Theme, language, and local visit values are browser-side preferences for rendering the public website.
Privacy.
Mullusi.com is a static public website. You can read pages, save display preferences in your browser, and contact Mullusi by email. A separate limited pilot may process Gmail data only after a user authorizes read-only access and requests the governed feature described below.
This page applies to the public website, contact routes, the external PayPal support link, and the governed Gmail read-only pilot. Other product-service data handling remains unavailable until its own privacy and runtime gates close.
Choose the trust surface.
Move between website security, privacy, terms, use rules, and disclosure without losing the current public boundary.
Contact messages are created by your email client and delivered through the mailbox you choose.
Product, status, news, and language files are published site data, not private customer records.
Raw message content is excluded from retained governance receipts and application logs.
Local storage
The site may save theme, language, and local visit count values in your browser. These values stay on your device and are not site-wide analytics.
Contact by email
Mail links open your email client. Mullusi receives the message only when you choose a mailbox, write the message, and send it.
External payment processing
Choosing the PayPal support link takes you to PayPal. PayPal processes the payment and may collect payment, account, or device information under its own policies. The Mullusi static site does not receive your card, bank, password, or PayPal login credentials.
Public website files
The site serves public pages and public JSON for display content such as product, status, news, and language text. These files do not contain private customer records.
Other product services
Other live product services are not open from this privacy page. Their privacy terms, support path, and data handling rules will be published before customer access opens.
Google user data and Gmail read-only access
Access. When a user explicitly connects a Google Account, Mullusi requests only the Gmail read-only scope https://www.googleapis.com/auth/gmail.readonly. The pilot may access message content and metadata returned by Gmail only for the user-requested read or interpretation operation. It does not request Gmail send, draft, modify, or delete authority.
Use. Google user data is used only to provide or improve the prominent user-facing Gmail read and interpretation feature the user requested, and to verify that the governed operation completed without an external write. Google user data is not used for advertising, retargeting, credit or lending decisions, sale to data brokers, or training or improving generalized machine-learning models.
Storage and retention. Raw Gmail message content is processed only in ephemeral memory for the requested operation. It is not written to persistent application storage, retained governance receipts, or application logs. Retained evidence is content-free and may include request and account-binding identifiers, timestamps, scope, proof state, status, cryptographic digests, and error classifications. OAuth client credentials and refresh tokens are retained only while the connection remains authorized.
Sharing and human access. Mullusi does not sell Google user data. It does not transfer or disclose Google user data except to infrastructure processors acting on Mullusi's behalf as necessary to provide or secure the requested feature, when required by law, or as otherwise permitted by the Google API Services User Data Policy. Humans do not read message content unless the user gives affirmative permission for specific data, access is necessary for security, access is required by law, or the data is aggregated for lawful internal operations.
Data protection mechanisms. Mullusi protects Google user data in transit with HTTPS/TLS connections to Google's OAuth and Gmail API endpoints. OAuth client credentials and refresh tokens are kept in access-restricted secret systems with encryption at rest; they are not stored in source code, command arguments, retained receipts, or application logs. Access is limited to authorized operators and the minimum gmail.readonly execution path. Short-lived access tokens and raw message content remain ephemeral in memory, and logs and retained evidence exclude message content and credential values.
Operational security. Governed validation rejects a missing, malformed, expired, revoked, or broader-scope credential before Gmail data is admitted. Provider requests are bounded to Google HTTPS endpoints and read-only operations. Mullusi monitors content-free proof and error records for unauthorized access or disclosure. If a security incident is suspected, Mullusi can disable the affected integration, rotate or revoke credentials, restrict access, preserve content-free investigation evidence, and notify affected users when required.
Revocation and deletion. Users can revoke Mullusi's Google access from their Google Account permissions at any time, which prevents subsequent token refresh and Gmail access. To request deletion of retained account-binding evidence or OAuth credentials, contact support@mullusi.com. Mullusi verifies the request, removes the governed connection records within its control, and retains only information required for security, legal, or compliance obligations.
Limited Use. Mullusi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Effective date. This Google user data disclosure was last updated on August 10, 2026.
What data may exist
| Class | Where it lives | Boundary |
|---|---|---|
| Theme and language preference | Your browser | Used to render the public site in your chosen mode. |
| Local visit count | Your browser | Used as a local display value, not transmitted as analytics by this site code. |
| Email content | Your email provider and Mullusi mailbox | Exists only if you send a message. |
| Payment information | PayPal | Processed by PayPal after you choose the external support link; not collected by the Mullusi static site. |
| Delivery logs | Hosting and network infrastructure | Standard infrastructure may create request logs outside this static repository. |