← Back to Mitlus

Privacy Policy

Version 1.0 — Effective date: 24 March 2026

1. Data Controller

Mitlus ("we", "us", "our") is the data controller responsible for your personal data. If you have questions about this policy or your data, contact us at [email protected].

2. Data We Collect

We collect and process the following categories of personal data:

  • Account information: name, email address, username, profile image, hashed password
  • OAuth tokens: access and refresh tokens from Google OAuth (stored encrypted, used for authentication only)
  • AI conversations: chat messages, conversation history, and AI-generated responses within your startup workspaces
  • Startup business data: business plans, assumptions, interview notes, financial data, team information, milestones, and all other data you enter into your startup workspaces
  • File uploads: documents and files you upload to the platform (metadata and content)
  • Usage logs: AI model usage, token counts, timestamps, and estimated costs for billing and analytics
  • Payment data: billing information processed by Stripe (we do not store credit card numbers directly)
  • Audit logs: records of significant account and data actions for security purposes
  • Technical data: IP addresses (for rate limiting and security), session cookies

3. Legal Bases for Processing (GDPR Article 6)

We process your data under the following legal bases:

  • Contract performance (Art. 6(1)(b)): providing the core platform features — startup workspaces, AI assistant, billing, and account management
  • Legitimate interest (Art. 6(1)(f)): security monitoring, fraud prevention, audit logging, rate limiting, and platform stability
  • Consent (Art. 6(1)(a)): processing your data through AI providers for generating insights, suggestions, and conversational assistance

4. Recipients and Sub-Processors

We share your data with third-party service providers (sub-processors) to deliver our services. See our full sub-processor list for details. Key recipients include:

  • Google: OAuth authentication (EU/US)
  • Stripe: payment processing (US, with EU data handling)
  • Anthropic: AI model provider — Claude (US)
  • OpenAI: AI model provider — GPT (US)
  • Google AI: AI model provider — Gemini (US)
  • OpenRouter: AI model routing — Mitlus One (Gemini 3.8 Flash) and Mitlus Max (Kimi K3) (US/EU)
  • Tavily: web search API (US)
  • Hosting provider: infrastructure and database hosting

5. Data Retention

  • Account data: retained while your account is active. After account deletion request, data is retained for a 30-day grace period, then permanently deleted.
  • AI usage logs: retained for 1 year for billing and analytics, then deleted.
  • Audit logs: retained for 2 years for security and compliance, then deleted.
  • Stripe events: retained for 6 months, then deleted.
  • Chat messages: retained while your account is active, deleted with your account.

6. Your Rights (GDPR Articles 15–22)

Under GDPR, you have the following rights:

  • Right of access (Art. 15): request a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate personal data via your account settings
  • Right to erasure (Art. 17): request deletion of your account and all associated data
  • Right to data portability (Art. 20): export your data in machine-readable JSON format
  • Right to object (Art. 21): object to processing based on legitimate interest
  • Right to restrict processing (Art. 18): request restriction of processing in certain circumstances
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time (does not affect prior processing)
  • Right to lodge a complaint: file a complaint with your local Data Protection Authority (DPA)

You can exercise your right to data export and account deletion directly from your account settings. For all other requests, contact [email protected].

7. International Data Transfers

Some of our sub-processors are located outside the EU/EEA, primarily in the United States. For these transfers we rely on:

  • EU–US Data Privacy Framework adequacy decisions where applicable
  • Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Supplementary technical measures (encryption in transit and at rest)

Models accessed through OpenRouter are routed by OpenRouter (US) to pinned inference providers: Mitlus One runs on Google infrastructure (US/EU) and Mitlus Max runs on US inference providers (Fireworks, Together, Baseten). Routing outside these pinned providers is disabled.

8. Anonymized Data Aggregation

We never access your individual chats, business data, or personal information for purposes beyond delivering the Service to you. If you opt in (via Settings > Privacy & Data), we may use anonymized, aggregated data — such as feature usage patterns and aggregate statistics — to improve the platform. This data cannot be traced back to you. You can opt out at any time without any impact on your experience.

9. Cookies

We use only essential cookies required for authentication and session management. We do not use analytics, advertising, or tracking cookies. The session cookie is a secure, HTTP-only cookie set by NextAuth.js.

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS)
  • Password hashing with bcrypt (cost factor 12)
  • Security headers (X-Content-Type-Options, X-Frame-Options, etc.)
  • Rate limiting on authentication and API endpoints
  • Audit logging of significant actions
  • Cascading deletes to prevent orphaned personal data

11. Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].

12. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will notify you through the platform (via a consent banner) and update the version number and effective date above. Your continued use of the platform after accepting the updated policy constitutes your acknowledgment of the changes.

13. Contact

For any questions about this privacy policy or to exercise your rights, contact us at: [email protected]