Privacy Policy

Version 1.0 · Last updated 16 July 2026

This Privacy Policy explains how Dreamer Studios [GmbH], trading as Elev8labs (“Elev8labs”, “we”, “us”), collects, uses and protects personal data when you use the mastroHQ platform and our websites. We comply with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

The short version

  • We collect only what we need to run mastroHQ for you, and we never sell your data.
  • Data about your own customers stays under your control — we process it on your behalf, not for our own purposes.
  • We share data only with vetted providers (like Supabase and Stripe) who help us run the service.
  • If you connect a Gmail mailbox, that data powers your inbox and nothing else — see the Google user data section below.
  • You can access, correct, export or delete your data at any time.
  • Written to the Swiss FADP and GDPR — questions go to privacy@mastrohq.com.

The short version is a friendly summary — the full text below is what applies. This is a working draft and will be reviewed by counsel before launch; items in square brackets are still to be filled in.

1. Controller and contact

For the personal data described in this policy that we process for our own purposes (for example account administration and our website), the controller is Dreamer Studios [GmbH], [Registered address, Basel-Stadt, Switzerland].

For personal data you upload about your own clients and projects (Customer Data), you are the controller and we act as your processor — see our Data Processing Agreement.

Privacy contact: privacy@mastrohq.com. If required, our representative in the EU/EEA is [EU representative — to be appointed if applicable].

2. The personal data we collect

CategoryExamplesSource
Account & identityName, business name, email, role, canton, team sizeYou, at sign-up / booking
AuthenticationMagic-link tokens, OAuth identifiers, session cookiesYou / identity providers (Google, Supabase Auth)
BillingPlan, billing interval, payment status, last 4 digits / card brand (held by Stripe)You / Stripe
Customer Data you uploadYour End Clients’ names, addresses, contact details, quotes, project notes, photos, signatures, messagesYou and your Authorised Users
CommunicationsEmails, WhatsApp messages, and metadata routed through connected mailboxes / numbersYou and your correspondents
Usage & deviceIP address, browser/device type, pages viewed, actions, log timestampsAutomatically, via our app and analytics
Support & marketingEnquiries, demo requests, waitlist / newsletter sign-upsYou

We do not intentionally collect special-category data. Please do not upload sensitive personal data unless strictly necessary for your work.

3. Why we use it and our legal basis

PurposeLegal basis (GDPR / revFADP)
Provide, operate and secure the Service; create and manage your accountPerformance of a contract
Process payments and prevent fraudContract; legal obligation; legitimate interests
Provide support and respond to enquiriesContract; legitimate interests
Improve, troubleshoot and develop the Service (incl. analytics)Legitimate interests (a stable, useful product); consent where required for non-essential cookies
Send service messagesContract; legitimate interests
Send marketing / newsletterConsent (and you can opt out at any time)
Comply with legal, tax and accounting obligationsLegal obligation

Under the revFADP we may process personal data where there is a justified interest and no overriding interest of the data subject prevails; the bases above map to the equivalent revFADP grounds.

4. Cookies and analytics

We use cookies and similar technologies as described in our Cookie Policy. Non-essential analytics (for example PostHog) are used to understand and improve the product, and are set in line with your cookie choices where consent is required.

5. Who we share data with (sub-processors)

We share personal data with carefully selected service providers who process it on our behalf under contract. Current providers include:

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageEU [region to confirm]
VercelApplication hosting and deliveryEU / global edge
StripePayment processingEU / US
ResendTransactional & marketing emailEU / US
TwilioWhatsApp / messagingEU / US
GoogleSign-in and Gmail mailbox sync (if you connect it)EU / US
OpenAI / ReplicateAI room renders (if used)US
Cal.comDemo bookingEU / US
PostHogProduct analyticsEU [region to confirm]

We also disclose data where required by law, to protect our rights, or in connection with a merger or acquisition (with appropriate safeguards). We do not sell personal data.

6. Google user data (Google Sign-In and Gmail)

If you sign in with Google or connect a Gmail mailbox to mastroHQ, we receive data from Google APIs. This section describes exactly how that data is handled, in line with the Google API Services User Data Policy.

What we access

  • Google Sign-In: your name, email address and profile picture, used only to create and authenticate your account.
  • Gmail — read (gmail.readonly, only if the account owner connects a mailbox in Settings → Connections): new messages arriving from the moment of connection onwards. For each message we store the sender and recipient addresses, subject, date, threading headers and the plain-text body (truncated). We do not store attachments, and drafts, spam and trash are excluded from sync.
  • Gmail — send (gmail.send): used solely to send messages you compose and send from the mastroHQ inbox, from your own connected address.

How we use it

Google user data is used only to provide the user-facing features you see in the app: showing your email conversations threaded by client and project in the unified inbox, matching messages to your contacts, and sending the replies you write. We do not use Google user data for advertising, we do not sell it, and we do not use it for any purpose unrelated to these features. Google user data is not used to develop, improve or train generalised artificial-intelligence or machine-learning models, and is not transferred to third-party AI/ML services.

Who we share it with

We do not transfer Google user data to third parties except: to the sub-processors listed in section 5 that host and operate the Service (Supabase for storage, Vercel for hosting) strictly on our behalf; to the authorised users of your own organisation, according to their roles; and where required by law or to protect the security of the Service. It is never sold and never shared with data brokers or advertisers.

How we protect it

Gmail OAuth tokens are encrypted at rest with AES-256-GCM and are accessible only to our server tier — never to browsers or other organisations. Synced messages are protected by the same encryption in transit, database row-level security and multi-tenant isolation described in section 9.

Retention and deletion

Synced messages are retained as part of your organisation's records for as long as your account is active, and are deleted as described in section 8. You can disconnect a mailbox at any time in Settings → Connections: syncing stops immediately, we delete the stored OAuth token and revoke it with Google. You can also revoke mastroHQ's access at any time from your Google Account permissions, and request deletion of all synced Google data by contacting privacy@mastrohq.com.

Limited Use

mastroHQ's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. International transfers

Some providers process data outside Switzerland or the EU/EEA. Where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner) and additional technical measures.

8. How long we keep it

  • Account & Customer Data: for as long as your account is active, then deleted or anonymised within a reasonable period after termination (typically 30 days for export, then deletion), subject to your instructions in the DPA.
  • Billing & tax records: retained for the periods required by Swiss law (generally up to 10 years).
  • Marketing data: until you withdraw consent or unsubscribe.
  • Logs & analytics: retained for a limited period for security and improvement.

9. How we protect data

We use technical and organisational measures including encryption in transit, access controls, multi-tenant isolation enforced at the database level (row-level security), least-privilege service credentials, and encryption of stored integration credentials. No system is completely secure, but we work to protect your data and to notify you of material breaches as required by law.

10. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your local authority.

To exercise your rights, contact privacy@mastrohq.com. If your request concerns data held on behalf of one of our business customers (where you are an End Client), we will refer you to that customer as the controller.

11. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app. The “last updated” date above shows the current version.

13. Contact

Dreamer Studios [GmbH] (trading as Elev8labs), [Registered address, Basel-Stadt, Switzerland]. Privacy enquiries: privacy@mastrohq.com.