Skip to main content

Legal

Privacy Policy

At Mishka, protecting your data is a priority. This policy explains how we collect, use and protect your personal information.

Last updated: 6 September 2026

1. Data controller

The data controller for personal data collected on usemishka.com is: Joris Ricard (Sole trader (entreprise individuelle)), trading as Agence JRi Registered address: 19 rue Gambetta, 69270 Fontaines-sur-Saône, France SIRET: 10169722500015 APE code: 6201Z - Programmation informatique VAT: not applicable - VAT exemption (article 293 B of the French General Tax Code) Contact: mishka-team@usemishka.com Privacy contact: mishka-team@usemishka.com

2. Scope - controller vs processor

Mishka acts as data controller for your account data (registration, billing, support). When you enter data about your own clients, contacts or projects in Mishka, you remain the data controller for that business data. Mishka acts as a data processor on your behalf, in accordance with our Data Processing Agreement (DPA) available at /dpa.

3. Data collected

We collect: • Identification: name, email, company name (optional) • Account: password (hashed), OAuth profile (Google: email, name, photo), MFA settings • Usage: actions in the app, preferences, language, timezone • Billing: processed by Stripe (payment method, invoices) • Technical: IP address, connection logs, browser, error reports (Sentry) • Anti-abuse: hCaptcha signals on signup/login • Analytics (with consent only): Google Analytics GA4 • Business content you create: projects, tasks, client contacts, encrypted client credentials, attachments, meeting notes, documents • Client portal: data about people outside an organization who have been invited by it to its client portal (see section 8) Admin access ("view as"): for support and operational needs, an authorized administrator may temporarily access an account, excluding super-admin accounts, disabled accounts and their own. This access is logged, time-limited, and disclosed to the person concerned: a history is shown in self-service (Profile → Security) and an email is sent at the end of each support session. We do not intentionally collect sensitive data or data from minors.

5. Retention periods

• Account data: until the account is deleted, then a 14-day grace period before permanent deletion • Billing data: 10 years (legal accounting obligation) • Authentication logs (sign-ins, attempts): kept for 7 days by Supabase Auth, our authentication subprocessor (log retention of its Pro plan); we apply no further purge to those logs • Read notifications: 90 days from the moment they are read. Unread notifications are not automatically purged • Action history (audit): depends on your plan - 7 days below Team, 30 days on Team and Agency, unlimited on Enterprise. Past that point records are permanently deleted: there is no archive. The history can be viewed in the app from the Team plan; on lower plans the records are kept for those 7 days as a technical buffer, without being exposed • Admin audit logs: 365 days • Processed payment events: 30 days • Internal analytics events: 365 days • Trash (soft-deleted items): 30 days before permanent deletion • Deleted account (grace period): 14 days (restoration possible), then deletion • Revoked client portal access: 12 months after revocation, then the access record is deleted. A portal authentication account left without any access for 12 months is deleted • Client portal notifications: 90 days after being read, and 365 days in any event • Content created by a portal user (requests, messages, comments, approvals, uploaded files): kept in the workspace of the organization that invited them, for the retention periods applicable to its content • Support email exchanges: 2 years after the request is closed, in our business mailbox

6. Hosting and security

Application data is hosted in the European Union (Supabase - EU West, Ireland). The web application is served via Vercel Inc. (a US company, ISO 27001, Standard Contractual Clauses): its server functions run in the European Union (Dublin, Ireland region), while its content delivery network (CDN) is worldwide. Security measures: • Encryption at rest (AES-256) • Encryption in transit (TLS 1.3) • Client credentials encrypted with AES-256-GCM • Role-based access control (RLS) • Daily database backups, and weekly backups of uploaded files • Optional two-factor authentication (TOTP), whose secret is generated and stored by our authentication subprocessor, separately from the credential vault encryption described above

7. Your rights

Under GDPR, you have the right to access, rectify, erase, restrict, object and data portability. • Self-service, for users holding an organization account: export your data (Profile → Data) and delete your account (Profile → Danger zone) • Self-service, for client portal users: export your data (Portal → Preferences → My data, JSON format) • Email: mishka-team@usemishka.com - we respond within one month. That period may be extended by two months for complex or numerous requests (GDPR article 12.3), in which case we inform you within the first month, stating the reasons • Complaint: you may contact the CNIL (www.cnil.fr) Account deletion is not available in self-service to client portal users: the access is opened by the organization that invited them, and it is the one that can revoke it (see section 8). If you are a contact stored by a Mishka customer (agency), please contact that agency directly. Mishka assists its customers as processor.

8. Client portal users

This section is for people outside an organization using Mishka who have received from it an invitation to its client portal. It constitutes information under GDPR articles 13 and 14. Where your data comes from: you did not create your account yourself. The organization that invited you passed on your email address and, where applicable, the name and role held in its own contact record. Your data was therefore obtained indirectly, from that organization, which is the controller for it and warrants to Mishka that it was entitled to invite you and that it informed you (Terms of Service, section 5). The identity of that organization appears in the invitation email and in the portal, and may be requested from us at any time. Data processed: email address, technical identifier of the authentication account, creation and login dates, timestamp of acceptance of the terms and of this policy; display name, avatar, language and timezone where you provide them; the client your access relates to, your role (viewer, validator, client_admin), the status of the access and the date you were last seen; the content you create (requests, messages, comments, approval decisions and change requests, uploaded files where that module is enabled); notifications sent to you in the portal and their read status; emails (invitation, single-use login link, notifications, service messages); technical data (IP address, connection logs, browser and device information, error reports, portal cookies). No password is processed: login is by single-use email link. Purposes and legal bases: opening and maintaining your access and allowing you to view, comment, approve and submit (performance of the contract between Mishka and the organization, and legitimate interest of that organization in working with you); sending the emails required for the portal to work (contract / legitimate interest); security, prevention of abuse and traceability of approvals (legitimate interest); audience measurement on the portal and non-essential cookies (consent); keeping evidence of acceptance of the terms (legal obligation / legitimate interest). Recipients: the members of the organization that invited you see your email address, name and avatar, your role, the status of your access and the date you were last seen, as well as all the content you create in the portal - your contributions are not anonymous. Other people invited to the same client space see the content shared within it. Our subprocessors (section 10) act within the limits of their respective services. Your data is never sold. Your rights: access, rectification, erasure, restriction, objection and portability, and withdrawal of consent at any time for the processing that relies on it. Exporting your data is available in self-service from the portal (Preferences → My data, JSON format): it contains your profile, your authentication account, your accesses (role, status, dates, notification preferences), your requests and messages, your comments, your review decisions, the files you uploaded and the notifications sent to you. Account deletion, however, is not available in self-service: your access was opened by the organization that invited you, and it is the one that can revoke it. For other requests, write by email to mishka-team@usemishka.com, stating the organization that invited you. For the data held by that organization in its workspace, contact it directly: it is the controller, and Mishka assists it as processor. You may also lodge a complaint with the CNIL (www.cnil.fr). After your access is revoked by the organization, your authentication account remains for twelve months without any possibility of login, in order to preserve the traceability of past actions; after that period the access record is deleted, and so is your authentication account if you have no other access left. The content you submitted stays in the workspace of that organization (see section 5). Role of Mishka: Mishka acts as processor of the organization that invited you for the portal content and management data. For the technical management of the authentication account, security and logging, Mishka acts on its own behalf, as controller.

9. Cookies and analytics

We use: • Strictly necessary cookies: Supabase session, preferences, consent record (mishka_consent, kept for 6 months) • Analytics cookies (only with your consent): Google Analytics GA4 with Consent Mode v2 These rules also apply to the client portal, where an authentication session cookie and an application cookie remembering the client space you selected (mishka-portal-client, 30 days) are also set. Portal users are shown the same consent banner and have the same choices. See our Cookie Policy at /cookies. You can manage preferences via the banner or footer link at any time.

10. Subprocessors

We use the following subprocessors (all under GDPR-compliant agreements): • Supabase - EU (Ireland): database, authentication, file storage • Vercel Inc. - US: hosting and content delivery (worldwide CDN), server functions run in the EU (Dublin) (SCC) • Stripe - EU/US: payment processing (SCC) • Resend (Plus Five Five, Inc.) - US: transactional email delivery (SCC) • Sentry - US: error monitoring; session recording only when an error occurs in the application (never on the public website, text and inputs masked) (SCC) • Google - US: OAuth login; Analytics measurement, with your consent (SCC) • hCaptcha (Intuition Machines, Inc.) - US: bot protection (SCC) • Upstash, Inc. - data hosted in the EU (Frankfurt, eu-central-1): Redis, rate limiting and cache • Anthropic PBC - US: AI generation of summaries and briefs, on demand only, Studio plans and above (DPA with SCC; API data is not used to train models) Transfers outside the EEA are governed by Standard Contractual Clauses or equivalent safeguards.

11. Marketing and engagement emails

We may send service-related emails (notifications, billing, security) based on contract or legitimate interest. Engagement emails (onboarding tips, weekly summary, inactivity reminders, trial reminders) may be sent to help you use Mishka. You can opt out via the unsubscribe link in each email or by contacting us. Promotional emails require your explicit consent where applicable.

12. AI features

Since version 1.5.0, Mishka offers AI-assisted generation of summaries and briefs: • Project state summary • Client account synthesis • Meeting note or report summary • Writing assistance inside documents • Personalized daily brief (your priorities, expected replies and deadlines) These features are available from the Studio plan, triggered only on a user’s explicit request ("Generate" button), and capped by a monthly quota per organization. Provider: Anthropic PBC (Claude API, US), under a Data Processing Addendum including Standard Contractual Clauses; API data is not used to train its models. Legal basis: contract performance. Only the work content strictly necessary to the requested synthesis is transmitted (project names and descriptions, tasks, comments, activity history, time tracked) - never client credentials or vault passwords, nor billing data. Generated summaries are stored in your organization’s account and follow the same deletion rules as other content. AI-generated content may contain inaccuracies: review it before any binding use.

13. Changes

We may update this policy. Substantial changes will be notified by email or in-app notification. The French version prevails in case of discrepancy.

For any question: mishka-team@usemishka.com

See also: CGU · CGV · Privacy · Cookies · DPA