Privacy Policy
Last updated: July 2, 2026
Mushka (“Mushka,” “we,” “us”) is an AI project-management assistant that your company installs into its Slack workspace and connects to its issue tracker. Because the product works by reading messages in channels you invite it to, we want to be unusually plain about what we collect, how long we keep it, and what we never do with it. This policy covers both our marketing site (mushka.ai) and the Mushka service.
The short version
- We only read messages in channels your team explicitly invites the bot into.
- Raw message content is held transiently — long enough to build the next activity digest — then deleted. Slack remains the source of truth for your message history.
- We never sell your data, never use it for advertising, and our AI model providers do not train on it.
- Integration credentials are encrypted at rest with per-customer keys.
- The only cookie we set is a session cookie for the dashboard. No ad trackers.
Information we collect
On the marketing site
If you submit our contact form, we collect the name, work email, company, and any optional details (role, team size, notes) you provide. Submissions are forwarded to our internal Slack so a human can reply. We do not add you to a mailing list. We briefly process your IP address in memory to rate-limit form submissions; it is not stored with your inquiry.
When you sign in to the dashboard
Sign-in uses your existing Slack identity (OpenID Connect). We receive and store your Slack user ID, email address, and display name, and we set a session cookie so you stay signed in. We do not receive your Slack password.
When your company uses the service
- Channel messages. Mushka receives messages from channels it has been invited to. Messages are buffered only long enough to assemble the next activity digest for the AI agent, then deleted from our systems.
- Agent working context. The agent keeps a running summary of recent activity so its proposals make sense over time. Older raw content is rolled up into summaries and dropped past a retention horizon (7 days by default).
- Audit log. Every action Mushka executes against your tracker — what was proposed, who approved it, what happened — is recorded as a business record. Retained for your contractual term (typically 12 months; configurable).
- Integration credentials. OAuth tokens for Slack and your tracker (e.g. Jira) are encrypted at rest using AES-256-GCM with keys derived per customer, and decrypted only at the moment of use.
- Usage records. Metering data (e.g. actions executed, model usage) kept for billing and service operation.
How we use information
We use the information above solely to operate, secure, support, and bill for the service: building activity digests, generating proposed tracker actions, executing actions your team approves, maintaining the audit trail, and responding when you contact us. We do not use customer data for advertising, and we do not sell it to anyone.
AI processing
Mushka sends activity digests and related context to large-language-model providers (Anthropic by default) to generate proposals. This processing happens over provider APIs under agreements that prohibit using your data to train their models. Proposed actions that change your tracker are executed only after a member of your team explicitly approves them in-channel.
Who we share data with
We share data only with the service providers (subprocessors) needed to run Mushka:
- Railway — application hosting and database.
- Anthropic — AI model inference.
- Slack and Atlassian — the platforms your company connects; data flows to them as part of the integrations you authorize.
Beyond that, we disclose information only if required by law, or as part of a corporate transaction (in which case this policy continues to apply to your data).
Security
All traffic is encrypted in transit (TLS). Credentials are encrypted at rest with per-customer derived keys. Customer data is isolated per tenant at the database layer, and every action the agent takes against your tracker is scope-checked against the projects you connected and gated behind human approval. No security measure is perfect, but the system is designed so that reading is minimal and writing requires a human.
Data retention and deletion
Raw channel messages: deleted after digest processing. Agent working context: raw content dropped after the retention horizon (default 7 days). Audit log and usage records: retained for the contractual term. When your subscription ends, we delete your tenant’s data, including stored credentials. You can also request deletion at any time at hello@mushka.ai.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold about you, or to object to certain processing. Email hello@mushka.ai and we will honor these requests. If your company is our customer, we may route requests about workspace data through your company’s administrator, since they control that data.
Children
Mushka is a workplace tool for businesses and is not directed to anyone under 16. We do not knowingly collect personal information from children.
Changes to this policy
If we make material changes, we will update the date at the top of this page and notify customer administrators by email or in the dashboard before the changes take effect.
Contact
Questions about this policy or our data practices: hello@mushka.ai.