Privacy Policy
Last updated: June 6, 2026
Muesli is a meeting operating system: it reads your calendar, prepares notes before each meeting, records and transcribes calls you authorize, and stores the resulting brief, tasks, and transcript so you can find them later. This page explains, in plain language, what data Muesli collects, what we do with it, who can see it, and how to remove it.
1. Who runs Muesli
Muesli is operated by Hexa ("we", "us"). The contact for any privacy question is raphael@hexa.com.
2. What we collect
We only collect data you connect to Muesli yourself. Specifically:
- Google account profile (name, email, profile photo) — used to sign you in and show your identity in the app.
- Google Calendar events from every workspace you connect — read so the timeline can show your meetings; write only when you create or edit a meeting from Muesli.
- Google Gmail (read-only)— recent threads with the people you're about to meet, so Muesli can pre-fill the "Context" section of an upcoming note. We never send, draft, or modify mail through this scope.
- Meeting recordings + transcripts, only for calls you explicitly opt into: audio captured by our bot (via Recall.ai) or by the desktop app; the resulting transcript text; an AI-generated summary; and any notes you type.
- Third-party integrations you connect (Attio, Ashby, Notion, Composio, Granola, Fireflies, Superhuman, etc.) — only the data and scopes you grant during the connect flow; used to enrich notes and to push outputs you explicitly trigger.
- App usage telemetry — basic server logs (request paths, status codes, timestamps) used to operate the service and debug errors. No third-party advertising or analytics trackers run on Muesli.
3. What we do with it
- Render your timeline, upcoming briefs, recorded summaries, and the task list.
- Generate summaries, tasks, and assignment classification using AI providers we route through (OpenAI via the Vercel AI Gateway). The provider receives the transcript or note content for the request and returns the result; it is not used to train models.
- Sync data to and from the third-party tools you explicitly connect.
- Operate, secure, and troubleshoot the service.
We do not sell your data. We do not show ads. We do not share your data with anyone outside the processors listed in section 5.
4. Who can see your data
- You, always.
- People you explicitly invite to a note(by email, by space, or with an anyone-with-the-link share). Sharing is per-note and per-section; the default for new notes is "private to you".
- Members of a space you join, for notes that are scoped to that space. Personal notes are never visible to other members of your organization unless you share them.
- Hexa staff, only when you ask for support and only to the extent needed to answer the question.
5. Processors we use
- Vercel (hosting + serverless functions, US/EU).
- Supabase (Postgres database, EU region).
- Recall.ai (meeting recording bot and transcription, EU region).
- OpenAI via Vercel AI Gateway (summaries, classification, action extraction). Inputs are processed per-request and are not used to train models.
- Resend (transactional email — share invites, access requests).
Each provider receives only the data needed to perform its function. Each is bound by its own DPA with Muesli.
6. Where data is stored
Primary storage is in the European Union (Supabase EU). Some serverless functions execute in the United States; transcript processing runs in the Recall.ai EU region. Data in transit uses TLS; data at rest is encrypted by the provider.
7. Retention and deletion
- Notes, transcripts, summaries, and tasks are kept until you delete them.
- Disconnecting an integration revokes our token immediately and stops further reads. Anything we already pulled stays on your existing notes until you delete it.
- You can delete your entire account by emailing raphael@hexa.com; we'll erase your row, all your notes, and all your tokens within 30 days. Server logs are kept for up to 30 days for security and debugging.
8. Your rights
You can ask us at any time to give you a copy of the data we hold about you, to correct it, to restrict how we use it, to object to a specific use, or to delete it. Email raphael@hexa.comand we'll respond within 30 days.
9. Google API Services
Muesli's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except for the processors listed above, do not use it for ads, do not allow humans to read it (except to comply with law, to ensure security, or with your explicit permission), and do not use it to train AI models.
10. Changes
When we change this page in a material way we'll update the "last updated" date and email signed-in users.
11. Contact
Email raphael@hexa.com for any privacy question, deletion request, or feedback.