m
Myra
Draft. This document is a working draft pending final legal review and company incorporation. Items shown in square brackets are still to be completed. It does not yet take effect.

Security

Myra — Effective date: [Effective date — set at publication]

Myra works with your email, messages and calendar, so we hold your data to a high standard. This page describes exactly how we protect it — and, just as importantly, what we do not claim.

Encryption

All traffic to and from Myra is encrypted in transit with TLS, and HTTPS is enforced on every response (HTTP Strict Transport Security). Data at rest is encrypted at the storage layer by our infrastructure providers. In addition, the access credentials for accounts you connect — your OAuth tokens and any app-specific password — are encrypted a second time by Myra with AES-256-GCM before they are stored.

Account isolation

Every account’s data is isolated. Each database query is scoped to the signed-in account by a structural per-account data layer that refuses to read or write another account’s rows, with PostgreSQL row-level security as a backstop. This isolation is checked by an automated test suite that fails the build if a cross-account read or write ever becomes possible.

Access and identity

The application is behind an authentication gate: every request must carry a valid, signed session. The identity used by our backend is derived only from that verified session — a client cannot forge it, because any identity supplied by the browser is discarded and replaced with the server-verified one. Secrets and keys are held only in environment configuration and are never committed to our code repository.

Application hardening

Standard hardening headers are enforced on every response — clickjacking protection (X-Frame-Options), MIME-sniffing protection, a strict referrer policy and a restrictive permissions policy. A Content-Security-Policy is deployed in report-only mode while we tighten it ahead of enforcement. Incoming webhooks from our payment and integration providers are verified by cryptographic signature and rejected if unsigned or altered.

Privacy by design

Myra uses no third-party advertising or analytics trackers. When error monitoring is enabled, message content, email addresses and request payloads are stripped before any error report leaves Myra. We do not sell your data, and we do not use your content to train generalised AI models.

Your control over your data

You can export a copy of your data at any time, and you can delete your account. Deletion is immediate and permanent: your content is erased, files are removed and connected accounts are disconnected in a single operation. Encrypted system backups are retained for up to 30 days for disaster recovery and then expire, except where the law requires longer retention of specific records.

What we are candid about

Myra is an early-stage product, and we describe only what we actually do. We do not claim certifications we have not earned, such as SOC 2 or ISO 27001. As part of Google API verification we are pursuing an independent application security assessment (CASA). And because Myra reads your content in order to provide its features, it is not end-to-end encrypted — we would rather state this plainly than imply otherwise.

Reporting a vulnerability

If you believe you have found a security issue, please contact privacy@getmyra.com. We will acknowledge your report and keep you informed as we investigate.

[Legal entity name — pending incorporation] · the United Arab Emirates · privacy@getmyra.com
PrivacyTermsSubprocessorsSecurityBack to Myra