— Privacy Policy

How we handle your data.

Effective: 2026-05-20 · Last updated: 2026-09-08

Note · This policy reflects Mallin's current practice during the design-partner phase. Mallin is operated by roomrefund LLC, a Colorado limited liability company, doing business as Mallin. Your data handling is described below. Questions: privacy@mallin.io.

1. Who we are

Mallin is the operating layer of the revenue organization — an AI agent that helps sales reps prepare for, run, and follow up on customer calls. The product is operated by roomrefund LLC (doing business as "Mallin"; the "Company", "we", "us"), a Colorado limited liability company. Our contact email for all privacy matters is privacy@mallin.io.

2. What data we collect

Account data

When you create a Mallin account, we collect: your name, email address, company name, role/title, and authentication credentials (managed by our auth provider — see Subprocessors). If you enable multi-factor authentication, we additionally store the TOTP secret or recovery codes associated with your account.

Deal data

Mallin collects data about the deals you work — account information, opportunity records, stakeholder names and titles, call transcripts (when you load them), notes, stakeholder interactions, and any custom fields you populate. This data either originates inside Mallin (when you write a note or load a transcript) or is synced from your CRM when you connect one.

CRM-connected data

If you connect Mallin to a CRM (HubSpot, Salesforce, Pipedrive), we read deal, contact, account, and activity data from your CRM to populate Mallin's working surfaces. We also write back to your CRM: notes you create in Mallin, action items you save, drafted emails. We never modify CRM data that wasn't explicitly produced or approved in Mallin.

Usage data

We collect telemetry about how you use Mallin: which pages you visit, which features you engage with, errors you encounter, the timing of those interactions. This data is used to operate, debug, and improve the product. Telemetry is associated with your account but is not sold to or shared with advertising networks.

Support chat

Our in-app help is built by Mallin. There is no third party chat provider, no chat widget loaded from another company, and no third party chat cookie. Earlier versions of this policy described a chat provided by Crisp. That is no longer used.

When you ask the help widget a question, your message is sent to Mallin and answered using Anthropic's API, the same provider described elsewhere in this policy and listed at /subprocessors. The widget answers questions about how to use Mallin. If it cannot help, you can ask to be handed to a person, which sends your question and your account email to us so we can reply. We do not need your deal content in order to answer a support question.

Visitor identification on public pages

On our public marketing pages — such as our homepage, pricing, and product-overview pages — we currently enable a third-party service, RB2B, for visitors whose connection geolocates to the United States, to help us understand which businesses are showing interest in Mallin. RB2B does not run on signed-in Mallin application pages, and we do not enable it for visitors outside the United States.

When these public pages load for an eligible U.S. visitor, RB2B may process information such as IP address, browser or device information, page and referring-page URLs, timestamps, cookies or similar identifiers, and related technical information. RB2B may use this information together with its own and third-party data sources to identify the visiting company and, where available, an associated professional profile.

We use this information to understand prospective-customer interest and for business-to-business sales and marketing outreach. We do not connect RB2B visitor-identification data to your authenticated Mallin account, deal data, call information, or other customer workspace content. For more information, see our /subprocessors page and RB2B's Privacy Policy.

Advertising and conversion measurement

On those same public marketing pages, and again only for visitors whose connection geolocates to the United States, we load the LinkedIn Insight Tag. We advertise Mallin on LinkedIn, and this tag is how we measure which of those advertisements actually lead someone to the site. It does not run on signed-in Mallin application pages, and we do not enable it for visitors outside the United States.

When it loads, LinkedIn may receive information such as IP address, browser or device information, the page and referring-page URLs, timestamps, and cookies or similar identifiers, and may associate that visit with a LinkedIn member. LinkedIn is an advertising network and uses this information under its own privacy policy, including to report on advertisement performance and to show advertisements. We do not send LinkedIn your account, deal, call, or workspace content, and we do not upload customer, contact, or lead lists to LinkedIn or to any other advertising platform.

For more information, see our /subprocessors page and LinkedIn's Privacy Policy.

3. How we use your data

  • Deliver the service: generate pre-call briefs, surface stakeholder intelligence, draft follow-ups, and write back to your CRM.
  • Learn within your tenant: notes you save become context that shapes future briefs for your account only. We do not train shared models on your data.
  • Customer support: respond to your questions, debug issues, send service-related communications.
  • Security & compliance: detect abuse, prevent fraud, meet legal obligations.
  • Improve the product: aggregate, anonymized usage patterns inform engineering priorities.

We do not: sell your data, share your account, deal, or workspace content with advertising networks, or use your deal content to train shared AI models. Advertising and visitor-identification tags run only on our public marketing pages, for visitors who geolocate to the United States, and never on signed-in product pages, and are described under “Advertising and conversion measurement” in section 2. See our AI Governance Policy for the specific rules around the AI layer.

4. Who we share data with

We share data only with the subprocessors required to operate the service. Each one has a specific role and a data-processing relationship with us. The complete list, with location and purpose, is at /subprocessors.

We do not share your data with third parties for any other purpose. We will not share your data with law enforcement without legal process; if we are compelled by valid legal process, we will notify you unless prohibited from doing so.

5. How long we keep your data

  • Account data: retained while your account is active. Deleted within 30 days of account closure (or sooner on written request).
  • Deal data: retained until you delete the deal or close your account. Soft-deleted records purged within 30 days.
  • Backups: our database provider (Supabase) retains point-in-time recovery snapshots for up to 7 days. Deleted data is removed from active systems immediately and from backups within 7 days.
  • Logs & telemetry: retained for up to 90 days for operational debugging, then deleted.
  • Audit logs: retained for the life of the account for compliance and security review.

6. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access: request a copy of the data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: have your data deleted (subject to legal retention requirements).
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction: ask us to limit how we process your data.
  • Objection: object to specific processing activities.
  • Withdrawal of consent: where processing is based on your consent, withdraw it at any time.

To exercise any of these rights, email privacy@mallin.io. We respond within 30 days. We may need to verify your identity before fulfilling certain requests.

7. Where your data is stored

Your data is stored on infrastructure operated by our subprocessors. Primary storage (Supabase, Vercel) is in United States data centers (AWS US-East). Some metadata (authentication tokens, session state) may transit through globally-distributed edge networks for performance.

For customers in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data outside those regions are protected by the standard contractual clauses where applicable. Contact us if you need a Data Processing Addendum (DPA).

8. Security

See our Security & Trust page for the full picture. In short: data is encrypted in transit (TLS 1.3) and at rest (AES-256 via our infrastructure providers); multi-tenant isolation is enforced at the database row level; access controls are role-based with audit logging; multi-factor authentication is available on all accounts.

9. Children

Mallin is a business tool. It is not directed to, and not intended for use by, children under the age of 16. We do not knowingly collect data from children under 16. If you believe we have inadvertently collected such data, contact us and we will delete it.

10. Changes to this policy

We'll update this policy as Mallin evolves. The "Last updated" date at the top reflects the most recent change. Material changes — anything that meaningfully expands the data we collect or how we use it — we notify you of by email before they take effect.

11. How we handle Google user data

Google access is granted in two separate pieces, and you can hold either without the other. Connecting Gmail grants gmail.compose, which lets Mallin create draft emails in your Gmail Drafts folder and send an individual message at the moment you choose to send it. Connecting Google Calendar grants either calendar.events.readonly, which lets Mallin read the events on your calendar and nothing else, or calendar.events in workspaces that have turned on sending the invite for a call you book inside Mallin. The consent screen names which one you are granting before you accept, and Settings, Integrations says which one your account currently holds. Our access to and use of Google user data is limited to what is described here.

  • What we access (Gmail): the ability to create drafts in your Gmail account, the ability to send a message when you press Send on it in Mallin, and your Google email address (to show which account is connected). We do not read your inbox, sent mail, or any existing messages.
  • What we access (Calendar): the events on your own calendar. For each event we read the time, the title, who is invited, the meeting link if there is one, and whether it was cancelled. By default this is read only: Mallin cannot create, change or delete anything on your calendar. Where your workspace has turned on booking a call from inside Mallin, the grant also lets Mallin create an event — only the one you ask it to create, at the moment you book that call, with the people you selected. It never edits or deletes an event it did not create, and in neither case can it see your calendar settings or sharing rules.
  • How we use Calendar data: to show you your upcoming meetings inside Mallin, to prepare a briefing before a call with someone outside your company, and to work out which meeting a call recording belongs to. Where writing is granted, to place an event on your calendar for a call you booked in Mallin and invite the people you chose. Calendar data is not used for anything else.
  • How we use it: to place Mallin-drafted emails into your Drafts folder for you to review and send yourself, and — only when you press Send on a message shown to you in Mallin, which you can edit first — to send that one message from your account. Mallin never sends email on its own. There is no automated, scheduled, or bulk sending: every message goes to a single recipient, at the moment you press Send on that specific message, and nothing is ever sent without that action.
  • How we store it: your Google OAuth tokens are stored securely (encrypted at rest via our infrastructure providers) and used only for the actions described above. They are never sold, never shared with third parties, and never used for advertising.
  • How to revoke: disconnect Gmail or Google Calendar at any time from Settings, Integrations. Disconnecting asks Google to revoke the grant and then deletes the tokens we store. You can also revoke Mallin's access directly at myaccount.google.com/permissions.

Mallin's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use Google user data for any purpose other than providing the drafting and meeting features you asked for, and we do not use it to train generalized artificial intelligence or machine learning models.

12. How we handle Microsoft data

Outlook access is granted in two separate pieces, and you can hold either without the other. This is deliberate: some people want Mallin to read their calendar without giving it any access to their mailbox, and that is a supported choice rather than an all or nothing one.

  • What we access (Calendar): the Calendars.Read permission, on your own calendar. For each event we read the time, the title, who is invited, the meeting link if there is one, and whether it was cancelled. It is read only. Mallin cannot create, change or delete anything on your calendar. We deliberately do not request Calendars.ReadWrite, and we do not request access to calendars other people have shared with you.
  • What we access (Mail): the Mail.ReadWrite permission, which is what Microsoft requires in order to place a draft in your Drafts folder. We never request Mail.Send. Mallin cannot send email from your Outlook account under any circumstances. You press Send yourself, from your own mailbox.
  • Identity: the User.Read permission, used once to confirm which mailbox you connected so we can show it to you. We do not read your directory, your colleagues, or your organization's data.
  • How we use it: calendar data shows your upcoming meetings inside Mallin and prepares a briefing before a call with someone outside your company. Mail access places Mallin drafted emails into your Drafts folder for you to review. Nothing else.
  • How we store it: your Microsoft OAuth tokens are stored securely, encrypted at rest through our infrastructure providers, and used only for the actions described above. They are never sold, never shared with third parties, never used for advertising, and never used to train generalized artificial intelligence or machine learning models.
  • How to revoke: disconnect Outlook Mail or Outlook Calendar at any time from Settings, Integrations. Disconnecting one of them narrows what we are able to do and expires our access token immediately, so it stops working the moment you click rather than whenever it would have lapsed. Disconnecting the last one deletes our stored tokens altogether. Microsoft does not offer a way for an application to withdraw its own consent on your behalf, so to remove the grant entirely you or your administrator should also remove Mallin at myapplications.microsoft.com or from Enterprise applications in the Microsoft Entra admin center.

Administrator approval. Depending on your organization's settings, Microsoft may require an administrator to approve Mallin once for the whole company before anyone can connect. Approval is per permission: an administrator can approve calendar access without approving any mailbox access. Approval does not connect anyone automatically. Each person still chooses to connect their own account, and can disconnect it themselves at any time.

13. How we handle Zoom data

Connecting Zoom lets Mallin read the transcript Zoom already made of a call you recorded. It is read only in every respect: Mallin never joins a meeting, never places a recording bot in one, and cannot start, end, schedule, change or delete anything in your Zoom account.

  • What we access: the list of cloud recordings on your own Zoom user account (cloud_recording:read:list_user_recordings), the files belonging to those recordings so we can find the transcript (cloud_recording:read:list_recording_files), and your Zoom name, email address and account id (user:read:user) so we can show you which account is connected. We request no write permission of any kind, and we read only the account that authorized us.
  • How we use it: every thirty minutes Mallin asks Zoom which meetings you recorded in the last two days. When a recording has an audio transcript, we download that transcript and use it to build a deal record, a written brief of the call, and a coaching pass on the questions asked and missed. We download the transcript only — never the audio or the video.
  • What has to be true on your side: cloud recording is a paid Zoom feature, and the audio transcript setting is a separate switch under Settings, Recording, Advanced cloud recording settings. If either is off, Zoom produces no transcript, there is nothing for Mallin to read, and Mallin does nothing.
  • How we store it: your Zoom OAuth tokens are stored securely, encrypted at rest through our infrastructure providers, and used only for the actions described above. They are never sold, never shared with third parties, never used for advertising, and never used to train generalized artificial intelligence or machine learning models. Transcript content is stored against your workspace and is subject to the retention periods in section 5.
  • How to revoke: disconnect Zoom at any time from Settings, Integrations. Disconnecting revokes the grant with Zoom and deletes the tokens we store. You can also remove Mallin yourself in the Zoom App Marketplace, under Manage then Added Apps.

14. Contact

Privacy questions, requests, complaints: privacy@mallin.io.