Miracue · privacy

Privacy at Miracue

What the app stores, where, and what we can and cannot see.

updated 31 August 2026

Miracue is made by Lumira Studio, a video production company in Hertfordshire. We built it for our own shoots, and we use it the way you do. The short version: we designed Miracue so that trusting us is mostly unnecessary.

If you use Miracue without an account

Your scripts live in your browser, on your device. They are not sent to us, and we have no way of reading them.

There is no route that uploads a guest script. Pressing "Share scripts" as a guest introduces the free account rather than sending anything, because moving scripts between devices is what accounts are for.

If you have an account

Scripts on an account are stored in Miracue's database so they can appear on your other devices. They are encrypted at rest with keys we hold; we do not analyse them, use them for advertising, or sell them. An account is your email address. We use it to sign you in, to send the things you ask for, and to tell you about anything that affects your account, your payments, or this policy. If you turn on occasional emails in your account preferences, we will also write now and then about Miracue itself: what has changed, and the occasional question. That setting is off unless you choose it, every one of those emails carries a one-click way out, and turning it off changes nothing else about your account. We never sell your address and never share it for anyone else’s marketing; our emails are delivered by Brevo, which processes the address for that purpose only. A password, if you choose to add one, is stored in a protected, one-way form. Deleting your account destroys the key that encrypts your scripts, which makes every stored copy of them permanently unreadable, backups included.

If you send us feedback from inside the app, or tell us how you found Miracue, we keep what you wrote so that we can act on it and, where it needs an answer, reply to you. Both are optional, both can be skipped, and neither changes anything about your account. We ask how you found us because Miracue carries no analytics, and what a person tells us is the more useful half of the answer.

The other half we record ourselves, and it is worth being exact about. When you first arrive at this site from somewhere else, your browser keeps one small note of where you came from: the campaign tag on the link if it had one, and the domain of the site that sent you, never the full address you came from. That note stays in your browser and is sent nowhere. If you go on to create an account, it is handed over once and attached to it, so we can tell whether the people signing up arrived from a video, an article or a search. If you never create an account, it is never sent. It is cleared from your browser as soon as it has been used, it is written once and never updated, it is not a cookie, and it neither identifies you nor follows you to any other site.

Content you keep in an account, meaning scripts, shot lists, take notes and voice notes, is stored on our servers for one purpose: so it can follow you between the devices you sign in on. It is protected in transit, access is restricted to your account, and it is used for nothing beyond operating the service. It is not read, analysed, used for advertising or model training, shared, or sold. Voice notes are recordings you choose to make, and uploading them is their purpose: they travel with the script so an editor elsewhere can listen. Deleted scripts sit in your bin for 30 days and are then removed, along with any voice notes attached to them.

We continue to strengthen how account content is protected, and any material change to the protections described here will be dated on this page.

Share links

A share link, made from an account, encrypts your scripts on your device before anything leaves it. The key travels in the link itself, in a part of the address that browsers never send to any server, so what we store is unreadable to us. Anyone with the link can open the scripts, so treat it like a key. A share link expires seven days after you create it, whatever happens in between, and you can delete it sooner from the same screen.

One practical note: because the link is the only key, we cannot recover what is behind it if the link is lost. Scripts in an account do not have this problem - signing in on any device brings them back.

If you write to us

The Get in touch form stores your message, your email address, your name if you gave one, and the network address it was sent from, which we use to slow abuse of the form. That is what lets us read the thread, reply to it, and keep the conversation's history; our lawful basis is our legitimate interest in answering the people who write to us. The notification that carries your message to our inbox is delivered by Brevo, the same processor that delivers sign-in emails, and a reply goes to the address you gave and nowhere else. Messages are kept while the conversation is live and then deleted; ask in a message and we will delete its thread sooner.

Voice

When you use voice follow, speech recognition runs on your device, using a model the app downloads once and keeps. Your audio never leaves the device and nothing you say is sent to a server, ours or anyone else's. You can verify this with your browser's developer tools open, and we would rather you did than took our word for it.

The Chrome extension

Miracue also comes as a Chrome extension, which puts the same prompter in the browser's side panel. Everything above applies to it unchanged: what you paste stays in your browser, on that computer; speech recognition runs on your device; your audio is never sent anywhere; and there are no analytics of any kind inside it.

It asks Chrome for very little. Storage, to remember your scripts and your display settings on that computer. The microphone, and only while you switch voice follow on. And access to miracue.app, so that if you are already signed in there the panel can open the scripts in your own library. It never handles your password, because it uses the session your browser already holds, and it reaches no other website apart from the one-off speech model download described above.

Reading in the panel needs no account, exactly as it does on the web.

What we do not do

Inside the app there are no analytics, no tracking scripts, no advertising tags and no cookies beyond one essential session cookie that keeps signed-in devices signed in. The public pages of this site count visits with Ahrefs' privacy-friendly analytics, which uses no cookies and collects no personal data; the app itself carries none. The one note your browser keeps of where you first arrived from is described above, and it is not a cookie either. We do not sell data, share data or profile anyone.

What any web server sees

Like every website, our hosting provider keeps standard access logs: the IP address a request came from and the page it asked for. These are used for security and for counting how busy the service is, and they are kept briefly.

The app and its fonts are served from our own domain, so opening Miracue does not announce you to anyone else. There is one exception, and it happens once: the first time you use voice follow, the speech model is fetched from the servers of the company that publishes it, which sees that request the way any website sees a visitor. After that the model lives on your device and is never fetched again.

Two of our pages carry a short film, and it is built so that the same promise holds. Opening those pages loads nothing from YouTube: what you see is a still image served from our own domain, with a play button. Only if you press play does the player load, from youtube-nocookie.com, and from that moment YouTube sees you the way it would on any site that embeds a video. If you never press it, nothing about you reaches Google at all.

Your rights, wherever you are

Miracue is used all over the world, so this section covers the main regimes rather than only ours.

The United Kingdom and the European Union

Lumira Studio Limited is the data controller. Under the UK GDPR and the EU GDPR you can ask what we hold about you, ask for it to be corrected or deleted, object to processing, or ask for a copy of your data. Our lawful basis is the performance of the service you asked for; we do not process anyone's data for marketing or profiling. Our servers are in the United Kingdom, which the European Commission recognises as providing an adequate level of protection, so no separate transfer mechanism is required for data moving from the EU to us.

The United States

We do not sell personal information, we do not share it for advertising, and we do not profile anyone, so the rights created by state privacy laws such as California's are already met by the way the app works. If you live in California, Colorado, Virginia, Connecticut or a state with comparable law, you can still ask us to confirm, correct or delete what we hold, and we will treat the request the same way as any other.

Everywhere else

Ask us for the same things. We do not intend to run one standard for some countries and a weaker one for others.

For guests the answer to most of these requests is short: we hold nothing we can read, and nothing that identifies you. For accounts, email us and we will delete the account and everything in it.

If you think we have handled your data badly you can complain to the Information Commissioner's Office in the UK, or to your own supervisory authority in the EU, though we would appreciate the chance to put it right first.

Miracue is not directed at children, and we do not knowingly collect data from anyone under 13.

Changes and contact

If this page changes, the change will be dated here and noted on the What's new page. Questions to [email protected]. I read these myself.

Last updated 8 September 2026. Miracue is operated by Lumira Studio Limited, Hertfordshire, United Kingdom. Registered in England and Wales, company number 15280964.