Our AI agent can ring you back now.Get a call back
Privacy

What we collect, and what we do not

This covers mirakash.com — this website, the demo form on it, and the AI assistant in the corner of it. It is written to be read rather than to be survived, and everything in it is checkable against the site itself.

Last updated 15 August 2026

The short version
  • If you fill in the demo form, we get your email and whatever else you chose to type. We use it to reply to you. Nothing else.

  • If you talk to the AI assistant on this site, the conversation is transcribed and kept, and we read it. It is our own product running on our own infrastructure.

  • Google Analytics runs only if you press Accept. Reject and no cookie is written; if you had accepted before, rejecting deletes the ones already there.

  • Our web server keeps its own access log — IP, page, time — the way every web server does. A cookie banner cannot switch that off, so it is written down here instead.

  • We run no advertising, no remarketing and no cross-site tracking, and we do not sell or share any of this.

  • Ask us to delete any of it — there is a form at /contact for exactly that — and we will, within 30 days.

01

Who we are

Mirakash runs this website and the platform it describes. For everything on this page Mirakash is the data controller: we decide what is collected here and why.

The way to reach us about any of it is the form at /contact. It goes into our own system rather than a shared mailbox, and a person reads it.

02

When you ask for a demo

The form on /demo sends us a work email address, which is the only field it requires, plus anything else you choose to fill in: your name, your company, a phone number, and what you would like an agent to handle.

Along with that it sends three things you did not type:

  • the page you submitted the form from, so we know what you were reading;
  • the site that referred you, and any utm parameters on the URL, so we can tell which campaign or article brought you;
  • your browser's user-agent string.

Your IP address is used to rate-limit the form: more than five submissions an hour from one address is refused. It is held in the running server's memory for that and nothing else, and it does not survive a restart. It is never written to the database, and it is not stored with your enquiry.

We use all of this to reply to you and to arrange a demo. There is no newsletter, no mailing list, and the record is not sold, shared or passed to anyone outside Mirakash. The lawful basis is taking steps at your request before entering into a contract, together with our legitimate interest in answering business enquiries.

The submission is stored in our own Postgres database, running on AWS in eu-central-1 (Frankfurt).

03

When you talk to the Mirakash Guide

There is an AI assistant in the corner of every page on this site. It is our own product, running on our own infrastructure — the same thing we sell — and this part deserves to be said plainly rather than buried: if you talk to it, the conversation is kept.

Every message you send and every reply it gives is written to a conversation record in our console, the same kind of record a customer's phone call produces: the transcript, the page you were on, the language, the timing, and what the exchange cost us to run. We read those records — to find where the agent is wrong, to score it against the same quality rubric we sell to customers, and because a visitor's question is often the most useful product feedback we get. A chat widget is not usually expected to keep a transcript, so we would rather you knew before you typed.

Please do not put anything in it you would not put in an email to us. It is a sales and support assistant, not a secure channel, and it has no way to verify who you are.

If you start a voice conversation it will ask your browser for the microphone first. The audio is streamed to our own voice gateway and transcribed, and the transcript is kept as above. Where a recording of the audio is kept it is stored in our own AWS account alongside the conversation record.

No third party is given the transcript. The models that produce the replies are operated by third-party providers under contract, and the content of your messages is sent to whichever model is handling the conversation in order to answer it — that is what an AI reply is. We do not name a vendor here on purpose: speech recognition, the language model and speech synthesis are separate, swappable stages by design, so any name printed on this page would be out of date the next time we change one.

While the widget is open it also stores a few things in your browser's session storage — a session id, the conversation so far, the panel's size and position, and which pages you have seen in this tab. That is per-tab and is gone when you close it.

04

Analytics, only if you accept

We use Google Analytics 4 (property G-1P6WX2Q1NB) to see which pages get read, in what order, and whether anyone reaches the demo page. It writes _ga cookies to your device, which is exactly the thing you get asked about.

It runs only if you press Accept on the banner. Until then — and permanently, if you press Reject — analytics storage is switched off before Google's tag is allowed to load, so no cookie is written. If you accepted once and change your mind, rejecting also deletes the cookies that were already set.

Accepting turns on analytics and nothing else. We run no advertising, no remarketing and no ad personalisation, so the three advertising permissions in Google's consent model stay denied even when you say yes. Asking for a permission we have no use for is the habit these rules exist to break.

Being straight about the limit of this: with analytics denied, Google's tag still loads and can send a cookieless ping. Nothing is stored on your device and nothing accumulates into a profile of you, but a request does reach Google. Google acts as our processor for what its tag collects.

You can change this decision at any time — the button is at the bottom of this page.

05

The server's own access log

This site is served by a CDN, and the CDN writes down every request it answers: the IP address it came from, the browser's user-agent string, the URL, the time, the response status, and which edge location served it. Those log files land in a storage bucket in our own AWS account in eu-central-1 (Frankfurt) and are deleted automatically after 400 days.

This is not covered by the cookie banner and cannot be. Nothing is stored on your device and no cookie is involved — it is the web server writing down what it was asked for, which is what web servers have done since there were web servers. Switching it off would mean not knowing whether the site is up.

We rely on legitimate interest: keeping the site running, finding what is broken, seeing which AI crawlers read our pages, and having a record if someone attacks it. We query it in aggregate — visitor counts, popular pages, crawler activity — and never to build a profile of an individual. An IP address is still personal data, which is precisely why it is named here rather than quietly left out.

06

What is stored on your device

  • _ga, _ga_G-1P6WX2Q1NB — cookies, Google Analytics, written only after you accept. Google's default lifetime is two years; rejecting deletes them.
  • mirakash.consent.v1 — local storage, not a cookie, and never sent to any server. It holds one word: your answer to the banner. We keep it so we do not ask you again, and it is the one thing here we do not ask permission for, because it exists to record a decision you already made.
  • Guide widget keys — session storage, per tab, cleared when you close the tab. Session id, the conversation so far, panel size and position, pages seen.

There are no advertising cookies, no cross-site trackers, no social plugins, no session recording or heatmap tools, and no fingerprinting.

07

Who else sees any of it

  • Amazon Web Services — hosting, the database and the log storage. Nobody at AWS reads it; it is the ground it sits on.
  • Google — analytics, and only if you accepted.
  • The model and speech providers behind the Guide — the content of your messages, in order to answer them. See section 03.

That is the whole list. We do not sell personal data, we do not share it with data brokers or advertising networks, and there is no arrangement under which anyone gets a copy in exchange for anything.

08

Where it is held

Our infrastructure is in AWS eu-central-1 (Frankfurt): the database holding demo requests, the conversation records from the Guide, and the access-log bucket.

The model and speech providers that power the Guide may process the content of a conversation outside the EU. Analytics data, if you accepted, is processed by Google under its own terms.

09

How long we keep it

  • Access logs — 400 days, then deleted by an automatic lifecycle rule.
  • Demo requests — kept while we are in contact and afterwards as a record of the enquiry.
  • Guide conversations — kept with the conversation record they belong to.
  • Analytics — held by Google under the retention setting on the property.

Honestly: only the first of those has a fixed schedule enforced by a machine. The rest are kept until they are no longer useful, which is a description of practice rather than a promise. If that matters to you, ask us to delete yours and we will.

10

Your rights

You can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct it if it is wrong;
  • delete it;
  • stop processing it, or restrict what we do with it;
  • object to the processing we do on the basis of legitimate interest — the access logs, and using your enquiry to reply to you;
  • send it to you, or to someone else, in a portable form.

You can withdraw analytics consent at any time from the button at the bottom of this page, without emailing anyone.

For anything else, use the form at /contact — it has an option for each of the requests above. We will reply within 30 days. It helps to say roughly what you are asking about — for a Guide conversation, the day and the page you were on — because there is no account here to look you up by, and an email address is often all we have.

If you are not happy with how we handle it, you can complain to the data protection authority for the country you live in.

11

If you spoke to a customer's agent

If you found this page after talking to an AI agent that belongs to one of our customers, this is not the policy you want. In that case the customer decides what their agent does and what is kept from the conversation; we run the platform for them and act on their instructions. Ask them, or write to us and we will pass it on.

The same goes for the console at app.mirakash.com: what happens to a customer's call data is governed by the written agreement with that customer, not by this page.

12

Children

This site is aimed at businesses. We do not knowingly collect anything from children, and we have no reason to. If you believe a child has sent us something, tell us and we will delete it.

13

Changes, and reaching us

This is the first version of this policy, published 15 August 2026. If it changes, the date at the top changes with it, and anything material will say what changed.

Everything on this page goes to one place: /contact.

The terms for using this website are at /terms.

Cookie preferences

Change your mind, any time

This clears your stored answer, switches analytics back off, deletes any Google Analytics cookies already on this device, and asks you again. Nothing is turned on until you choose.

Checking your current choice…