Earning your trust, one connector at a time.
Your training data, commitments and reflections deserve clear controls. Here is how Mustro treats the information you share.
How we treat your data.
Four practices built into the platform from the first commit.
Encrypted at every hop
TLS 1.2 or better in transit, AES-256 at rest in Google Cloud, encrypted backups. OAuth tokens and connector data are encrypted before they reach the database.
Least-privilege OAuth scopes
You choose which Health sources to connect and can disconnect them. Habits uses the commitments and check-ins you enter yourself.
Secrets managed, not sprinkled
Google Secret Manager holds every credential, rotation runs on a schedule, and engineering access is least-privilege and audit-logged.
Zero training on your data
Our inference providers are bound by zero-retention enterprise terms. Your prompts are not stored beyond inference and are never used for training.
The sources you choose.
Health reads the sources you authorize. Habits starts with your own words. Your connection settings show the access you grant.
Apple Health
Your health data on iPhone
Health reads the data types you allow from your iPhone. You can review and change those permissions in Apple Health.
Oura
Sleep, recovery and workouts
Connect Oura from Health to bring your recorded sleep, recovery and activity into Mustro. You can disconnect it from your Health settings.
Habits
Commitments, check-ins and reflections
Habits uses the week you define and the entries you write. You choose what to record and when to pause reminders.
Our commitments, in writing.
Promises that show up in our legal documents, our codebase, and our monitoring.
We will never sell your data, share it with advertisers, or use it to train models.
We will never send email under your name. Drafts are always staged for your review.
We will never move money. There is no level that changes that.
We will email you about material policy or subprocessor changes with the notice period in your DPA, which is 30 days by default.
We will respond to security disclosures within one business day and patch critical issues within seven.
Read the policies before you connect anything.
Every document that governs how Mustro handles your data lives in the legal center.