Privacy Policy
The short version. We collect only what we need to run the site and the Mission R application. We do not sell personal information, we do not share it for advertising, and we do not use it to train AI models. The public website sets no cookies. The application sets two cookies that are strictly necessary to keep you signed in.
- Who we are
- What we collect
- How we use it
- Cookies and similar technologies
- Who we share it with
- International transfers
- How long we keep it
- Security
- Your rights and choices
- Children
- Changes to this policy
- Contact us
1. Who we are
Mission R LLC ("Mission R", "we", "us") provides digital transformation services and the Mission R application, a multi-tenant control plane for managing projects and data. This policy covers:
- missionr.ai, our public website ("Site"); and
- the Mission R application and related services ("Application"), together with the Site, the "Services".
We play two different roles. For information about visitors, account holders, and people who contact us, we are the controller (or, under US state laws, the "business"). For information that our customers put into their workspaces, such as customer records they manage in the Application, we act as a processor (a "service provider") on the customer's behalf and handle it only on their instructions. If your data is in a workspace, your organization is the one to ask about it. Section 9 explains how.
2. What we collect
When you visit the Site
- Technical data such as your IP address, browser type, and the pages requested. Our hosting provider (Cloudflare) processes this to deliver the Site and protect it from abuse.
- Optional analytics. If we enable analytics on the Site, we load it only after you accept it (see Section 4).
When you contact us
If you use the contact form on the Site, we receive the name, email address, company name (optional), and message you enter. We also record the IP address and browser user-agent of the device that submitted it, which we use to prevent spam and abuse and to limit repeated submissions. The form is relayed through Cloudflare to the Mission R application and stored there, where Mission R staff can review and respond to it. If you email us instead, we receive your email address, name, and whatever you choose to write. We use it to reply.
When you sign in to the Application
The Application does not use passwords. You sign in with your organization's identity provider, currently Google Workspace. From it we receive and store:
- your name, given name, family name, and email address;
- the URL of your Google profile photo (we store the link, not a copy of the image), and your language/locale setting;
- a stable identifier for your account from the identity provider; and
- your role in the Application (owner, admin, operator, or viewer) and the workspaces you can access.
These fields refresh each time you sign in. We ask the identity provider for only the openid, email, and profile information; we do not receive your Google password or access your Gmail, Drive, or other Google data.
When you use the Application
- Session and security data: a hashed session token, your browser's user-agent string, and session start, last-active, and expiry times. Sign-in attempts are recorded along with the IP address they came from, to limit abuse (rate limiting).
- Audit records: a log of actions taken in your organization's workspace (who did what, to which resource, and when), so administrators can see activity and we can investigate security issues.
- Server logs from our hosting environment, used for operations and troubleshooting.
Customer content
Customers and their authorized users may store business information in the Application, for example customer records (names, email addresses, statuses, notes). This content is kept separately for each workspace. We do not use it for our own purposes and do not look at it except as needed to provide support, keep the Services secure, or comply with law.
3. How we use it
| Purpose | Examples | Legal basis (EEA/UK) |
|---|---|---|
| Provide the Services | Signing you in, applying roles and workspace access, showing your name and photo, running the Application | Contract; legitimate interests |
| Security and abuse prevention | Session management, rate limiting (including contact-form submissions), spam prevention, audit logs, investigating incidents | Legitimate interests (keeping the Services and our customers safe) |
| Communicate with you | Replying to contact-form messages and emails, service notices, support | Legitimate interests; contract |
| Understand Site usage | Optional analytics, only if enabled and only if you accept | Consent |
| Legal and compliance | Meeting legal obligations, enforcing our terms, responding to lawful requests | Legal obligation; legitimate interests |
We do not sell personal information. We do not "share" it for cross-context behavioral advertising. We do not use personal information or customer content to train artificial intelligence models. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
4. Cookies and similar technologies
| Name | Where | Purpose | Lifetime | Type |
|---|---|---|---|---|
mr_session | Application | Keeps you signed in (HttpOnly, not readable by scripts) | 8 hours from your last activity; removed when you sign out | Strictly necessary |
mr_csrf | Application | Protects against cross-site request forgery | Same as the session cookie | Strictly necessary |
mr_consent (browser storage) | Site | Remembers your analytics choice, only if analytics is enabled | 12 months | Strictly necessary |
Strictly necessary cookies do not require consent under EU/UK ePrivacy rules, so we do not ask for it. The Site itself sets no cookies. Fonts on the Site are hosted by us, so your browser does not contact Google Fonts or any other third party to render the page.
Optional analytics. If we turn on analytics for the Site, it stays off until you choose "Accept analytics" in the banner. "Reject" is equally easy, and you can change your mind at any time through the "Cookie settings" link in the footer. We also treat the Global Privacy Control signal from your browser as a rejection.
5. Who we share it with
We share personal information only with service providers that help us run the Services, under contracts that limit their use of it, and in the other cases below.
| Provider | What they do | Data involved |
|---|---|---|
| Amazon Web Services | Hosts the Application (compute, encrypted storage, logging) in the US East (Ohio) region | Application data, account data, contact-form submissions, logs |
| Identity provider for sign-in (Google Workspace); serves profile photos | Sign-in identity; your browser requests your profile photo from Google when it is displayed | |
| Cloudflare | Hosts and delivers missionr.ai; DNS; relays contact-form submissions to the Application | Technical data from Site visits; contact-form submissions in transit |
We may also disclose information: (a) if required by law, subpoena, or valid legal process; (b) to protect the rights, property, or safety of Mission R, our customers, or others; and (c) in connection with a merger, financing, or sale of some or all of our business, in which case we will require the recipient to honor this policy. Within a workspace, your name, email, photo, and role are visible to other people in your organization according to their permissions.
6. International transfers
We are based in the United States and the Application is hosted in the United States, so personal information is processed there. If you are in the European Economic Area, the United Kingdom, or Switzerland, we transfer your information to the US under appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an applicable adequacy decision, and we rely on the same mechanisms our infrastructure providers offer.
7. How long we keep it
- Sessions expire 8 hours after last activity. Session records that have expired are deleted.
- Sign-in attempt records (including IP addresses) are kept for up to 24 hours.
- Hosting logs are kept for 30 days.
- Account data and audit records are kept while your organization has a workspace with us, so your organization has a complete history. After a workspace is closed, we delete or anonymize its data within a reasonable time unless we must keep it to meet legal obligations or resolve disputes.
- Contact-form messages and emails to us are kept as long as needed to deal with your request and for our business records. Ask us and we will delete yours.
8. Security
Access to the Application requires single sign-on. Each customer's data is isolated in its own workspace store, access is controlled by role, and stored data is encrypted at rest. We protect sessions with secure cookies and request forgery tokens, and we log administrative activity. No system is perfectly secure, so if we learn of a breach affecting your personal information we will notify you and regulators as the law requires.
9. Your rights and choices
Depending on where you live, you may have the right to:
- know what personal information we hold about you and get a copy of it;
- correct inaccurate information;
- delete your information;
- restrict or object to certain processing, including processing based on our legitimate interests;
- receive your information in a portable format;
- withdraw consent at any time, where processing is based on consent (this does not affect earlier processing); and
- not be discriminated against for exercising these rights.
US state residents (including California, Colorado, Connecticut, Virginia, Texas, and others with comparable laws) have these rights under their state's privacy law. We do not sell personal information or share it for targeted advertising, so there is nothing to opt out of, and we honor Global Privacy Control signals.
People in the EEA and UK have the rights above under the GDPR and UK GDPR, and may lodge a complaint with their local data protection authority. We would appreciate the chance to address your concern first.
How to exercise your rights. Email michael@missionr.ai. We may need to verify your identity, and we will respond within one month (45 days for US state requests, extendable as the law permits). You may use an authorized agent where your state's law allows it. If your information sits in a customer's workspace, we will point you to that customer, since they decide what happens to it. Your workspace administrator can also update or remove your account.
10. Children
The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy as our Services or the law change. We will post the new version here with a new "Last updated" date, and for material changes we will give additional notice, such as an email to workspace owners.
12. Contact us
Mission R LLC
Email: michael@missionr.ai
If you need a data processing agreement for your organization's use of the Application, ask us at the address above.