THE MIRROR / 06 / PRIVACY & CONTROL

What the mirror knows about you.

An observation is not the same as a saved record. Inspect what stays in this tab, what reaches the server, and what you have deliberately kept.

01 / DATA FLOW

Observed here

Browser, display, capabilities and interaction counts.

02 / DATA FLOW

Sent to the server

Request metadata only. Your pointer and interaction counts stay here.

03 / DATA FLOW

Persisted

Off. Anonymous measurements live in this tab’s memory.

04 / DATA FLOW

Shared with others

No analytics or ads. OpenAI and Cloudflare provide hosting.

Current session

IN MEMORY
00:00

Starting session

Identity
Anonymous
Local signals
0 current values
Saved snapshot
None
Observation
Active
Saved sessions
No account

What this site has stored locally

No application-owned local or session storage keys. The only optional local preference is your chosen theme.

Sign-in cookies are managed by the hosting platform and may be HttpOnly, so JavaScript cannot inspect or erase them. No local telemetry database, cache or service worker is created by THE MIRROR.

Permission states observed this session

YOU DECIDE

No permission changes recorded. Visit the Permission Lab to inspect browser-reported states. The site never requests these on page load.

Permission history stores state names only if you save a reflection. Camera, microphone, clipboard contents and precise coordinates are excluded. Browser permission revocation happens in site settings.

Open Permission Lab

The retention contract

What storage mechanisms mean

Cookies are sent automatically with requests. Session storage belongs to a tab. Local storage survives closing the browser. IndexedDB holds structured local records; the Cache API holds responses. Service workers can handle background requests. Storage availability does not mean this site has placed information there.

Who receives information

OpenAI Sites and Cloudflare provide hosting, transport security, authentication and database infrastructure. They process connection metadata and may retain operational logs under their policies. There are no advertising tags, behavioral analytics SDKs or external IP metadata services. Fonts and scripts are served by this site.

Signing in sends identity information through ChatGPT authentication. THE MIRROR receives a site-scoped user identifier and email. This implementation does not receive passwords, retain authentication tokens, record media, or sell visitor telemetry.

The limits of erasure

Deleting a saved reflection removes live application rows and their dependent records. A website cannot erase records held under a hosting provider’s backup or security retention policy, erase network traffic that already occurred, or revoke browser permissions for you. Browser site settings provide the final controls for cookies, local storage and permissions.