Privacy Policy

Last updated: May 26, 2026

This Privacy Policy describes how MistryOS, Inc. (“MistryOS”, “we”, or “us”) collects, uses, shares, and protects information when you use our platform, websites, APIs, and related services (collectively, the “Service”). By using the Service, you agree to the practices described here.

1. Definitions

Customer Data means content, records, files, prompts, outputs, communications, workspace information, metadata, uploaded media, and other information submitted to, stored in, generated through, or processed by the Service on behalf of a customer.

Personal Data means information relating to an identified or identifiable natural person under applicable privacy laws.

2. Information we collect

We collect the following categories of information:

  • Account Information: Name, email address, organization name, and authentication identifiers when you sign up or sign in.
  • Customer Data from Connected Systems: When you authorize MistryOS to connect to a third-party system (such as HubSpot, QuickBooks, Google Drive, Microsoft 365, or similar), we ingest data from that system on your behalf, limited to the scope and resources you authorize.
  • Workflow and Agent Activity: Records of actions taken by you, your authorized users, or AI agents within the Service, including conversation history with the assistant, communication metadata, voice-to-text transcriptions, and media uploads (such as job-site images or technical schematic files).
  • Usage and Device Information: Standard server logs (IP address, user agent, timestamps), product analytics events, and error reports. We filter known crawler and bot traffic before any of this is attributed to a real user.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service for you.
  • Authenticate you and your authorized users.
  • Sync data between your connected systems and your MistryOS workspace as you direct.
  • Power workflows and AI assistant features that you explicitly invoke.
  • Communicate with you about the Service, including security and operational notices.
  • Diagnose technical issues, monitor service health, comply with legal obligations, and enforce our agreements.

AI and Communication Disclaimers:

  • No Data Selling or Model Training: We do not sell Customer Data. We do not use Customer Data to train, fine-tune, or develop any general-purpose or foundation AI models. Customer Data is processed solely to provide the Service to you.
  • Third-Party AI Processing: Certain Service features rely on third-party AI providers to process Customer Data in order to generate outputs requested by users. AI-generated outputs may be inaccurate, incomplete, or unsuitable for operational, legal, engineering, construction, financial, or customer-facing decisions and should be reviewed before use.
  • Messaging Consent: If you enable automated customer-facing workflows via WhatsApp or SMS, you (the Customer) represent that you have obtained appropriate consent from your end-users to communicate with them via these channels. MistryOS acts strictly as a data processor for these communications.

4. Legal bases (for users in the EEA / UK)

Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases for processing personal data:

  • (a) performance of a contract with you or your organization;
  • (b) our legitimate interests in operating, securing, and improving the Service, balanced against your rights;
  • (c) compliance with legal obligations; and
  • (d) your consent where required, for example when you connect a third-party account.

5. How we share information

We share information only as needed to provide the Service. We do not sell personal data. We rely on the following categories of subprocessors:

  • Supabase: Database, authentication, and encrypted secrets storage (United States).
  • Cloudflare: Application hosting, CDN, and DDoS protection (global edge).
  • Trigger.dev: Background job execution for syncs and long-running tasks.
  • AI Inference Providers (e.g., Anthropic, OpenAI, Gemini): MistryOS configures supported AI providers to process Customer Data solely to provide the requested functionality and does not permit the use of Customer Data to train publicly available foundation models.
  • Resend: Transactional and inbound email delivery.
  • PostHog: Product analytics and session telemetry.
  • WhatsApp Business Platform (Meta): Only if you enable the WhatsApp agent on your workspace.

We may update subprocessors from time to time and maintain an updated list.

Other Disclosures:

  • Legal & Corporate Compliance: We may share information when required by law, to enforce our Terms, to protect against fraud or security threats, or in connection with a merger, acquisition, or sale of assets. Where practicable, affected customers will be notified.
  • Internal Personnel Access: Authorized personnel may access limited Customer Data only when reasonably necessary for customer support, debugging, abuse prevention, security investigations, or legal compliance.

6. Third-Party Connected Services and API Data Policy

MistryOS allows you to connect various third-party cloud services and platforms (such as Google Workspace, Microsoft 365, and other integrated applications) to your workspace. Our use, access, and transfer of any information received from these third-party APIs will strictly adhere to the respective provider’s developer policies, including any applicable “Limited Use” requirements.

Specifically, when you connect a third-party document, spreadsheet, or account to MistryOS:

  • Granular and Restricted Access: MistryOS requests only the permissions necessary to function (such as per-file access). We use platform-native file pickers wherever possible to ensure we access only the files you explicitly select. We do not request broad, unrestricted access to your cloud storage or account directories.
  • Scope of Data Access: We access only the specific files, data, or systems you intentionally authorize. We do not read, list, enumerate, or modify any other files or assets within your connected third-party accounts.
  • Purpose of Processing: Data from the selected third-party services is used solely to provide and support the specific features you invoke (such as syncing a document into your workspace, answering context-based questions, or executing updates at your request).
  • Data Transfer Restrictions: We do not transfer data received from these APIs to any third party except to the trusted subprocessors listed in Section 5, and only as strictly necessary to provide, improve, or secure our user-facing features. We never sell this data or use it for serving advertisements.
  • Human Access Restrictions: We do not allow human review of data retrieved via third-party integrations unless: (a) we have your explicit, affirmative consent for specific data points or files; (b) it is necessary for security purposes (such as investigating abuse or system vulnerabilities); (c) it is required to comply with applicable laws or regulations; or (d) the data has been fully aggregated and anonymized for internal technical operations.

7. Data retention

We retain Customer Data for as long as your account is active or as needed to provide the Service. When your account is terminated, we delete Customer Data within a reasonable retention window unless we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Server logs and analytics events are retained for shorter periods consistent with operational needs.

8. Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit, encrypted storage of third-party credentials in Supabase Vault, principle-of-least-privilege access for staff, and security monitoring. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security.

Security concerns may be directed to: security@mistryos.com

9. Your rights and choices

Depending on where you reside, you may have rights under applicable law (including GDPR, UK GDPR, and the California Consumer Privacy Act) to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at legal@mistryos.com. You can also disconnect any third-party integration at any time from your workspace settings, which revokes our ongoing access to that system.

10. Customer vs. End User Data

Our Service is designed for use by businesses. If you use the Service through your employer or an organization, they act as the Data Controller, and MistryOS acts as the Data Processor. Please refer to your organization’s privacy policy for questions about how your workspace data is managed.

11. International transfers

MistryOS is operated from the United States and has its primary infrastructure there. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States. Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and measure product usage. Most browsers let you control cookies through their settings. Disabling cookies may prevent parts of the Service from working.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will notify you by posting the updated policy on this page and updating the “Last updated” date above, and, for paid customers, by sending a notice to the email address on file. Your continued use of the Service after a change becomes effective constitutes your acceptance of the updated policy.

15. Contact

Questions about this Privacy Policy or our handling of your information can be sent to legal@mistryos.com.