Privacy Policy
Last updated May 30, 2026
This Privacy Policy explains what information Medula Labs (“Medula,” “we,” “us”) collects, how we use it, and the choices you have. Medula operates an AI agent that connects to the tools you authorize and performs work on your behalf. Protecting the data in those tools is fundamental to how the product is built.
Information we collect
Account information. Your name, email address, and authentication details when you sign up.
Connected-tool data. When you connect a service (such as Gmail, Slack, or Notion) via OAuth, we access only the data and scopes required to perform the tasks you request. We never receive or store your passwords for those services.
Usage data. Tasks you run, the steps the agent takes, and basic diagnostic and device information used to operate and improve the service.
How we use your data
We use your data solely to provide the service: to understand your requests, plan and execute tasks across your connected tools, show you what happened, and keep your account secure. We do not sell your data, and we do not use the contents of your connected tools to train third-party AI models.
How we protect it
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. Connections use OAuth tokens that you can revoke at any time from your settings or directly from the provider, which immediately cuts off Medula's access.
Your control and choices
You decide which tools Medula can access and can disconnect any of them at any time. You can request a copy of your data or ask us to delete your account and associated data by contacting us. Consequential actions (like sending email) require your approval before they run.
Third-party services
Medula relies on infrastructure and AI providers to deliver the service. These providers process data on our behalf under agreements that restrict their use of it to providing services to us.
Data retention
We retain your account and task data for as long as your account is active or as needed to provide the service. When you delete your account, we delete or anonymize your data within a reasonable period, except where retention is required by law.
Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the “last updated” date above. Material changes will be communicated where appropriate.
This document is provided for transparency and is not a substitute for legal advice. Please have counsel review before relying on it for compliance purposes.
