Legal
Last updated 4 August 2026
We collect what's needed to run your workspace and nothing we can't justify. We don't sell personal data, and we don't use your business data or your Google data to train AI models. If you connect a calendar, we read busy/free times only — never event titles, attendees, or contents.
Mulstra Inc. (“Mulstra”, “we”) provides a workspace platform for running business operations — records, workflows, dashboards, and communications. This policy covers mulstra.com, workspaces hosted at *.mulstra.app, and the Mulstra application.
Questions, requests, or complaints: privacy@mulstra.com.
This distinction matters for everything below. When you use Mulstra we are a controller of your account data (your email, name, billing, how you use the product). For the records you put into your workspace — your contacts, leads, deals, files — we are a processor. That data is yours. We act on your instructions, we don't mine it, and we hand it back or delete it when you ask.
We do not run advertising trackers, we do not sell personal data, and we do not use behavioural profiling.
Connecting a Google Calendar is optional and per person. If you connect one:
calendar.freebusy — and only this.Limited Use. Mulstra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we do not transfer Google user data to third parties except as necessary to provide or improve this feature, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law; and we do not use it to develop, improve, or train generalised AI or machine-learning models.
Revoking access. Disconnect at any time from Settings → Profile → My calendar, or revoke Mulstra directly at myaccount.google.com/permissions. Revoking deletes the stored refresh token; availability simply becomes unknown again and no other part of your workspace is affected.
Some features send workspace content to a large language model to generate text, build schema, or answer questions. This happens only when you invoke such a feature. We use providers under agreements that prohibit training on our customers' data, and we do not use your workspace content or your Google data to train models— ours or anyone else's.
These sub-processors are part of running Mulstra itself:
Separately, you may connect optional integrations — Slack, Stripe, SendGrid, Apollo, a CalDAV server, your own database, and others. Those are your choices and your agreements with those providers; we pass data to them only as your configuration directs. You can disconnect any of them at any time.
Workspace content is kept while your workspace is active. Delete a record and it is soft-deleted first so it can be recovered from mistakes, then removed. Close your account and we delete your workspace content within 30 days, except where we must keep something to meet a legal or accounting obligation. Operational logs are kept for a limited period for security and debugging. Encrypted integration credentials are deleted as soon as you disconnect the integration.
Want everything gone sooner, or want an export first? Email privacy@mulstra.com and we'll do it.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a data protection authority. Exercise any of these by emailing privacy@mulstra.com. We'll respond within 30 days. We won't charge you or treat you differently for asking.
If your personal data sits inside someone else's Mulstra workspace — because they are our customer and you are their contact — direct your request to them; we'll assist them in fulfilling it.
Data is encrypted in transit (TLS) and at rest. Integration credentials get an additional layer of application-level AES-256-GCM encryption. Access to production systems is limited to people who need it. No system is perfectly secure, and we don't claim otherwise — but if a breach affects your data we will tell you promptly and tell you what we know.
Our infrastructure providers operate globally, so your data may be processed outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Mulstra is a business tool and is not directed at anyone under 16. We don't knowingly collect their data; if we learn we have, we delete it.
We'll update this page when our practices change and move the “last updated” date. If a change materially reduces your rights, we'll tell account holders by email before it takes effect.