Privacy Policy
Last updated: April 10, 2026
What we collect
When you use Mission HQ, we collect the following data:
- Account information: email address, name, and hashed password
- Project metadata: plans, tasks, modules, decisions, sessions, rules, and memories you create through MHQ
- Usage data: which MCP tools your agent calls and when (for rate limiting and debugging)
- API keys: stored as cryptographic hashes, never in plaintext
What we do NOT collect
- Your source code: it never leaves your machine
- Chat messages between you and your AI agent
- File contents from your local projects
- Tracking cookies or behavioral analytics
How we use your data
- To provide and operate the Mission HQ service
- To maintain session continuity across your AI coding sessions
- To communicate with you about your account (transactional emails only)
- To improve the service based on aggregate usage patterns
Data storage & security
Your data is stored in PostgreSQL on dedicated servers in Europe (Hetzner, Germany). All connections use TLS encryption. Passwords are hashed with bcrypt. API keys are stored as SHA-256 hashes.
We never sell your data
We do not sell, rent, or share your personal data with third parties. Your project data is yours alone.
Your rights (GDPR)
You have the right to:
- Access: request a copy of all data we store about you
- Delete: request deletion of your account and all associated data
- Export: download your project data in a machine-readable format
- Correct: update or correct your personal information
To exercise any of these rights, email privacy@missionhq.dev.
Cookies
We use a single authentication cookie to keep you logged in. We do not use tracking cookies, advertising cookies, or third-party analytics that track individual users. We use privacy-friendly analytics (no cookies, no personal data).
Contact
For privacy-related questions, contact us at privacy@missionhq.dev.