Privacy
Musta prepares, runs and remembers a team's recurring meetings. To do that it holds material your team gives it. This page says what, why, where it goes, and how long it stays — in plain words.
Last updated 2026-09-17 · Questions: [email protected]
Who is responsible
Musta is operated by Limineer SAS (935 316 620 R.C.S. Melun, VAT FR26935316620). For your account and this website we are the controller of the personal data described here; for what your team puts into its meetings, your organisation is the controller and we process it under a data processing agreement, available on request. Reach us at [email protected] for anything on this page, including requests about your data.
What we collect
- Your account. Your work email, the name you give, and your role. Your organisation in Musta is derived from your email domain; personal-mail domains get an organisation of one.
- Your team's meeting material. Agendas, briefs and the answers people write to them, decisions, commitments, wins and follow-ups, and the notes a facilitator takes in the room.
- Documents you upload. Files a team adds to its brain so Musta can prepare from them. We store the file and an index of its text.
- Transcripts, when you connect a notetaker. If a team turns on the meeting notetaker, a recording bot (Recall.ai) joins the call you point it at and returns a transcript. Nothing is recorded unless a facilitator sets this up for a specific meeting.
- Calendar data, when you connect a calendar. See the next section — it is the most specific grant you can give us and deserves its own words.
- Bug reports. When you press the feedback button we keep what you typed, the page you were on and, if you attach one, a screenshot. These are deleted after 90 days, automatically.
- Email delivery. When Musta sends a brief, recap or sign-in link we log that a message went to an address and whether the provider accepted it — never the message body.
Optional product analytics
With your permission, PostHog in the EU receives action names, counts, the deployment environment and your organisation's identifier and company name. While you are signed in, each event also carries your account's internal identifier — a random UUID that only Musta can resolve to a person — so your own steps can be counted as one journey. We exclude personal names, emails, meeting content and page URLs. Screen recording and location enrichment are disabled; the only profile PostHog holds for you is that identifier, with no properties attached.
The identifier is attached only while you are signed in and have allowed analytics. Signing out, withdrawing, or declining detaches it, and a declined choice sends nothing at all. When your account is erased we delete the events held under your identifier from PostHog.
Choose Allow analytics or Decline analytics in the analytics notice. Change or withdraw your choice at any time using Analytics settings. Declining does not limit Musta. Each browser and domain keeps its own choice for up to six months; a change to this policy requires a new choice.
We save a consent audit record before enabling analytics: the choice, server timestamp, policy version, a random browser reference and your account identifier if signed in. This reference is not sent to PostHog. If the record cannot be saved, analytics stays off. Withdrawal stops collection immediately, including when saving the withdrawal fails.
Calendar connections — Google and Microsoft
Connecting a calendar is optional and personal: it is your account, for your use, and it affects nobody else's. When you connect, Musta asks for read-only access to your calendar events (and, only where a deployment has event creation switched on and you consent to it separately, the right to create events). We use it for exactly two things: to suggest which of your recurring meetings could be a Team Weekly, and to find the video-call link of a meeting so the notetaker can join it.
The access and refresh tokens the provider issues are stored server-side in a table no browser can read, and are used only by our servers to make those calls. We never return a token to a browser and never read your mail. Disconnect on your connectors page deletes our copy of the grant immediately; you can also revoke Musta from your Google or Microsoft account at any time.
Connecting your calendar also lets a colleague in your organisation, when setting up a recurring 1:1 with you, ask whether a given time works for both of you. We answer only with the instants you are both free — never a busy span, an event title, or a count of your other meetings — and only for colleagues who have also connected a calendar. Disconnecting turns this off immediately, the same as everything else above.
Musta's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to provide the features described above, is not used for advertising, and is not sold or transferred to third parties except as needed to provide those features.
Why we process it
To run the service you signed up for: preparing briefs, running the meeting, writing the recap, and remembering what the team decided so the next meeting starts from it. That is performance of our agreement with you and your organisation. Bug reports and delivery logs are processed on our legitimate interest in keeping the product working. We do not sell personal data, and nothing from inside a meeting is ever used for advertising — not a brief, a transcript, a recap, an uploaded document or a participant list. We do measure responses to our own advertising on the public pages you see before signing in, which is the next section.
AI processing
Musta uses language models to draft briefs, suggest questions, summarise a meeting and answer questions about a team's own material. Meeting content and uploaded documents are sent to these providers only to produce the output you asked for: Anthropic (Claude) for generation and Voyage AI for the text embeddings that make your documents searchable. Both are US-hosted processors — Musta has no EU model endpoint today. Every model call is attributed to the team it served.
Cookies, and the advertising tag on our public pages
Musta itself uses cookies only to keep you signed in. There is no advertising or profiling cookie anywhere in the signed-in product.
On our public pages — the home page, pricing, the audience pages under /for, workshops, the sign-in page and the ninety-second walkthrough — we can run the LinkedIn Insight Tag, so we can tell which of our LinkedIn campaigns brought someone to Musta. It sets its own cookies, records that a browser reached that page, and is a US-hosted processor. It is listed on our sub-processors page.
It waits for your yes. These pages load the tag only after you press Allow ad measurement. Until then no LinkedIn script, pixel or cookie loads, and no request goes to LinkedIn. This is a separate choice from analytics: allowing analytics does not allow the tag. Declining is one press, as prominent as allowing; Not now leaves the choice unmade and loads nothing. Your choice is kept in this browser for six months, and Ad measurement settings on those pages changes it at any time. Withdrawing reloads the page so the tag stops, and clears the cookies it set on our domain; cookies LinkedIn holds on its own domain are governed by your LinkedIn settings.
Where it does not run, and why that is enforced rather than intended. The tag is not loaded on any signed-in screen, and not on any link we email you — a brief, a recap, a meeting room or a scheduling poll. Those web addresses contain the key that opens them, and the tag reports the address of the page it runs on, so loading it there would send that key to an advertising network. An allowlist in our code decides which pages may load it, and a test in our build fails if a meeting link or a signed-in page is ever added to it.
On musta.ai, it waits for your yes. Our marketing site at musta.ai loads the tag only after you press Allow ad measurement. Until then no LinkedIn script, pixel or cookie loads, and no request goes to LinkedIn. Declining is one press, as prominent as allowing; Not now leaves the choice unmade and loads nothing. Your choice is kept in this browser for six months, and Cookie settings in the site's footer changes it at any time. Withdrawing reloads the page so the tag stops, and clears the cookies it set on musta.ai; cookies LinkedIn holds on its own domain are governed by your LinkedIn settings.
You can also block it with any tracker-blocking extension or browser setting, and LinkedIn members can turn off off-site ad tracking in their own LinkedIn settings. Blocking it changes nothing about how Musta works.
Where it is stored, and who else touches it
Musta runs in the European Union. The services that process data on our behalf:
- Supabase — database and file storage (EU regions).
- Vercel — application hosting (Paris region).
- Postmark — sending the emails Musta writes for you (US-hosted).
- Recall.ai — the meeting notetaker, only when a team connects it (EU-hosted; its own engine transcribes by default, though some recordings route through AssemblyAI, a US-hosted transcription engine, instead).
- Anthropic and Voyage AI — the model providers above (both US-hosted).
- ElevenLabs — speech-to-text when you dictate or a room's live listening is on, and voice narration when you use read-aloud (US-hosted).
- Google and Microsoft — only when you connect your own calendar.
- Linear — where bug reports are filed for our team to act on (US-hosted).
- LinkedIn — the advertising tag described above. Our public pages only; never a signed-in screen and never a meeting link (US-hosted).
- Firecrawl, ScreenshotOne, xAI and Buzzabout.ai — only if you use the sales-research features, to look up a prospect company or a named executive you are meeting (all US-hosted); never your team's meeting content.
How long it stays
- Account and meeting material: for as long as your organisation uses Musta, and for a short wind-down afterwards. Your organisation's admin can also set a shorter window that erases a past meeting's transcript, answers and reactions on a sweep — the meeting's rhythm, roster and recorded decisions stay.
- Calendar tokens: until you disconnect, or until the provider revokes them.
- Bug reports and screenshots: 90 days.
- Anything, on request: write to us and we will delete it, unless the law requires us to keep it.
Your rights
You can ask to see the personal data we hold about you, correct it, receive a copy, have it deleted, or object to a use of it. Write to [email protected]. If you are in the EU or EEA you may also complain to your national data-protection authority.
Security
Data is private by default: every table is protected by row-level security, and material is readable only within the organisation and team it belongs to. Secrets and provider tokens stay on the server. Traffic is encrypted in transit and data is encrypted at rest by our providers.
Changes
If this page changes in a way that matters, we will say so here with a new date, and tell the administrators of the organisations affected.