Last Updated: July 20, 2026
Mirri Diabetes LLC (“Mirri,” “we,” “us,” or “our”) develops and operates a family of diabetes and metabolic health management applications — including Mirri One (for Type 1 diabetes) and Mirri Navigator (for general metabolic health and Type 2 diabetes) — available on Apple iOS and Android, together with related services (each, an “App,” and together, the “Apps”). This Privacy Policy applies to each Mirri App you use; where it refers to “the App,” it means each Mirri App you use. It explains what information the Apps handle, how it is stored, and how an App can share your health information with people and organizations you choose when you turn on that App’s optional Sharing feature.
This Privacy Policy replaces all prior versions. Earlier versions of the App kept all information on your device and did not transmit it to our servers. The App now additionally offers an optional, opt-in Sharing feature that, when enabled by you, uploads health information in encrypted form to our servers so it can be delivered to recipients you select. If you installed the App under a prior, on-device-only version, we will ask for your fresh, affirmative opt-in before any of your health information is uploaded. If you do not enable Sharing, the App continues to keep your health information on your device as described below.
Please read this Privacy Policy together with our Terms of Service.
The Apps are consumer health and wellness tools intended to help you record, understand, and — at your option — share diabetes- and metabolic-health-related information (covering Type 1 diabetes, Type 2 diabetes, and general metabolic health) (“health information” or “Health Data”). Some users refer to this as “personal health information” or “PHI”; we use those terms descriptively only.
Mirri is a consumer app and is not a HIPAA covered entity or business associate, and HIPAA does not govern the App. We provide the App to you as an individual. If you choose to share information with a healthcare provider, you do so as an individual directing the disclosure of your own information; we do not act on behalf of, or under contract with, any provider.
Your health information is sensitive, and we handle it in accordance with this Policy and applicable privacy laws, including the Federal Trade Commission’s Health Breach Notification Rule; the Washington My Health My Data Act; the Nevada Consumer Health Data Privacy Law; the Connecticut Data Privacy Act; the Indiana Consumer Data Protection Act; the California Consumer Privacy Act (as amended by the California Privacy Rights Act); and similar state laws, where they apply to you.
Where required by law, we obtain your affirmative, opt-in consent before we collect or process your health information, and we obtain a separate consent before we share it through the Sharing feature. These consents are requested through clear, unbundled choices in the App — not merely by your acceptance of our Terms of Service — and you can withdraw your consent at any time (see Section 12). Withdrawing consent stops future collection or sharing that depended on it, and we will act on your withdrawal as described in Sections 6 and 11.
a. Health information from your device’s health platform. With your permission, an App can read health data from your device’s health platform — Apple HealthKit on iOS, or Android Health Connect (or Google Fit) on Android — such as blood glucose readings, insulin dosing, carbohydrate or meal information, activity, and related metrics, only for the categories you authorize. You can change or revoke these permissions at any time in the Apple Health app (iOS) or in Android Health Connect or your device settings (Android).
b. Information you log. You can manually enter information such as glucose values, insulin doses, medications, meals and carbohydrates, physical activity, symptoms, and notes.
c. Account and contact information. To enable Sharing, we may collect an account identifier such as your email address, and information about the recipients you designate (for example, a recipient’s email address, phone number, or in-app identifier) so we can deliver shared information.
d. Routing and technical information. When you use the Sharing feature, our servers process “routing information” needed to deliver your shared information to the correct recipients — such as recipient identifiers, your sharing settings, timestamps, and delivery and read status. We also process limited technical and diagnostic information — such as device and app version, crash reports, and general app-performance metrics, including information that Apple or Google make available to us through their standard app-store and developer tools — and your IP address, to operate, secure, and improve the App. We use your IP address only to deliver and secure the service and to infer general region for security and fraud prevention; we do not use it to track your precise location.
On your device (default). By default, the health information you log and the health-platform data you authorize remain on your device. If you never enable Sharing, your health information is not uploaded to our servers.
On our servers (only when you enable Sharing). When you turn on Sharing, the App uploads copies of the health information you choose to share to our servers in encrypted form so we can deliver it to your selected recipients, as described in Sections 6 and 7.
Sharing is off by default and is entirely opt-in. You decide whether to enable Sharing, what information to share, and with whom, and you provide separate opt-in consent (Section 3) before sharing begins. If you do not enable Sharing, this Section does not apply to you.
Who you can share with. You can share with individuals and organizations you select, such as family members and caregivers and your healthcare providers or care team. Recipients are chosen by you and are not vetted, controlled, or supervised by Mirri.
What you control. You choose which categories of information to share, which recipients receive it, and when to start or stop. You can disable Sharing or revoke a recipient’s access at any time in the App.
Revocation and deletion. When you disable Sharing or revoke a recipient, we stop future sharing, and we delete the encrypted copies of your shared information from our active servers within 30 days and from routine backups within 90 days. Information already delivered to a recipient cannot be recalled, deleted, or controlled by us, and remains subject to the recipient’s own practices. When you withdraw consent or delete your account, we also instruct our service providers to delete the associated information.
Not an alert system. As explained in our Terms of Service, the Sharing feature is not a medical alert, monitoring, or emergency-notification system, and information may be delayed, incomplete, or undelivered. Do not rely on it for urgent or safety-critical purposes.
We do not sell your health information, and we do not use it for advertising (see Section 14).
When you enable Sharing, we handle the health information you choose to share as follows:
No method of encryption, transmission, or storage is completely secure, and we do not guarantee that our security measures cannot be circumvented or that security will never fail. See Section 9.
If you grant an App access to your device’s health platform, we handle that data in accordance with the platform’s requirements and this Policy:
We use administrative, technical, and physical safeguards designed to protect your information, including encryption of health information in transit and at rest, access controls, and monitoring, and we maintain a written incident-response plan. These safeguards are designed to protect your information but are not a guarantee; no application, server, or transmission method is 100% secure, and we do not warrant that our safeguards will prevent every incident.
If a breach of the security of your health information occurs — including any acquisition, access, use, or disclosure of your information without your authorization — we will notify affected individuals without unreasonable delay and no later than 60 days after discovery, and we will notify the Federal Trade Commission, prominent media (where required by the number of affected residents), and applicable state authorities (including the Indiana Attorney General), as required by law, including the FTC Health Breach Notification Rule and applicable state breach-notification and consumer-health-privacy laws. Our notice will describe, to the extent required, what happened and when, the categories of information involved, the name of any third party that acquired the information (if known), steps you can take, what we are doing in response, and how to contact us.
We retain your information only for as long as needed to provide the App and the features you use, and as required for legal, security, and record-keeping purposes.
Managing the App. You can control health-platform permissions in the Apple Health app (iOS) or in Android Health Connect or your device settings (Android), enable or disable Sharing, choose and remove recipients, withdraw consent, and delete information you have logged.
Your rights. Depending on where you live, you may have the right to: confirm whether we process your information and access it; correct it; delete it; obtain a portable copy; withdraw consent to processing of your health information; opt out of any sale, sharing for targeted advertising, or certain profiling; limit the use of sensitive personal information; and appeal a decision we make about your request. We do not discriminate against you for exercising these rights.
How to exercise them. Contact us at support@mirridiabetes.com or use the in-app request option. We will confirm receipt within 10 days and respond within 45 days (extendable once by an additional 45 days with notice). We take reasonable steps to verify your identity before acting, and we accept requests from authorized agents with proof of authorization. If we deny your request, you may appeal by replying to our decision or contacting support@mirridiabetes.com; if your appeal is denied, you may contact your state Attorney General.
Opt-out preference signals. We honor the Global Privacy Control (GPC) and other recognized opt-out preference signals where required by law.
This Section provides the disclosures required for “consumer health data” under the Washington My Health My Data Act and similar state laws, and applies to the consumers those laws protect. We also publish these disclosures as a standalone Consumer Health Data Privacy Policy, which we link from our homepage and within the Apps.
We do not sell your health information, and we do not share it for cross-context behavioral advertising, as those terms are defined by applicable law. We do not use your health information for advertising or data mining, and we do not use third-party analytics or advertising software development kits (SDKs) that sell or share your information. Aside from limited information that Apple or Google may automatically collect as the app-store and platform providers (which is governed by their own privacy policies), we do not collect information about you beyond what you provide to us or authorize. We use a limited number of service providers for hosting and security under contracts that prohibit them from using your information for their own purposes.
We use service providers — such as cloud hosting and infrastructure providers — to operate the App. They process information on our behalf under contracts requiring them to protect it and use it only to provide services to us. We do not sell your personal information, and we do not share it with third parties for their own marketing.
The App is a general-audience service intended for adults and is not directed to children. Only an adult (18 or older, or the age of majority in their jurisdiction) may create an account and be an account holder. When you set up the App, we ask whether you are 18 or older:
A child’s health information in the App is entered and managed by an adult account holder who is responsible and authorized for it; the child is not an independent user, and the adult account holder controls the encryption keys, the recipients, and all sharing. We ask only whether you are 18 or older — we do not ask a child’s date of birth or specific age.
We do not knowingly permit anyone under 18 to be an account holder, and we do not knowingly collect personal information from a child under 13 who is using the App as an independent user. If we learn that a child under 13 has created an account, or has used the App other than through an adult-provisioned Managed Device or Managed Profile, we will delete that account and the associated information. If you believe a child’s information has been provided to us improperly, contact us at support@mirridiabetes.com and we will address it.
When a person whose information is managed through a Managed Profile or Managed Device reaches the age of majority, they may create their own account, and the adult may unlink the device, relinquish control, and transfer that person’s information to their new account or request its deletion.
The App is intended for users in the United States, and we operate it and store information in the United States. We do not offer the App to individuals in the European Economic Area or the United Kingdom. If you use the App from outside the United States, you understand that your information will be processed in the United States.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date and, for material changes, provide additional notice as required by law (for example, in the App or by email). If a change materially affects how we collect, use, or share your health information, we will obtain your fresh, affirmative opt-in consent before it applies to you, rather than relying on your continued use.
If you have questions about this Privacy Policy or our privacy practices, or to exercise your rights, contact us at:
Mirri Diabetes LLC
300 Main St., Ste. 900
Lafayette, IN 47901, United States