Scope
This policy covers mymula.io and the same product in the Telegram Mini App, Discord Activity, Telegram and Discord bots, and mymula.io/mcp. It sits with our terms of service. Third parties you connect (Privy, Apple, Telegram, Claude, a trading venue) have their own policies.
Who is responsible
The operator of mymula.io (“Mula”, “we”) decides how product data is used. Identity, wallets, balances, and signing are handled by Privy as the source of truth. Our database stores product state only — never a balance ledger, private keys, or signing material.
What we collect
Depending on how you use Mula, that includes:
- Account. Privy user id, login method (email, passkey, Apple, Google, Telegram, Discord, Farcaster, wallet, or guest), and linked-account identifiers those providers give us.
- Wallet pointers. Public addresses and Privy wallet ids we cache so the app can show send, receive, and activity. Balances are read from Privy and the chain, not stored as our ledger.
- Product state. Display name or handle if you set one; follows and copy-trade limits; autopay rules; MCP grants; channel links for Telegram/Discord; organisation membership if you use business features; audit logs of permission changes.
- Chat. Messages you send to in-app Chat so we can answer. Chat, bots, and MCP never receive private keys.
- Technical. IP address, device and browser data, and security signals needed to run the site, stop abuse, and complete OAuth.
- Optional KYC/KYB. If a funding, card, or business feature requires it, identity checks run through Privy (and their KYC providers), not a Mula document vault.
We do not ask for seed phrases on our API. Do not paste export material into Chat.
How we use it
- Create and authenticate your account.
- Operate send, receive, swap, earn, agents, copy, autopay, and MCP — including quotes you confirm and passkey step-up.
- Show the public treasury (agent wallets and PnL, not your email).
- Deliver Telegram/Discord reads and signals you ask for.
- Secure the service, debug incidents, and meet legal duties.
- Measure how the site is used (pages, devices, referrers) via Google Analytics.
- Improve the product using aggregated or de-identified signals.
We do not sell your personal information. We do not run other advertising networks. Google Analytics may still set measurement cookies.
Processors
We use companies who process data for us so the product can run:
- Privy — identity, embedded wallets, policies, intents, MFA, KYC/KYB. See privy.io/privacy.
- Neon — PostgreSQL for product state.
- Vercel — hosting, logs, and the AI gateway that powers Chat.
- Google Analytics — traffic and usage measurement. See policies.google.com/privacy.
- Stripe — fiat on-ramp where that rail is enabled.
- Apple, Google, Telegram, Discord, Farcaster — if you sign in or open Mula inside those apps.
- Anthropic / OpenAI — if you connect Claude or ChatGPT. The assistant sees the tool results you authorise, not your keys.
- Venues and infrastructure — chains, RPCs, Hyperliquid, Polymarket, bridges, and WalletConnect as needed to complete an action you signed.
How long we keep it
Account and product-state records last for as long as you have a Mula account, then for a limited period if we need them for security, disputes, or law. Onchain history exists on public networks independently of Mula and cannot be deleted by us. Chat logs are kept only as long as needed to provide Chat and operate the service.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, to object or restrict certain processing, and to withdraw consent. To use them, ask in Chat and tell us you are making a privacy request.
You can unlink login methods and revoke MCP, copy, and autopay grants in Settings. Signing out does not delete onchain assets. If you want the Mula account removed, say so in Chat; we will delete or anonymise product-state we control, except what we must keep. Privy holds identity and wallet records under their policy — we will point you there where the request sits with them.
Security
Passkey (or other MFA) is required for money moves. Chat, bots, and MCP never see keys. Copy and MCP signers are policy-capped and revocable. No method is perfect. You still need to protect your device and any wallet export you make in Settings.
Children
Mula is not for anyone under 18. We do not knowingly collect personal information from children. If you think we have, tell us in Chat and we will delete it.
International
We and our processors may handle data in the UK, EEA, United States, and other countries. Where we transfer personal information out of your region, we rely on appropriate safeguards those processors provide (for example standard contractual clauses) plus the fact that you are using a global onchain service.
Changes
We may update this policy. The effective date at the top will change. Continued use means you accept the updated policy. Material changes will be posted on this page.
Contact
Privacy questions and requests: Chat at mymula.io. Product questions: How Mula works.