Legal
Privacy Policy
Last updated: September 28, 2026
This policy explains how Mutora ("Mutora", "we", "us") handles personal data on the mutora.app website and in the Mutora application. Mutora is operated out of Argentina. Mutora is currently in beta: some parts of this policy describe practices that are still being built out, and we've marked those clearly below rather than overstate what exists today.
If you have questions about this policy or your data, contact us at info@mutora.app.
1. Who this applies to — a B2B, invite-only product
Mutora is a business-to-business tool. There is no public sign-up: nobody can create their own account by visiting our site or app. Accounts exist only because a client organization (the "vendor") set up Mutora and either created accounts for its own staff or invited specific client-side contacts to a shared project. If you have a Mutora account, it's because an organization you work with or for put you there.
This policy covers: (a) visitors to the mutora.app marketing website, and (b) the vendor and client users an organization has added to the Mutora application. It does not cover third-party sites we link to.
Practically, this also means Mutora usually acts as a data processor for the project content a vendor organization and its clients put into the app — the vendor organization is the data controller for that content and is responsible for having a lawful basis to share it with us and with its own clients. Mutora acts as the controller only for the limited account data described below (name, work email, organization, role) that's needed to operate the service and bill the organization.
2. No sensitive data, by design
Mutora is a project-status tool, not a consumer product, and we don't ask for or intentionally collect any sensitive or "special category" personal data — things like health information, financial account or payment card numbers, government ID numbers, biometric or genetic data, precise geolocation, or data about racial or ethnic origin, religious beliefs, or sexual orientation. The only personal data the product needs is what's necessary to identify a work contact and track who owns a project item. We ask organizations using Mutora not to paste sensitive personal data into item descriptions, comments or file attachments, since the product isn't designed to handle that category of information.
3. What data we collect
On the website
The marketing site at mutora.app does not use cookies, analytics, or advertising trackers of any kind, and has no sign-up form. If you email us or use the "Book a demo" link, we receive whatever you choose to put in that email (typically your name, work email address and message).
In the application
Once an organization has added you as a user, Mutora holds:
- Account data: name, work email address, password (stored hashed, never in plain text), organization and role — entered by your organization's administrator when they add you, or by you when you first set your password after being added.
- Project content: items, descriptions, comments, status changes, handoffs, action requests, and files your organization or its clients upload.
- Usage data needed to run the service: a session cookie that keeps you signed in (HTTP-only, so it can't be read by page scripts, and marked
Securein production). We do not use this cookie for tracking or advertising, and today we do not run any analytics on the application either.
4. How we use it
- To provide, operate and secure the service the organization contracted (this is the core "contractual necessity" basis under GDPR).
- To authenticate you and keep each organization's data separate from every other organization's.
- To send in-app notifications about activity on items you're responsible for.
- To respond to support requests you or your organization send us.
We do not use your data for advertising, and we do not sell or rent personal data to anyone.
5. Cookies
The application sets exactly one cookie: a session cookie used solely to keep you signed in. It is strictly necessary for the service to function, so it does not require a cookie-consent banner under GDPR/ePrivacy rules. The marketing website sets no cookies at all.
6. Sharing your data
We do not sell or share personal data with data brokers or advertisers. Within an organization, project content is visible according to role: client users never see content marked internal-only, and vendor organizations are isolated from one another. As the product grows we may add infrastructure providers (for example, file storage or transactional email) who process data on our behalf under a data processing agreement; if and when that happens, we will update this section and the "last updated" date above.
7. Data retention
We keep account and project data for as long as the organization's account is active. If an organization closes its account, or asks us to delete a user's or the organization's data, we will delete it within a reasonable time, except where we're required to keep limited records for legal or security reasons.
8. Your rights
Because Mutora accounts are created by an organization rather than by the individual, requests to access, correct or delete your personal data should generally go to the organization that added you first — they hold the underlying records and can usually resolve this fastest. We support them in doing so, and we will also action a request directly if you contact us. Depending on where you're located, you may have some or all of the following rights:
- If you're in the European Economic Area (GDPR): the right to access, correct, delete or export your data, to restrict or object to certain processing, and to lodge a complaint with your local data protection authority.
- If you're in Argentina (Ley 25.326, Personal Data Protection Law): the right of access, rectification, updating and deletion of your data (habeas data), and the right to lodge a complaint with the Agencia de Acceso a la Información Pública (AAIP).
- If you're in California (CCPA/CPRA): the right to know what personal information we hold about you and to request deletion or correction. Mutora doesn't sell or share personal information, so the right to opt out of that doesn't apply here; some of this data may also fall under the CCPA's business-contact exemption, but we'll honor these requests either way.
To exercise any of these rights, email info@mutora.app. We may need to verify your identity, or check with the organization that added you, before acting on a request.
9. Security
We take reasonable technical and organizational measures to protect your data, including hashed passwords and HTTP-only session cookies. As Mutora moves from beta toward general availability we intend to add encryption at rest and formal data-residency options; no online service can guarantee absolute security, and we'll be upfront here about what's actually in place at any given time.
10. Children's privacy
Mutora is a business tool used by companies for their own staff and clients. It is not directed at children, nobody can self-register, and we do not knowingly hold data on anyone under 16. If you believe a child has been given access to an account, contact us and we'll remove it.
11. Changes to this policy
We may update this policy as the product changes. We'll update the date at the top of this page when we do, and for material changes we'll make a reasonable effort to let account holders know in-app or by email.
12. Contact
Mutora — info@mutora.app