90 Total
14 High severity
55 Medium severity
21 Low severity
Summary

Miro's Privacy Policy covers how Miro collects, uses, and shares personal data from users of its online collaborative whiteboard platform, including account registration details, usage activity, device identifiers, and content placed on boards. The policy authorizes sharing personal data with advertising, analytics, and service-provider partners, and describes how users in the EU, UK, and California may exercise access, deletion, portability, and opt-out rights. Enterprise customers are subject to a separate Data Processing Addendum that governs how Miro handles board content as a data processor on behalf of business customers.

Technical / Legal Breakdown

This document is Miro's Privacy Policy, governing the collection, use, disclosure, and retention of personal data by Miro (RealtimeBoard, Inc. and its affiliates) in connection with the Miro collaborative workspace platform, with legal bases including consent, legitimate interests, and contractual necessity depending on jurisdiction. The policy states that Miro collects account identifiers, contact information, device and usage data, content users place on boards, and data from third-party integrations, and the terms authorize sharing this data with service providers, advertising partners, analytics vendors, and business partners. The policy addresses AI feature data handling through a separate AI Terms Addendum, and the scope of data shared with advertising and analytics partners warrants review given Miro's positioning as an enterprise collaboration tool where sensitive business content may be processed. The policy engages GDPR for EU/EEA users (with Miro identifying as data controller for account data and data processor for customer board content), CCPA/CPRA for California residents, and references data transfers under Standard Contractual Clauses; applicability of specific rights and obligations depends on user jurisdiction and account type. Enterprise customers are directed to a separate Customer Data Processing Addendum, which governs processor-level obligations and may supersede certain policy provisions for business accounts.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance

9 important changes detected

9 versions captured · Last updated: July 2026

What changed Miro's privacy policy underwent organizational restructuring on July 11, 2026. The document removed 13 numbered section headings from its table of contents (including sections on applicability, data collection types, use of data, retention, sharing, security, third-party links, age restrictions, international transfers, rights, US-specific rights, policy changes, and contact information) while preserving the substantive policy text. The policy's effective date remains August 1, 2025. This change appears to be a formatting or structural reorganization rather than a substantive modification of data practices.
Why this matters The privacy policy's underlying substantive terms remain unchanged. The modification removes numbered section headings from the table of contents (such as 'Applicability of this Privacy Policy', 'How we use Personal Data', 'Data retention'), but the policy text itself continues to describe how Miro collects, uses, and discloses personal data as before. Users navigating the policy may find the restructured table of contents affects document organization but not the rights, obligations, or data practices described.
View full change record →
What changed Miro added a structured table of contents to its Privacy Policy on June 19, 2026, organizing the document into 13 numbered sections including 'Applicability of this Privacy Policy,' 'The types of Personal Data we collect,' 'How we use Personal Data,' 'Data retention,' 'How we share and disclose Personal Data,' 'Security,' 'Your rights,' and others. The underlying privacy policy text and effective date (August 1, 2025) remain unchanged. This is a formatting and organizational restructuring that improves document navigation without modifying the substantive privacy commitments or data practices disclosed.
Why this matters This change is a formatting and organizational update only. Miro added a numbered table of contents to its Privacy Policy that groups related topics into 13 sections. The substantive privacy disclosures, data collection practices, rights, and procedures remain as previously stated. Users operating under the terms face no new obligations or restrictions.
View full change record →

May 22, 2026 low

The detected change consists of minor text additions in the navigation and header areas of Miro's Privacy Policy document. Two words—'Andrey' and 'Jeff'—were inserted into non-substantive sections of the page …

View change record →
May 21, 2026 low

Miro updated its Privacy Policy on May 21, 2026 by modifying promotional language on the policy landing page. The previous version referenced a San Francisco event registration, while the updated …

View change record →
May 19, 2026 low

Miro updated the footer of its Privacy Policy on May 19, 2026, changing one word in a navigation link. The previous version linked to 'Private Policy' while the updated version …

View change record →
May 16, 2026 low

On May 16, 2026, Miro's Privacy Policy was updated to add a navigation link to 'Connectors' in the product menu structure. This is a navigation and site organization change with …

View change record →
May 14, 2026 low

Miro updated its Privacy Policy on May 14, 2026 by adding a navigation link labeled 'AI Trust' in the policy header. The change does not alter substantive privacy terms, rights, …

View change record →
May 6, 2026 low

Miro updated their privacy policy navigation on May 6, 2026 by changing the call-to-action button from 'Sign up free' to 'Get started free' in the header. This is a minor …

View change record →
May 5, 2026 low

Miro updated the navigation text in their Privacy Policy header on May 5, 2026, changing 'Get started free' to 'Sign up free'. This is a formatting and UI text change …

View change record →
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

90 provisions
12 featured
15 clause types
14 high severity
privacy_rights 22
data_collection 16
data_usage 15
data_sharing 12
contract_terms 5
legal_jurisdiction 5
data_retention 3
policy_changes 3
liability_limitation 2
platform_discretion 2
ai_automated 1
arbitration 1
disclosure_requirements 1
enforcement_actions 1
restricted_content 1

Monitoring

Miro has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle Access to Customer Content via Third-Party Services and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured July 11, 2026 01:04 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000556
Version ID CA-V-004709
SHA-256 d9e3abfd48dbcdd723de123949b654381913f05dc72ef10e218e3d0c10e1cc35
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans