This page explains, in practical terms, what data the Fisga platform processes, who processes it, where it lives, how it is protected, and what we and our customers are each responsible for. It supports our Terms of Service and Privacy Policy and is written for buyers, security reviewers, and procurement teams.
For the documents, briefs, study configurations, and other materials a customer uploads ("Customer Content"), Micstura LLC acts as a service provider and processor. The customer decides what to upload and for what purpose, and we process that content on the customer's behalf and per its instructions. For account, billing, and website analytics data, we act as a controller. This split is described in our Privacy Policy.
| Category | Examples | Role |
|---|---|---|
| Account data | Name, business email, organization, role, hashed credentials | Controller |
| Customer Content | Uploaded documents, briefs, study parameters, prompts, and any personal information a customer chooses to include | Processor |
| Generated Outputs | Modeled panels, analyses, and reports produced from customer inputs | Processor |
| Usage and telemetry | Requests to study and chat features, timestamps, credits used, prompt and response metadata, diagnostics | Controller |
| Billing data | Plan, transaction status, last four digits of card (full card data handled by the payment processor) | Controller |
| Log and device data | IP address, browser type, access logs | Controller |
The federal reference datasets that ground the modeling (for example U.S. Census, BLS, BRFSS, FRED, and GSS) are public data sources and do not contain your Customer Content.
We process Customer Content solely to provide the Service: to run the studies you configure, to generate Outputs, and to store and make those Outputs available to you. We also process operational data to secure, maintain, debug, and improve the Service. We do not use Customer Content for advertising, and we do not sell it.
We engage the following subprocessors to deliver the Service. Each is bound by contractual obligations to protect data and to process it only to provide their service to us.
| Subprocessor | Function | Data processed | Location |
|---|---|---|---|
| OpenAI | AI model APIs (panel generation, content features) | Inputs and relevant Customer Content sent for generation | United States |
| Anthropic | AI model APIs (platform and assistant features) | Inputs and relevant Customer Content sent for generation | United States |
| Supabase | Database and file storage | Account data, Customer Content, Outputs | United States |
| Railway | Application hosting and deployment | Application traffic and runtime data | United States |
| Langfuse | Prompt management and observability/telemetry | Prompt and response metadata and content for requests | United States |
| SerpAPI | Third-party search and trends signals (Google Trends) | Query terms derived from study configuration | United States |
| Resend | Transactional and notification email | Recipient email and message content | United States |
| [Payment processor] | Payments and billing | Billing and payment data | United States |
We may update this list as our infrastructure evolves. For contract customers, we will provide advance notice of new subprocessors where the Data Processing Addendum requires it.
We access AI providers through their API tiers under terms that do not permit them to use your content to train their models. We do not use Customer Content to train our own or any third party's foundation models. Customer Content is used to generate the Outputs you request and to operate and debug the Service, not to build general-purpose models.
No system is perfectly secure. We continue to improve our controls as the product matures.
Customer Content, account data, and Outputs are stored and processed in the United States. Our subprocessors process data in the United States as listed in Section 4.
We retain Customer Content for the life of your account or until you delete it. When you delete content or close your account, it is removed from active systems and purged from backups within a limited period, except where retention is required to comply with law, resolve disputes, or enforce our agreements. On termination, we make Customer Content available for export for a limited period on request before deletion. Contract customers may agree to specific retention and deletion terms in an Order Form or Data Processing Addendum.
If we become aware of a security incident that compromises the confidentiality, integrity, or availability of Customer Content, we will notify affected customers without undue delay and provide information reasonably available to us to help the customer meet its own obligations. Specific timelines may be set in a Data Processing Addendum.
Because you control what you upload, you are responsible for:
Contract customers that need a Data Processing Addendum (DPA), a subprocessor notification commitment, or a security questionnaire completed can request one at fisga@micstura.com. We are happy to support procurement and vendor-security reviews.
We may update this page as the Service and our infrastructure change. Material changes will be reflected in the "Last updated" date above.
Micstura LLC
2720 S W Temple St
South Salt Lake, UT 84115
United States
Data and privacy: fisga@micstura.com
Security: fisga@micstura.com