API & MCP
Last updated: July 22, 2026
This policy covers the MiroMiro design-extraction API and the MiroMiro MCP server (together, the "API"), including when they are used through an AI client such as ChatGPT, Claude, or Cursor. It explains what data we process when you call the API, why, and how long we keep it. Our browser extension and website are covered by a separate privacy policy.
The API is operated by MiroMiro ("we", "our", "us"). For any privacy question, contact us at our support page.
The core function of the API is to extract design information from a website. When you (or an AI agent acting on your behalf) call an endpoint or MCP tool, you provide a target URL. Our servers then fetch that URL and any resources it references (stylesheets, fonts, images, SVGs), read the page's publicly available HTML and CSS, and return the extracted result - colors, fonts, spacing, design tokens, brand identity, component code, images, SVGs, or Lottie files.
To issue an API key or link an account over MCP, we collect the email address, name, and provider identifier from your chosen sign-in provider (Google, GitHub, or email). We store API keys only as a one-way hash plus a short non-secret display prefix - the full key is shown to you once and never stored.
For each API call we record the endpoint used, the target URL, a timestamp, the response status, the credits spent, and the API key it belongs to. We use this to meter usage against your plan, enforce rate limits, detect abuse, show you your own usage history, and debug problems. We do not store the full extracted result in these logs.
To avoid re-fetching the same public page repeatedly, extraction results are cached for a short period (currently up to 24 hours) keyed by the target URL. The cache holds design data derived from public pages, not personal information, and a cached result may be served to any caller requesting the same URL.
Paid plans are billed through Stripe. We do not receive or store your full card details; Stripe processes payments and we retain only subscription status and identifiers needed to manage your plan.
We do not sell your data, and we do not use the URLs you submit or the results we return to build advertising profiles.
When you use the API through a third-party AI client (for example ChatGPT, Claude, or Cursor), that client sends your prompts and the target URLs to the API on your behalf, and displays our results back to you. Your use of that client is also governed by the client provider's own privacy policy and terms, which we do not control. When you connect an account via OAuth, we receive only an authorization granting the client access to your MiroMiro API usage - never your password.
We share data only with the processors needed to run the service:
These providers process data under their own security and privacy commitments and only to provide their service to us.
We keep account information for as long as your account is active. Request logs are retained to provide usage history and for abuse prevention, and cached extraction results expire automatically (currently within 24 hours). You can request deletion of your account and associated data at any time via our support page.
Depending on your location (including under the GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us and we will respond within the period required by applicable law.
We protect the API with hashed credentials, scoped access, rate limiting, and network-level protections against requests to internal or private addresses. No system is perfectly secure, but we work to keep your account and usage data protected and to fix issues promptly.
We may update this policy as the API evolves. Material changes will be reflected by the "last updated" date above, and significant changes affecting how we handle your data will be communicated to account holders.
Questions about this policy? Contact us. See also the API Terms of Service.