Loading...
Loading...
Legal
Last updated: July 8, 2026
At Mithrilis, we are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered logistics intelligence platform.
This policy applies to information collected through our website, platform, APIs, and any related services (collectively, the "Service").
When you create an account, we collect:
When you use the Service, we may process:
We specifically do not store:
Raw payloads from connected systems are retained temporarily so we can re-derive the unified intelligence if our extraction logic improves. The specific retention periods are listed in Section 4.
To connect to your logistics systems, we securely store:
We use the information we collect to:
We follow a tiered retention model: the unified intelligencewe derive from your data is kept for the life of your account so you retain full historical insight, while the raw operational data that already lives in your source systems is aged out on the schedule below.
| Data Type | Retention Period |
|---|---|
| Unified shipment records, entity registry, match decisions, embeddings | Life of account |
| Account data | Life of account. Your user record and the data linked to it are deleted on closure, except the security audit records listed below. |
| Security audit records (who did what, and when) | Retained after account closure, including the email address of the person who took the action. These records are append only: we cannot edit or delete them, which is what makes the trail trustworthy. |
| Field-level change history (values) | 365 days (audit metadata kept; values then nulled) |
| Query audit logs | 180 days (rows flagged for ML feedback are retained) |
| Raw ingestion payloads | 180 days (normalized payload kept; raw blob then nulled) |
| Email attachment OCR text | 180 days (structured extraction kept; raw text then nulled) |
| Filtered/spam email messages | 90 days |
| Staging records, dead-letter jobs | 30 days |
| Integration sync logs | 14 days |
| Auth sessions | 7 days of inactivity |
| Cached query results | 24 hours to 7 days (by tier) |
We do NOT sell your personal information.
We may share information only in the following circumstances:
We access third-party systems only using your credentials and only to provide the Service you have requested.
Mithrilis builds intelligence from the systems you connect, inside your organization boundary.
We do not sell, share, or benchmark your data against other customers'.
We implement comprehensive security measures including:
SOC 2 Type II: planned. We are not currently SOC 2 certified and are not undergoing an audit at this time. We will update this page when that changes.
For detailed security information, visit our Security page.
All users have the right to:
If you are located in the European Union, you also have the right to:
If you are a California resident, you have the right to:
To exercise any of these rights, contact us at hello@mithrilis.com.
Your data may be processed in the United States where our servers are located. For transfers from the European Economic Area, we use Standard Contractual Clauses approved by the European Commission to ensure adequate protection of your data.
We use the following types of cookies and tracking technologies:
We do not use third-party advertising cookies.
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will take steps to delete that information.
We may update this Privacy Policy from time to time. We will provide at least thirty (30) days' notice of material changes via email and will update the "Last updated" date at the top of this page.
Your continued use of the Service after the effective date of changes constitutes acceptance of the modified policy.
If you have questions about this Privacy Policy or our data practices, please contact us: