Pilot data notice

This notice describes the exact data path implemented by the public pilot request form.

Effective August 29, 2026

What the request form collects

The form stores your work email, company name, optional product URL, target type, customer-flow description, consent time, a keyed hash of the request IP address, and a limited user-agent string.

Why Mirage collects it

The business details are used to review pilot fit, contact you about scope, and prepare commercial terms only if both sides agree to proceed. The keyed network hash and user-agent string support abuse prevention.

Storage and notification path

Requests and immutable submission snapshots are written to the configured pilot-intake PostgreSQL database. If an operator notification endpoint is enabled, the same transaction also records a delivery event. Signed delivery may be retried, so that service deduplicates on the event ID. The notification contains the submitted business fields, policy identifiers, and submission time; the raw IP address and its keyed hash are not included.

Retention and removal

The current intake service does not run an automatic deletion job. A request remains until an operator removes it or you request removal. If a pilot proceeds, its written scope can define a separate retention period for pilot materials.

More detail

The broader privacy notice covers service providers, pilot evidence, and your contact choices. Do not put passwords, access tokens, customer personal data, or confidential build material in this public form.