This Privacy Policy explains how Mitr ("Mitr", "we", "us", "our") collects, uses, and protects information when you use heymitr.com and the Mitr chat app (together, the "Service"). It applies to anyone who visits our website or chats with Mitr, whether or not you ever pay for the service.
Questions, requests, or concerns about your data can be sent to hello@heymitr.com at any time — this is also our contact point for grievances relating to how your personal data is handled. We aim to respond within a reasonable time, and in any case within 30 days.
Mitr is intended for people 18 years of age or older. We don't knowingly collect personal information from anyone under 18. If you believe a minor has used the Service and shared personal information with us, please contact us at hello@heymitr.com and we will take appropriate steps to remove it.
Mitr is a companion for everyday emotional reflection — it is not a therapist, not a crisis service, and not a substitute for professional medical or mental health care. See Section 7 for what happens if a conversation suggests you may be in crisis.
When you send a message, it's sent to our server just long enough to generate a reply, then forwarded to our AI provider to actually produce that reply (see Section 5). We do not write your messages to a database or file on our server. Your conversation history is kept in your own browser's local storage, on your own device — if you clear your browser data or switch devices, that history is gone, and we have no copy of it.
The first time you open Mitr, your browser generates a random id (stored locally as heymitr_device_id) and sends it with each message. We use this only to count how many free messages a device has used and to check whether that device is linked to a paid plan — it isn't tied to your name or any other identity unless you also give us your email (below).
We only ask for an email address when you choose to pay for Mitr Plus, or when you want to restore access on a new device. We send a one-time verification code to confirm it's really you. After that:
All payments are processed by Razorpay, a licensed payment gateway. Your card, UPI, or bank details go directly to Razorpay's own secure checkout — Mitr's server never receives or stores them. We only receive a payment confirmation (an order ID, a payment ID, and a signature we use to verify the payment is genuine) so we can activate your plan.
Like any website, our server briefly sees your IP address as part of handling each request. We use it only to apply a short-lived rate limit (to stop bots or scripts from overloading the service) — it isn't stored long-term or linked to your conversations.
If you use the microphone or "speak aloud" features, they run using your browser's own built-in speech capabilities (the Web Speech API). Audio is processed on your device / by your browser, not uploaded to or stored on our server.
Your language choice, currency display preference, and ambient-sound setting are saved only in your browser's local storage, so the app remembers your preferences on that device.
Our marketing homepage (heymitr.com) uses Google Analytics to understand overall traffic — things like how many people visit, which pages they view, and roughly what device or region they're browsing from. This is standard, aggregate web analytics, not an ad tracker, and it does not run inside the chat app itself (heymitr.com/startchat) — once you start talking with Mitr, Google Analytics is not active.
Google Analytics sets its own cookies and is subject to Google's own privacy policy, which governs how Google itself processes that data. We don't use it to identify you personally or to connect your homepage visit to anything you say in a conversation with Mitr.
Mitr's replies are generated by a third-party AI service (currently, Anthropic's Claude models, accessed via OpenRouter). When you send a message, its content — along with the recent messages in that same conversation, so Mitr has context — is transmitted to that provider to generate a response, then the reply is returned to you. This is the one point where your message content leaves your device and our server to be processed elsewhere; it happens for every message, because it's how the reply gets written.
We don't control how our AI provider's own infrastructure logs or retains data on their side — that's governed by their own privacy and data-processing terms, not this policy. We chose a provider that doesn't use API traffic like ours to train their models, but we'd encourage anyone who wants the technical detail to review OpenRouter's and Anthropic's own privacy documentation.
Because this provider may process data on servers outside India, using Mitr means your message content may be transferred internationally for the moment it takes to generate a reply.
Before generating a reply, Mitr runs an automatic, on-the-spot check for language that may indicate someone is in crisis (for example, mentions of self-harm). This check happens as part of producing your reply — it is not separately logged or stored — and if it's triggered, we add crisis-support resources (such as helpline numbers) to Mitr's response, regardless of what the AI itself says. This is a safety measure, not a monitoring or reporting feature: we do not notify anyone or take any action beyond including these resources in your own reply.
| Who | What they receive | Why |
|---|---|---|
| OpenRouter / Anthropic | Your message content and recent conversation history, for that request only | To generate Mitr's reply |
| Razorpay | Your email address, device id, and order/payment details | To process your payment and issue receipts |
| Our hosting provider | Standard web server logs (e.g. IP address, request timing) | To run and secure the website itself |
| Google Analytics | Aggregate homepage traffic data (not active inside the chat app) | To understand how people find and use heymitr.com |
We don't share your information with anyone else, and we don't share it for marketing or advertising purposes. We may disclose information if required to by law, or to protect the safety of a user or the public.
You can ask us, at any time, by writing to hello@heymitr.com, to:
If you're in India, these rights are consistent with the Digital Personal Data Protection Act, 2023. If you're elsewhere, we'll still honour these requests on the same basis.
We take reasonable technical measures to protect the limited data we do store — for example, storage directories that hold account and usage records are configured to block direct public access, and email addresses are never stored in plain text, only as a one-way cryptographic hash. No online service can guarantee perfect security, but we design Mitr to minimise what we collect in the first place, which is itself a form of protection.
If we make material changes to how we handle your information, we'll update the effective date at the top of this page. Continued use of Mitr after a change means you accept the updated policy.
For anything in this policy — questions, requests, or concerns — write to us at hello@heymitr.com.