Skip to content

MirageCFO

Privacy

MirageCFO is used by businesses anywhere in the world. This notice describes what the service actually holds about you and your business, why it holds it, and what happens to it — written from the system as it is built, not from a template.

Last updated

Read this first

This notice was drafted in-house against published law rather than by outside counsel, and it is not legal advice to you. It is written to be accurate rather than reassuring: where the product does not do something, it says so.

Who publishes MirageCFO

MirageCFO is a product of Mirage Global Technologies LLC, a limited liability company registered in Wyoming, United States under filing number 2026-002050350, with its mailing address at 1621 Central Ave #8434, Cheyenne, WY 82001, United States. That company decides what this service does with your data, and it is the one to write to about it.

Questions about this notice, and requests to see, correct or erase your data, go to [email protected]. What the product can and cannot actually remove is set out below, and the Contact page states the limits of that route plainly.

What MirageCFO holds

Your account
Your name, your email address, the interface language you chose, and the time you last signed in. Your password is never stored in readable form — only a one-way hash of it, from which the password cannot be recovered.
Your organisation and companies
The account that owns your subscription, and each company under it: its name, its industry, the reporting currency and timezone you chose for it, who its members are, what role each member has, and the invitations you send.
The financial data you bring
Everything you import or enter: transactions, the files you import them from, financial accounts, categories, the categorisation rules you create, the corrections you make, exchange rates applied, and the reports you save together with the figures they were built from.
Your use of the AI CFO
The question you asked, the answer you were given, which of your own figures the answer was drawn from, which model answered, and how long and how much the request cost. This record cannot be edited or deleted by the application — it is what makes it possible to prove afterwards that an answer came from your data.
The people you invoice
When you issue an invoice or record a bill you enter the other side of it: a customer or supplier name, and optionally their email address, phone number, tax number, address and country. These are often details about a real person, entered by you rather than by them. They belong to your company, are used only to produce your own documents and reports, and are never shared with other companies using MirageCFO.
Resetting your password
When you ask for a password reset, the service stores a one-way hash of the reset token, when it was issued, when it expires and whether it has been used — never the token itself — and sends the link to your email address. Completing a reset signs out the existing sessions. Nothing else about the request is kept.
Integration keys
If you create a key for the read-only public API, the service stores a one-way hash of it, the name you gave it, the scopes you chose, when it was last used, and which membership it acts as. The key itself is shown once and never stored, and it cannot outlive the membership it belongs to.
Sessions and security
For each signed-in session: the device or browser it belongs to, its network address, the browser identification string it sent, when it was last used, and when it expires.
A record of changes
Financial and administrative changes are recorded with who made them, when, what the value was before and after, and the network address and browser the change came from. The application can add to this record but cannot alter or erase it.

Why MirageCFO holds it

  • To run the service you signed up for: importing, categorising, calculating, reporting and exporting your figures.
  • To keep each company's data separate and to decide who inside your company may see or change what.
  • To keep the service secure and usable — including limiting how often requests can be made from one network address, so that one user cannot exhaust the service for everyone.
  • To make financial changes auditable, so that a figure can always be traced back to who produced it and from what.
  • To operate and repair the service: diagnostics, error investigation and backups.

Your figures are used to answer your questions. They are not sold, and they are not shared with other companies using MirageCFO.

What leaves the service when you use the AI CFO

The AI CFO is answered by a large language model operated by a third party — Anthropic, whose Claude models are the only ones MirageCFO is built to use today. When you ask a question, what is sent to that provider is:

  • the question you typed;
  • a short profile of the company you are asking about — its name, industry, country and reporting currency;
  • the figures the assistant retrieves in order to answer, which can include individual transactions such as amounts, dates, descriptions and counterparties.

Nothing is sent to the model provider unless you use an AI feature. If the AI CFO is not configured on the service, those routes are simply unavailable and nothing leaves.

This notice does not describe how that provider stores or uses what it receives, because that is governed by our agreement with them and not by this page. A precise, named list of every third party that processes your data must be published before MirageCFO is offered publicly. It does not exist yet, and this notice does not pretend otherwise.

Where your data is held

Your company's data is held in one region at a time, on infrastructure the company controls, and it is not spread across regions for convenience. Backups are made daily and encrypted, and the key that opens them is kept away from the machines that hold them — so reaching the servers is not the same as reading a backup.

Two things leave that region, and only those two. When you use the AI CFO, the question and the figures the engine has already computed are sent to the model provider, which operates in the United States — described in full below. And a password-reset email travels to whoever operates your mailbox, wherever that is. Nothing else about your account or your ledger goes anywhere else.

If you need to know the current region before deciding what to put into the product, ask and we will tell you. It is deliberately not printed here: a page that names today's data centre becomes untrue the day it changes, and a privacy notice that has quietly gone out of date is worse than one that tells you where to ask.

The company that publishes MirageCFO is registered in the United States, so it may be required to respond to a lawful order from a United States authority. We tell you this because it is true of the arrangement, not because it has happened.

How your company's data is kept apart

Separation between companies is enforced by the database itself, not by application code remembering to filter. Each company's rows are readable only in the context of that company, and the application connects with an identity that cannot override that rule. Someone who is not a member of your company does not receive an error explaining that your company exists — they are told there is nothing there.

Cookies

MirageCFO sets exactly one cookie, and only after you sign in. It holds your session so that you are not asked for your password on every request. It cannot be read by scripts in the page, it is sent only to the authentication routes of our own service and to no other address, and it is not sent at all when a request originates from another site.

MirageCFO sets no analytics, advertising or third-party tracking cookies, and loads no third-party tracking scripts. That is why the site has no cookie consent banner: there is nothing optional to consent to.

What leaves the service otherwise

One email leaves the service: the password-reset link, sent to the address you signed up with. It is sent by our own mail server rather than by a third-party mailing service, so your address is not handed to a marketing platform. Like any email, it then travels to whoever operates your mailbox, and they see it as they see any message.

MirageCFO sends you nothing else — no reports, alerts, newsletters or product mail — and there is no facility to make it do so.

Your rights over your data

Data-protection law differs by where you live, and several of them give people the same core rights: to know what is held, to get a copy, to correct what is wrong, to have data deleted, and not to be discriminated against for asking. MirageCFO answers all of those requests the same way, from the same address, regardless of which law you are covered by — because sorting people by jurisdiction before answering is worse than simply answering.

Write to [email protected]. We will ask enough to be sure the request comes from you, and no more.

  • A copy of your data does not need a request: exports of your ledger, reports and documents are built into the product and available to you at any time.
  • Correction is likewise in your hands for anything the product lets you edit.
  • Deletion is answered by a person, and the limits are real ones described just below rather than a policy we hide behind.
  • We do not sell your personal information, we do not share it for advertising, and there is no advertising in the product to share it for.
  • We do not use your financial data to train any model. It is sent to the model only to answer the question you asked, and the record of that is kept for you to audit.

Whose data, and who answers for it

For your own account details — your name, your email, your sessions — the company that publishes MirageCFO decides what happens and answers to you directly. For the financial records you put into a company, including details of the people you invoice, your business decides what is collected and why; MirageCFO holds and processes it on your instructions. If someone you invoiced asks us about their details, we will point them to you, because you are the one who can answer.

Keeping, deleting, and what is not promised

Some things are deliberately hard to erase, because a financial record that can be quietly removed is not a financial record:

  • Deleting a transaction hides it and keeps it recoverable, rather than destroying it immediately.
  • The record of changes and the record of AI answers are append-only. The application can add to them; it cannot rewrite or remove them.
  • A saved report keeps the figures it was built from, even after you import more history.

Stated plainly

MirageCFO does not currently offer a self-service control that deletes your account and everything in it, and this notice states no retention period, because no automatic deletion schedule is in place. Requests to see, correct or erase your data are answered by a person at [email protected] — that route exists and is read. What it cannot do is promise a timetable that nothing automated enforces, or reach inside the append-only records described above.

What this notice does not claim

  • MirageCFO has not been independently audited or assessed against any security or data-protection standard.
  • No claim is made that the service meets the requirements of any particular data-protection regime.
  • No promise is made that the country your data is held in will never change. If it does, this page changes with it and the date at the top moves.
  • No retention or erasure timetable is guaranteed, because none is automated.
  • No complete list of the third parties that process your data is published yet.

Data-protection law where you live may give you rights over your data. This notice does not restate those rights or promise a process that does not yet exist; it tells you what the service does today so that you can decide what to put into it.

Changes to this notice

When what the product does changes, this page changes with it, and the date at the top moves. Material changes will not be made silently.