Legal center
Privacy Policy

Privacy Policy

Updated September 24, 2026

Effective Date: September 24, 2026

Last updated: September 24, 2026

Mustro, Inc., a Delaware corporation ("Mustro," "we," "us," or "our") operates an agentic operating system for one human being, a personal-management platform that, with your permission, connects to your bank, card, and brokerage accounts, your calendar, and your email inboxes (and, over time, additional sources you opt into) so that it can help you manage money, time, and inbox in one place. This Privacy Policy explains how we handle your information when you create an account, connect data sources, use Mustro, or otherwise interact with Mustro at mustro.ai and our mobile applications (collectively, the "Services").

The data Mustro touches is unusually sensitive: your transactions, your meetings, the people you talk to, what they wrote you, what you have not replied to. We treat it that way. The commitments below are deliberately strict: we do not sell your data, we do not share it with advertisers, we do not use it to train machine-learning models, and we do not allow humans to read your connected-account data except in the narrow circumstances described in Section 4.

By accessing the Services, you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.

1. Information We Collect

1.1 Information You Provide When You Sign Up

When you create a Mustro account you provide:

  • Identity and contact details: name, email address, and (optionally) a profile photo. Authentication is handled by Firebase Authentication; we receive the verified email and a stable Firebase user identifier.
  • Preferences: time zone, briefing channel (email, push, or both), preferred briefing time, AI model preference (Claude or OpenAI), and daily token-budget settings.

1.2 Information We Collect via Connected Accounts ("Connector Data")

You choose each outside account you connect to Mustro. The sources listed below send data to Mustro after you authorize access. Strava is an optional destination for sessions you choose to share from Mustro. We do not import your Strava activity history. Section 1.8 describes Strava sharing.

  • Plaid (bank accounts and credit cards). When you complete Plaid Link, we receive an access token and item identifier, and we sync your accounts (name, type, mask, balances), transactions (date, amount, merchant, category, payment channel), and liabilities (statement balances, due dates) covering up to the maximum history Plaid provides for the institution (typically 24 months). We do not receive online-banking usernames or passwords; Plaid holds those.
  • Google Calendar. When you authorize access, we receive access and refresh tokens and read your calendar list and events. Event data includes titles, times, locations, attendees, descriptions and conferencing links. You choose the calendars to connect, and you can connect more than one Google account.

Time's automatic scheduling controls are being introduced in stages. The following applies when those controls become available in your account and you enable them.

When you turn on automatic scheduling in Time, Mustro creates, moves, resizes and deletes the events it places for workouts, plan sessions, recovery, habits, tasks, focus time and buffers. Time writes these events as private. You choose real titles or the neutral title "Mustro block". If you enable Busy copies, Mustro adds events titled "Busy", without descriptions, to your other connected accounts. Mustro creates a separate Mustro calendar only if you select that option.

You can also choose Never Move, Ask First or Move rules for your own events without guests. Move lets Mustro move those events within your daily move limit. Appointments and travel default to Never Move. Mustro does not edit or delete events organized by other people. A change to an event with guests requires your approval. Automatic changes have a 24-hour undo window. If the previous time is no longer available, Mustro shows the conflict and alternatives. When you remove Time, you choose whether to keep or delete its events.

Health calendar integration can also write scheduled, live and completed workouts. Health items require the separate sharing choice in the Consumer Health Data Privacy Policy. A Google permission grant alone does not replace that choice.

  • Calendar feeds. When you add a calendar feed address, Mustro stores the address encrypted and fetches the feed on a schedule. Mustro reads the feed and does not write changes back to it. Removing the feed deletes its stored address.
  • Gmail. When you complete the Google consent flow we receive a refresh token and access token. We sync your email threads and messages (headers, meaning sender, recipients, subject, date; the message body in text/plain and text/HTML; attachment counts but not attachment binaries) from up to three Gmail mailboxes per Mustro account that you explicitly grant access to. We use gmail.modify to read your email, organize it with labels you request, and create drafts in your Gmail Drafts folder for you to review and send. We never send mail on your behalf. The Mustro codebase contains no users.messages.send code path.
  • Mustro Health (Apple HealthKit and Oura). When you install the Health Skill you connect your own body and training data from two sources. Apple HealthKit is read on your device under your per-category HealthKit permission (no health data is sent to Apple by us); Oura is connected through Oura's OAuth consent flow, and we sync your Oura data from the Oura API. Across these sources we sync your workouts and training (including cardio, and recovery sessions such as sauna, cold plunge, and mobility), sleep (sessions and sleep stages), heart-rate variability, resting heart rate, and Oura readiness / sleep / activity scores, activity and energy (steps, active energy, exercise minutes), body composition (weight, body-fat percentage, lean mass), vitals (blood pressure, SpO2, respiratory rate, body and wrist temperature), cardiorespiratory fitness (VO2 max), daytime stress and resilience (from Oura), and mindfulness minutes. We also derive rolling baselines (for example your 7-day HRV and 30-day resting-heart-rate baselines) to power recovery and anomaly signals. This is health and biometric data, a sensitive category: we never sell it, never share it with advertisers, and never use it to train machine-learning models (see Sections 4 and 5).

Additional Connectors, for example journal, goals, news, investments, tax, travel, and memberships, may be added over time. Each new Connector is opt-in: you authorize it through that source's own consent flow before any data is synced, this Privacy Policy and the Subprocessors list are updated before the new Connector becomes available to you, and the Connector can be revoked at any time on the schedule described in Section 5.

1.3 Information We Generate About You

To make the platform useful we derive a second layer of information from your raw connector data:

  • Categorization and tagging of transactions, threads, and events (e.g., "needs reply," "VIP," "unusual spend").
  • Briefings and insights: the morning briefing, weekly summary, and ad-hoc anomaly alerts Mustro produces. These are stored in your account so you can re-read them.
  • Agent events: discrete signals Mustro watches for (e.g., large_transaction, calendar_conflict, vip_email_silent_too_long). These are AI memory, not raw audit logs.
  • Cross-Skill connections: once you have connected two or more Skills, Mustro may connect signals across them when writing your briefing, for example noting that a dinner on tonight's calendar is one your rewards card earns more on, or that a rise in dining spend lines up with dinners you have scheduled. Where a connection is stored as a structured record rather than as briefing text, we also record which specific items it rests on, for example the card and the calendar event it joined, so it is clear what Mustro concluded and why. Mustro receives no compensation for these recommendations. A connection is kept in two places: as part of the briefing that contains it, and, where it is stored as a structured record, in a standalone list you can review and delete at any time in /settings (see Section 8.1). That standalone record also notes when Mustro last drew on it. When you delete a connection, we delete that standalone record and keep a fingerprint of it, a hash rather than the connection itself, which exists only so Mustro does not draw the same conclusion again. The briefing that already contained the connection is kept as written, so deleting a connection does not edit briefings you have already been sent. Retention for all three is in Section 5. These connections are used to serve you inside Mustro and to measure whether the feature is useful, which we report only in aggregate. We do not sell them, we do not share them, and we do not use them to train machine-learning models.
  • Facts you ask Mustro to remember: Mustro can save a standing preference, relationship, or correction you give it in chat. Each saved fact records when it was first learned, when it was last used, and the chat message that supplied it. In Settings > Memory, you can review all saved facts and cross-Skill connections together, edit a chat fact, or delete one or all records. Deletion removes the saved record and retains a suppression fingerprint so the same memory is not saved again. It does not erase the original conversation or an already-written briefing. Brief-correction notes whose source has not been verified remain available for review and deletion but are not used in future answers.
  • Your cross-Skill control: Settings > Memory lets you turn off connections across Skills. This stops new cross-Skill connections and immediately removes existing standalone connections from use. Those records remain labelled as pending deletion until they are permanently removed within thirty (30) days. Turning the setting back on does not restore them. Mustro continues to answer inside each Skill and can still remember facts you give it in chat. Delete All clears the records without changing this setting.
  • Conversation history: messages you exchange with Mustro, the tools it invoked, and the responses returned.
  • Intents: proposed write actions (e.g., draft a reply, label a thread) that require your approval before execution.
  • Time records. When you use Time scheduling, Mustro stores your scheduling preferences, placed blocks and their history, changes and their reasons, planning runs, tasks and event classifications. Classifications describe scheduling kinds such as meetings, appointments and travel. They do not infer your health status.
  • Training plans: if you use training plans in Mustro Health, the plan we generate for you, its revisions, your benchmark results, and your adherence records. Because that data starts from a goal and constraints you write yourself, it is described in full in Section 1.6.

1.4 Information We Collect Automatically

When you use the Services we automatically collect:

  • Device information: IP address, browser type and version, operating system, device identifiers, and language settings.
  • Usage information: pages visited, features used, session duration, and aggregated interactions with the Platform.
  • Authentication information: Firebase ID tokens (short-lived) and, if you opt in, biometric identifiers used by your device locally for sign-in (these never leave your device).
  • Server logs: error reports and performance data used to diagnose issues. Logs never contain decrypted tokens, decrypted email content, or full account numbers.

1.5 Information from Third Parties

We may receive limited information about you from:

  • Plaid: the verified institution identity, account masks, and the connection-status webhook stream tied to your linked items.
  • Google: the verified sub (Google user id) and email claims from the OAuth id_token, plus the webhook / Pub/Sub change notifications for Calendar and Gmail.
  • Firebase Authentication: the verified identity provider, email-verification status, and MFA status reported by Google's Identity Platform.
  • Apple HealthKit, which provides the health and workout samples you permit Mustro to read on your device. HealthKit shares that data with the Mustro app on-device under your per-category permission, and we sync it to Mustro; we send no health data to Apple.
  • Oura, which provides your verified Oura account data (sleep, readiness, activity, HRV, and related biometrics) retrieved from the Oura API under your OAuth grant.
  • Strava. When you connect Strava, we receive authorization tokens and your Strava athlete identifier. We store encrypted tokens, their expiry, the permission granted, and the athlete identifier. We receive identifiers and processing results for activities we send. We use these records to operate sharing, show its status, and help prevent duplicate activities.

1.6 Training Data (Mustro Health Training Plans)

If you use training plans in Mustro Health, we hold a second class of health data. It is not synced from Apple HealthKit or Oura: part of it you write yourself, and part of it we generate for you.

  • Provided by you: the training goal you set (goal type, event name and date, start date, plan length, sessions per week, your self-reported experience level, and the gym whose equipment the plan should assume) and the free-text context you write to shape the plan. That field is there for your constraints, and people write injuries and medical limitations into it (for example "bad knee, no running"). We treat what you write there as health information about you. The field is optional: you can leave it blank, or describe a limitation without naming a diagnosis. If you import a plan instead of generating one, the plan text you paste is also data you provide, and it may carry the same kind of health information.
  • Generated by Mustro: the plan itself and every revision of it (with the reason for the change and whether you, Mustro, or the system made it), the weekly phases and targets, the prescribed sessions, your benchmark results (measured tests such as a timed run, a max-repetition set, or a one-rep-max lift) and the training zones we derive from them, and adherence records that link each prescribed session to what you actually logged.

We use training data to generate and revise your plan, to warn you when a scheduled session conflicts with a constraint you stated, to resolve your training zones from your benchmarks, and to let Mustro answer questions about your plan and your adherence. We treat all of it the way we treat your synced health data: we never sell it, never share it with advertisers, and never use it to train machine-learning models. We send the training data needed for a request to our AI subprocessors at inference time under their zero-retention terms. This occurs when we generate or revise a plan, or when you ask Mustro about it (see Sections 3 and 4). If you enable Strava sharing, we also send the completed session fields described in Section 1.8. Strava acts as a separate service under its own privacy policy. This does not add Strava to our AI subprocessors.

Deleting a plan deletes that plan and everything held under it: its revisions, its prescribed sessions, and the adherence records for those sessions. Your benchmark results are kept at the account level, not under one plan, because they describe your measured performance across plans and set your training zones, so deleting a plan detaches a benchmark from it but does not delete the result. Benchmarks are deleted when you uninstall Mustro Health or close your account. The full schedule is in Section 5.

1.7 Sensitive Information

By its nature, Connector Data may include financial transactions, calendar meetings, and email correspondence that are sensitive to you. If you install Mustro Health, it also includes health and biometric data from Apple HealthKit and Oura (see Section 1.2), which is a special category of personal data. We collect health and biometric data only when you install the Health Skill (an opt-in action) and grant the relevant source through its own permission step: the iOS Health permission sheet for Apple HealthKit (which records the specific categories you grant) and Oura's OAuth grant for Oura. Where the law requires explicit consent for this special category (for example under the GDPR), that consent is the affirmative grant you give in those steps. We do not sell your health data or share it with advertisers. We send health data needed for AI requests to our zero-retention AI subprocessors, as described in Sections 3 and 4. If you separately enable Strava sharing, we also send the session fields described in Section 1.8 to Strava. Strava's own privacy policy governs its processing. You decide which sources to connect and which accounts to grant. You may disconnect any source at any time from /connectors, which immediately stops syncing and triggers the deletion described in Section 5.

Your training data is in the same special category. A constraint you type, such as "bad knee, no running," states a medical condition, and the plans, benchmarks, and adherence records we generate from it describe your body and your health. We give the whole of Section 1.6 the same special-category treatment as your synced health data, even though it comes from you and from us rather than from a connected source. Where the law requires explicit consent for this category (for example under the GDPR's Article 9, and under U.S. consumer-health-data laws that treat this information as sensitive), we ask you for it directly. Before you can save a constraint or import a plan, we show you what the data is, that it goes to our AI providers under zero-retention terms, that we never sell it or use it to train models, and how to withdraw. We record that you agreed, which version of that wording you were shown, and when. We also record a fingerprint of the exact text on your screen and check it against the published wording, so your consent can never be recorded against a paragraph you did not read. The constraint field is still optional: you can use training plans without describing a medical condition, and if you leave it empty we do not ask you for anything. You can withdraw in Settings at any time, which stops us using it going forward. Because this data is not synced from Apple HealthKit or Oura, disconnecting either source does not by itself delete it; uninstalling the Health Skill or closing your account does, and deleting a plan removes the records held under that plan, on the schedule in Section 5.

1.8 Optional sharing to Strava

You can connect your Strava account to share completed strength, cardio, and recovery sessions from Mustro. We request permission to write activities. We do not import activities from Strava. We receive connection information and the results of our own uploads, as described in Section 1.5.

Each activity includes its name, sport type, start time, duration, and a description. Strength activities include routine and exercise names, sets, warmup labels, repetitions, weights, and recorded muscle groups. Cardio activities include recorded distance, average heart rate, and calories. Heart rate and calories appear in the description. Recovery activities include their kind and recorded temperature.

We exclude notes fields. Routine and exercise names still appear in the activity. The description includes a link to Mustro's waitlist. If you own a referral code, the link includes it. That code can link the referral to your Mustro account.

Before manual sharing, you review the activity summary, description, and warnings. Automatic sharing starts off for each kind. If you enable a kind, Mustro sends future eligible native sessions without a separate preview or confirmation. Imported sessions are not shared automatically.

Activities use your Strava privacy settings and may be visible to other people. Strava handles its copy under its own Privacy Policy. Review those settings before sharing. Sections 3 and 5 explain the recipient and deletion choices.

2. How We Use Your Information

We use your information for the following purposes:

  • Provide the Services. Show your connected information, answer your questions, generate briefings, send alerts, and help you review email and prepare drafts. When you use Time scheduling, classify calendar events and plan, place and adjust your schedule under the controls described in Section 1.2.
  • Connect and sync your accounts. Refresh OAuth and Plaid tokens, run incremental syncs on webhook delivery, and back-fill data where the source supports it.
  • Communicate with you. Send the briefings and anomaly alerts you have configured, plus service-related messages (security notices, billing, OAuth-grant expiry warnings).
  • Improve the Services. Diagnose errors, monitor performance, and refine features based on aggregated, de-identified usage signals. We do not use Connector Data, Mustro conversations, or any user content to train machine-learning models.
  • Security and abuse prevention. Detect and respond to fraud, unauthorized access, and conduct that violates our Terms of Service.
  • Legal compliance. Comply with applicable laws, regulations, and lawful requests.
  • We create the Strava activities you request and operate automatic sharing for the session kinds you enable. We keep sharing status and related records to show results and help prevent duplicate activities. The activity description includes the Mustro referral link described in Section 1.8.

We will never use your information for cross-context behavioral advertising or for targeting by third parties.

3. How We Share Your Information

We share your information only as described below.

  • With service providers (subprocessors). We share information with vendors who help us run the Services, under contracts that require them to protect your information and use it only for our purposes. The current roster lives in Subprocessors.md (Section 11 below summarizes it) and at <https://mustro.ai/legal/subprocessors>.
  • With AI providers, under zero-retention enterprise terms. When you use Mustro chat or receive a generated briefing, the relevant portion of your data is sent to Anthropic and/or OpenAI for inference under enterprise agreements that contractually require zero retention of inputs/outputs and no training on your data. When Time classifies calendar events or uses AI to plan your schedule, it sends the event titles and times needed for that request to Anthropic. AI planning can also use your scheduling preferences, tasks and the health-session information you consent to use for scheduling. The same zero-retention and no-training commitments apply. Rule-based planning does not itself send a planning request to an AI provider. Separate event classification may still use AI. See Section 4 for the full Limited Use commitment.
  • For legal reasons. We may disclose information when required by law, regulation, legal process, or governmental request, and to protect the rights, property, or safety of Mustro, you, or others.
  • With your explicit consent. We share information for the specific purposes you agree to. When you enable Strava sharing, we send the session fields in Section 1.8 to Strava. Strava provides its own fitness service and handles that copy under its Privacy Policy. It does not act only on Mustro's instructions.
  • Strava API usage. Strava may collect and use data about our API access for its business purposes, including service improvement, support, and compliance. See Strava API Policy, Section 6.5.
  • In a business transfer. If Mustro is involved in a merger, acquisition, financing, or sale of assets, your information may transfer as part of that transaction. We will notify you in advance and your information will continue to be protected by this Privacy Policy or an equivalent successor. Google data transfers also require the explicit prior consent described in Section 4.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We do not provide your personal information to advertisers, data brokers, or third-party targeting platforms.

4. Limited Use Commitments for Google Workspace APIs

Mustro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  1. Only to provide user-facing features. Mustro uses Google data for the features described here: calendar overview, scheduling, inbox triage, draft replies, briefings and the AI assistant. It does not use that data for unrelated purposes.
  2. Transfers remain limited. Mustro transfers Google data only to support permitted, visible user-facing features with your consent, for security, or as required by law. A transfer in a merger, acquisition or sale of assets requires your explicit prior consent. Consent does not authorize unrelated uses prohibited by Google's policy.
  3. No advertising. We do not use Gmail or Calendar data for advertising purposes, including but not limited to serving, retargeting, personalizing, or ranking advertisements.
  4. No human reading. We do not allow humans to read your Gmail or Calendar data unless (a) we have obtained your affirmative consent, (b) it is necessary for security purposes (such as investigating abuse or a bug you have reported), (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized so it cannot be linked back to you. Access requests from Mustro personnel are logged in our audit-trail system.
  5. No model training. We do not use Gmail or Calendar data to develop, improve, or train generalized or non-personalized AI/ML models. Our AI subprocessors (Anthropic and OpenAI) operate under enterprise agreements that contractually require zero retention of inputs and outputs and prohibit training on customer data.

The same Limited Use commitments apply to Plaid financial data and to any other Connector Data we hold on your behalf, by our own choice.

5. Data Retention and Deletion

We retain your information for as long as your account is active and as needed to provide the Services. The retention windows below apply per data class.

Data classRetention while account is activeAfter account closure or disconnection
---------
Account profile, preferencesFor account lifetimeDeleted within thirty (30) days
Encrypted OAuth tokens (Plaid, Google)Until you revoke the connectorWiped at revocation; the installation is marked `revoked` and a credentials-audit row is appended
Plaid accounts + transactionsLifetime of connectorSoft-deleted at revocation; hard-deleted within thirty (30) days
Imported Google Calendar eventsLifetime of connectorSoft-deleted at revocation; hard-deleted within thirty (30) days
Calendar feed addresses and imported feed eventsUntil you remove the feedRemoved from the active database when you remove the feed. Backup copies follow the backup schedule below.
Time preferences, placed blocks, block history, changes and tasks, when you use Time schedulingLifetime of TimeDeleted within thirty (30) days of Time removal or account closure. Events held by Google are covered separately below.
Planning input snapshots, when you use Time planningThirty (30) days, then only an input hash remainsThe hash and other planning-run records follow the Time deletion schedule. Deleting an input snapshot does not delete the associated blocks or change history.
Email threads, messages, drafts metadataLifetime of connectorSoft-deleted at revocation; hard-deleted within thirty (30) days
Health and biometric data (workouts, sleep, HRV, readiness, activity, body composition, vitals, daytime stress and resilience, mindfulness)Lifetime of the Health Skill installationSoft-deleted at revocation of the Health Skill or the HealthKit / Oura source; hard-deleted within thirty (30) days
Training data tied to a plan (the goal and constraints you provide; the plan, its revisions, its prescribed sessions, and its adherence records; Section 1.6)Lifetime of the plan and of the Health Skill installationSoft-deleted when you delete the plan, uninstall the Health Skill, or close your account; hard-deleted within thirty (30) days. Disconnecting Apple HealthKit or Oura does not by itself delete it, because it is not synced from those sources
Benchmark results and the training zones derived from them (Section 1.6)Account level, kept across plans for the lifetime of the Health Skill installationNot deleted by deleting a plan: the result is detached from that plan and kept, because it describes your measured performance across plans. Deleted within thirty (30) days of uninstalling the Health Skill or closing your account
Conversation history, briefings, insights, and the cross-Skill connections held inside a briefing (Section 1.3)For account lifetimeDeleted within thirty (30) days of account closure. Disconnecting a source does not delete briefings already written
Cross-Skill connections held as standalone records, and the date each was last used (Section 1.3)For account lifetime, or until you delete them or turn the capability offDeleted immediately when you delete them in Settings > Memory, individually or all at once. Turning cross-Skill connections off or disconnecting a source Skill removes affected records from use immediately and permanently deletes them within thirty (30) days. Deleted within thirty (30) days of account closure
Saved chat facts and brief-correction notes, including their source references and first-learned and last-used dates (Section 1.3)For account lifetime, or until you delete themDeleted immediately through Settings > Memory. A saved fact with a recorded source Skill is removed from use when that Skill is disconnected and permanently deleted within thirty (30) days. Deleted within thirty (30) days of account closure
Suppression fingerprints for deleted memories (Section 1.3)For account lifetimeRetained to prevent the same memory from being saved again. Deleted within thirty (30) days of account closure
The one-way fingerprint kept when you delete a cross-Skill connection (Section 1.3)For account lifetimeKept for as long as your account is open, because deleting it would let Mustro draw the same connection again. Deleted within thirty (30) days of account closure
Agent events, intentsFor account lifetimeDeleted within thirty (30) days
Strava authorization tokensUntil access endsLocal disconnect, verified provider deauthorization, or account deletion removes the stored tokens. We attempt provider revocation on disconnect. Provider revocation may remain unconfirmed.
Strava activity content prepared for sharingOnly while preparing and sending the requestWe do not retain the activity payload in the export record. The source session follows its own retention schedule above.
Strava athlete identifier, export identifiers, payload hashes, activity URLs, and sharing eventsWhile the connection remains authorizedWe remove these records 30 days after access ends. A new connection has its own records. Account deletion removes the linked records.
Strava sharing agreement and withdrawal evidenceFor account lifetimeDisconnect stops sharing and resets automatic choices. We keep the wording, version, digest, choices, and agreement and withdrawal events until account deletion. These records do not contain Strava activity content.
BackupsRolling 30-day windowBackup copies age out within ninety (90) days of original deletion
Aggregated, de-identified analyticsIndefinitely (cannot be linked back to you)Not applicable
Audit logs (security and compliance)Up to seven (7) years where required by lawRetained per law; never used for other purposes

You may request earlier deletion at any time by emailing privacy@mustro.ai or by deleting your account in /settings → Account.

Events in Google Calendar. When you remove Time after using its scheduling controls, Mustro follows your choice to keep or delete the events it placed. On account deletion, Mustro attempts to remove those events unless your last recorded choice was to keep them, then revokes its Google access. If Google access has already ended or Google cannot complete a deletion, the event may remain. You can delete it in Google Calendar or contact privacy@mustro.ai for help. Events you keep remain in Google Calendar under Google's terms and your account settings. A consumer health data deletion request remains subject to the separate Health Policy, including recipient-notification duties.

Strava copies. Disconnecting Strava stops future sharing from Mustro. Deleting a session, uninstalling the Health Skill, or deleting your Mustro account does not automatically delete an activity already sent to Strava. A request already in progress may still complete. You can delete the activity in Strava.

For a request to delete consumer health data, contact privacy@mustro.ai. Where applicable law requires us to notify recipients, we also notify Strava of the request. Your ability to delete an activity yourself does not replace our obligations.

Account deletion timing. When you confirm account deletion, Mustro stops new Strava sharing. You can cancel account deletion for 14 days. Mustro schedules permanent deletion 30 days after your confirmation. Permanent deletion removes your account's Strava records from our production database. Consumer health data follows any shorter deadline required by applicable law and our Consumer Health Data Privacy Policy.

6. Data Security

We protect your information using technical and organizational measures appropriate to its sensitivity, including:

  • Encryption in transit using TLS 1.3 (or, where 1.3 is not supported by the requesting client, TLS 1.2).
  • Encryption at rest using AES-256-GCM for all sensitive data, including every OAuth token, Plaid item, and webhook payload. Master keys are managed by Google Cloud Secret Manager and are rotated; ciphertext is versioned so rotation does not require a full re-encryption pass.
  • Token isolation. OAuth tokens are decrypted only at point of use and never written to logs or analytics pipelines. The credential-storage helper (services/connectors/shared/credentials.ts in our source tree) is the single audited code path that reads or writes tokens.
  • Multi-tenant discipline from day one. Every domain table has a user_id column with composite indexing, and every database query in router code goes through a scoped database helper that auto-applies a WHERE user_id = ... filter. A CI lint test fails any pull request that imports the raw database client in a router file.
  • Access controls including role-based access, the principle of least privilege, multi-factor authentication for administrative access (provided by Firebase Identity Platform), and automated session timeout.
  • Audit logging of access to user data. Every authenticated request and every administrative action writes an immutable row to audit_logs, also exportable to Google Cloud Logging.
  • Webhook idempotency. Inbound webhook deliveries from Plaid and Google are deduplicated against a webhook_deliveries table so retries never produce duplicate data or duplicate actions.
  • Edge protections. Cloudflare provides DNS, DDoS mitigation, and an edge-level web application firewall for traffic to mustro.ai and api.mustro.ai. Google Cloud Armor enforces geographic restrictions consistent with U.S. export-control and sanctions law (see Section 18 of the Terms of Service).
  • Regular vulnerability scanning and penetration testing of the Platform.
  • Secure software development practices and protections against the OWASP Top 10.
  • Vendor risk management. Every subprocessor in Section 11 is contractually bound to protect your information.
  • Independent security review. We plan to complete Google's required security assessment before enabling Gmail access for external users beyond initial testing. Calendar-only Time access does not establish that this Gmail assessment is complete.

No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify you and applicable regulators consistent with applicable law.

7. International Users and Data Transfers

Mustro, Inc. is incorporated under the laws of Delaware, and our primary infrastructure is hosted on Google Cloud Platform in the United States. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States and may also be processed by our AI subprocessors in the United States.

For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable) or another lawful transfer mechanism. We perform transfer impact assessments where required.

8. Your Rights and Choices

Depending on your location, you may have the rights described below. We will respond to verified requests within the timeframes required by applicable law.

8.1 Rights Available to All Users

  • Access: request a copy of the personal information we hold about you, including a structured export of your Connector Data.
  • Correction: ask us to correct information that is inaccurate or incomplete (you can also edit your own profile and preferences in /settings).
  • Deletion: ask us to delete your information, subject to the limited exceptions described in Section 5.
  • Portability: request a copy of your information in a structured, machine-readable format (JSON).
  • Disconnect a source: revoke any connector at any time from /connectors; we stop syncing immediately and proceed with deletion per Section 5.
  • Manage what Mustro connects across your Skills: review every cross-Skill connection it holds as a standalone record in Settings > Memory, delete any of them or all of them, or turn cross-Skill connections off. You can also review and delete saved chat facts there, and edit an active chat fact without deleting it. Deleting is permanent in both directions: the record goes, and Mustro is stopped from drawing that same connection again. This does not edit briefings you have already been sent, which are kept as written per Section 5.
  • Opt out of non-essential communications: turn off briefings, push notifications, or marketing emails in /settings → Notifications. Service-related communications (e.g., security notices, billing) cannot be opted out of while your account is active.
  • Stop Strava sharing. Open You > Strava in the Mustro app and select Disconnect Strava. This withdraws your Strava sharing consent and turns off automatic sharing. You can also change the kinds enabled for automatic sharing on that screen. If Mustro cannot confirm provider revocation, open Strava App Settings and remove Mustro there. If the disconnect control is unavailable, contact privacy@mustro.ai to withdraw. You can also use that address to request deletion of consumer health data.

8.2 Additional Rights for EEA, UK, and Swiss Residents

If you are located in the EEA, the United Kingdom, or Switzerland, you also have the right to:

  • object to or restrict our processing of your personal data;
  • withdraw consent at any time where we rely on your consent;
  • lodge a complaint with your local supervisory authority.

We process your personal data on the following legal bases under the GDPR / UK GDPR:

  • Contract: to provide the Services that you have requested.
  • Legitimate interests: to operate, secure, and improve the platform and to prevent abuse. We have balanced these interests against your rights.
  • Legal obligation: to comply with applicable law.
  • Consent: where we ask for it (e.g., optional marketing communications, optional AI features that send your Connector Data to AI subprocessors).

8.3 Additional Rights for California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know, delete, and correct your personal information; to opt out of "sale" or "sharing" of personal information; and to non-discrimination for exercising these rights.

We confirm: we do not sell or share personal information in the senses defined by the CCPA/CPRA. We do not engage in cross-context behavioral advertising.

8.4 Exercising Your Rights

To exercise any of these rights, contact privacy@mustro.ai. We may need to verify your identity before responding. You may also designate an authorized agent to act on your behalf, subject to verification.

9. Children's Privacy

The Services are not intended for, or directed to, individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. If you believe a child has provided information to us, please contact privacy@mustro.ai.

10. Third-Party Links and Services

The Platform may link to or integrate with third-party sites or services (for example, the institution-selection screens that Plaid renders, or a "View in Gmail" link). This Privacy Policy does not apply to those services, and we are not responsible for their practices. Review their privacy policies before using them.

11. Subprocessors

We rely on the subprocessors below to provide the Services. Each is contractually bound to protect your information. The authoritative list, including the data classes shared with each subprocessor and the legal mechanism for any international transfer, lives in Subprocessors.md in our public legal repository and at <https://mustro.ai/legal/subprocessors>.

SubprocessorLocationPurpose
---------
Google Cloud PlatformUnited StatesCloud infrastructure (Cloud Run, Cloud SQL/Postgres, Cloud Tasks, Cloud Scheduler), Secret Manager, Cloud Logging, Cloud Armor (edge geographic / abuse protections)
Firebase (Google)United StatesUser authentication and identity, including MFA via Identity Platform
AnthropicUnited StatesAI inference (Claude) under zero-retention enterprise terms, including calendar event classification and schedule planning when you use Time
OpenAIUnited StatesAI inference (GPT) under zero-retention enterprise terms; only when explicitly enabled
PlaidUnited StatesFinancial-account connectivity, transactions, balances, liabilities
Google APIs (Calendar, Gmail)United StatesCalendar event and calendar-list sync, push notifications, and user-directed event creation and updates. When you use Time scheduling, removal of Mustro-placed events, optional Busy copies and creation of a Mustro calendar you select. Google Limited Use commitments apply. Gmail message, draft and user-requested label sync.
Oura (Oura Health Oy)Finland / United States (see Subprocessors.md)Health Skill recovery, sleep, and activity sync (sleep, HRV, readiness, activity, daytime stress, resilience, SpO2, wrist temperature; not workouts); your own Oura account data via the Oura API
StripeUnited StatesSubscription billing for paid Mustro tiers (PAN never held by Mustro)
ResendUnited StatesTransactional email delivery (briefings, alerts, service notices)
VercelUnited StatesHosting for `mustro.ai` (marketing + waitlist) and the Mustro admin web app
SanityUnited StatesHeadless CMS that serves blog and legal content rendered on `mustro.ai`
Expo (Application Services)United StatesPush-notification delivery to the mobile app
CloudflareUnited StatesDNS, CDN, and DDoS protection for `mustro.ai`
SentryUnited StatesApplication error tracking (Connector Data excluded from event payloads)

We may update this list. Material changes are published at <https://mustro.ai/legal/subprocessors> and, for institutional partners under a Data Processing Agreement, notified with the lead time required under that agreement.

Strava is an optional recipient you connect for session sharing, as described in Sections 1.8 and 3. It operates its own service under its own privacy policy. The processing restrictions in this subprocessor list do not describe Strava's independent processing.

Google Calendar also receives the event information you ask Mustro to place in your connected account. Google handles your calendar copy under the terms and privacy settings of that account. Health calendar sharing follows the separate Consumer Health Data Privacy Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date above and provide notice through the Platform or by email. Your continued use of the Services after the change becomes effective constitutes your acceptance of the updated Privacy Policy.

We obtain fresh consent before we begin a materially different Strava sharing practice that requires your consent. Continued use of Mustro does not replace that consent. For consumer health data, Section 10 of the Consumer Health Data Privacy Policy also applies.

13. Contact Us

For privacy questions or requests:

Mustro, Inc. Privacy: privacy@mustro.ai Legal: legal@mustro.ai Security: security@mustro.ai Website: mustro.ai

EEA, UK, and Swiss residents may also contact their local supervisory authority. The lead supervisory authority for our processing of EEA personal data is the Irish Data Protection Commission.