Privacy Policy

Last updated: May 25, 2026

1. Introduction

Custard ("Custard," "we," "us," or "our") is a customer discovery research platform operated by Mira Insight, Inc. This Privacy Policy describes how we collect, use, disclose, store, and protect personal information when you visit our websites, create an account, use the platform, or interact with any feature that integrates with third-party services such as Google, Microsoft, or Zoom.

We act as a data controller for information about our account holders and visitors to our marketing site. We act as a data processor for the research content, transcripts, prospect records, and integration data that account holders upload, connect, or generate inside their projects, and we process that content on our customers' behalf and only in accordance with our customer agreements and this Privacy Policy.

2. Information We Collect

2.1 Account information

  • Name, email address, and password (passwords are stored as bcrypt hashes, never in plaintext)
  • Profile details you choose to provide (institution, role, photo, time zone)
  • Authentication identifiers from Sign in with Google, Microsoft, or Replit when used
  • Billing contact details, if you are on a paid plan (payment card data is handled by our payment processor and never stored by Custard)

2.2 Project and research content

  • Hypotheses, project briefs, wiki pages, evidence, scoring, and analyses
  • Interview transcripts, recordings, and notes you upload or generate
  • Prospect and contact information you import, capture, or generate for outreach
  • Email drafts, sent messages, and replies routed through the platform
  • Scheduled interviews, availability windows, and meeting metadata

2.3 Integration data

When you connect a third-party service, we store the minimum information required to operate the integration. Tokens are stored encrypted at rest. We describe the data flows for the major integrations in Sections 6, 7, and 8.

2.4 Usage and device data

  • Log data including IP address, user-agent, request paths, and timestamps
  • Product telemetry needed to operate, secure, and improve the platform
  • Essential cookies that maintain your session and CSRF protection

3. How We Use Information

We process information to:

  • Provide, secure, and operate the platform and your account
  • Execute the features you invoke, such as drafting outreach, scheduling interviews, generating insights, and creating meetings
  • Communicate with you about your account, service updates, and security notices
  • Detect, prevent, and respond to fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our Terms of Use

For users in the European Economic Area, the United Kingdom, and Switzerland, our lawful bases are performance of a contract, our legitimate interests in running and securing the platform, your consent where required (for example, for non-essential cookies), and compliance with legal obligations.

4. We Do Not Sell Your Data and We Do Not Train AI on It

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use customer content, interview transcripts, integration data, or any data obtained from Google APIs, Microsoft Graph, or Zoom APIs to train, fine-tune, or improve general-purpose AI or machine-learning models, our own or any third party's. AI features run on customer content only to produce outputs back to the customer that requested them, and our model providers are contractually prohibited from training on prompts or completions generated from customer content.

5. AI Processing

Custard's platform AI features run on Amazon Bedrock, an AI infrastructure service operated by Amazon Web Services, through an OpenAI-compatible endpoint. When you invoke an AI feature, the relevant project content is sent to Amazon Bedrock through a zero-retention endpoint: we do not retain, save, or sell your data, the request is not stored beyond the period needed to detect abuse, and it is never used to train models. You can disable AI features for a project at any time. AI-generated output may be inaccurate; you are responsible for reviewing it before relying on it.

If you configure a bring-your-own AI provider (an OpenAI-compatible endpoint or Anthropic) in your account settings, your project content is sent to the vendor you chose and is handled under that vendor's terms and privacy policy. The no-retention, no-training, and no-sale commitments above apply to the platform default only; we are not responsible for how your chosen vendor stores, retains, or uses that data.

6. Google User Data - Limited Use Disclosure

Custard's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we affirm that:

  • We only request Google scopes that are necessary to provide the user-facing features you enable, such as Google Calendar availability and event creation, Google Meet link generation, and Sign in with Google.
  • We use data obtained from Google APIs only to provide or improve user-facing features that are prominent in our application's user experience. We do not use it for serving advertisements.
  • We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or for our internal operations and only when the data has been aggregated and anonymized.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.

Google scopes we may request: profile, email, openid (Sign in with Google); calendar.events and calendar.readonly (read your availability and create or update interview events on your calendar); Gmail send-only scope only if you explicitly enable Gmail outreach. You may revoke access at any time at myaccount.google.com/permissions, which will cause Custard to delete the corresponding tokens and associated data within thirty (30) days.

7. Zoom Data Handling

When you connect your Zoom account, Custard creates and manages meetings on your behalf for interviews you schedule through the platform.

  • Scopes requested: meeting:write, meeting:read, user:read. We request only the scopes needed for the features you enable.
  • Data stored: your Zoom user ID, account email, encrypted OAuth access and refresh tokens, and the meeting IDs and join URLs created by Custard. We do not store Zoom recordings, transcripts, or chat unless you explicitly upload them into Custard.
  • How we use it: to create, update, and cancel meetings for interviews scheduled in Custard, to add the join link to calendar invites, and to display upcoming interviews to you.
  • How we do not use it: we do not send marketing to Zoom contacts, do not share Zoom data with third parties for advertising, and do not use Zoom data to train AI models.
  • Uninstall and deletion: if you uninstall the Custard Zoom app from your Zoom account, we receive a deauthorization webhook and delete the associated OAuth tokens, your Zoom user ID, and meeting metadata derived from the integration within thirty (30) days. You can also disconnect Zoom from inside Custard Settings, which deletes the same data on the same timeline.

8. Microsoft 365 and Microsoft Graph

When you connect Microsoft 365 (Outlook Calendar, Outlook Mail, or Microsoft Teams), Custard uses Microsoft Graph to schedule interviews, send outreach if enabled, and create Teams meeting links.

  • Scopes requested: User.Read; Calendars.ReadWrite (read availability and create or update interview events); OnlineMeetings.ReadWrite (Teams links); Mail.Send (only if Outlook outreach is enabled).
  • Data stored: your Microsoft account identifier, display name, primary email, encrypted OAuth tokens, and the event and meeting IDs Custard created.
  • How we use it: only to provide the calendar, meeting, and outreach features you enable. We do not read mailbox contents beyond messages that are replies to outreach you sent through Custard.
  • Retention and deletion: when you disconnect Microsoft from Custard or revoke consent from your Microsoft account, we delete the associated OAuth tokens and integration-specific identifiers within thirty (30) days.

9. Recording, Transcripts, and Consent

Custard does not record meetings on its own. If you upload a recording or import a transcript from Zoom, Microsoft Teams, Google Meet, or any other source, you represent that you have obtained any consents required by applicable law from the participants. We store recordings and transcripts in your project, encrypt them at rest, and process them only to provide the features you have invoked. You can delete a recording or transcript at any time, and we delete it from active systems immediately and from encrypted backups within thirty (30) days.

10. Prospects and Outreach Recipients

Custard helps you discover potential research participants and send outreach. When we discover or enrich prospect data we rely on lawful public sources and licensed data providers (such as Exa AI, Hunter.io, and Apollo). When you send outreach, you are the controller of that communication and are responsible for any required disclosures, opt-out handling, and compliance with anti-spam laws (CAN-SPAM, CASL, GDPR, ePrivacy). Recipients of outreach can request access to or deletion of data Custard processes about them by emailing privacy@mira-insight.com.

11. Sub-processors

We engage the following sub-processors to operate the platform. Each is contractually required to process personal data only on our instructions and to maintain appropriate technical and organizational safeguards.

  • Replit, Inc. - cloud hosting, application runtime, PostgreSQL database, object storage (United States)
  • Amazon Web Services, Inc. (Amazon Bedrock) - large language model inference for platform AI features (United States; zero-retention endpoint, no data retained, saved, or sold, no training on customer content)
  • Zoom Video Communications, Inc. - meeting creation when you connect Zoom (United States)
  • Google LLC - calendar, Meet, and Sign in with Google when you connect Google (United States, EU)
  • Microsoft Corporation - Microsoft Graph for Outlook Calendar, Outlook Mail, and Teams when you connect Microsoft (United States, EU)
  • Postmark (ActiveCampaign LLC) - transactional and outreach email delivery (United States)
  • Exa AI, Hunter.io, Apollo.io, ScholarAI - prospect discovery and enrichment data providers

We will give customers at least thirty (30) days' notice of new sub-processors by updating this page and, for customers on plans with a Data Processing Addendum, by direct notice to the contract contact.

12. International Transfers

Custard is operated from the United States and personal information may be processed in the United States and other countries where our sub-processors operate. For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum and Swiss Annex where applicable) and on the EU-U.S. Data Privacy Framework where our sub-processors are certified.

13. Retention and Deletion

  • Account data: retained for as long as your account is active, plus up to ninety (90) days for backups and audit logs.
  • Project content: retained for as long as you keep the project. You may delete a project at any time; we remove it from active systems immediately and from encrypted backups within thirty (30) days.
  • Integration tokens and integration-specific data: deleted within thirty (30) days of disconnect, uninstall, or revocation, as described in Sections 6, 7, and 8.
  • Closed accounts: we delete personal information within thirty (30) days of account closure unless retention is required by law (for example, tax records).

14. Security

  • Data in transit is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256 on managed PostgreSQL and object storage.
  • OAuth tokens are encrypted at the column level using application-layer keys.
  • Passwords are stored using bcrypt with per-user salts.
  • Access to production systems is limited to a small number of authorized personnel, requires single sign-on, multi-factor authentication, and is logged.
  • We maintain an incident response plan and will notify affected customers and regulators of a confirmed personal data breach as required by applicable law (typically within 72 hours of discovery for GDPR).

15. Your Rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information, to object to processing, and to withdraw consent. California residents have rights under the CCPA and CPRA, including the right to know what we collect, the right to delete, the right to correct, and the right to opt out of "sharing" for cross-context behavioral advertising (we do not engage in such sharing).

To exercise any of these rights, email privacy@mira-insight.com. We will respond within the timelines required by applicable law (generally 30 days). You also have the right to lodge a complaint with your local supervisory authority.

16. Cookies

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies or cross-site trackers. If we add analytics in the future, we will update this policy and, where required, request your consent first.

17. Children

Custard is not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, please contact privacy@mira-insight.com and we will delete it.

18. Changes

We may update this Privacy Policy from time to time. We will post the new version here and update the "Last updated" date. Material changes that reduce your rights will be communicated by email or in-product notice at least thirty (30) days before they take effect.

19. Contact

Questions, requests, or complaints about this Privacy Policy can be sent to:

  • Privacy contact: privacy@mira-insight.com
  • Data Protection Officer: dpo@mira-insight.com
  • Company: Mira Insight, Inc.