Terms & Policies

Data Handling

A technical summary of Mission’s local and hosted boundaries. The complete disclosure is in the Privacy Policy.

Last updated August 9, 2026

Local and hosted modes.

Local workspace files remain on storage controlled by the operator unless the operator invokes a connector, model API, or hosted service. Hosted workspaces use Mission’s Render-hosted persistent storage and Cloudflare-protected network endpoint. The Privacy Policy lists the data, recipients, and retention period for each mode.

ChatGPT tool boundary.

The Mission app receives only the declared tool fields: setup/navigation options, search text, opaque item references, dates, and prepare-only packet fields. Results are compact summaries and aggregate status. Mission does not return credentials, session IDs, filesystem paths, trace or receipt IDs, request IDs, IP addresses, or tool-call timestamps.

Authentication boundary.

Passwords are entered only on Mission-owned pages, salted and hashed, and never accepted by an MCP tool. OAuth authorization codes expire after 10 minutes. Raw MCP access tokens are returned once to the client; Mission persists only a hash, with a 30-day expiry.

GoMission Remote boundary.

The iPhone stores the paired Mission base URL in app-only preferences and the raw pairing token in the iOS Keychain. It calls only allowlisted /api/mobile/* routes. Direct pairing sends content only to the operator’s Mission host. The optional gomission.io relay stores token hashes and carries encrypted, allowlisted requests; requests expire after 60 seconds and request/response bodies expire from relay storage within 120 seconds. QR camera frames remain on device. The app contains no advertising or analytics SDKs.

Source material is untrusted.

Email, calendar, chat, social, website, and document content can be incomplete, adversarial, stale, or misleading. Mission treats it as evidence, keeps it structurally separate from instructions where possible, and requires review before consequential action.

Preparation is not execution.

Public app tools read small summaries or prepare a local approval packet and waiting receipt. They do not send email, publish posts, schedule events, spend money, delete data, or mutate external accounts. External action remains outside this app surface and subject to explicit approval.

Retention and controls.

Local files remain until the operator deletes them. Hosted content remains while the workspace is active and is deleted from the active service within 30 days of a verified request. Current application logs are retained for 7 days; current Cloudflare HTTP logs are available for 3–7 days. See the Privacy Policy for account-session, support-record, export, correction, deletion, and revocation details.