Last Updated: July 20, 2026
Mirri Diabetes LLC (“Mirri,” “we,” “us,” or “our”) provides Mirri Studio (“Studio”), a portal that lets organizations — such as diabetes camps, community or support groups, and clinicians or care teams — and their authorized staff (each, an “Organization User”) receive, view, and manage diabetes- and metabolic-health information that individuals choose to share with them through Mirri’s consumer applications, Mirri One and Mirri Navigator (the “Consumer Apps”). Clinical and other HIPAA-regulated use is not yet available — see Section 2.
This Privacy Policy explains how we handle information in connection with Studio. Please read it together with our Terms of Service for Studio and, where relevant, the Privacy Policy for the Consumer Apps.
Studio is a professional and organizational tool. Organizations and their Organization Users use it to work with health information that individuals (participants, or people they care for) have chosen to share from the Consumer Apps.
Studio is currently a non-HIPAA service, and Mirri does not act as a HIPAA covered entity or business associate. Studio is not currently offered to, and may not be used by, a HIPAA covered entity or business associate in any way that would cause Mirri to create, receive, maintain, or transmit protected health information on that organization’s behalf. If you are a covered entity or business associate, do not use Studio for that purpose until Mirri offers a HIPAA-compliant version and you and Mirri have signed a Business Associate Agreement (BAA). We plan to support clinical and HIPAA-regulated use in the future; until then, Studio is offered as a general, non-HIPAA service.
We handle information in accordance with this Policy and applicable privacy laws, including the Federal Trade Commission’s Health Breach Notification Rule; the Washington My Health My Data Act; the Nevada Consumer Health Data Privacy Law; the Connecticut Data Privacy Act; the Indiana Consumer Data Protection Act; the California Consumer Privacy Act (as amended by the California Privacy Rights Act); and similar state laws, where they apply.
Studio involves two broad categories of information:
a. Shared health information received from the Consumer Apps. When an individual — or an adult managing another person’s profile — enables Sharing in a Consumer App and selects your organization or an Organization User as a recipient, Studio receives the health information they choose to share, in order to display it to the authorized Organization Users. Individuals choose what to share and can stop sharing at any time from the Consumer App.
b. Organization and account information. We collect the organization’s details and each Organization User’s name, email address, role and permissions, and credentials to create and secure accounts and to control who may access shared information.
c. Routing and technical information. We process routing information needed to deliver shared information to the correct organization and users, and limited technical and diagnostic information — such as device and browser type, IP address, log-in and access activity, and general usage metrics — to operate, secure, and improve Studio.
We use information to: provide Studio and display shared health information to authorized Organization Users; create, secure, and administer organization accounts, users, and permissions; deliver information from the Consumer Apps to the recipients the individual selected; support, maintain, and improve Studio; and comply with law. We do not use shared health information for advertising or data mining, and we do not sell it.
Studio uses the same approach as the Consumer Apps:
No method of encryption, transmission, or storage is completely secure, and we do not guarantee that our security measures cannot be circumvented or that security will never fail.
Not a monitoring or alert system. Studio is not a medical device, alarm, or real-time monitoring or emergency-notification system. Shared information may be delayed, incomplete, out of order, inaccurate, or undelivered. Organization Users must not rely on Studio for urgent or safety-critical purposes and should use their own clinical judgment, devices, and emergency services. In an emergency, call your local emergency number (such as 911).
We use administrative, technical, and physical safeguards designed to protect information, including encryption of information in transit and at rest, role-based access controls, authentication, access logging, and monitoring, and we maintain a written incident-response plan. These safeguards are designed to protect information but are not a guarantee; no application, server, or transmission method is 100% secure, and we do not warrant that our safeguards will prevent every incident.
If a breach of the security of health information occurs — including any acquisition, access, use, or disclosure of information without authorization — we will notify affected individuals and, where appropriate, the affected organization, and applicable authorities (including the Federal Trade Commission, prominent media where required, and applicable state authorities such as the Indiana Attorney General), without unreasonable delay and no later than 60 days after discovery, as required by law, including the FTC Health Breach Notification Rule and applicable state breach-notification and consumer-health-privacy laws. If Studio later operates under a Business Associate Agreement, the HIPAA Breach Notification Rule and the terms of that agreement will also apply.
We retain information only as long as needed to provide Studio and as required for legal, security, and record-keeping purposes, and we do not retain shared health information longer than necessary.
Individuals exercise their privacy choices — including access, deletion, and withdrawing consent — primarily through the Consumer Apps and their sharing settings, or by contacting us at support@mirridiabetes.com. Organizations and Organization Users will reasonably assist individuals in exercising these rights and will honor an individual’s decision to stop sharing.
If you are an Organization User, you may have the right to access, correct, or delete your own account information, and to exercise other rights under applicable law. To do so, contact us at support@mirridiabetes.com or your organization’s administrator. We will respond as required by applicable law and will verify your identity before acting.
The health information handled in Studio is “consumer health data” under laws such as the Washington My Health My Data Act and similar state laws. That information is received in Studio at the individual’s direction, based on the consent the individual provided in the Consumer App. We do not sell consumer health data, we do not use it for advertising, and we do not use geofencing. For the full consumer-health-data disclosures that apply to Studio, see our Mirri Studio Consumer Health Data Privacy Policy, which we link from our homepage and within Studio.
We do not sell health information handled in Studio, and we do not share it for cross-context behavioral advertising, as those terms are defined by applicable law. We do not use it for advertising or data mining, and we do not use third-party analytics or advertising software development kits (SDKs) that sell or share it. We use a limited number of service providers for hosting and security under contracts that prohibit them from using information for their own purposes.
We use service providers — such as cloud hosting and infrastructure providers — to operate Studio. They process information on our behalf under contracts requiring them to protect it and use it only to provide services to us. We do not sell personal information, and we do not share it with third parties for their own marketing.
Diabetes camps, groups, and other organizations that use Studio may work with children who have diabetes. A minor’s health information reaches Studio only when an adult — a parent or legal guardian managing the minor’s profile in a Consumer App — chooses to share it with the organization, consistent with the adult-managed model described in the Consumer Apps’ Privacy Policy. Children do not use Studio, and we do not knowingly allow anyone under 18 to be an Organization User.
The organization is solely responsible for obtaining any parental or guardian consents its own activities require (for example, camp registration or program participation) and for handling children’s information appropriately. By using Studio, the organization represents that it has obtained the consents and has the authority its activities require.
Studio is intended for use in the United States, and we operate it and store information in the United States. We do not offer Studio to individuals or organizations in the European Economic Area or the United Kingdom. If you use Studio from outside the United States, you understand that information will be processed in the United States.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date and, for material changes, provide notice as required by law. If a change materially affects how we handle health information, we will obtain any consent required by law before it applies.
If you have questions about this Privacy Policy or our privacy practices, or to exercise your rights, contact us at:
Mirri Diabetes LLC
300 Main St., Ste. 900
Lafayette, IN 47901, United States