Subprocessors
Effective Date: September 24, 2026 Last reviewed: September 24, 2026
This page lists every subprocessor that Mustro, Inc., a Delaware corporation ("Mustro") engages to deliver the Services described in our Privacy Policy. Google Calendar also operates the connected account where you ask Mustro to place events. Google's handling of that account follows its own terms and privacy settings. Listing its API here does not convert that account into a service operated only on Mustro's instructions. Each subprocessor, for processing on Mustro's behalf, is contractually bound to:
- process personal data only for the purposes Mustro directs,
- maintain appropriate technical and organizational security measures, and
- comply with applicable data-protection laws (including, where relevant, the GDPR, UK GDPR, CCPA/CPRA, and the EU Standard Contractual Clauses).
For Mustro's direct individual users, this list is informative. For institutional customers under a Data Processing Agreement, this list is authoritative and material changes are notified with the lead time specified in that DPA.
Active subprocessors
| Subprocessor | Location | Data classes processed | Purpose | Transfer mechanism |
|---|---|---|---|---|
| --- | --- | --- | --- | --- |
| **Google Cloud Platform** (Cloud Run, Cloud SQL/Postgres, Cloud Tasks, Cloud Scheduler, Secret Manager, Cloud Logging, Cloud Storage, Cloud Armor) | United States | All Mustro data, at rest and in transit on Mustro infrastructure | Cloud infrastructure, encrypted-at-rest data store, queue processing, scheduled jobs, secret management, observability, edge geographic / abuse protection (Cloud Armor) | SCCs + GCP Data Processing Addendum |
| **Firebase** (Google): Authentication / Identity Platform | United States | Email, hashed credentials, MFA factors, sign-in events | Sign-in, identity verification, MFA (TOTP / SMS / recovery codes) | SCCs + Google Cloud DPA |
| **Anthropic**: Claude API | United States | Excerpts of Connector Data, training-plan inputs (the user's training goal and stated constraints, which may include injury information), calendar event titles and times, scheduling preferences, tasks, consented health-session information for Time planning, and Mustro prompts at inference time only; **zero-retention** of inputs and outputs | AI inference for Mustro chat, briefings, and training-plan generation and revision. Calendar event classification and schedule planning when you use Time. | Anthropic Zero Data Retention enterprise agreement + DPA; no training on customer data |
| **OpenAI**: GPT API | United States | Excerpts of Connector Data, training-plan inputs (the user's training goal and stated constraints, which may include injury information), and Mustro prompts at inference time only; **zero-retention** of inputs and outputs | AI inference for Mustro chat, briefings, and training-plan generation and revision (when the user opts to use OpenAI as the model) | OpenAI Enterprise zero-retention agreement + DPA; no training on customer data |
| **Plaid**: Financial connectivity | United States | Item access tokens (held by Plaid, encrypted reference held by Mustro); account, transaction, balance, and liability data | Connecting bank and credit card accounts via Plaid Link; transaction and balance sync via `transactions/sync` | Plaid End User Privacy Policy + Plaid Data Processing Addendum |
| **Google APIs (Calendar)** | United States | Calendar list and event information for connected calendars. Information in events Mustro places at your direction, including titles, times and the other event fields disclosed in the Privacy Policy. | Calendar event and calendar-list sync, push notifications, and user-directed event creation and updates. When you use Time scheduling, removal of Mustro-placed events, optional Busy copies and creation of a Mustro calendar you select. Google Limited Use commitments apply. | Google API Services User Data Policy, Limited Use; data is the user's own Google account data |
| **Google APIs (Gmail)** | United States | Email threads, messages (headers + bodies), draft metadata for mailboxes the user has granted | Inbox sync via `users.history.list`; draft creation via `users.drafts.create`; user-requested label changes; push notifications via Pub/Sub. **Send is not used.** | Google API Services User Data Policy, Limited Use; restricted-scope verification required (`gmail.modify`) |
| **Oura Health Oy** (Health and recovery connectivity) | Finland (Oura Health Oy). United States (Oura Inc.). Data is cloud-stored. Mustro has not confirmed the exact processing region. | Oura Ring biometrics for the Health Skill: sleep sessions and stages, HRV, resting heart rate, readiness / sleep / activity scores, daytime stress, resilience, SpO2, wrist temperature. Oura workout records are **not** retrieved. **Special-category health data.** | Recovery, sleep, and activity sync for the Health Skill via the Oura API | Oura Data Processing Addendum. For any transfer outside the EEA or UK, EU Standard Contractual Clauses and the UK Addendum as applicable. The exact entity, processing region, and transfer basis remain unconfirmed. The data is the user's own Oura account data, retrieved at end-user direction under OAuth. |
| **Stripe** | United States | Billing contact identity, payment-method tokens (full PAN never held by Mustro), subscription metadata | Subscription billing for paid Mustro tiers | Stripe Data Processing Addendum |
| **Resend** | United States | Email-address recipient, message content for transactional emails (briefings, alerts, service notices) | Transactional email delivery | Resend DPA + SCCs |
| **Vercel** | United States | IP addresses, request metadata; rendered HTML/JSON for the marketing site and admin web app, with **no decrypted Connector Data and no Mustro conversation content traverse Vercel edge** | Hosting and edge serving of `mustro.ai` (marketing, waitlist, blog, legal) and the Mustro admin web app | Vercel DPA + SCCs |
| **Sanity** | United States | Editor-authored content (blog posts, legal pages, marketing copy) and editor identities. **No end-user personal data, no Connector Data, no Mustro content is sent to Sanity.** | Headless CMS that serves blog and legal content rendered on `mustro.ai` | Sanity DPA + SCCs |
| **Expo (Application Services)** | United States | Push tokens, push-message content | Push-notification delivery to the Mustro mobile app on iOS and Android | Expo Terms of Service + DPA |
| **Cloudflare** | United States | IP addresses, request metadata for `mustro.ai` and `api.mustro.ai` | DNS, CDN, DDoS protection, edge-level WAF | Cloudflare DPA + SCCs |
| **Sentry** | United States | Error events, stack traces, request URLs, and **never** decrypted token material, decrypted Connector Data, or message bodies | Application error tracking | Sentry DPA + SCCs |
Connector flows are end-user-directed
Plaid, Google APIs, and Oura are listed above as subprocessors because Mustro calls them on the user's behalf. The data they hand back, however, is the user's own data from the user's own accounts, accessed by the user's explicit consent through each provider's standard connect flow. Mustro stores that data on the user's behalf under the Privacy Policy; we do not purchase data from these providers.
Training plans and related records originate inside Mustro. We store them on Mustro infrastructure and send the data needed for AI requests to our AI subprocessors under zero-retention terms. Section 1.6 of the Privacy Policy describes that processing.
If you separately enable Strava sharing, Mustro also sends the completed session fields described in Privacy Policy Section 1.8 to Strava. Strava operates its own service under its own Privacy Policy. It acts as an independent recipient of these exports. Its processing is not subject to the processor-only instructions described at the top of this page.
Cross-Skill connections that Mustro draws in a briefing (Section 1.3 of the Privacy Policy) add no subprocessor. They are derived inside the platform from data the user already connected, stored on Mustro infrastructure, and sent to the AI subprocessors above only at inference time under the same zero-retention, no-training terms; they are not shared with any additional subprocessor.
Saved chat facts use the same storage and AI subprocessors. They are sent to the AI providers only to answer or compose a briefing, under the existing zero-retention and no-training terms. The Memory view adds no subprocessor.
Apple HealthKit is not a subprocessor. Health Skill data from HealthKit is read locally on the end user's device under the user's per-category HealthKit permission and synced to Mustro; Mustro transmits no health data to Apple. HealthKit is a data source for the Health Skill, governed by the Privacy Policy.
Notification of changes
We may add, remove, or replace subprocessors as the Services evolve.
- For direct individual users: material changes are published here and at <https://mustro.ai/legal/subprocessors> and, where required by applicable law, reflected in the next version of the Privacy Policy.
- For institutional customers under a DPA: Mustro gives at least thirty (30) days' written notice (or the period stated in the DPA, whichever is longer) before an intended change to subprocessors affecting customer data, as specified in the DPA. Customers may object in writing within that notice period if they have a reasonable, lawful basis for doing so, in which case Section 6.3 of the DPA controls.
Subscribe to subprocessor updates
To be notified by email when this list changes, email legal@mustro.ai with the subject line "Subprocessor notice subscription." Institutional customers under a DPA receive notifications automatically per their agreement.
Contact
For questions about a subprocessor or this list:
Mustro, Inc. Legal: legal@mustro.ai Privacy: privacy@mustro.ai Website: mustro.ai