Privacy Policy
MiroMind Plugin for Dify
Last updated: 18 May 2026
This Privacy Policy describes the data practices of the MiroMind plugin for Dify (the "Plugin"). The Plugin acts as a transparent client between Dify and the MiroMind API; it does not collect, store, or log any data on its own.
1. Data Collection
The Plugin itself collects no personal data. The following data flows through the Plugin during normal operation and is sent to MiroMind:
- API credentials. The
api_keyyou configure is stored by Dify (not by this Plugin) and forwarded as a Bearer token to MiroMind on each request. - Prompt content. User messages and any system prompts configured in your Dify app are forwarded verbatim to the MiroMind API as the request's
inputfield. This content may contain whatever information the end user chooses to include. - Request parameters. The selected model name,
max_output_tokens, andtemperaturevalues configured in your Dify app.
The Plugin does not transmit IP addresses, device identifiers, browser fingerprints, Dify user or workspace IDs, or any telemetry to the Plugin author.
Classification per Dify's plugin privacy guidelines
- Type A (Direct Identifiers — names, emails, phone numbers, etc.): Not collected by the Plugin. May incidentally appear in user-authored prompts forwarded to MiroMind.
- Type B (Indirect Identifiers — device IDs, IP addresses, location data, etc.): Not collected by the Plugin. The
api_keyis a service credential for the MiroMind account, not an end-user identifier. - Type C (Combinable Data — age, gender, occupation, interests, etc.): Not collected by the Plugin. May incidentally appear in user-authored prompts.
2. Data Usage
Data forwarded to the MiroMind API is used by MiroMind to execute the requested deep-research query and stream the response back to Dify. Details of MiroMind's retention, processing, and any use of inputs for service improvement or model training are governed by the MiroMind Privacy Policy, available at https://www.miromind.ai/policies/privacy.
The Plugin itself uses received data only to translate MiroMind's streamed response into Dify's chunk format. Nothing is persisted by the Plugin.
3. Third-Party Sharing
The Plugin transmits user input to one third party:
- MiroMind — the deep-research backend at the configured
base_url(defaulthttps://api.miromind.ai/v1). MiroMind's privacy practices are described at https://www.miromind.ai/policies/privacy.
MiroMind's deep-research pipeline may internally invoke third-party search and content-extraction services to fulfill research queries. Those upstream relationships are managed by MiroMind and disclosed in MiroMind's own privacy policy.
The Plugin does not share data with any other third party.
4. Model Training and Opt-Out
Content forwarded to the MiroMind API through the Plugin — including prompts, system instructions, and request parameters — may, in de-identified or aggregated form, be used by MiroMind to train, improve, calibrate, and evaluate MiroMind's artificial intelligence and machine-learning models, as further described in Section II.5 of the MiroMind Privacy Policy and Section 2.6 of the MiroMind Data Processing Addendum.
You have the right to object to this use at any time. To opt out of having content forwarded through the Plugin used for model training, contact legal@miromind.ai. Exercising the opt-out will not affect your access to the core functionality of the Plugin or the MiroMind Services.
If you are a Dify application developer deploying this Plugin, you are responsible for ensuring that the appropriate disclosures and, where required by applicable law, the appropriate legal basis or consent is in place with respect to the end users of your Dify application before their prompts are forwarded through the Plugin.
5. International Transfers
MiroMind generally provides the MiroMind Services from Singapore. When you use the Plugin, content forwarded to the MiroMind API may be transferred to, processed in, and stored in jurisdictions outside the country in which you or your end users are located. Data protection laws in those jurisdictions may differ from, and in some cases may be less protective than, those of your home jurisdiction.
MiroMind relies on legally valid transfer mechanisms for cross-border transfers. For transfers of personal data originating in the European Economic Area or the United Kingdom, MiroMind relies on the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor, Decision 2021/914), as incorporated by reference into the MiroMind Data Processing Addendum. For transfers originating in other jurisdictions, MiroMind applies the transfer mechanism required by applicable law.
Supplementary technical measures are applied to content in transit and at rest, including encryption in transit (TLS 1.2 or higher) and encryption at rest (AES-256), as further described in Section VII of the MiroMind Privacy Policy.
6. Children's Data
The Plugin and the underlying MiroMind Services are not directed to, and MiroMind does not knowingly collect personal data from, individuals under the age of 18. If you, as a Dify application developer, deploy this Plugin in an application that may be accessed by minors, you are responsible for ensuring that no personal data of individuals under the age of 18 is forwarded to MiroMind through the Plugin.
If you become aware that personal data of an individual under the age of 18 has been provided through the Plugin, please contact legal@miromind.ai and MiroMind will investigate the matter and, where appropriate, delete the relevant data.
7. Your Rights
Depending on the jurisdiction in which you are located, you may have the following rights with respect to your personal data:
- the right to access your personal data and information about how it is processed;
- the right to request erasure or deletion of your personal data;
- the right to update or correct your personal data;
- the right to data portability;
- the right to restrict or object to processing of your personal data;
- the right to withdraw any consent you have previously provided; and
- the right to lodge a complaint with the data protection authority in your country.
Because the Plugin does not itself store personal data, requests to exercise these rights with respect to content that has been forwarded to MiroMind should be directed to MiroMind at legal@miromind.ai. Requests with respect to data held by Dify (including the api_key and any data stored by your Dify deployment) should be directed to Dify in accordance with Dify's own privacy policy and to the operator of the Dify application in which the Plugin is deployed.
MiroMind will respond to verified requests in accordance with applicable data protection laws.
8. Relationship to the MiroMind Privacy Policy and Data Processing Addendum
This Privacy Policy is a supplemental notice. It describes the data practices specific to the Plugin and is intended to be read together with, and not in place of, the MiroMind Privacy Policy and the MiroMind Data Processing Addendum, each of which governs MiroMind's processing of content forwarded to the MiroMind API by the Plugin. The MiroMind Privacy Policy and the MiroMind Data Processing Addendum are incorporated into this Privacy Policy by reference.
In the event of any conflict between this Privacy Policy and the MiroMind Privacy Policy or the MiroMind Data Processing Addendum with respect to processing performed by MiroMind, the MiroMind Privacy Policy or the MiroMind Data Processing Addendum, as applicable, shall control.
The current versions of these documents are available at https://www.miromind.ai/policies/privacy.
9. Contact
For privacy or data-protection questions about the Plugin or the MiroMind Services:
E-mail: legal@miromind.ai