Privacy Policy
Last updated September 24, 2026
This policy explains what information Mistro (“Mistro”, “we”, “us”) collects when you use mistro.work and the Mistro runner, how we use it, and the choices you have. If you have questions, email privacy@mistro.work.
Information we collect
- Account information. Your email address, and the name you give us during setup. We use your email to sign you in with one-time links.
- Content you create. Workspaces, projects, threads, messages, and the records of agent runs you start.
- Runner information. When you connect a device, we store an identifier for it, its name, and whether it is online, so work can be routed to it.
- Credentials you provide. API keys and access tokens for services you connect. These are encrypted at rest and used only to perform actions you request.
- Technical data. A session cookie that keeps you signed in, and standard server logs (such as IP address, browser type, and request times) kept by our hosting provider for security and debugging.
We do not use advertising trackers and we do not sell your information.
Connected accounts and third-party data
You can connect third-party accounts (for example Google, GitHub, Slack, or Linear) using OAuth. When you do, we receive only the permissions you approve on that provider’s consent screen, and we use the resulting access solely to provide the features you asked for — such as letting an agent read or update data in a project you’ve linked.
- We do not sell data obtained from connected accounts or use it for advertising.
- We do not use it to train generalized AI or machine-learning models.
- We do not allow humans to read it, except with your explicit permission, when needed for security or to comply with law, or when aggregated and anonymized for operations.
- We do not transfer it to others except as needed to provide the service, as below.
Mistro’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect an account at any time from within Mistro or from the provider’s own security settings. Disconnecting deletes the stored tokens.
How agent work is processed
Agent runs execute on a device you control, using your own Claude account. Prompts and the material an agent works with are sent from that device to Anthropic under your agreement with Anthropic. Mistro stores the conversation and run records so you can see them in the app.
Service providers
We rely on a small number of providers to operate Mistro:
- Vercel — application hosting
- MongoDB Atlas — database
- Resend — sending sign-in emails
- Anthropic — AI models, used through your own account
We may also disclose information if required by law, or to protect the rights and safety of our users and of Mistro.
Retention and deletion
We keep your information for as long as your account is active. You can ask us to export or delete your account and everything associated with it by emailing privacy@mistro.work; we will complete deletion within 30 days, except where we must keep something to meet a legal obligation.
Security
Data is encrypted in transit, and stored credentials are encrypted at rest with a key held separately from the database. No system is perfectly secure, but we work to protect your information and will notify you of a breach that affects it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, or to object to how it is processed. Contact us to exercise any of these rights.
Children
Mistro is not directed to children under 16, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date above, and tell you by email or in the app if the change is significant.