Skip to content

Privacy Policy

Last updated: this is a first-draft template — see the note at the bottom.

What we collect

When you use Mucho Gusto, we collect:

  • Account information — your name, email address, role/title, and an optional bio. We also store a SHA-256 hash of your email address, used for the contact matching described below.
  • Phone number for sign-in verification — if you set up SMS as a second sign-in factor, our authentication provider (Clerk) collects and verifies your phone number, and we store the verified number to show it back to you as your MFA method. It is never shown to other members, never used to contact you, and never used as a way to sign in on its own.
  • Video content — the short intro videos you record, plus their auto-generated transcript, captions, summary, topics, detected spoken language, and a vector embedding used for recommendations. If you or an admin edit a video's captions, we store the edited caption text.
  • Watch behavior — which videos you watch, how many seconds you watched, and whether you finished them.
  • Reactions and comments — the reaction you leave on a video (one of a small fixed set: like, wave, fire, funny) and the text of any comment you post. Comments are visible to your coworkers in your organization, are screened by our automated content check when you post them, and are retained (soft-deleted, not erased) after you delete them.
  • Gusto points, streaks, and collectibles — our in-product game layer records an append-only ledger of the points you earn and the reason for each award, your daily activity streak (including the current and longest streak, the last day that counted, and the time-zone offset your device reports so we can work out what "today" means for you), each booster pack you open and which teammate cards it contained, and a "met" record for each teammate you've met in the product — recorded when you watch their intro to the end, open their profile, or share a synced calendar meeting with them.
  • Profile and org-chart data — your position in your organization's org chart. If you tell us who your manager is and they aren't on Mucho Gusto yet, we store the name and email address you give us so we can invite them and link them up when they join.
  • Invitation data — if an admin, your organization's directory sync, or your organization's identity provider (via SCIM) invites you, we hold your name, email, and invitation status until you join.
  • Meeting data — if your organization connects Google Calendar, we store meetings you're on (title, start and end time, an external calendar id) and their attendees, plus a record of which meeting-prep prompts we've already sent you so you don't get the same one twice. For calendar-sourced meetings we only store attendees who are already members of your organization on Mucho Gusto — external attendees' email addresses are not stored.
  • Notification preferences — which notification types you want, on which channels.
  • Safety data — if you report a video, we record which video, the reason you chose, any note you add, and that it was you; your organization's admins can see all of it. If you block someone, we record that you blocked them. The person you block is never told.
  • Contact matching — if you enable contact matching, your device hashes your contacts' email addresses (SHA-256, lowercased) on-device before anything is sent to us. Raw email addresses from your address book never leave your device and never reach our servers; we receive only the hashes, cannot reverse them back into addresses, and use them for nothing except telling you which of your contacts are already members of your own organization on Mucho Gusto. We do not match your contacts against any other organization.
  • Push notification token — if you enable notifications on our iOS app, your device registers a token with Apple's Push Notification service (APNs) and we store it, with your device platform, to deliver notifications to your device.
  • Purchase history — if your organization's admin buys a Growth seat-band upgrade through our iOS app, their device sends us the signed purchase record Apple's App Store gives it (product id, transaction ids, and whether it was a sandbox or production purchase), so we can verify and activate the purchase. We never receive payment details for these purchases — Apple handles them directly. If your organization pays by card instead, Stripe handles the payment details and we never receive them either.
  • Administrative audit records — we log sensitive actions with who did it, what it targeted, and when: promoting or demoting an admin, inviting or removing a member, provisioning or deprovisioning over SCIM, deleting your own account, reporting a video, blocking or unblocking someone, hiding a video, deleting a video or comment, editing a transcript or captions, requesting a data export, and trial/plan/billing changes. These records are kept for security and accountability; there is no in-product browser for them today.

Trying Mucho Gusto without an account

You can record a video on our public "try it" page without signing up. When you do, we create a temporary, anonymous placeholder profile for your visit (identified only by a signed session token — we never ask for your name or email) and run your video through the same production pipeline a real member's video goes through: upload and transcoding, automatic captions, an embedding, and an AI-generated summary and topics.

If you never turn that visit into a real account, we permanently delete the anonymous profile and the video — including the stored video file at our video provider — within 48 hours. If you do sign up, the video is moved onto your real account in your organization and is treated like any other video from then on. To keep this page from being abused, Cloudflare Turnstile checks that you're a real browser before a session starts, and we apply rate limits keyed on your IP address.

Data that comes from your organization's systems

Mucho Gusto is sold to organizations, and an admin at your organization can connect it to systems your organization already runs. When they do, data flows to us from those systems:

  • Directory sync — Google Workspace, Microsoft 365 / Entra ID, and Slack can each be connected by an admin to list your organization's people (names, email addresses, job titles, and manager relationships where available) so they can be invited and placed on the org chart.
  • SCIM inbound provisioning — your organization's identity provider can create, update, and deactivate Mucho Gusto accounts directly over SCIM 2.0, using a bearer token your admin generates. An account deactivated this way is soft-deleted on the same 30-day window described below, not erased immediately.
  • Calendar sync — Google Calendar, if connected, supplies the meeting data described above so we can prompt attendees about coworkers they haven't met yet.
  • Slack and Microsoft Teams notifications — if connected, we post notifications into those workspaces, and meeting-prep prompts as Slack direct messages, which means the notification content (including teammate names) reaches Slack or Microsoft.

These connections are set up by your organization's admins, not by us, and what your organization chooses to sync is governed by your organization's own policies.

Why we collect it

We use this data to run the core product: showing you and your teammates each other's intro videos, matching you with relevant people and content, generating transcripts, captions, summaries and recommendations, running the points/streaks/booster-pack game layer, sending the notifications you've opted into, moderating content for safety, and billing your organization. We do not use your data for advertising, and we do not sell it (see CCPA rights below).

What your organization's admins can see

Mucho Gusto is an organization-wide product, and your organization's admins can see aggregate usage analytics (member, video, and watch counts and trends), the moderation queue — reported videos and the reports themselves, plus comments our automated check flagged — and the member list. Admins can hide videos, remove members, and delete videos that aren't theirs. You can delete your own videos yourself.

How long we keep it

If you delete your account, your data is soft-deleted immediately — it stops appearing anywhere in the product right away — and permanently erased within 30 days. You can request deletion any time from Account settings. An account deactivated by your organization's identity provider over SCIM follows the same 30-day window. If an admin removes you from the organization outright, your account and videos are deleted immediately rather than after 30 days.

Videos recorded on the anonymous "try it" page and never claimed by signing up are deleted within 48 hours, as described above.

Your rights

Under GDPR (if you're in the EU/EEA), you have the right to:

  • Access and export your data — available today from Account settings.
  • Request erasure of your data — available today from Account settings.
  • Lodge a complaint with your local data protection supervisory authority.

Under CCPA (if you're a California resident), you have the right to:

  • Know what personal information we collect (see above).
  • Delete your personal information — available today from Account settings.
  • Opt out of the sale of your personal information — we don't sell personal information, to anyone, ever.

The self-service export available today returns your profile (name, email, role/title, bio, and when you joined), your videos with their status, transcript, summary and topics, your watch history, and any pending invitation. If you want anything else we hold about you — for example your comments, reactions, or Gusto points history — email us at [email protected] and we'll get it to you.

Who we share data with

We use the following subprocessors to run the product. None of them are permitted to use your data for their own purposes.

  • Clerk — authentication and identity.
  • Neon — primary database hosting (Postgres). Your profile, videos' metadata, transcripts, engagement, game state, and org data all live here.
  • Render — hosts our backend, web, and marketing services; every request to the product transits it.
  • Upstash / Redis — caching, rate limiting, and background job queueing.
  • Mux — video upload, storage, transcoding, automatic captions/transcription, and playback.
  • Cloudflare — bot/abuse protection (Turnstile) gating the anonymous "try it" flow, the only part of the product usable without an account; receives visitor IP addresses.
  • Anthropic (Claude) — video summary and topic generation, spoken-language detection, profile-writing assistance, and the Team Concierge assistant.
  • Voyage AI — text embeddings for recommendations/matching, generated from video transcripts and profile bios.
  • Stripe — billing and payment processing for card-paid plans.
  • Apple — push notification delivery (APNs) and App Store in-app purchase processing and receipt verification, for our iOS app. Apple is a payment processor for the iOS org upgrade, alongside Stripe for card payments.
  • Slack — optional workspace notifications, direct-message meeting-prep prompts, and directory sync, if your org connects it.
  • Google (Workspace and Calendar) — optional directory sync and optional calendar sync, if your org connects them.
  • Microsoft (365 / Entra ID and Teams) — optional directory sync and optional Teams notifications, if your org connects them.
  • Resend — transactional email (invitations and invite nudges).

Beyond these, data leaves Mucho Gusto only where you or your organization direct it: notifications go to the Slack or Teams workspace your admins connected, and directory, SCIM, and calendar data comes in from the systems your organization already runs.

How your data is separated from other organizations

Every organization's data is isolated at the database level, not just by application code — each tenant-scoped table enforces row-level security so one organization's rows are unreachable from another's session. Contact matching, search, feeds, and the org chart are all scoped to your own organization only.

International data transfers

Our subprocessors host data in the United States and other regions where they operate infrastructure. If you're located outside those regions, your data may be transferred internationally to provide the service.

Contact us

Questions about this policy or your data: [email protected].

This page is a solid first-draft technical and policy foundation, not a substitute for review by a lawyer before public launch. The controls it describes (export, erasure, retention) are real and live in the product today; the wording above still needs legal sign-off.