Minro Privacy Policy
Last updated: August 1, 2026
Minro Inc, a Delaware corporation ("Minro," "we," "us"), provides a customer-success platform
that helps software companies understand and act on their own customers' usage and health. This
Privacy Policy explains how we collect, use, and protect personal data.
1. Definitions
"Customer" — a company with a Minro account.
"End User" — a person whose data a Customer connects to or uploads into Minro about their
own customers (e.g., via PostHog, CSV import, or a connected email/Slack channel)."Personal Data" — information that identifies or relates to an identifiable individual.
"Service" — the Minro platform.
2. Who this policy covers, and our role
We handle Personal Data in two capacities:
About Customers and the people at Customer companies — we are the data controller.
This includes account holders, billing contacts, and anyone we correspond with directly.About End Users — data our Customers connect or upload so Minro can help them run their own
customer-success program. For this data, we act as a data processor / service provider on
our Customer's behalf; the Customer is the controller. If you are an End User with a question
about your data, we'll generally direct you to the Customer whose product you use — they
control that relationship.
3. Personal Data we collect, and where it comes from
CategoryExamplesSourceAccount/contact dataName, email, roleProvided directly by CustomersProduct usage dataFeature usage, engagement events, health/churn signalsConnected by Customers (e.g., PostHog), about their End UsersCommunications dataEmail threads, Slack messagesConnected by Customers, scoped to their own workspace, used to generate drafts and surface signalsTechnical/log dataIP address, browser/device info, access logsGenerated automatically by using the Service
We do not collect more Personal Data than we need to provide the Service, and we do not sell
Personal Data.
4. How we use Personal Data
To provide the Service: computing health/churn signals, drafting outreach, surfacing bugs and
patterns for our Customers.To operate, secure, maintain, and improve the Service.
To communicate with Customers about their account and the Service.
To comply with legal obligations.
5. How we use AI
We use AI models to power features like draft generation and the AI chat assistant. Our AI
provider (Anthropic) does not train its models on Minro customer data. AI-generated content is
produced to assist our Customers and is never used to improve models for other customers.
6. How we share Personal Data
We share Personal Data only as needed to run the Service, with the following sub-processors:
Cloud infrastructure
ProviderPurposeAmazon Web ServicesCloud hosting, database, storage, and transactional email delivery
AI providers
ProviderPurposeAnthropicAI inference to generate draft outreach and power the AI chat feature
Other services
ProviderPurposeSentryError monitoring and application diagnosticsStripeBilling and payment processingPostHogMinro's own first-party product analytics (how Customers use the Minro app)SlackFor Customers who enable the Slack integration — bot notifications, digests, approvalsDiscordFor Customers who enable the Discord integrationRevenueCatFor Customers who connect RevenueCat, to ingest their subscription/revenue dataResendFor Customers who connect their own Resend account as their outbound email delivery channel
This list is kept current and updated when we add or remove sub-processors. All sub-processors
are contractually obligated to protect Personal Data and use it only for the purposes we specify.
We may also share Personal Data:
For legal reasons — if required to comply with law, legal process, or to protect rights,
safety, or property.In a business transfer — if Minro is involved in a merger, acquisition, or asset sale,
Personal Data may be transferred as part of that transaction, subject to this policy.
We do not sell Personal Data to third parties.
7. Cookies and tracking technologies
Minro does not currently use cookies, advertising trackers, or third-party analytics scripts on
minro.com or within the product beyond what's strictly necessary for authentication (keeping you
logged in). If this changes, we'll update this section and add a cookie notice where required.
8. Security
Data is stored in our production AWS environment (Amazon RDS PostgreSQL and S3, US West region),
encrypted at rest (AES-256) and in transit (TLS). Database storage runs in a Multi-AZ
configuration for resilience. Access is restricted to authorized personnel on a least-privilege
basis.
9. Data retention and deletion
We retain Personal Data only as long as needed to provide the Service or as required by law. Upon
a deletion request, we remove the relevant data from our production systems; database backups are
purged on a rolling 7-day cycle, so backup copies clear out within 7 days of deletion (longer
during an active incident investigation, if one is in progress). We aim to complete deletion
requests within 30 days.
In the event of a data breach affecting Personal Data, we will notify affected Customers without
undue delay, and in any event within 72 hours of confirming the breach, consistent with our
Incident Response Plan.
10. Your rights and choices
If you are a Customer, you can access, correct, or delete Personal Data in your account by
contacting us. If you are an End User and want to access, correct, or delete your Personal Data,
please contact the Customer whose product you use directly, or reach us at team@minro.com and
we will route your request appropriately. We'll honor reasonable requests to know, correct, or
delete your Personal Data, and to opt out of any sale of Personal Data (we don't sell it).
11. Children's privacy
The Service is intended for business use and is not directed to children. We do not knowingly
collect Personal Data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the
"last updated" date above.
13. Contact us
Questions about this policy, or to exercise your rights: team@minro.com