Legal

Privacy Policy

Last updated: 26 May 2026

1. Who We Are

MissionRobo (“we,” “us,” or “our”) operates the MissionRobo intelligence platform at missionrobo.com. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.

For privacy questions, contact [email protected].

2. Information We Collect

We collect the following categories of personal information:

  • Account information. Email address, password hash (never the cleartext password), and any profile fields you provide. If you sign in with Google or another OAuth provider, we receive the basic profile information that provider shares with us (typically name, email, and a stable identifier).
  • Subscription and billing information. Tier, billing cycle, billing status, and a Stripe customer identifier. Payment card details are collected and stored by Stripe, not by us; we never see or store the full card number.
  • Newsletter information. Email address, subscription preferences (digest / breaking / articles), and engagement metadata (open, click, bounce, unsubscribe).
  • Usage information. Pages viewed, features used, search queries entered, and timestamps. Includes standard server-side metadata such as IP address, user-agent string, and approximate location derived from IP.
  • Communications. Messages you send to support, feedback, or editorial addresses, including any attachments.
  • Cookies and similar technologies.Authentication cookies, theme preference, and minimal product analytics. See “Cookies” below.

We do not knowingly collect special-category data (e.g. health, biometric, precise geolocation, or government identifiers) and we do not intentionally collect information from children under 18.

3. How We Use Information

We use your personal information to:

  • provide, operate, and improve the Service;
  • authenticate you and secure your account;
  • process payments and manage subscriptions;
  • send transactional email (receipts, password resets, account notifications);
  • send the newsletter and product announcements you’ve opted into, and let you opt out at any time;
  • detect, prevent, and respond to fraud, abuse, security incidents, and policy violations;
  • comply with legal obligations and enforce our Terms of Service.

We do not sell personal information. We do not use your data to train third-party advertising models, and we do not run a third-party ad network on the Service.

4. Legal Bases (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following lawful bases:

  • Contract.To provide the Service you’ve subscribed to.
  • Legitimate interests. To secure the Service, improve features, and communicate with you about your account in ways you would reasonably expect.
  • Consent. For marketing emails and any optional analytics, where required.
  • Legal obligation. For tax, accounting, and compliance records.

5. Who We Share Information With

We share personal information only with the following categories of recipients:

  • Service providers (data processors) acting on our instructions under written contract:
    • Stripe, Inc. - payment processing, billing, customer portal.
    • Supabase, Inc. - authentication, database, and storage.
    • Resend, Inc. - transactional and newsletter email delivery.
    • Microsoft Azure - application hosting (Azure Static Web Apps) and operational telemetry.
    • Anthropic, PBC - backend processing of editorial analysis drafts (does not include user-account data).
  • Professional advisors (lawyers, accountants, auditors) where necessary and bound by confidentiality.
  • Authorities, where compelled by law, valid legal process, or to protect rights, safety, or property.
  • Successors, in the event of a merger, acquisition, or asset sale, in which case we will provide notice before personal information becomes subject to a different privacy policy.

6. International Transfers

Our service providers operate primarily in the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US and other jurisdictions whose data protection laws may differ from your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards provided by our processors.

7. Cookies

We use a small number of first-party cookies and local storage entries, none of which are used for third-party advertising:

  • Authentication cookies (set by Supabase Auth) to keep you signed in.
  • Theme preference (light/dark mode) stored in local storage so we remember your choice across visits.
  • Admin session cookie for back-office users only.

You can block or delete cookies via your browser settings, but doing so may make parts of the Service (notably signed-in pages) stop working.

8. Your Rights

Depending on where you live, you may have the following rights with respect to your personal information:

  • access a copy of the information we hold about you;
  • correct inaccurate information;
  • delete your account and associated personal data;
  • object to or restrict certain processing (including direct marketing - every marketing email includes an unsubscribe link, and you can manage newsletter preferences in your account);
  • request portability of the information you provided to us in a structured, commonly used format;
  • withdraw consent at any time where processing was based on consent (without affecting the lawfulness of processing before withdrawal);
  • lodge a complaint with your local data protection authority.

California residents have similar rights under the CCPA/CPRA, including the right to know what categories of information we collect and to whom we disclose it, the right to delete, the right to correct, and the right to opt out of any “sale” or “sharing” of personal information (we do not sell or share personal information in the CCPA sense).

To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within the time required by applicable law.

9. Data Retention

We keep personal information only as long as we have a legitimate purpose for doing so. In general:

  • Account data: for as long as your account is active, then for up to 90 days after closure for backups and dispute resolution, unless a longer period is legally required.
  • Billing records: retained for the period required by tax and accounting law (typically 7 years).
  • Newsletter data:retained until you unsubscribe, plus a small suppression record so we don’t accidentally email you again.
  • Server logs and operational telemetry: typically up to 90 days.

10. Security

We use industry-standard technical and organisational measures to protect personal information - including HTTPS in transit, encryption at rest where provided by our infrastructure providers, principle-of-least-privilege access control, and audit logging. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected such information, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or via the Service at least 14 days before the effective date. The “Last updated” date at the top of this page always reflects the current version.

13. Contact

Questions, requests, or concerns? Email [email protected]. For general support, use [email protected].

See also our Terms of Service.