Mission Command
Privacy Policy
Effective July 14, 2026
Mission Command (missioncommandhq.com) is a personal productivity app for job seekers, offered as a free tier and as paid subscription plans. The short version: your data belongs to you, it is stored privately in your own account, we never sell it, and we never share it except with the service providers required to run the app.
What we store
- Account basics — your email address, display name, and (if you enable it) two-factor authentication settings. Passwords are stored only as secure hashes by our authentication provider.
- Your content — tasks, calendar events, notes, interview pipelines, resumes, finance entries, and documents you upload. Everything lives in a database protected by row-level security: your rows are readable by your account only.
- A local cache — the app keeps a copy of your content in your own browser so it opens fast and works offline. Signing in as a different account on the same browser wipes that cache before anything is shown.
- Usage counters — we count AI requests per account to enforce fair-use quotas. Counters store numbers, not your content.
- Payment records — if you buy a subscription or an AI top-up, we store your billing status, plan, and Stripe customer id. We never store full card numbers — those are handled entirely by Stripe.
- Mission Inbox email — if you use the in-app Mission Inbox, the messages you send and receive through it are stored in your account so you can read and reply to them.
Google user data (only if you connect Google)
Google connectors are optional. If you connect them, Mission Command requests the minimum scopes it needs:
- Gmail — reads your unread count for the dashboard and creates draft emails (for example, recruiter follow-ups) inside your own Gmail. You review and send drafts yourself; Mission Command does not send email on your behalf.
- Google Calendar — two-way sync: events you create in Mission Command are pushed to your Google Calendar, and your upcoming Google events appear in the Calendar tab.
- Google Drive — read-only file metadata (names and links) so you can jump to a recent document. File contents are never downloaded or stored.
OAuth tokens are stored securely server-side, used only to provide these features, and deleted when you disconnect a connector. Google data is never used for advertising and is never sold.
Mission Command's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI features
When you use an AI feature (the resume engine, interview prep, cover letters, or the XO assistant), the text you submit — for example a resume or a job description — is sent to Anthropic's API to generate the result, then returned to your account. Anthropic does not use API data to train its models. We do not use your content to train anything either.
Payments
Card payments are processed by Stripe, our payment processor. We never see or store your full card number — Stripe collects and handles card details directly. Stripe's handling of your payment information is governed by Stripe's privacy policy.
Email & Mission Inbox
Transactional email — sign-in links, confirmations, and receipts — and the optional Mission Inbox are delivered through Resend, our email provider. Inbound email sent to your Mission Inbox address is received and stored in your account so you can read and reply to it.
Calendar feed links
The optional Phone Calendar Sync feature creates a secret, random link that serves your events to your phone's calendar app. Anyone who has that exact link can read your events — treat it like a password. You can reset it at any time from the Connectors tab, which immediately disables the old link.
Who we share data with
We share data only with the service providers (subprocessors) required to run the app:
- Supabase — database, authentication, and file storage.
- Vercel — hosting.
- Anthropic — AI processing, as described above.
- Stripe — payment processing.
- Resend — email delivery.
- Browserbase — optional; the cloud browser that powers auto-apply, used only when you use that feature.
- ElevenLabs — optional; text-to-speech for the XO assistant's voice, used only when you enable it.
- Google — optional; only at your direction when you connect a Google service.
We do not sell your data, run ads, or share your information with data brokers.
Cookies
Mission Command uses cookies only to keep you signed in. There are no advertising or cross-site tracking cookies.
Your controls
- Export all of your data any time from Settings → Data.
- Disconnect any connector any time from the Connectors tab.
- Delete your account and its data by emailing the address below — we complete deletion requests within 30 days.
Your privacy rights
You can access, export, correct, or delete your data at any time. You can also opt out of any sale of your personal information — though we do not sell personal information — and we will not discriminate against you for exercising any of these rights.
These rights include those provided under laws such as the California Privacy Rights Act (CPRA) and, for users in the EU and UK, the General Data Protection Regulation (GDPR) — including the rights of access, deletion, portability, and objection.
Data retention
We keep your data for as long as your account is active. If you request account deletion, we delete or anonymize your data within 30 days, except where a longer retention period is required by law — for example, tax and payment records.
Children's privacy
Mission Command is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us their data, contact us and we will delete it.
International users
Mission Command is operated from the United States. Wherever you use the service, your data is processed and stored in the United States.
Governing law
This policy and any dispute relating to it are governed by the laws of the State of Florida, USA.
Contact
Questions or deletion requests: jc93stro@gmail.com