Legal
Privacy Policy
Effective date: August 19, 2026
Mysa, Inc. (“Mysa,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect information when you access or use our Go-To-Market (GTM) execution platform and related services, Pharo (“Pharo” or the “Service”).
1 Who We Are
Pharo is an enterprise GTM execution platform offering WebRTC power dialing, automated campaign workflow creation, zero-margin data enrichment waterfalls, and GTM strategy testing environments. Mysa, Inc. is headquartered in San Francisco, California:
Mysa, Inc2261 Market Street #78533
San Francisco, CA 94114
Contact: privacy@withpharo.com
2 Information We Collect
When you access or interact with Pharo, we collect the following types of information:
- Business & Account Information: Company name, industry, size, account credentials, and contact details provided by your designated administrators and Authorized Users.
- Connected Account Data: Email and calendar data accessed via integrations (e.g., Google Workspace) to sync communication history, manage campaigns, and schedule prospect meetings on your behalf.
- Telephony & Telecommunications Metadata: Telephony call metadata, WebRTC connection logs, audio stream diagnostic metrics, and telecom network SIP response codes (e.g., 200 OK, 404 Not Found) generated during power dialer operations.
- Automatically Collected Usage Data: System interactions, feature usage events, device telemetry, browser type, and IP address collected via diagnostic tools (such as PostHog).
- Third-Party Enrichment Data: Contact and firmographic details processed through third-party data providers via our pass-through enrichment waterfall.
3 Google User Data (Limited Use Policy)
Pharo connects to Google Workspace services (Gmail and Google Calendar) only after explicit authorization via Google’s OAuth consent screen.
- Usage Scope: We use Google data solely to provide customer-requested features, including syncing email and calendar context into your Pharo workspace, auto-drafting responses, managing labels/filters, and updating calendar events.
- Limited Use Compliance: Pharo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- No Advertising or General Training: We never sell Google user data, use it for targeted advertising, or share it with data brokers. Neither Mysa nor our third-party AI sub-processors use your Google data or personal context to train generalized machine-learning or foundational AI models.
- Human Access Restrictions: Staff will only access synced Google data with explicit consent for technical support, to investigate security or abuse incidents, or as required by applicable law.
4 How We Use Information
We process collected data for the following core business purposes:
- Operating, maintaining, and providing the Pharo platform and WebRTC dialing infrastructure.
- Executing customer-configured campaign workflows and data enrichment searches.
- Logging telecommunication network signals (SIP outcome codes) to benchmark vendor quality and optimize data routing.
- Monitoring platform stability, security, and usage metrics.
5 How We Share Information
We do not sell personal data. We share information only with trusted service providers bound by strict data protection obligations:
- Infrastructure & Telephony Partners: Hosting providers (AWS), message queuing services, and underlying telecom carriers required to route WebRTC calls and maintain network connectivity.
- AI Processing Sub-processors: Infrastructure providers (e.g., OpenAI, Anthropic, Google Gemini) used strictly to execute real-time research, context summarization, and workflow automation for your workspace.
- Data Enrichment Providers: Third-party B2B data vendors used to execute customer-initiated waterfall searches at exact pass-through cost.
- Legal & Security Requirements: Disclosures required by legal process, regulatory telemarketing audits, TCPA compliance validation, or to protect the safety and integrity of our Service.
6 Data Security
We maintain industry-standard technical and organizational safeguards designed to protect Customer Data against unauthorized access, loss, or misuse. This includes end-to-end encryption for data in transit and at rest within AWS cloud infrastructure.
7 Data Retention & Disconnects
Data synced from connected third-party accounts (e.g., Gmail, Google Calendar) is purged immediately upon disconnecting the integration within Pharo. Remaining account data is retained for no longer than 180 days after account termination or formal deletion request, including rolling encrypted backups, unless longer retention is required by law.
8 Your Rights & Choices
Depending on your location, you may have rights regarding your personal information, including:
- Accessing, updating, or correcting personal records.
- Requesting deletion of your personal data.
- Revoking connected account permissions at any time via Pharo settings or your identity provider (e.g., Google Account permissions).
To exercise these rights, submit a request to privacy@withpharo.com.
9 International Data Transfers
Mysa operates out of the United States. Information processed through Pharo may be transferred to, stored, and processed in the US or other jurisdictions where our cloud infrastructure providers maintain facilities, subject to standard contractual clauses and legal safeguards.
10 Changes to This Policy
We may update this Privacy Policy periodically. Significant updates will be communicated via email or through an in-app notice prior to taking effect.
11 Contact Us
Mysa, Inc.2261 Market Street #78533
San Francisco, CA 94114
Email: privacy@withpharo.com