Skip to content
Mirific
Platform Vantage Customers Company
Sign in Request a demo
PlatformVantageCustomersCompany
Sign in Request a demo

Privacy Policy

Mirific Technologies Inc.

Last updated: July 20, 2026


1. Who we are

Mirific Technologies Inc. (“Mirific,” “we,” “us,” or “our”) is a company incorporated in British Columbia, Canada. We provide an execution intelligence platform that helps organizations connect their strategic plans to the operational and financial systems where their work happens.

This Privacy Policy explains what information we collect, how we use it, who we share it with, how we protect it, and the rights and choices you have. It applies to the Mirific platform at mirific.ai and its associated applications and services (the “Service”).

Data controller. For the purposes of applicable data protection law, the controller is Mirific Technologies Inc., 6620 East Boulevard, Vancouver, BC V6P 5R1, Canada.

Contact. Privacy questions and product support: support@mirific.ai.


2. Information we collect

Account and profile information. When you create an account or accept an invitation, we collect your name, email address, role, and organization. If you sign in through a third-party identity provider, we receive the basic profile information that provider shares to establish your identity.

Information you provide about your business. The Service works by capturing what you tell it about your organization: strategic goals, initiatives, projects, deliverables, team structure, and the financial figures you choose to enter, such as revenue, cash on hand, operating burn, and headcount cost. This information is provided by you and is the core of what the Service reasons over.

Information from systems you connect. If you choose to connect a supported third-party system, we read a defined, limited set of information from it, described in Section 3.

Usage and technical information. We collect information about how the Service is used, such as pages viewed and actions taken, together with standard technical data such as IP address, browser type, and timestamps, for security, reliability, and product improvement.

We do not intentionally collect special categories of sensitive personal information, and we ask that you do not enter such information into the Service.


3. Connected systems, including QuickBooks and Xero

Mirific lets you connect supported third-party systems so that figures you would otherwise enter by hand can be read directly. Connections are always initiated by you, are read-only, and can be disconnected by you at any time from within the Service.

Accounting connections (QuickBooks Online; Xero when available)

What we read. We read only a small number of aggregate financial figures derived from summary reports: cash on hand, annual revenue, an estimate of monthly operating burn, and payroll cost. These are read from summary report endpoints (such as the Balance Sheet and Profit and Loss reports).

What we never read. We do not read, request, or store your customers, vendors, employees as individuals, invoices, bills, payments, individual transactions, journal entries, line items, accounts-receivable or accounts-payable detail, tax records, attachments, or per-person payroll records. Our access is technically constrained to summary report endpoints; the connection cannot retrieve transaction-level or individual-level data.

Read-only. The connection is read-only. Mirific cannot create, modify, or delete anything in your accounting system.

Why we read it. These figures populate your financial view in Mirific and allow the Service to reason about your plan against your stated financial position. When a figure read from your accounting system differs from a figure you previously entered yourself, we show you both. We never silently overwrite what you told us.

Connection credentials. The credentials that authorize a connection are encrypted at rest using envelope encryption under a dedicated, automatically rotated key management service key, isolated per environment. Every decryption is logged and auditable.

How you control it. You can disconnect at any time. On disconnection we immediately stop reading new data and the connection’s credentials are no longer usable by the Service. Figures previously synced remain in your workspace as part of your organization’s historical record, clearly labeled with their source and date, and are deleted when your account is deleted or earlier on request to support@mirific.ai.

Our access to and use of information received from Google, Intuit, and Xero APIs complies with those providers’ applicable developer and API policies, including limited-use requirements.


4. How we use information

We use the information we collect to:

  • provide, operate, and maintain the Service;
  • generate the strategic and financial reasoning, summaries, and reports that are the Service’s core function;
  • authenticate you and secure your account and your organization’s data;
  • send transactional communications such as invitations and password resets;
  • monitor, improve, and secure the Service; and
  • comply with legal obligations.

We do not use your business or financial information for advertising, and we do not sell it.


5. AI processing

The Service uses large language models to generate reasoning, summaries, and reports. To do this, relevant information from your workspace, which can include the business and financial figures described above, is sent to our model provider to be processed into the output you see.

Our model provider is Anthropic. Information sent for processing is governed by Anthropic’s commercial API terms, under which data we send is not used to train Anthropic’s models and is automatically deleted by Anthropic within 30 days of processing.

We do not use your data to train third-party models, and our agreements with our providers prohibit them from doing so.


6. How we share information

We do not sell personal or financial information, and we do not share it for advertising. We share information only as follows.

Within your organization. Information in your organization’s workspace is visible to other authorized members of that organization according to their roles.

With sub-processors. We use a small number of service providers to operate the Service. They process information only on our instructions and only to provide services to us. Our sub-processors as of the date above are:

Sub-processorPurposeData involved
Amazon Web ServicesCloud hosting, storage, infrastructureAll Service data, encrypted at rest
AnthropicLarge language model processing (Section 5)Business and financial information relevant to a given request
Postmark (ActiveCampaign)Transactional email deliveryEmail addresses and message content; no financial data

We maintain this list on this page and update the “Last updated” date when it changes. If we add a sub-processor that processes customer financial data, we will provide notice through the Service or by email before the change takes effect.

For legal reasons. We may disclose information if required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, safety, or property of Mirific, our users, or the public.

In a business transfer. If Mirific is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy’s protections.


7. Security

We treat connection credentials and customer financial data as the most sensitive information we hold, and our security program is designed accordingly:

  • encryption in transit for all Service traffic and encryption at rest for stored data;
  • envelope encryption of connection credentials under dedicated, per-environment, automatically rotated keys, with every decryption logged and auditable;
  • organization-level data isolation enforced at the infrastructure layer, not only within the application;
  • read-only, minimum-scope access to connected systems, technically constrained as described in Section 3;
  • least-privilege internal access controls and audit logging.

We maintain a security program aligned with recognized industry frameworks and are progressing toward independent certification of that program. No method of transmission or storage is perfectly secure, but we design our systems so the most sensitive data receives the strongest available protection.


8. Retention

We retain information for as long as your account is active. When an organization’s account is deleted, associated workspace content, including synced financial figures, is deleted from active systems within 30 days, and from encrypted backups within 90 days thereafter, except where longer retention is required by law or necessary to resolve disputes or enforce agreements. Transactional email records and operational logs are retained on shorter operational schedules.

You may request earlier deletion of specific information at any time via support@mirific.ai.


9. Your rights and choices

Depending on where you are located, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact support@mirific.ai. We respond within the timeframe required by applicable law, and in any case within 30 days.

You can disconnect any connected system at any time from within the Service, and you can request deletion of your account by contacting us.

Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including the right to access personal information we hold and to challenge its accuracy, and the right to complain to the Office of the Privacy Commissioner of Canada.

The Service is currently offered to organizations in North America. If we begin serving users in the European Economic Area, the United Kingdom, or California, we will add the disclosures those laws require before doing so.


10. International data transfers

Our infrastructure is hosted in the United States (AWS, US West region). If you access the Service from outside the United States, including from Canada, your information is transferred to and processed there. We put appropriate safeguards in place for such transfers, including contractual commitments from our sub-processors.


11. Children

The Service is not directed to individuals under the age of majority in their jurisdiction, and we do not knowingly collect their personal information.


12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date at the top and, where appropriate, notify you through the Service or by email before the change takes effect. Your continued use of the Service after an update means you accept the revised policy.


13. Contact

Mirific Technologies Inc. 6620 East Boulevard, Vancouver, BC V6P 5R1, Canada Privacy and support: support@mirific.ai

Mirific

Mirific Technologies Inc. connects strategy to the systems where work happens, so daily decisions move the business toward what leadership set out to achieve.

The execution intelligence company

Platform

  • Overview
  • Architecture
  • The operating loop
  • Security

Vantage

  • Advisory practice
  • AI opportunity scans
  • Process automation

Customers

  • Customer stories
  • What leaders say

Company

  • About
  • Team
  • Request a demo

Legal

  • Privacy
  • Terms

© 2026 Mirific Technologies Inc. All rights reserved.

Sign in