Effective and last updated August 9, 2026
1. Scope and controller.
This policy applies to Mission websites, local Mission workspaces, hosted Mission workspaces, Mission’s remote MCP service, the Mission app used from ChatGPT or another compatible client, and GoMission Remote for iPhone. Phenomena Labs Ltd. (“Mission,” “we,” “us”) is responsible for the hosted service and optional mobile relay. For questions or requests, email founders@phenomenalabs.com.
A local workspace is controlled by the person or organization operating that installation. A hosted workspace stores its operational files on Mission’s infrastructure. The interface identifies which mode you are using.
2. Data we collect.
Account and connection data. If you create or connect an account, we process your name, email address, a salted password hash (never the plain-text password), account and sign-in state, OAuth client/provider, requested scope, redirect URI, login hint, authorization code, hashed access token, token expiry, and workspace association. Mission tools do not accept passwords, API keys, multi-factor authentication codes, or raw access tokens as tool input.
Workspace and professional context. Depending on what you add or connect, Mission may process workspace settings; goals; tasks; priorities and due dates; relationship or promise notes; draft titles and summaries; approval packets; receipts and outcome summaries; voice-learning preferences, counts, keep/cut phrases, edits, approvals and rejections; learning-rule counts; market-research signals, sources, topics and task summaries; and connector-derived email, calendar, chat, social, document, or website context.
Tool inputs. The current Mission app accepts only: optional local origin and navigation path; account setup intent; search text and result limit; an opaque Mission item reference; optional brief date; and, for prepare-only tools, a packet title, purpose, recommendation, notes, urgency, market thesis, audience, and optional source reference. ChatGPT may send these fields to Mission when you invoke a tool. Mission does not request the full conversation unless you deliberately place conversation text into one of those fields.
Tool outputs. Mission returns only the result needed for the selected tool: account-state booleans and Mission-owned setup links; task, open-loop, draft, receipt, voice, learning, or market-radar summaries; priority/due-date fields where relevant; aggregate counts; opaque follow-up references; and confirmations that a local approval packet and receipt were recorded. Outputs can contain names or professional details already present in a title or summary. They do not include passwords, raw access tokens, account session IDs, filesystem paths, trace IDs, receipt IDs, request IDs, IP addresses, or tool-call timestamps.
Operational data. Our application records the request method, endpoint path without its query string, response status, duration, RPC method name, error count, and authentication mode. It does not log tool arguments, tool results, authorization headers, OAuth query parameters, remote IP addresses, or workspace identifiers. Network and hosting providers may independently receive standard connection metadata such as IP address, user agent, host, path, status, and time.
Website analytics. The public gomission.io site currently uses Google Analytics and StatCounter. They may collect visit time, pages and referrer, approximate location derived from IP address, browser, operating system, device and screen information, and first-time/returning-visitor identifiers. Google Analytics uses first-party _ga cookies; StatCounter may use is_unique or sc_is_visitor_unique cookies. Website analytics are not joined to private Mission workspace content or returned by Mission tools.
2A. GoMission Remote data.
The iPhone app stores the paired Mission base URL in app-only iOS preferences and the pairing token in the iOS Keychain. It reads workspace status, Mission prompts and items, approval packets, enabled capability descriptions, execution state, and receipts from the workspace you pair. It sends only the local edits, decisions, commands, and exact action fields you deliberately enter or approve. QR camera frames are processed on device and are not stored by Mission. The app contains no advertising or analytics SDKs and does not track you across apps or websites.
3. How we use data.
We use the data above to authenticate and route the correct workspace; answer the tool you chose; search, summarize, prioritize, and display your Mission context; prepare local review artifacts and receipts; learn workspace-specific drafting preferences from your decisions; connect GoMission Remote to the workspace you chose; carry an allowlisted mobile request to that workspace; prevent unauthorized or excessive access; diagnose availability and security problems; respond to support and privacy requests; and comply with law. We do not use private workspace content for advertising, sell it, or use it to train a general-purpose Mission model.
4. Recipients and disclosures.
OpenAI. When you use Mission in ChatGPT, OpenAI receives the tool inputs ChatGPT sends and the tool outputs Mission returns. OpenAI processes that data under your OpenAI account settings and OpenAI’s applicable terms and privacy policy.
Infrastructure providers. Render hosts the current MCP application and hosted workspace storage. Cloudflare provides DNS, network delivery, TLS, abuse prevention, and related security services. They process service data on our behalf under their own data-processing and privacy terms.
Website and communications providers. Google receives public-site analytics events and serves Google Fonts; StatCounter receives public-site analytics events; and Google Workspace receives email you send to our support/privacy address. These providers do not receive private workspace content from Mission unless you put it in an email or separately direct a connection.
User-directed connectors. If you enable Gmail, Google Calendar, Slack, Discord, Telegram, a social platform, or another connector, the relevant provider receives the requests necessary for that connection. Mission does not enable those services through the public ChatGPT app unless you separately authorize them.
People and legal disclosures. A limited number of authorized Phenomena Labs personnel or contractors may access hosted data when necessary for support, security, deletion, or legal compliance. We may disclose data to advisers, authorities, or a successor organization where required by law or a corporate transaction, subject to appropriate safeguards. We do not sell or rent personal data.
4A. GoMission Remote recipients.
If you pair directly with a local or user-controlled Mission host, mobile request content goes only between your iPhone and that host. If you choose the optional gomission.io mobile relay, DreamHost hosts the relay and may process encrypted connection metadata plus the allowlisted request and response while carrying it between your iPhone and your Mission connector. The relay stores only token hashes, not raw tokens. Apple processes App Store, TestFlight, device, crash, and purchase or download information under Apple’s terms; Mission does not add a third-party analytics SDK to the app.
5. Retention.
Local workspaces: workspace files remain until you or your organization delete them. Mission’s local privacy commands can inventory, export, harden, encrypt, or delete selected local data. Local connector copies and provider-side data may require separate deletion or revocation.
Hosted account and workspace content: account records, workspace files, prepared packets, receipts, and learning preferences are retained while the account or workspace remains active. After a verified deletion or account-closure request, we delete the active hosted copy within 30 days. The current runtime does not create a separate Mission-managed archive for deleted hosted workspaces.
Authentication: OAuth authorization codes expire after 10 minutes. Hashed MCP access-token records expire after 30 days and are removed on the next authentication operation after expiry. Account sessions expire after 90 days; expired and signed-out session rows are removed on the next account operation. Password hashes and basic account records remain until account deletion.
GoMission Remote: the paired base URL remains on the iPhone until you disconnect the app or remove it. The pairing token remains in the iOS Keychain until you disconnect or remove the app. Optional mobile-relay requests expire after 60 seconds; connector leases expire after 15 seconds; transient request and response bodies expire from relay storage within 120 seconds. Hashed mobile and connector tokens remain until the relay workspace is reprovisioned or deleted.
Operational logs: as currently configured, Render retains application service logs for 7 days. Cloudflare makes HTTP request logs available for at least 3 and up to 7 days. Mission does not stream these logs to a separate long-term logging provider. Security/audit records about changes made by Mission administrators, rather than your tool content, may remain in provider audit logs for the provider’s published retention period.
Website analytics: Google Analytics user- and event-level data is retained for no more than 14 months; its _ga cookies can remain for up to 2 years. StatCounter detailed visits are stored in a rolling, capacity-limited log: the oldest visit is removed when a new visit exceeds the configured log capacity. StatCounter’s visitor cookies can remain for 2 years (sc_is_visitor_unique) or 5 years (is_unique). We do not download or maintain a separate long-term copy of raw visitor logs.
Support and privacy correspondence: we keep support messages until the issue is resolved, and privacy-request records for up to 24 months so we can document the request and our response. We may retain a narrowly limited record longer where law requires it or to establish, exercise, or defend legal claims.
6. Your controls.
You can choose what to place in Mission; inspect, edit, export, or delete local workspace files; use mission privacy summary, mission privacy export, or the documented scoped delete commands; decline a prepare action; disconnect Mission in ChatGPT; and revoke a connected provider’s authorization in that provider’s settings. Disconnecting stops future app access but does not by itself delete an existing hosted workspace.
You can block or clear analytics cookies in your browser, use Google’s Analytics opt-out controls, or use StatCounter’s cookie-refusal control. Blocking analytics does not prevent use of Mission’s public information pages or app tools.
For a hosted workspace, email founders@phenomenalabs.com to request access, a portable export, correction, deletion, restriction, or withdrawal of consent. Include the account email and say “Mission data request.” We may verify your identity before acting. We respond within 30 days, or explain any legally permitted extension. You may also object to processing or complain to your local data-protection authority where those rights apply.
6A. GoMission Remote controls.
You choose the Mission host and whether to use a direct connection or the optional relay. You can inspect the paired URL in Settings, reject or defer an action, refresh the workspace, disconnect to delete the iPhone’s pairing URL and Keychain token, revoke or rotate the token from the paired workspace, and delete the app. Disconnecting the iPhone does not delete the underlying Mission workspace or provider-side drafts and data.
7. Sensitive data and credentials.
Do not place passwords, API keys, authentication tokens, multi-factor codes, financial account credentials, government identifiers, health records, or other highly sensitive data in Mission tool fields. Enter account credentials only on a Mission-owned login page or the relevant provider’s authorization page. Pair GoMission Remote only with a Mission URL and token generated for you; do not send the pairing link to another person. Professional workspace content can incidentally identify colleagues, clients, or other people; only add or connect data you are authorized to use.
8. Security, transfers, and limits.
Mission uses encrypted network transport, hashed credentials and tokens, access controls, scoped tools, human approval boundaries, and data-minimized tool results. No system is perfectly secure. Render, Cloudflare, OpenAI, and other providers may process data in countries other than yours under their applicable safeguards.
9. Children and changes.
Mission is a professional product and is not directed to children under 18. If you believe a child provided data, contact us for deletion. We will update the date above when this policy changes materially and will provide additional notice where required.