Trust is the product

Face photos are sacred.
We built like it.

Miera holds the most personal data in your business — your clients' faces over time. Here is exactly how it's protected, in plain English, with the receipts. Show this page to your most careful client, or your lawyer.

Consent-scoped photos — never the camera roll

The app can only see photos your client explicitly selects and confirms. There is no bulk upload, no background scanning, no 'grant access to everything.' Her photo library is read only on her device — nothing leaves it until she confirms the specific photos to share.
Design principle #1 — it has survived every feature request since day one.

Per-photo marketing consent, revocable

Using a before/after in your marketing requires her approval on that specific photo — and she can withdraw it later, which pulls it from your library automatically. Your Instagram is built on paperwork that actually exists.
Approval status is enforced server-side, not by front-desk memory.

Isolation enforced by the database — and proven

Every table carries row-level security: your clinic's staff mathematically cannot query another clinic's clients, photos, or messages. This isn't a policy document — it's the database refusing the query.
A real Postgres runs our isolation test suite on every code change: cross-clinic reads, forged writes, and anonymous probes across every table must return nothing, or the change cannot ship.

A consent ledger that can't be quietly edited

Every consent decision and product event is recorded append-only — staff can add entries but never delete or rewrite them. And client photos can be added clinic-side but never deleted clinic-side. When a dispute arrives, the timeline is the timeline.
Append-only enforcement on the consent and event ledgers is verified by automated tests on every code change.

Photos in a private vault

Media lives in private cloud storage — no public links, ever. Every view goes through a short-lived, signed URL issued only to someone already authorized to see that photo.
Direct object access without a signed URL returns nothing.

Export free, deletion true

Your clinic's data is yours to take — standard formats, free, within 48 hours of asking, forever. Your client can export her own record in-app — or delete her account, which purges her data and photos from our systems, not just hides them.
Deletion is a true purge across the database and the photo vault — not a soft-hide.
The honest part

Where we are on formal compliance.

Straight answers, because you'll ask: consent, isolation, and encryption are built and enforced today, and our Canadian pilot runs on privacy-first Canadian infrastructure. Formal attestations — signed healthcare data agreements with every vendor, third-party audits — are sequenced ahead of US patient-data scale, not claimed early. If a vendor tells you “fully HIPAA compliant” in their first breath, ask to see the paperwork; when we make that claim, ours will be real.

Privacy this careful is a pitch
to your best clients.

Start free — 30 daysRead the privacy policy