Back homeMithrandir

Privacy Policy

Last updated · 16 August 2026

Mithrandir (“we,” “us”) runs an early-access waitlist, a design-partner application program, and, where a customer connects it, a Slack workspace integration. This policy explains what we collect in each case, why, and the rights you have over your data. It is written for the EU General Data Protection Regulation (GDPR) and Turkey's KVKK (Law No. 6698).

1. Who is responsible

Mithrandir is the data controller for the information described here. For any privacy question or request, email support@trymithrandir.com.

2. What we collect

When you submit the waitlist form we store:

  • Your email address: required, so we can contact you about early access.
  • An optional message: the free-text field describing your team's knowledge-loss problem, if you choose to fill it in.
  • A timestamp: when you joined.

When you apply to the design-partner program we store:

  • Your name and work email: so we can identify and contact you about the application.
  • Your company, function, and company size: so we can understand whether the current program fits your organization.
  • Your description of the problem: the free-text answer about where important context gets lost across your company.
  • The application source and timestamp: which site link led to the form and when it was submitted.

We also briefly process your IP address when either form is submitted, purely to prevent spam and abuse (rate limiting). It is not stored with your form submission.

If you continue from a design-partner application to scheduling, we share your name and email, plus an opaque application reference, with Cal.com. Cal.com processes the booking details you choose to provide on its scheduler.

Slack workspace integration (upcoming): workspace message capture is not yet live. Once the Slack connector ships and a workspace administrator connects Mithrandir to Slack, we will capture messages and their authorship in the public channels, private channels, and direct messages the app has been explicitly added to, so we can build a permanent record of the decisions and context those conversations describe.

3. Why we use it

We use your information to contact you about early access, assess your design-partner application, arrange a founder conversation, provide relevant product updates, and keep the forms secure from abuse. Our legal basis is your consent (GDPR Art. 6(1)(a)), your explicit consent / açık rıza under the KVKK, given when you submit the form. You can withdraw it at any time (see section 6), and every email we send you will include a simple way to opt out.

4. Who processes it

We use a small number of service providers (sub-processors) to run Mithrandir. They process data on our behalf and only as needed:

  • Supabase: stores your waitlist entry and, if you apply, your design-partner application (database).
  • Upstash: processes your IP address for rate limiting.
  • Vercel: hosts and serves this website.
  • Model providers: where a workspace is connected, captured conversation content is processed by a large-language-model provider to identify and answer questions about the reasoning behind decisions. Today that is OpenAI by default, and Anthropic for the public live demo. Self-hosted deployments can instead run a model inside their own infrastructure, in which case this content never leaves it.
  • Resend: sends the welcome email when you join the waitlist.
  • Cal.com: provides the scheduling interface when you choose to book a founder conversation.

These providers may process data on servers outside your country, including outside the EU/EEA and Türkiye.

5. How long we keep it

We keep your waitlist entry until we launch and finish onboarding, or until you ask us to delete it, whichever comes first. We keep a design-partner application while we evaluate it and operate the program with you. If we decline an application, we delete it within 90 days; if an application is submitted but never proceeds to a conversation, we delete it automatically after 180 days. You can also ask us to delete it at any time (see section 6). Data captured through a connected Slack workspace is retained for as long as that account is active, until the workspace deletes the app or requests deletion.

6. Your rights

You can ask us to access, correct, or delete your data, restrict or object to its processing, receive a copy in a portable format, and withdraw your consent at any time. Under the KVKK (Art. 11) you also have the right to learn whether your data is processed and to request that incorrect data be corrected. To exercise any of these, email support@trymithrandir.com and we'll take care of it. You may also lodge a complaint with your local data protection authority.

7. Cookies

Vercel Analytics measures aggregate site usage without cross-site tracking cookies. The Cal.com scheduler is loaded only after a design-partner application is submitted; Cal.com may use storage or cookies needed to operate its booking experience. We do not use advertising cookies on this site.

8. Changes

We may update this policy as the product develops. The date at the top of this page always reflects the current version.

9. Contact

Questions about this policy or your data? Email support@trymithrandir.com.

← Back to home