Privacy
Last updated [set LEGAL_LAST_UPDATED].
This page is not ready to publish.
4 values still to set: LEGAL_ENTITY_NAME, LEGAL_ADDRESS, LEGAL_CONTACT_EMAIL, LEGAL_JURISDICTION. Until then the gaps are marked in the text below rather than filled in with a guess. Have a lawyer read the result before you rely on it.
This policy describes what [set LEGAL_ENTITY_NAME] stores when you use Mutator, why, and what you can do about it. It is written to be checkable: the retention periods and the list of companies below match how the product actually behaves.
What we store
Your account. Your name, email address, and a hash of your password — never the password itself. Sessions are stored so you stay signed in, and you can revoke them all from Settings.
What you create. Brands, automations, generated videos, images and captions, approval decisions, and the record of what was published where. Some of this contains whatever you typed into it, so it is worth knowing that brand profiles and prompts are stored as you wrote them.
Connections to other services. When you connect a provider account, the credential is encrypted (AES-256-GCM) before it is stored and is only ever decrypted to make a call you asked for. Credentials are never shown back to the browser, never written to logs, and are deliberately excluded from data exports.
Results. Views, watch time, clicks and similar figures for posts you published, retrieved from the account that published them.
Operational records. An activity log of security-relevant actions, a record of emails sent to you, error reports (which can include a stack trace), and first-party product events — named actions like “created an automation”, stored in our own database. There is no advertising tracker, no fingerprinting, no session replay, and no third-party analytics script anywhere in the product.
Who else sees it
Mutator passes data to a small number of companies, only where the feature requires it:
- The providers you connect yourself — your generation and publishing accounts. You hold those accounts directly, and their own terms and privacy policies govern what they do with what you send.
- Payment processing — handled by Stripe. Card details go to Stripe and never reach Mutator’s servers.
- Hosting, storage and email — the infrastructure this deployment runs on, which stores the database, your media, and sends the notifications you have turned on.
Nothing is sold, and nothing is shared for advertising.
How long it is kept
Generated media is deleted after 90 days. The record of what was published survives that, so your history and reporting stay readable after the files themselves are gone. Everything else is kept until you delete it.
What you can do
From Settings you can export everything a workspace holds as a readable file, delete a workspace and its contents permanently, delete your account, revoke every active session, and read the activity log. These are built into the product — you do not need to email anyone to use them.
If you are in the UK or EU, you also have rights of access, correction, portability, erasure and objection under the GDPR, and the right to complain to your local data protection authority.
Contact
Privacy questions go to [set LEGAL_CONTACT_EMAIL].
[set LEGAL_ADDRESS]