Missa privacy
What Missa keeps, and why.
Browsing without an account
You can browse the catalogue, directory and rankings without signing in. Detailed product analytics only start if you accept them, and declining changes nothing about what you can use. If you accept, Missa records a first-party session identifier and basic product analytics, such as which pages and filters are used, so we can tell what is working. We do not use it to build a public profile of you, and we do not sell personal data or run advertising.
Cookies and analytics
A banner asks for your analytics decision on your first visit. Turning analytics off stops both the third-party analytics client and Missa's own event records; turning it on starts them. The cookieless visit counts described below are not affected by this choice. Accepting is never required to use Missa. The only thing stored on your device before you choose is a record of the choice itself, so the banner does not reappear.
Separately, Missa counts visits without cookies so we know how many people use the site. For each page you open we record the page address, the site that linked you here, the country from your connection, your device type and browser, and page-speed and error measurements. To tell one visit from another we use a code made by scrambling your IP address and browser details with a random key that changes every day and is then deleted. That code cannot be turned back into your IP address, cannot follow you from one day to the next, and nothing is stored on your device. We never store your IP address or browser details themselves. If your browser sends a Global Privacy Control signal, these visits are not counted.
Signing in, saving an Opportunity, or submitting an application still produces account and operational records. Those are part of the service you asked for, not optional analytics.
Checking your current choice…
Your account
When you create an account we store your name, email address and a hashed password. Your email is used to sign you in, to keep your account secure, and to send product messages you have asked for. We never publish your email address.
Saves, applications and preparation
When you save an Opportunity, follow a deadline, or prepare application material, that content is stored on your account so it is there when you return. This work is private by default. Missa does not send an application, and does not contact an Organization on your behalf, unless you take that step with the official source yourself.
Portfolio
If you publish a portfolio, the details you add there are visible to anyone with the link. You choose what to include, and you can change or remove it. Anything you leave unpublished stays out of your public portfolio.
Submissions to Organizations
When you submit to an Organization through Missa, the material and details you choose to include are shared with that Organization and the reviewers it assigns. The Organization then handles them under its own privacy policy. Missa keeps a receipt of the submission on your account.
Connected services
If you connect a Google or Microsoft calendar, Missa stores the access you grant, encrypted, so it can add and update the deadlines you ask for. It does not read your other calendar events. You can disconnect at any time in your account settings, which stops further access, and you can also revoke access from your Google or Microsoft account.
If you connect Gmail, Missa reads recent messages to find submission confirmations and responses, so it can suggest a status for you to confirm. It uses message content only for that purpose. Missa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use that information for advertising, do not sell it, and do not let people read it except with your permission, for security, or where the law requires.
Service providers
These providers process data on Missa's behalf, under contract, only to run the service:
- Vercel and Railway, for hosting and background jobs;
- Neon, for the database and sign-in;
- Resend, for email delivery;
- Telnyx, for text reminders: if you are a Plus member and turn on text reminders, Telnyx processes your phone number to deliver them;
- Stripe, for Plus payments (Stripe handles card details; Missa never sees them);
- Upstash, for rate limiting that protects sign-in;
- Cloudmersive, for scanning uploaded files for malware;
- PostHog, for analytics, only if you accept it;
- Sentry, for error reports that help us fix problems, with personal details removed where possible.
Some of these providers process data outside the country where you live, including in the United States. Where data protection law requires it, those transfers rely on safeguards such as the European Commission's standard contractual clauses.
Why we use your data
We use account, saved, and submission data to provide the service you asked for. We use security records and rate limits because we have a legitimate interest in keeping Missa safe. We use optional analytics only with your consent, which you can withdraw at any time above. We keep billing records because the law requires it.
Retention and your choices
We keep account records while your account is open. Closing your account from Profile deactivates it and signs you out. To have your personal data deleted, email us and we will delete or anonymize it within 30 days, except billing records we must keep by law and backups that expire on their normal cycle. Submissions already sent to an Organization stay with that Organization.
You can ask us to access, correct, export, or delete your data, to restrict or object to how we use it, or to explain what we hold. Email us using the address below and we will reply within 30 days. You can also complain to your local data protection authority, such as the Nigeria Data Protection Commission, the UK Information Commissioner's Office, or a supervisory authority in the European Union.
Security
We encrypt data in transit, store passwords only as hashes, encrypt connected-service credentials, keep uploaded files private, and scan submission files for malware. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.
Children
Missa is not for children under 16, and we do not knowingly collect their data. If you think a child has created an account, email us and we will remove it.
Changes to this notice
If we make a material change, we will tell you by email or in Missa before it takes effect.
Who is responsible, and how to reach us
Missa is responsible for the personal data described here.
To ask a privacy question or request removal, email hello@usemissa.com. See the Terms for the rules of using Missa.
Last updated October 3, 2026.