Last updated October 8, 2026. This policy explains what Mirella LLC ("Mirella", "we", "us") collects through the Mirella platform at portal.mirellahq.com, and what we do with it. The Mirella website at mirellahq.com has its own privacy policy.
Mirella provides the platform to registered investment advisory firms. Advisors at those firms use it to manage their clients' portfolios, taxes and meetings. We process client information on the firm's behalf and on its instructions, under our agreement with the firm. The firm remains responsible for its own clients' information, and its own privacy notice to its clients continues to apply.
We don't use advertising or analytics trackers or third-party tracking scripts. The platform's only cookies keep you signed in and remember your demo mode setting. Because we don't track you, the platform works the same whether or not your browser sends a "Do Not Track" signal.
We don't sell or rent personal information, and we don't use it for advertising.
Your Google connection is held by our sign-in provider, Clerk. Each time the platform needs your calendar or mail, it asks Clerk for a short-lived access token for your account and does not store it. Because the token is your own, one advisor's connection can never read another advisor's calendar or mailbox.
gmail.readonly permission and contains no code that sends, changes or deletes mail. It searches only for messages to or from the email addresses of clients you can see in the platform, and shows you each thread's subject, date and which of your clients are on it, with a link that opens the thread in Gmail. Message contents are not stored by the platform.Gmail data is used only to provide these features to you. It is never sold, never used for advertising, and never transferred to anyone else except as needed to provide these features, for security, or to comply with the law. No one at Mirella reads it, unless you ask us to for support with a specific message, it is needed for security or to investigate abuse, or the law requires it.
Mirella's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnect, in your account settings, stops the platform reading Gmail at once; the permission itself stays with Google until you remove it. Removing Mirella in your Google Account permissions removes Gmail and Calendar access together.
The platform's assistant uses AI models to answer your questions and write your Daily Brief. Every allocation and tax figure comes from the platform's own calculation engine, not from the model. The model receives what it needs to answer, such as client and household names, account figures and your meeting titles and times.
Each request takes one of two routes, both answered only in the United States:
When you ask about a client's notes or prepare for a meeting, the assistant reads the household's recent CRM notes, and the note text is given to the model as information to summarize; the assistant is built to ignore instructions inside it. Once reading email for meeting preparation is available to your firm, recent email with the client is handled the same way. This text is never used to train any model, by us or by anyone else.
Client records are stored in Google Cloud's us-central1 region, and AI requests are answered only by models hosted in the United States, through either route in "AI processing". These providers process data for us:
Charles Schwab, Wealthbox and OnceHub are services your firm chose and holds its own agreements with. The platform exchanges data with them on your firm's instructions: Wealthbox and OnceHub with your firm's own keys, and Schwab through the data files your firm's custodian sends.
We also share information with anyone the law requires us to share it with, or where needed to protect people or our rights. If Mirella is ever sold or merged, the new owner would receive it and this policy would still apply; Google user data would move to a new owner only with your consent, as Google's policy requires.
If you use the platform from outside the United States, your information is transferred to the United States, and client records are stored there.
Every connection uses TLS 1.2 or later. Data is encrypted at rest, and tax identification numbers, dates of birth and each firm's integration keys are additionally encrypted field by field with keys we rotate. Every sign-in needs a second factor. Each advisor sees only their own firm's clients, and a firm can keep each advisor to their own clients, with the firm's administrators able to review the whole book. No system is perfectly secure, but we work to protect what you and your firm entrust to us.
You can disconnect Gmail at any time, as described above. For access to, correction of or deletion of client information, contact your firm, which controls it. To see, correct or delete your own account information, ask your firm's administrator, or email hello@mirellahq.com. We'll reply within 30 days, and we may need to confirm your identity before acting on a request. We delete what you ask us to, except records the law requires us to keep. If the law where you live gives you other privacy rights, we'll honor them.
The platform is for financial professionals. It isn't meant for children under 13, and we don't knowingly collect information from them. If we learn that we have, we'll delete it. A firm's client records can include information about a client's children, such as a custodial account, which we process only on the firm's behalf as described above.
When we change this policy, we'll update the date at the top of this page. If a change significantly affects how we use information we already hold, we'll also post a notice in the platform and tell the firms we work with before it takes effect.
Questions about this policy: hello@mirellahq.com.