Legal

Data Use and Processing

Effective date: July 14, 2026  ·  Last updated: July 14, 2026

This page explains, in practical terms, what data the Fisga platform processes, who processes it, where it lives, how it is protected, and what we and our customers are each responsible for. It supports our Terms of Service and Privacy Policy and is written for buyers, security reviewers, and procurement teams.

The short version. Fisga (a product of Micstura LLC) processes customer content only to run the studies you request. Data is stored in the United States. We do not sell data and we do not use your content to train AI models. A Data Processing Addendum is available for contract customers on request.
Contents
  1. Roles
  2. Data We Process
  3. Purpose and Scope
  4. Subprocessors
  5. No Model Training on Your Content
  6. Security Measures
  7. Data Residency
  8. Retention and Deletion
  9. Incident Notification
  10. Customer Responsibilities
  11. Data Processing Addendum
  12. Changes and Contact

1. Roles

For the documents, briefs, study configurations, and other materials a customer uploads ("Customer Content"), Micstura LLC acts as a service provider and processor. The customer decides what to upload and for what purpose, and we process that content on the customer's behalf and per its instructions. For account, billing, and website analytics data, we act as a controller. This split is described in our Privacy Policy.

2. Data We Process

CategoryExamplesRole
Account dataName, business email, organization, role, hashed credentialsController
Customer ContentUploaded documents, briefs, study parameters, prompts, and any personal information a customer chooses to includeProcessor
Generated OutputsModeled panels, analyses, and reports produced from customer inputsProcessor
Usage and telemetryRequests to study and chat features, timestamps, credits used, prompt and response metadata, diagnosticsController
Billing dataPlan, transaction status, last four digits of card (full card data handled by the payment processor)Controller
Log and device dataIP address, browser type, access logsController

The federal reference datasets that ground the modeling (for example U.S. Census, BLS, BRFSS, FRED, and GSS) are public data sources and do not contain your Customer Content.

3. Purpose and Scope

We process Customer Content solely to provide the Service: to run the studies you configure, to generate Outputs, and to store and make those Outputs available to you. We also process operational data to secure, maintain, debug, and improve the Service. We do not use Customer Content for advertising, and we do not sell it.

4. Subprocessors

We engage the following subprocessors to deliver the Service. Each is bound by contractual obligations to protect data and to process it only to provide their service to us.

SubprocessorFunctionData processedLocation
OpenAIAI model APIs (panel generation, content features)Inputs and relevant Customer Content sent for generationUnited States
AnthropicAI model APIs (platform and assistant features)Inputs and relevant Customer Content sent for generationUnited States
SupabaseDatabase and file storageAccount data, Customer Content, OutputsUnited States
RailwayApplication hosting and deploymentApplication traffic and runtime dataUnited States
LangfusePrompt management and observability/telemetryPrompt and response metadata and content for requestsUnited States
SerpAPIThird-party search and trends signals (Google Trends)Query terms derived from study configurationUnited States
ResendTransactional and notification emailRecipient email and message contentUnited States
[Payment processor]Payments and billingBilling and payment dataUnited States

We may update this list as our infrastructure evolves. For contract customers, we will provide advance notice of new subprocessors where the Data Processing Addendum requires it.

5. No Model Training on Your Content

We access AI providers through their API tiers under terms that do not permit them to use your content to train their models. We do not use Customer Content to train our own or any third party's foundation models. Customer Content is used to generate the Outputs you request and to operate and debug the Service, not to build general-purpose models.

6. Security Measures

No system is perfectly secure. We continue to improve our controls as the product matures.

7. Data Residency

Customer Content, account data, and Outputs are stored and processed in the United States. Our subprocessors process data in the United States as listed in Section 4.

8. Retention and Deletion

We retain Customer Content for the life of your account or until you delete it. When you delete content or close your account, it is removed from active systems and purged from backups within a limited period, except where retention is required to comply with law, resolve disputes, or enforce our agreements. On termination, we make Customer Content available for export for a limited period on request before deletion. Contract customers may agree to specific retention and deletion terms in an Order Form or Data Processing Addendum.

9. Incident Notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of Customer Content, we will notify affected customers without undue delay and provide information reasonably available to us to help the customer meet its own obligations. Specific timelines may be set in a Data Processing Addendum.

10. Customer Responsibilities

Because you control what you upload, you are responsible for:

11. Data Processing Addendum

Contract customers that need a Data Processing Addendum (DPA), a subprocessor notification commitment, or a security questionnaire completed can request one at fisga@micstura.com. We are happy to support procurement and vendor-security reviews.

12. Changes and Contact

We may update this page as the Service and our infrastructure change. Material changes will be reflected in the "Last updated" date above.

Micstura LLC
2720 S W Temple St
South Salt Lake, UT 84115
United States
Data and privacy: fisga@micstura.com
Security: fisga@micstura.com