Data & confidentiality
An operational disclosure of what the product does today. It is not a substitute for the signed engagement, data-processing terms, or your legal advice.
Where does our clients' data live?
Primary records live in the deployment's Neon PostgreSQL database. Documents live in its private Vercel Blob store in production, or on local disk in a lab installation. The actual regions are the regions selected for those projects and must be checked before onboarding. Email also passes through Resend Receiving, and WhatsApp messages and media pass through Meta, when those channels are enabled.
Who can see it?
Authenticated users of your firm can see data through the product. Authorised Mystri operators and the hosting providers may also access data when necessary for support, security, recovery, or legal obligations. The product audit log records consequential in-app actions; it does not claim to record every read, database-console access, infrastructure event, or provider access.
Is our data used to train AI?
Mystri does not use client data to train models. Anthropic says inputs and outputs from its commercial API are not used for model training by default. Anthropic may use data if a customer explicitly submits feedback or opts in; this product does neither on your behalf. The current commercial terms and privacy controls still need to be part of vendor review.
What exactly goes to the AI, and what happens to it?
The feature sends the content needed for that job: for example a bill or return image, notice text and client name, reconciliation summary, or drafting context. It does not give the model direct database access. Anthropic's standard API policy says inputs and outputs are deleted from its backend within 30 days, with stated exceptions including usage-policy enforcement, law, longer-retention features, or a different agreement. Zero-data-retention applies only when separately approved and configured.
Which outside services process data?
The production stack currently includes Vercel for application hosting and private file storage, Neon for PostgreSQL, Anthropic for enabled AI features, Resend for outbound email and inbound email receiving, and Meta for enabled WhatsApp traffic. Each receives only the data required for its role, but each remains a subprocessor whose terms, region, retention, and incident process must be reviewed in the signed deployment pack.
How long is data kept?
The application does not yet enforce a complete automated retention schedule. Operational records and documents remain until they are deleted under the agreed process; provider logs and backups may follow separate retention windows. A production engagement must specify active-record retention, backup expiry, inbound-message retention, legal holds, and who approves deletion.
What do you NEVER collect?
The product has no field or integration for GST or income-tax portal passwords, and no place for a DSC private key. Do not paste either into notes or messages. Portal login, signing, and filing stay under the firm's control outside this system.
Does anything get sent or filed automatically?
Nothing is filed to a statutory portal. Draft replies and filing packs pass through human review. Routine document reminders and the scheduled digest can send without case-by-case approval only after the firm deliberately enables their live channel. Inbound bills can be matched, extracted, validated, and placed in the bill queue automatically; that is intake automation, not statutory filing.
What if we leave?
The product currently provides workflow exports such as bill CSV and Tally voucher XML; a complete self-service tenant export and verified-deletion screen are not yet built. Until they are implemented and tested, offboarding requires an operator-assisted database and file export plus a documented deletion runbook. The signed engagement must state the format, timing, backup expiry, and evidence supplied.
Legal posture
This page does not assign statutory roles by itself. The firm's and Mystri's roles, instructions, subprocessors, safeguards, breach duties, data-principal request handling, retention, and deletion must be set in a signed Data Processing Addendum reviewed for the actual deployment and applicable Indian law. India-region processing, zero-data-retention, and redaction are requirements to verify, not features to assume.
Last reviewed 11 August 2026 · Questions? hello@mystri.ai · Back to sign in