Last updated October 5, 2026
Who runs the studio
Mustard Studio is operated by Modern Mustard Seed LLC, Kalispell, Montana. Contact sarah@modernmustardseed.com about this policy or your information.
What we keep
We keep account and agency information, email verification records, applications, team permissions, and work you save to the cloud. That work can include company context, client briefs, contacts, notes, outreach drafts, source files and versions, voice agent instructions, invoices, proposals, posts, campaigns, missions and financial records. We also keep approvals, provider receipts, usage and security records needed to operate the service.
When a recipient opens an invoice or proposal, we record the opening. When a recipient accepts a proposal, we record the submitted name and network address as the acceptance record.
Local work and cloud work
Some editors keep work in browser memory or local browser storage. That is not an automatic cloud backup. Clearing browser data or moving to another device can remove access to local work.
Saving to a cloud workspace, assigning an AI task, uploading artwork, publishing or connecting a provider sends the relevant content to that service. Each tool identifies its storage and export options. An exported file stays where you choose to save or share it.
How we use it
We use information to deliver the work you request, manage access and billing, protect the service, and provide support. We do not sell or rent your information, or use your client contacts to advertise to them. Public business research in a prospect record is not an endorsement or permission to contact that business automatically.
The services involved
Vercel hosts the application and coding virtual machines. Supabase stores cloud database records. Anthropic processes language tasks. Vercel AI Gateway and the selected image model provider process image prompts when image generation is enabled. Resend delivers email and returns delivery information. Stripe handles billing when used.
Optional connections send the information needed for the action you request: Vapi for voice agents and microphone tests, Shopify for catalogs and checkout, Printify for artwork uploads, E2B for cloud desktop sessions, and Pipedream for connected account authorization and actions. Connected social networks process content you publish. Each provider operates under its own terms and privacy policy. Connecting an account does not authorize every available action.
Google discovery and reporting
When you connect Google in Discovery, the Studio reads the Search Console sites, Analytics properties, and Business Profile locations available to that Google account so you can select this business. It saves encrypted authorization tokens, the selected property identifiers, and the reports you request in the corresponding agency or client workspace. Authorized members of that workspace can see its selected reports. Only the person who connected Google can browse the account’s property choices. Google Business Profile requires its management permission for these reporting APIs; Discovery only reads reporting data and does not edit the profile.
We use this data for the reporting features you request. We do not sell it, use it to target advertising, or use it to train general-purpose AI models. Mustard Studio follows the Google API Services User Data Policy, including its Limited Use requirements. Disconnect in Discovery to remove the saved tokens and stop further reporting access. You can also revoke access through your Google account connections. Saved reports remain in the workspace until replaced or deleted through an account data request. Contact sarah@modernmustardseed.com to request deletion.
We use this data for the reporting features you request. We do not sell it, use it to target advertising, or use it to train general-purpose AI models. Mustard Studio follows the Google API Services User Data Policy, including its Limited Use requirements. Disconnect in Discovery to remove the saved tokens and stop further reporting access. You can also revoke access through your Google account connections. Saved reports remain in the workspace until replaced or deleted through an account data request. Contact sarah@modernmustardseed.com to request deletion.
Website inquiries
A form on a Studio-hosted client website saves the submitted name, email, message, and campaign tags to that business’s private inquiry record. The agency and authorized client members can use it to respond. A configured email provider may also notify the agency. Spam and rate-limit checks use short-lived network identifiers. An exported client website operates under its owner’s privacy notice and configured services.
AI processing
API tasks send the prompt and relevant selected context to the configured model provider. Anthropic states that its commercial products do not use inputs or outputs for model training by default, with exceptions including submitted feedback or an explicit opt-in. Read Anthropic’s commercial data policy. Other providers and subscription workers have their own settings and policies. Share only the context needed for the assignment.
Teams, clients and public work
Agency permissions control cloud workspace access. Owners and editors can make the changes allowed by their role; reviewers receive the review access granted to them. Client spaces and shared deliveries have their own access boundaries. Publishing makes the selected content accessible at its public address. Copies downloaded or shared by others can remain after you revoke a publication.
Credentials and execution records
Manually saved provider keys are encrypted before database storage. Sign-in uses email verification. A project editor or terminal is not a credential vault: source files, command output, screenshots and provider receipts can contain whatever a task writes or displays. We use these records to show what happened and investigate failures.
Retention
Cloud records stay while needed to provide the service, maintain account history and meet applicable obligations. Coding virtual machines use bounded sessions; saved VM snapshots are configured to expire after seven days. Stopping a session does not erase project files, saved snapshots or execution receipts immediately. Provider logs, backups, billing records and security records can follow different retention periods.
Exports and data requests
Use the export controls available in each tool, such as source ZIP or JSON, artwork, video, and CRM CSV or JSON. There is no single export that promises every account record in every format. For account access, correction, export or deletion requests, email sarah@modernmustardseed.com from your verified account address. We verify identity and scope, explain any records that must be retained, and confirm the next step. A Studio account request does not automatically delete records held in your separate provider accounts.
Policy updates
This page carries the date of its latest revision. We will notify affected account holders when a material change requires notice.