Privacy policy
This policy explains what personal data MustGate Labs processes, why, and what rights you have. It covers this website, the Gatepost console and the telemetry we process on behalf of our customers.
Last updated 1 June 2026. Previous versions are available on request.
- 1. Who we are
- 2. This website
- 3. The console and your account
- 4. Telemetry processed for customers
- 5. Legal bases
- 6. Retention
- 7. Sharing and transfers
- 8. Your rights
- 9. Changes and contact
1. Who we are
MustGate Labs ("we") operates the Gatepost service and this website at mustgate.org. For data collected through this website and the console we act as the controller. For telemetry sent by our customers' apps we act as a processor on the customer's instructions; the customer is the controller and their privacy policy applies to the end users of their app.
2. This website
This website does not use cookies, analytics scripts, embedded third-party content or advertising. Our web server records the requesting IP address, the requested page, the time, the browser identification string and the referring page in a log that is kept for 30 days for security and capacity planning and then deleted. When you email us, we keep the correspondence for as long as needed to answer and for up to two years afterwards.
3. The console and your account
To use the console we process your name, work email address, password hash, two-factor secret, organisation membership and role, the IP addresses and times of sign-ins, and a log of the actions you take in the console. We use this to provide the service, to secure accounts and to send transactional email such as alerts you configured, invoices and security notices. We do not send marketing email unless you asked for it, and every such email has an unsubscribe link.
Billing details are processed by our payment provider; we store only the last four digits of a card, its expiry and the billing address.
4. Telemetry processed for customers
Apps that include the Gatepost SDK send performance telemetry to our collectors. The SDK is built so that this telemetry does not identify a person: it contains no names, contact details, advertising identifiers, precise locations, screen contents or network payloads. A full list of the fields it sends and the fields it never sends is in the documentation.
The IP address of a device connecting to a collector is used to select a coarse region label and is discarded before the telemetry is stored. If a customer chooses to set a user identifier, it is hashed on the device with a per-project salt before it reaches us; we cannot reverse it.
We process this telemetry only to provide the service to the customer, in the storage region the customer chose, and we delete it according to the retention rules of the customer's plan or earlier on the customer's instruction. Requests from end users about telemetry should be addressed to the app's publisher; we assist the publisher in responding.
5. Legal bases
- Performance of a contract: providing the console and the service to customers and their team members.
- Legitimate interests: securing the service, preventing abuse, keeping server logs, improving the product using aggregated usage data.
- Legal obligations: keeping invoices and tax records.
- Consent: marketing email, which you can withdraw at any time.
6. Retention
| Data | Retention |
|---|---|
| Web server logs | 30 days |
| Account data | For the life of the account and 90 days after deletion |
| Console audit log | 1 year |
| Invoices and tax records | As required by law, typically 5 to 7 years |
| Telemetry | According to the customer's plan; see retention by plan |
| Email correspondence | Up to 2 years after the last message |
7. Sharing and transfers
We share personal data only with providers that help us run the service: infrastructure hosting in the region the customer chose, a payment provider, an email delivery provider and a support ticketing tool. Each is bound by a contract that limits processing to our instructions. We do not sell personal data and we do not share it with advertisers.
Telemetry stays in the storage region chosen for the project. Account data for the console is stored in the European Union. Where data leaves the jurisdiction it was collected in, we rely on standard contractual clauses or an equivalent mechanism and, for customers subject to Russian Federal Law 152-FZ, on storage within the Russian Federation for the telemetry of Russian projects.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to processing, and to complain to a supervisory authority. Team members can view and edit their profile in the console and delete their account from the same page. For anything else, email hello@mustgate.org; we answer within 30 days.
9. Changes and contact
When we change this policy in a way that matters, we notify account owners by email at least 14 days before the change takes effect and keep the previous version available. Questions about this policy go to hello@mustgate.org.