Privacy Policy
Last updated on 2026-08-11
Plain-language summary: your data is used to operate the features you choose. We do not sell data or use your content for advertising. AI, maps, weather, notifications, and integrations share only necessary data when you invoke the feature.
1. Scope and controller identity
This Policy explains how myrna collects, uses, shares, protects, retains, and deletes personal data when you use the app, visit public pages, answer forms, connect services, or contact us. Read it together with the Terms of Use.
For its own processing described here, the controller is myrna, in Brasil. Contact privacidade@myrna.app for privacy matters and data-subject requests.
This Policy covers account holders, members and guests of shared workspaces, public-link visitors, form respondents, and people whose data a user enters. Some integrations act as independent controllers and also apply their own policies.
2. Roles of myrna, organizations, and users
Roles depend on context:
- Accounts and service operations: myrna determines the essential purposes of registration, authentication, billing, security, support, and platform operations and acts as controller.
- Personal content: you choose what to record and myrna processes it to provide the requested features.
- Teams and organizations: an organization may control work content, permissions, and member access; myrna acts as processor for activities performed on its instructions while remaining controller of its own account, security, and billing records.
- Public forms: the form creator decides what to request and how to use responses. Respondents should contact that creator about the collection purpose; myrna remains responsible for platform security and technical operations.
- Third-party data: anyone entering another person’s data must have an appropriate legal basis, provide transparency, and remain responsible for their own use.
3. Personal data we process
We process only the categories needed for the feature in use. Not all data below is collected from every person.
| Category | Examples | Source |
|---|---|---|
| Registration, profile, and authentication | Name, email, avatar, account identifier, sign-in provider, protected credentials, session, language, and theme. | You, your sign-in provider, or the organization inviting you. |
| Workspace content | Notes, notebooks, tasks, calendar, journal, habits, goals, contacts, tables, boards, mind maps, references, comments, tags, links, and feature history. | You and collaborators. |
| Files and media | PDFs, attachments, images, audio, covers, avatars, thumbnails, name, type, size, and storage key. | Uploads or imports you initiate. |
| Bibliographic references | Title, authorship, publication, DOI, ISBN, PMID, URL, citations, PDF-extracted text, and user corrections. | You, an uploaded PDF, and queried bibliographic sources. |
| Collaboration and sharing | Participants, roles, invitations, presence, edits, comments, permissions, public links, and workspace identifiers. | You, the organization, and participants. |
| Forms | Creator-defined fields, answers, timestamp, and a one-way hash of IP plus form identifier for abuse limiting. | Respondent and technical connection data. |
| Subscription and billing | Plan, status, period, customer/subscription IDs, invoices, and payment events. myrna does not receive the full card number. | You and Stripe. |
| AI, OCR, and transcription | Prompt, selected content, necessary context, image or audio submitted for processing, and generated result. | Your action and the AI provider. |
| Location, maps, and weather | Searched address, approximate or selected coordinates, map viewport, and weather conditions. | You, browser/device, and external providers. |
| Notifications | Preferences, reminders, Web Push endpoint and public subscription keys, status, and technical delivery history. | You, browser, and push service. |
| API and MCP | Tokens stored only as hashes, scopes, authorized integrations, and technical operation logs. | You and the authorized external client. |
| Support and communications | Message, attachments, email, privacy requests, reports, and records needed to respond. | You or the contacting person. |
| Technical and security data | IP where needed, time, route, browser, device, session identifiers, failures, usage limits, and security events. | Browser, server, and technical providers. |
| On-device data | Drafts, preferences, caches, synchronization queues, and offline state. | The app stored locally in your browser/device. |
4. Sources and third-party data
In addition to data you provide directly, we may receive data from your chosen social sign-in provider, an inviting organization, collaborators, Stripe subscription events, bibliographic services, and integrations you authorize.
Public work and author metadata may come from Crossref, OpenAlex, DataCite, PubMed/NCBI, Open Library, Google Books, Semantic Scholar, and DOI.org. It may contain errors or be subject to source terms; you can correct it in the app.
If you import or synchronize content, you are responsible for ensuring that you are authorized to transfer it to myrna.
5. Sensitive data and other people’s data
myrna does not generally require sensitive personal data. However, notes, journals, mood records, contacts, and files may contain health, beliefs, sexual-life, biometric, race or ethnicity, religion, political opinions, union membership, or other protected data.
When you voluntarily record your own sensitive data, we limit it to the requested feature and rely on the applicable LGPD Article 11 ground. If content belongs to another person or is processed by an organization, the submitting party must ensure a valid legal ground, legitimate purpose, transparency, and safeguards. Do not record third-party sensitive data unless you can meet those duties.
Avoid entering secrets, credentials, full financial details, or excessive information. AI features and public links require added care because selected data may be transmitted or exposed as described here.
6. Purposes and legal bases
The legal basis depends on the person, feature, and contractual relationship:
| Purpose | Main legal basis | Examples |
|---|---|---|
| Create/manage accounts and deliver requested features. | Contract performance or pre-contract steps (LGPD Article 7(V)). | Authentication, synchronization, storage, collaboration, export, and operational support. |
| Process subscriptions, billing, and mandatory records. | Contract performance and legal/regulatory obligations. | Plan, payment, invoice, dispute, and accounting records. |
| Protect accounts, prevent fraud/abuse/incidents, and maintain stability. | Legitimate interests, contract, credit protection, and establishment/exercise/defense of rights, as applicable. | Logs, rate limits, diagnostics, investigation, and any recovery copies. |
| Respond to support, reports, data-subject requests, and authorities. | Contract, legal obligation, and exercise of rights. | Communications, identity verification, and request history. |
| Run requested optional features. | Contract performance and consent where required. | AI, OCR, transcription, location, weather, notifications, and integrations. |
| Process sensitive data. | Specific consent or another applicable LGPD Article 11 condition. | Sensitive content voluntarily recorded by the data subject or processed on an organization’s instructions. |
| Operate organization workspaces and forms. | Instructions of the responsible controller; myrna also uses its own bases for security and technical operations. | Responses, permissions, and abuse prevention. |
| Comply with orders and defend rights. | Legal/regulatory obligations and establishment/exercise/defense of rights. | Court orders, legal holds, audits, and disputes. |
Where consent applies, you may withdraw it for future processing. Withdrawal does not invalidate prior processing or stop activities supported by another lawful basis.
7. Artificial intelligence, OCR, and transcription
AI features run when you take an action. To fulfill the request, myrna sends the configured provider the prompt and only the necessary content/context. OCR may send an image and transcription may send audio. OpenAI supports compatible functions, and DeepSeek may process text, including as a fallback if the first provider fails before returning an answer.
We do not use your content to train our own model. Provider processing follows the contracts and policies applicable to their API services, which may include technical retention and independent rules. Do not submit data you are not authorized to share, and review every result before use.
AI output may be inaccurate, incomplete, or biased. It does not replace professional judgment and is not used by myrna for solely automated decisions producing legal or similarly significant effects.
8. PDFs, attachments, and bibliographic references
PDFs uploaded to references are kept as private Cloudflare R2 attachments within your plan storage limit. The app may use PDF.js to extract text and suggest catalog metadata.
PDF content is not sent to public bibliographic metadata services. If you request search, capture, or citation discovery, we send only the necessary search term, DOI, PMID, ISBN, URL, or identifier. Extracted text, accepted suggestions, and corrected metadata may be saved with the reference.
You must have the rights or authorization required for every file. Uploading a copyrighted PDF does not make it public, but people you authorize in the relevant workspace may access it.
10. Data sales, advertising, and profiling
We do not sell or rent personal data. We do not use workspace content for behavioral advertising, show third-party ads, or install ad-network cookies.
We may produce aggregate or anonymized capacity, security, and improvement metrics where they cannot reasonably be linked to a person. If re-identification is possible using our own or reasonable means, the data remains subject to this Policy.
11. Providers, integrations, and other recipients
We share data only as needed to operate a feature, fulfill a request, comply with law, complete a legitimate corporate transaction, or protect rights and safety. The table distinguishes essential, conditional, and optional services. Not every recipient is a processor: sign-in, payment, public-source, and integration providers may also act as independent controllers.
| Provider | Purpose | Data shared | When it applies | Location |
|---|---|---|---|---|
| Supabase | Database, authentication, and sessions | Account data, structured content, permissions, and usage metadata | Essential | United States, in the contracted region |
| Cloudflare R2 | Private file storage | Attachments, PDFs, images, audio, covers, avatars, and thumbnails | When you upload files | Global infrastructure, according to account configuration |
| Stripe | Subscriptions, payments, invoices, and fraud prevention | Customer/subscription identifiers, plan, status, and billing data; myrna does not store full card numbers | When billing is enabled or you purchase a plan | United States and other regions operated by Stripe |
| Sentry | Error diagnostics and stability | Internal identifier, route, error type/message, and limited technical metadata; content bodies are removed | Only when monitoring is enabled | United States |
| OpenAI | AI-assisted writing, summarization, OCR, transcription, and generation | Prompt and user-selected content; for OCR/transcription, the corresponding image or audio; generated output | When you invoke an AI feature that uses OpenAI | United States |
| DeepSeek | AI-assisted writing and generation, including as a configured fallback | Prompt, user-selected content, and generated output | When you invoke AI and this provider is configured | China |
| Social sign-in and Google Books lookup | For sign-in: authorized identifier, name, email, and avatar; for references: search term or ISBN | When you choose Sign in with Google or use the corresponding bibliographic search | Global infrastructure | |
| Nominatim / OpenStreetMap | Geocoding, reverse geocoding, and maps | Queried address, coordinates, and language; maps loaded in the browser also reveal IP and viewed area to the tile server | When you search/locate addresses or open the map | United Kingdom/EU and distributed infrastructure |
| Open-Meteo | Journal weather conditions | Approximate coordinates and query language | When you use weather associated with a journal location | EU |
| Crossref, OpenAlex, DataCite, PubMed/NCBI, Open Library, Google Books, Semantic Scholar e DOI.org | Search, capture, and enrichment of bibliographic and citation metadata | Search term, DOI, PMID, ISBN, URL, or other queried identifier; PDF contents are not sent | When you use search, capture, or citation discovery | United States, EU, and global infrastructure, depending on the service |
| Openverse e Iconify | Licensed image search and icon catalog | Search term, requested asset, and technical connection data when the request is made by the browser | When you use these media pickers | Global infrastructure |
| Serviço Web Push do navegador | Delivery of reminders while the app is closed | Endpoint, public subscription keys, and encrypted notification payload | When you authorize notifications; the provider depends on the browser/device | According to Google, Mozilla, Apple, or another browser provider |
| PartyKit | Real-time text collaboration | Document updates, room, and participant presence | Only if real-time collaboration is enabled in the environment | According to configured hosting |
We may also disclose information to authorities, courts, professional advisers, or transaction parties where legally justified and necessary. In a reorganization, merger, or sale, we will require a successor to follow this Policy or provide notice of a material change.
12. International transfers
myrna is internet-based and uses providers with infrastructure in Brazil and abroad. Depending on the feature, data may be processed in the United States, EU, United Kingdom, China, or global infrastructure. DeepSeek may process data in China when invoked.
Where the LGPD applies, a transfer will use a mechanism permitted by Article 33 and ANPD rules, such as adequacy, standard contractual clauses, approved specific clauses, binding corporate rules, specific consent where appropriate, or another legal condition. We apply minimization and assess data nature and purpose before enabling a flow.
Request more information about destinations, recipients, and safeguards at privacidade@myrna.app.
14. Retention and disposal
We retain data for the shortest period compatible with the purpose, reasonable expectations, contract, and legal duties. A specific legal hold may override the periods below.
| Data | Retention criterion |
|---|---|
| Active account and content | While the account/contract is active and until the deletion date shown in the app, unless you delete it earlier. |
| Trash | Generally auto-deleted after 30 days. References with PDFs may be protected from automatic purging to avoid orphaned files until you empty trash, remove the PDF, or permanently delete. |
| Expired trial or canceled subscription | Until the deletion date shown in the app. Grace periods can vary by plan and administrative configuration and are disclosed before removal. |
| Account deletion | We start deleting database content and associated private files. Data required for law, disputes, fraud prevention, or a valid hold is isolated and retained only as needed. |
| Billing and tax records | For periods required by tax, accounting, consumer, and anti-fraud rules. |
| Access and security logs | As needed for security and law. Where Brazil’s Internet Civil Framework applies to an application provider, application access logs are confidentially retained for 6 months. |
| Form responses and technical hash | While the form/controller retains the response or until valid deletion, subject to legal holds. |
| Web Push and API/MCP tokens | Until disabled/revoked or account deletion. Personal tokens are stored only as hashes. |
| Error telemetry | Only when Sentry is enabled and for the minimum configured diagnostic/security period. |
| On-device data | Until synchronized, app-cleared, or removed by you from the browser/device. |
| External and AI providers | According to the request, our contract, and provider rules, which may include independent technical retention. |
Deletion may not instantly remove residual copies in any recovery systems, queues, or immutable records. Such copies must not return to ordinary use and are deleted or overwritten under the applicable technical cycle.
15. Export, portability, and account deletion
The app exports structured account data in JSON. Because of format and size limits, it may list attachment metadata/references without embedding binary files; separately download PDFs and other files you wish to keep before deleting the account.
Account deletion is permanent: it removes access, starts database-content deletion, and attempts to purge associated private storage objects. Organization content may remain under that organization’s control where another legal basis and workspace ownership rule applies.
If an in-app tool does not cover your format or request scope, contact privacidade@myrna.app. We may verify identity and clarify scope before taking an irreversible action.
16. Security and Vault limitations
Risk-based safeguards include encrypted connections, row-level security (RLS), private storage with temporary URLs, user/workspace segregation, hashed personal tokens, rate limiting, and content-field removal from error telemetry. Full payment card data stays with Stripe.
The optional Vault protects only compatible locked content, such as locked notes/notebooks and encrypted journal data. It uses AES-256-GCM and a PBKDF2-SHA-256-derived key; WebAuthn PRF may protect/unlock the key on supported devices. The server receives ciphertext and a wrapped key, but metadata, permissions, attachments, and other modules do not become end-to-end encrypted merely because Vault is enabled.
If you unlock Vault content and choose to send it to AI, sharing, or an integration, the selected data leaves the Vault boundary to perform your command. Protect passwords, devices, recovery keys, and sessions. No security method eliminates all risk.
17. Internal access, support, and legal requests
We do not routinely read your content. Administrative access is restricted to authorized personnel and what is necessary to operate, protect, or support the service, investigate abuse, fulfill your request, comply with law, or exercise rights. Confidentiality and data minimization apply.
Government and court requests are assessed for authority, validity, and scope. Where permitted and appropriate, we may seek to narrow a request and notify the affected person. Data may be preserved under a valid order despite a deletion request.
18. Security incidents
We maintain processes to detect, assess, and respond to incidents. If an incident may create relevant risk or harm, we will notify ANPD and affected people within applicable regulatory requirements, considering the data and safeguards involved.
If you detect unauthorized access, a lost device, or a vulnerability, change credentials, revoke sessions/tokens where possible, and immediately contact suporte@myrna.app.
19. Your LGPD rights
Subject to LGPD conditions, you may request:
- confirmation and access, in a simplified form immediately where possible or a complete statement within 15 days;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or unlawful data;
- portability, subject to regulation, trade/industrial secrets, and technical feasibility;
- deletion of consent-based data, subject to legal retention exceptions;
- information about public and private entities receiving shared data;
- information about refusing consent and its consequences;
- consent withdrawal and objection to non-consent processing where the LGPD is breached;
- review of solely automated decisions affecting your interests and clear information on the criteria used;
- petition to ANPD and consumer-protection bodies, and judicial remedies.
Rights are not absolute. We may retain only what is required for legal duties, appropriately anonymized research, legitimate transfers, controller-exclusive anonymized use, and other statutory exceptions.
20. Exercising rights and appeals
Use profile tools to correct, export, or delete data, or email privacidade@myrna.app. Identify the account and describe the right. Do not send full identity documents in the initial message.
To protect you, we may verify identity, representation, and relationship to the data. We respond without charge within legal deadlines and explain any need for more information. For organization spaces or forms, we may route the request to the responsible controller.
If dissatisfied, reply to the same case for review. You may also petition Brazil’s National Data Protection Authority (ANPD) and consumer-protection bodies.
21. Children and adolescents
The service is not directed to children under 13. People from 13 to the applicable age of majority must use myrna with guardian awareness/assistance where required. Children’s and adolescents’ data must be processed in their best interests; a child’s data generally requires specific, highlighted consent from at least one guardian, subject to statutory exceptions.
If you believe a child provided data without proper authorization, contact privacidade@myrna.app. We will investigate and delete or regularize the processing as required.
22. Automated decisions
myrna may automate operational tasks such as plan-limit checks, trial expiry, abuse protection, sorting, and AI suggestions. We do not use these routines to make solely automated decisions with legal or similarly significant effects involving credit, employment, health, or other rights.
If an automated operational decision restricts your account and you believe it is wrong, request human review at suporte@myrna.app.
23. External links, embeds, and services
Content may contain third-party links, images, maps, and videos. Opening a map or interacting with a YouTube, Vimeo, or other embed connects your browser directly to that provider and transmits technical data, including IP. The provider’s policy governs its processing.
We do not control external sites or their practices. Check the source before authorizing sign-in, importing content, installing an MCP client, or submitting information.
24. Changes, governing law, and contact
We may update this Policy for product, provider, or legal changes. The date above identifies the current version. Material changes will be highlighted in the app or communicated appropriately before taking effect where required. Prior versions may be requested from the privacy channel.
Brazilian law governs this Policy, particularly the LGPD (Law 13,709/2018), Internet Civil Framework (Law 12,965/2014), and Consumer Defense Code where applicable.
Controller: myrna.
Privacy and rights: privacidade@myrna.app.
Support: suporte@myrna.app.