and legal obligations.

7. Your rights

Wherever you live, we honor the basics: you can access and export your data, correct it, turn automatic completion sharing off, delete individual community posts or replies, delete authored community activity from Community settings, revoke guest checklist assignments, request account deletion, and object to processing. The account export includes the fixed current Right Now Habit state, its current answer and active completion-instance date, private dated answer and historical kind snapshots, active and revoked guest checklist snapshots and progress, your community profile, posts, replies, reactions, follows, blocks, reports, unexpired legacy generalized-result receipts, member-scoped Community interaction rate-limit records, notifications, and non-secret App Store entitlement and transaction history such as product and transaction identifiers, status, purchase and access dates, offer and ownership facts, and verification time. It never includes the App Store account token, a raw signed StoreKit payload, a signed-payload hash, an internal purchase binding, or an App Store notification receipt. It also never includes a guest capability token, the server pepper, token rotation metadata, connected capture routing drafts or replay receipts, provider callback tokens or event identifiers, or other capability-signing material. Internal hashed provider-spend buckets and the global spend bucket are not included. Residents of California, the EU/UK, and similar jurisdictions may have formal versions of these rights; email claycollins@gmail.com and we'll handle the request regardless of formality.

8. Security

Data is encrypted in transit, source PDFs and forwarded-email attachments receive additional application-layer encryption at rest, sessions are signed, payment credentials never touch our servers, and access to production systems is limited. Guest checklist links are bearer capabilities: possession grants the limited access described above, so keep them private and revoke any link that may have been forwarded or exposed. No system is perfect; if a breach affects your data, we will tell you promptly and plainly.

9. Children

The Service is for adults 18 and over. We do not knowingly collect information from anyone under 18. If you believe we have, contact us and we will delete it.

10. Changes to this policy

If we change this policy in a way that matters, we will post a notice on our updates page or in the app before it takes effect, and update the date above. We will not quietly weaken it.

11. Contact

Highway 86 LLC · claycollins@gmail.com · or use our contact page.