mirabotA Mirus Ventures system
The systemPrinciplesmirus.ventures ↗
Log in

Legal · Privacy

Privacy Policy

Effective date: September 12, 2026

This policy covers the Mirabot browser extension and the Mirabot web app (together, "Mirabot"), provided by Mirus Ventures ("we," "us," "our"). It explains what data Mirabot collects, why, and how it's handled.

What Mirabot does

Mirabot is an AI agent that acts on your behalf inside your browser: it reads pages you direct it to, captures knowledge you choose to save, chats with you about what it finds, and — only once you turn on Browser Control — performs actions like clicking, typing, and navigating on your behalf. This is Mirabot's single purpose: everything described below exists to support one of these directly, not for any separate or unrelated use.

Mirabot acts using the browser session you're already logged into. It does not store a separate vault of your website passwords, and it does not read or transmit your browser cookies or session tokens.

What we collect, and why

Account and connection data. When you connect an account, we store your authentication credentials (an API key or access/refresh tokens), your name and email, and your workspace selection, in the extension's local browser storage. This is what keeps you signed in between sessions.

Pages you explicitly capture. When you choose to save a page to Mirabot, we send the page's URL, title, and extracted text content (plus basic metadata like author or publish date, when available) to our servers, so it becomes part of your saved knowledge. This only happens when you take the capture action — Mirabot doesn't capture pages passively in the background.

Chat messages. When you chat with Mirabot, we send the text you type, along with the URL and title of your current page (for context), to our servers to generate a response.

Browser Control actions (only if you turn this on). With Browser Control enabled, Mirabot can take actions in your browser at your (or the AI agent's) direction — clicking, typing, navigating, and reading page content. To support this, we may send:

  • Screenshots of the tab Mirabot is actively controlling
  • Text extracted from the current page (what's visible, not hidden data)
  • The URL and title of pages Mirabot navigates to

Browser Control is off by default. You turn it on explicitly, and can turn it off at any time from the extension's popup.

Built-in safety limits. Mirabot maintains an internal list of sensitive sites (banks, password managers, and similar) where it will not capture, read, or act, regardless of your settings. This list is a best-effort safety measure, not a guarantee — it can't cover every sensitive site that exists, so use your own judgment about where you enable Browser Control.

What we don't do

  • We don't read or transmit your browser cookies, session tokens, or saved passwords.
  • We don't use any third-party analytics, advertising, or tracking services in the extension.
  • We don't sell your data or build advertising profiles from it.
  • We don't collect your general browsing history — only the specific pages you capture, chat about, or direct Mirabot to act on.

Where your data goes

Mirabot runs on Mirus Ventures' own servers (api.dwyerlab.com and agent-api.dwyerlab.com). To do its work, Mirabot passes parts of your data to the service providers listed below. Each one receives only what that task needs, and may use it only to provide the service to us. We don't sell your data, and none of it is used for advertising.

AI model providers. Your chat messages, the pages and files you give Mirabot, and the text Mirabot writes back are sent to the model provider that handles the request. Today those are Anthropic, OpenAI, Google, and OpenRouter, a gateway that passes a request on to a model host such as Novita or Together. We can also route a request to Meta, Fireworks, DigitalOcean or xAI when it asks for one of their models. Some requests may instead be served by a model we run ourselves, on our own hosting. In that case your content stays with us and our hosting providers, and no model provider receives it.

How we set up those providers. We use each provider's business terms, under which your prompts and the model's replies are not used to train their models. Where a provider offers a setting that keeps nothing at all, we turn it on — we do this for OpenRouter and xAI today. The other providers keep a copy for a short time to check for abuse: up to 30 days at Anthropic and OpenAI, and up to 55 days at Google. We do not use any provider tier that trains on customer data, and our software refuses such a request.

Search and page reading. When you ask Mirabot to research something, your question and the pages it reads are sent to search and page-reading services: Tavily, Brave Search, Exa, Perplexity, Firecrawl, Scrapfly, Bright Data, and X.

Voice. If you speak to Mirabot, your audio goes to Deepgram to be turned into text. If Mirabot speaks to you, the text goes to Cartesia or ElevenLabs to be turned into audio.

Hosting. DigitalOcean and Amazon Web Services host our servers, database, file storage and email handling.

This list is the current one. If we add a provider that receives your content, we update this page.

Your controls

  • Disconnecting your account (via Logout in the extension) clears your stored credentials from local browser storage.
  • Browser Control can be turned off at any time; while off, Mirabot cannot click, type, navigate, or capture screenshots.
  • Requesting deletion of your account and associated data: contact us at the address below.

Children's privacy

Mirabot is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If we materially change what data we collect or how we use it, we'll update this page and, where required, provide prominent notice within the extension itself before the change takes effect.

Contact

Questions about this policy, or requests regarding your data: privacy@mirabot.app

mirabotThe applied-AI agent
MIRUSventures
© 2026 Mirus Ventures · Built in-housePrivacy Policy · Terms of Service · A Mirus Ventures system · mirus.ventures