Privacy & Security Architecture
Your mind.
Your data.
Always.
Mystacy handles thoughts, contacts, and communications โ€” some of the most sensitive data a person can have. We treat it accordingly. Here's exactly how it works, technically and in plain English.
๐Ÿ”
Encryption
AES-256-GCM
๐Ÿ›๏ธ
Storage
Ciphertext only
๐Ÿšซ
Data sold
Never
๐Ÿ‘๏ธ
We can read your data
No
How it works technically
The encryption architecture.
This is not marketing language. This is how the system actually works. If you're a technical person, this section will satisfy you. If you're not, the summary is: we cannot read your data, even if we wanted to.
Encryption flow ยท Client โ†’ Server โ†’ AI
๐Ÿ’ป
Your Browser / Device
Data is encrypted here using AES-256-GCM before it leaves your device. Your encryption key never leaves the client.
Plaintext here only
โ†“ Encrypted payload travels over TLS โ†“
๐Ÿ—„๏ธ
Supabase Database
Stores only ciphertext. No plaintext. Even database admins cannot read your notes, tasks, or contact data.
Ciphertext only
โ†“ Fetched as ciphertext โ†’ decrypted in browser โ†“
๐Ÿ”“
Browser-side Decryption
Context is decrypted in your browser before being passed to the Claude API. The AI never sees raw ciphertext from the DB.
Decrypted locally
โ†“ Decrypted context sent to AI over TLS โ†“
๐Ÿค–
Claude API (Anthropic)
Receives context for your session only. Anthropic's data handling applies. We do not send your data to other AI providers.
Session-scoped only
Privacy principles
Six things we will always do.
01
Encrypt before it leaves your device
Every piece of data you create in Mystacy is encrypted client-side using AES-256-GCM before it is transmitted. This is non-negotiable and will never change.
02
Store only what's necessary
We collect the minimum data required to run the service. Your email address, subscription status, and encrypted content. Nothing more.
03
Never sell your data
We will never sell, rent, or trade your data to any third party, advertiser, or data broker. Our business model is subscriptions โ€” not your information.
04
Tell you if anything changes
If we ever change our data practices, we will notify you by email before the changes take effect โ€” not after. You will always have the opportunity to delete your data and leave.
05
Give you full data portability
You can export all your data at any time in standard formats. If you leave Mystacy, your information leaves with you. Nothing is held hostage.
06
Delete completely on request
If you request account deletion, all your data โ€” including encrypted content โ€” is permanently deleted within 30 days. No backups retained beyond that window.
Data collection
Exactly what we collect and why.
No ambiguity. Here is every category of data Mystacy handles, what we do with it, and whether it is encrypted.
Data Type Purpose Encrypted Shared
Email addressAccount identification, communicationNo (needed for auth)Never sold
Notes & capturesYour second brain contentAES-256-GCMNever
Tasks & projectsProductivity layerAES-256-GCMNever
Contact intelligenceRelationship layerAES-256-GCMNever
SMS contentStacy agent interactionsAES-256-GCMNever
Gmail contentContact intelligence (if enabled)AES-256-GCMNever
Subscription & billingPayment processing via StripeStripe-managedStripe only
Usage analyticsProduct improvement (anonymized)AnonymizedNever identified
Our commitments
What we will never do.
๐Ÿšซ
Never serve ads
There are no ads in Mystacy. There never will be. Advertising models require treating users as inventory. We treat you as a customer.
๐Ÿšซ
Never sell data
Your data has no value to us except as something to protect on your behalf. It will never be sold, licensed, or traded to any third party.
๐Ÿšซ
Never train AI on your data
Your captures, notes, and contact intelligence are never used to train AI models โ€” ours or anyone else's. Your thoughts are yours.
๐Ÿšซ
Never share without consent
We do not share your data with any third party without your explicit consent, except where legally required (and we'll tell you if that happens).
๐Ÿšซ
Never obscure our practices
This page is written in plain English. If our practices ever change, you'll hear about it before it happens โ€” not buried in a terms update.
๐Ÿšซ
Never hold your data hostage
Full export available at any time. Deletion is permanent and complete. You are never locked in.
Legal
The policy in plain English.
We've written an actual plain-English summary. The full legal document is below that. Read whichever suits you.
Contact us
Questions about your data? We respond personally.
Privacy questions
Questions about how we handle your data, requests to export or delete your account, or GDPR/CCPA inquiries.
[email protected] โ†’
Security disclosures
Found a security vulnerability? We take responsible disclosure seriously and will respond within 24 hours.