This policy explains how Mira Finance Agent, operated by Ray Chou, accesses, uses, stores and shares information. Mira is a private finance operations tool available only to authorised users.
1. Information Mira handles
- Google account information: the email address and basic identity information returned during authorisation.
- Google Drive information: metadata for the approved finance folder and its customer folders, plus invoice files that Mira creates, uploads or verifies there.
- Google Sheets information: the spreadsheet used as a one-way, read-only view of customer records maintained by Mira.
- Finance information: customer details, invoice line items, dates, currency, payment terms, document identifiers, file hashes and audit events supplied or generated during authorised workflows.
- Operational information: redacted error categories, timestamps and security/audit records needed to operate and protect the service.
2. How Google user data is used
Mira uses Google user data only to provide the finance functions chosen by the authorised user: validating the approved Drive destination, creating stable customer folders, storing and verifying confirmed invoice files, maintaining the customer Sheet mirror, and retrieving an exact stored document when explicitly requested.
Mira's application controls restrict operations to its approved finance locations even where the underlying Google permission is broader. Mira does not scan unrelated Drive content for advertising, profiling or unrelated purposes.
3. Storage and retention
- Final invoice DOCX and PDF files are stored in the approved Google Drive customer folders, not as persistent server copies.
- Temporary invoice rendering uses memory-backed staging and is removed after the operation.
- The private finance ledger stores customer and invoice records, Drive references, document hashes and append-only audit history for finance, security and recovery purposes.
- OAuth tokens are kept in a protected credential store and are not placed in source code or ordinary logs.
- Finance and audit records are retained while needed for operational, accounting, legal or security purposes. Google authorisation is removed when it is no longer required or when the user revokes access.
4. Sharing and transfer
Mira does not sell Google user data, use it for advertising, or share it with data brokers. Data is processed by Google APIs and the private infrastructure required to provide the requested workflow. A document is sent to another person only following the authorised user's separate, explicit delivery instruction and confirmation, or where disclosure is legally required.
5. Google API Limited Use
Google user data is used only for the user-facing finance features described above. It is not transferred for personalised advertising, creditworthiness, lending, surveillance or unrelated product development.
6. Security
Mira applies restricted server permissions, confirmation boundaries, deterministic validation, document hashing, approved-folder enforcement, redacted logs and append-only audit records. No method of storage or transmission is completely risk-free, but access is limited to what the finance workflow requires.
7. Your choices
You may revoke Mira's Google access from your Google Account permissions. Revocation stops new Drive and Sheets operations but does not automatically delete documents already stored in your Drive or finance records that must be retained. To request access, correction or deletion where applicable, contact [email protected].
8. Changes and contact
This policy will be updated when Mira's data practices materially change. The effective date above identifies the current version. Questions can be sent to [email protected].