MiroMiroMiroMiroAPI
PlaygroundMCPDocsBlogPricing
Sign inGet API keyKey

API & MCP

Privacy Policy

Last updated: July 22, 2026

This policy covers the MiroMiro design-extraction API and the MiroMiro MCP server (together, the "API"), including when they are used through an AI client such as ChatGPT, Claude, or Cursor. It explains what data we process when you call the API, why, and how long we keep it. Our browser extension and website are covered by a separate privacy policy.

Who we are

The API is operated by MiroMiro ("we", "our", "us"). For any privacy question, contact us at our support page.

What the API does with the URLs you submit

The core function of the API is to extract design information from a website. When you (or an AI agent acting on your behalf) call an endpoint or MCP tool, you provide a target URL. Our servers then fetch that URL and any resources it references (stylesheets, fonts, images, SVGs), read the page's publicly available HTML and CSS, and return the extracted result - colors, fonts, spacing, design tokens, brand identity, component code, images, SVGs, or Lottie files.

  • We fetch only URLs that are submitted to the API. We do not crawl beyond the requested page and its directly referenced assets.
  • We fetch publicly accessible content only. Requests to private, internal, or link-local network addresses are blocked at the network layer.
  • The API reads static HTML and CSS; it does not execute a target site's JavaScript and does not log into or submit forms on target sites.
  • You are responsible for ensuring you have the right to extract from the URLs you submit (see our API Terms of Service).

Information we collect

Account information

To issue an API key or link an account over MCP, we collect the email address, name, and provider identifier from your chosen sign-in provider (Google, GitHub, or email). We store API keys only as a one-way hash plus a short non-secret display prefix - the full key is shown to you once and never stored.

Request data

For each API call we record the endpoint used, the target URL, a timestamp, the response status, the credits spent, and the API key it belongs to. We use this to meter usage against your plan, enforce rate limits, detect abuse, show you your own usage history, and debug problems. We do not store the full extracted result in these logs.

Cached results

To avoid re-fetching the same public page repeatedly, extraction results are cached for a short period (currently up to 24 hours) keyed by the target URL. The cache holds design data derived from public pages, not personal information, and a cached result may be served to any caller requesting the same URL.

Payment information

Paid plans are billed through Stripe. We do not receive or store your full card details; Stripe processes payments and we retain only subscription status and identifiers needed to manage your plan.

How we use information

  • To provide the extraction service and return results to you or your AI client.
  • To authenticate requests, meter credits, and enforce plan limits and rate limits.
  • To detect, prevent, and investigate abuse, fraud, and security issues.
  • To operate billing and to contact you about your account or service changes.

We do not sell your data, and we do not use the URLs you submit or the results we return to build advertising profiles.

Access through AI clients

When you use the API through a third-party AI client (for example ChatGPT, Claude, or Cursor), that client sends your prompts and the target URLs to the API on your behalf, and displays our results back to you. Your use of that client is also governed by the client provider's own privacy policy and terms, which we do not control. When you connect an account via OAuth, we receive only an authorization granting the client access to your MiroMiro API usage - never your password.

Service providers

We share data only with the processors needed to run the service:

  • Supabase - authentication, database, and account/usage storage.
  • Vercel - application hosting and content delivery.
  • Stripe - payment processing for paid plans.

These providers process data under their own security and privacy commitments and only to provide their service to us.

Retention

We keep account information for as long as your account is active. Request logs are retained to provide usage history and for abuse prevention, and cached extraction results expire automatically (currently within 24 hours). You can request deletion of your account and associated data at any time via our support page.

Your rights

Depending on your location (including under the GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us and we will respond within the period required by applicable law.

Security

We protect the API with hashed credentials, scoped access, rate limiting, and network-level protections against requests to internal or private addresses. No system is perfectly secure, but we work to keep your account and usage data protected and to fix issues promptly.

Changes to this policy

We may update this policy as the API evolves. Material changes will be reflected by the "last updated" date above, and significant changes affecting how we handle your data will be communicated to account holders.

Questions about this policy? Contact us. See also the API Terms of Service.

MiroMiroMiroMiroAPI

The design API for AI coding agents - one call returns any website’s tokens, fonts, SVGs and images as clean JSON. MCP-native.

All systems operational

Product

  • Overview
  • Playground
  • MCP connector
  • Documentation
  • Authentication
  • Pricing
  • Changelog
  • Dashboard

Solutions

  • Design to code API
  • Website to code API
  • Design MCP server

Endpoints

  • Brand & colors
  • Design tokens
  • Images
  • SVGs
  • Fonts
  • Lottie

Free Tools

  • Asset extractor
  • Image extractor
  • Video extractor
  • Audio extractor
  • SVG extractor
  • Font extractor
  • Color palette extractor
  • All free tools →

Use Cases

  • Ground truth for AI agents
  • Rebuild a section as code
  • Auto-brand onboarding
  • Competitive teardowns
  • Design-system drift
  • Lottie recovery
  • Asset migration
  • All use cases →

Compare

  • Firecrawl alternative
  • Brandfetch alternative
  • Apify alternative
  • All comparisons →

Resources

  • Blog
  • Status
  • llms.txt
  • Support
  • miromiro.app
  • Browser extension

© 2026 MiroMiro. All rights reserved.

PrivacyTermsX / Twitter