Muster

Privacy Policy

Last updated: 3/31/2026

Muster ("we," "our," or "us") provides a practice management application. This Privacy Policy describes how we collect, use, and protect your information when you use our service.

1. Information We Collect

We collect information you provide directly:

  • Account data: email address, username, name, password (stored securely)
  • Profile data: photo, title, degrees, specialty, license number, contact information
  • Practice data: client/patient names, contact details, clinical notes, treatment goals, appointments, session ratings, receipts, and task lists

We also collect technical data: browser type, device information, and IP address for security and analytics. If you connect Google Calendar, we access calendar events only for syncing your appointments.

2. How We Use Your Information

  • To provide, maintain, and improve the Muster app
  • To authenticate your account and manage your session
  • To sync your data across devices when you use Supabase
  • To sync appointments with Google Calendar when you enable that feature
  • To process payments (PayPal, Mercado Pago) and manage subscriptions
  • To send transactional emails (e.g., password reset, invite redemption)

3. Storage and Third-Party Services

Your data may be stored using:

  • Supabase – Authentication and cloud database (when configured)
  • localStorage – Browser storage for cache and offline use
  • Google – Only if you choose to sync with Google Calendar (OAuth)
  • PayPal / Mercado Pago – Payment processing (we do not store full payment details)

Each service has its own privacy policy. We encourage you to review them.

4. Sharing, Transfer & Disclosure of Data

We do not sell your personal data or Google user data to any third party.

We may share or disclose your information only in the following limited circumstances:

  • Service providers: We use Supabase (database & authentication), Vercel (hosting), and Google APIs (Calendar sync, OAuth sign-in) to operate the app. These providers process data on our behalf and are bound by their own privacy policies and data protection agreements.
  • Payment processors: When you make a payment, your billing information is handled directly by PayPal or Mercado Pago. We do not store your full payment details.
  • Legal requirements: We may disclose data if required by law, regulation, legal process, or enforceable governmental request.
  • With your consent: We may share data when you explicitly authorize us to do so.

Google user data: When you sign in with Google or connect Google Calendar, we access only the data necessary to provide the requested feature (authentication or calendar sync). We do not share, transfer, or disclose your Google user data to any third party, except as described above. We do not use Google user data for advertising or profiling purposes. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

5. Cookies and Similar Technologies

We use session cookies and localStorage for authentication and to remember your preferences (e.g., language, subject type). Before we rely on this storage, we ask for your consent via a banner; you can accept to continue. You can clear cookies and local storage in your browser settings at any time, but doing so may log you out.

6. Data Security

We use industry-standard security measures (HTTPS, encrypted storage, secure passwords). You are responsible for keeping your login credentials confidential and for the security of data on your devices. We are not liable for unauthorized access resulting from your failure to protect your credentials or device.

7. Your Rights

You may:

  • Access and update your account and profile data in the app
  • Export or delete your data (contact us for assistance)
  • Disconnect Google Calendar integration at any time
  • Request account deletion by contacting us

8. Data Retention

We retain your data as long as your account is active. After account deletion, we remove or anonymize your data within a reasonable period, except where we must retain it for legal or regulatory reasons.

9. Children

Muster is not intended for users under 18. We do not knowingly collect data from children. If you become aware that a child has provided us with personal data, please contact us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy or your data, contact us at musterwithu@gmail.com.