Mission R

Privacy Policy

Last updated September 20, 2026

The short version. We collect only what we need to run the site and the Mission R application. We do not sell personal information, we do not share it for advertising, and we do not use it to train AI models. The public website sets no cookies. The application sets two cookies that are strictly necessary to keep you signed in.

  1. Who we are
  2. What we collect
  3. How we use it
  4. Cookies and similar technologies
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. Security
  9. Your rights and choices
  10. Children
  11. Changes to this policy
  12. Contact us

1. Who we are

Mission R LLC ("Mission R", "we", "us") provides digital transformation services and the Mission R application, a multi-tenant control plane for managing projects and data. This policy covers:

We play two different roles. For information about visitors, account holders, and people who contact us, we are the controller (or, under US state laws, the "business"). For information that our customers put into their workspaces, such as customer records they manage in the Application, we act as a processor (a "service provider") on the customer's behalf and handle it only on their instructions. If your data is in a workspace, your organization is the one to ask about it. Section 9 explains how.

2. What we collect

When you visit the Site

When you contact us

If you use the contact form on the Site, we receive the name, email address, company name (optional), and message you enter. We also record the IP address and browser user-agent of the device that submitted it, which we use to prevent spam and abuse and to limit repeated submissions. The form is relayed through Cloudflare to the Mission R application and stored there, where Mission R staff can review and respond to it. If you email us instead, we receive your email address, name, and whatever you choose to write. We use it to reply.

When you sign in to the Application

The Application does not use passwords. You sign in with your organization's identity provider, currently Google Workspace. From it we receive and store:

These fields refresh each time you sign in. We ask the identity provider for only the openid, email, and profile information; we do not receive your Google password or access your Gmail, Drive, or other Google data.

When you use the Application

Customer content

Customers and their authorized users may store business information in the Application, for example customer records (names, email addresses, statuses, notes). This content is kept separately for each workspace. We do not use it for our own purposes and do not look at it except as needed to provide support, keep the Services secure, or comply with law.

3. How we use it

PurposeExamplesLegal basis (EEA/UK)
Provide the ServicesSigning you in, applying roles and workspace access, showing your name and photo, running the ApplicationContract; legitimate interests
Security and abuse preventionSession management, rate limiting (including contact-form submissions), spam prevention, audit logs, investigating incidentsLegitimate interests (keeping the Services and our customers safe)
Communicate with youReplying to contact-form messages and emails, service notices, supportLegitimate interests; contract
Understand Site usageOptional analytics, only if enabled and only if you acceptConsent
Legal and complianceMeeting legal obligations, enforcing our terms, responding to lawful requestsLegal obligation; legitimate interests

We do not sell personal information. We do not "share" it for cross-context behavioral advertising. We do not use personal information or customer content to train artificial intelligence models. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

4. Cookies and similar technologies

NameWherePurposeLifetimeType
mr_sessionApplicationKeeps you signed in (HttpOnly, not readable by scripts)8 hours from your last activity; removed when you sign outStrictly necessary
mr_csrfApplicationProtects against cross-site request forgerySame as the session cookieStrictly necessary
mr_consent (browser storage)SiteRemembers your analytics choice, only if analytics is enabled12 monthsStrictly necessary

Strictly necessary cookies do not require consent under EU/UK ePrivacy rules, so we do not ask for it. The Site itself sets no cookies. Fonts on the Site are hosted by us, so your browser does not contact Google Fonts or any other third party to render the page.

Optional analytics. If we turn on analytics for the Site, it stays off until you choose "Accept analytics" in the banner. "Reject" is equally easy, and you can change your mind at any time through the "Cookie settings" link in the footer. We also treat the Global Privacy Control signal from your browser as a rejection.

5. Who we share it with

We share personal information only with service providers that help us run the Services, under contracts that limit their use of it, and in the other cases below.

ProviderWhat they doData involved
Amazon Web ServicesHosts the Application (compute, encrypted storage, logging) in the US East (Ohio) regionApplication data, account data, contact-form submissions, logs
GoogleIdentity provider for sign-in (Google Workspace); serves profile photosSign-in identity; your browser requests your profile photo from Google when it is displayed
CloudflareHosts and delivers missionr.ai; DNS; relays contact-form submissions to the ApplicationTechnical data from Site visits; contact-form submissions in transit

We may also disclose information: (a) if required by law, subpoena, or valid legal process; (b) to protect the rights, property, or safety of Mission R, our customers, or others; and (c) in connection with a merger, financing, or sale of some or all of our business, in which case we will require the recipient to honor this policy. Within a workspace, your name, email, photo, and role are visible to other people in your organization according to their permissions.

6. International transfers

We are based in the United States and the Application is hosted in the United States, so personal information is processed there. If you are in the European Economic Area, the United Kingdom, or Switzerland, we transfer your information to the US under appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an applicable adequacy decision, and we rely on the same mechanisms our infrastructure providers offer.

7. How long we keep it

8. Security

Access to the Application requires single sign-on. Each customer's data is isolated in its own workspace store, access is controlled by role, and stored data is encrypted at rest. We protect sessions with secure cookies and request forgery tokens, and we log administrative activity. No system is perfectly secure, so if we learn of a breach affecting your personal information we will notify you and regulators as the law requires.

9. Your rights and choices

Depending on where you live, you may have the right to:

US state residents (including California, Colorado, Connecticut, Virginia, Texas, and others with comparable laws) have these rights under their state's privacy law. We do not sell personal information or share it for targeted advertising, so there is nothing to opt out of, and we honor Global Privacy Control signals.

People in the EEA and UK have the rights above under the GDPR and UK GDPR, and may lodge a complaint with their local data protection authority. We would appreciate the chance to address your concern first.

How to exercise your rights. Email michael@missionr.ai. We may need to verify your identity, and we will respond within one month (45 days for US state requests, extendable as the law permits). You may use an authorized agent where your state's law allows it. If your information sits in a customer's workspace, we will point you to that customer, since they decide what happens to it. Your workspace administrator can also update or remove your account.

10. Children

The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy as our Services or the law change. We will post the new version here with a new "Last updated" date, and for material changes we will give additional notice, such as an email to workspace owners.

12. Contact us

Mission R LLC
Email: michael@missionr.ai

If you need a data processing agreement for your organization's use of the Application, ask us at the address above.