Effective July 28, 2026
Privacy Policy
This policy explains what data Medlar ("Medlar", "we", "us") collects, why we collect it, and the choices you have. It covers both this website and the Medlar app you sign in to and connect your accounts with. The effective date above always tells you which version you are reading.
The Medlar app and your connected accounts
When you sign in and connect an account, Medlar acts on your behalf to carry out the tasks you describe. This section covers how the app handles your data, including data from Google.
What we access. With your explicit authorization, Medlar accesses only the services you choose to connect — for example your Gmail (to read messages and prepare draft replies you approve) and Google Calendar (to read your events). We request the minimum scopes needed, and the assistant is read-only by default: any action that writes, sends, or changes something requires your explicit approval first.
How it's processed. To fulfill a request, the relevant content is sent to our AI provider (Anthropic) for processing, and other connected apps are reached through our integration provider (Composio). These providers process data on our instructions to deliver the service, not for their own purposes.
Storage and security. Connection tokens are encrypted at rest (AES-256-GCM) and never stored in plain text. Each run keeps an activity log — the steps, tool calls, and summary — so you can review exactly what happened.
Google Limited Use. Medlar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not use it to train generalized AI/ML models. Human access to your Google data is limited to what you explicitly approve, what a security or abuse investigation requires, or support you ask us for.
Your control. You can disconnect any account at any time, which removes its stored tokens; delete a run to remove its stored activity; or email hello@medlar.app to have your data deleted.
1. What we collect
Account information. When you sign up, we collect your name and email address (via our authentication provider) and the workspace you belong to. During optional onboarding you may tell us what your team does and your role.
Connected-account data. The content Medlar reads and the actions you approve in the apps you connect — described in the section above.
Billing information. Paid plans are processed by our payments provider (Paddle), who collects your payment details directly. We do not see or store your card number — only the plan, status, and non-sensitive billing metadata needed to run your subscription.
Usage and technical data. Your IP is processed briefly to rate-limit and prevent abuse. Our analytics tool records usage events (pages viewed, buttons clicked) with browser and device information. If you arrive through a campaign link, we record basic UTM tags. If you joined our early-access waitlist, we hold the email and optional details you gave until you ask us to delete them.
We do not knowingly collect data from anyone under 16.
2. How we use it
We use this data to:
- provide the service — run the tasks you ask for across your connected apps;
- create and secure your account and workspace;
- process subscriptions, credits, and payments;
- send you service and account emails (e.g. run reports, receipts, important notices);
- improve the product and prevent abuse.
Where the GDPR or similar laws apply, our legal bases are performing our contract with you (providing the service and billing), your consent (connecting accounts, optional marketing), and our legitimate interest in operating and securing the service.
3. What we don't do
- We do not sell your data — to anyone, ever.
- We do not share it with third parties for their own marketing.
- We do not run advertising or ad-tracking cookies on this site.
- We will not email you beyond what is described above without asking for separate consent first.
4. Service providers we rely on
Your data is processed by a small set of infrastructure providers acting on our instructions under data-processing agreements:
- Vercel — website and app hosting
- Neon — database (accounts, runs, billing state)
- Clerk — sign-in and account management
- Anthropic — the AI that processes your requests
- Composio — connections to third-party apps (Slack, Sheets, Calendar, Drive, and others)
- Paddle — payments and subscriptions (Merchant of Record)
- Inngest — running background jobs and scheduled runs
- Resend — transactional and run-report emails
- Upstash — rate limiting (brief IP processing)
- PostHog — product analytics
These providers may process data in the European Union and the United States. Where data leaves the EU/EEA, transfers rely on standard contractual clauses or equivalent safeguards.
5. Cookies and similar technologies
The site uses a small number of first-party cookies and browser storage entries set by our analytics tool to distinguish visitors and remember sessions. There are no third-party advertising cookies. You can block or clear cookies in your browser at any time; the site keeps working.
6. How long we keep data
Account, workspace, run history, and billing records are kept while your account is active, and deleted (or anonymized) after you close it or ask us to — subject to any records we must keep for legal, tax, or accounting reasons. Connection tokens are removed as soon as you disconnect an account; a run's activity log is removed when you delete the run. Analytics data follows our analytics provider's standard retention schedule, and rate-limiting records expire within minutes.
7. Your rights
Depending on where you live (including under the GDPR and Türkiye's KVKK), you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time.
To exercise any of these, email hello@medlar.app. You can also disconnect any account or delete a run yourself from within the app. You have the right to complain to your local data-protection authority.
8. Security
Data is transmitted over TLS and stored with access limited to what operating the service requires. Submissions are protected against automated abuse. No system is perfectly secure, but we deliberately collect little, which is the best protection of all.
9. Changes to this policy
If we change this policy in a way that matters, we will update the effective date above and, for significant changes, tell registered users by email.
10. Contact
Medlar is operated by the Medlar founding team. For anything related to your data, write to hello@medlar.app.