Privacy
A privacy policy is usually written to make collection sound harmless. This one is written to say what happens. The site collects nothing. The engagements collect what you send and nothing else. The lab’s own tooling reads accounts that belong to one person, and that section is the one worth reading.
Effective 28 August 2026.
01 / this site
No cookies, no analytics, no trackers.
This site sets no cookies and writes nothing to your browser’s storage. There is no analytics package, no tag manager, no advertising pixel, and no session recording. Nobody is counting you.
Two things do reach servers other than your own. Typefaces are served by Google Fonts, which receives the request your browser makes for them, including your IP address, under Google’s own terms. The site is hosted on Vercel, whose infrastructure keeps standard server logs of requests, including IP address and user agent, for operational and security purposes.
The forms do not post anywhere. Every form on this site opens a message in your own email client, addressed to the lab. Nothing is submitted to a server here, and no record of what you typed exists until you press send in your own mail application. If you close the message instead, the lab never sees it.
02 / enquiries and engagements
What you send, used for what you sent it for.
When you write to the lab, it holds your message and whatever you chose to put in it: your name, your email address, and the description of your product. That material is used to answer you and to scope the work you asked about. It is not added to a mailing list, not used for a sequence, and not passed to anyone for marketing.
If an engagement proceeds, the handling of your code, systems and documents is governed by the engagement letter you sign before access is granted, which is the document that controls confidentiality, scope and retention. Where that letter and this page differ, the letter governs.
Published work. The lab publishes teardowns of open-source and publicly available software. Client work is not published. Findings from a paid engagement appear in your report and nowhere else, unless you ask in writing for something to be shared.
Requests. Write to contact@mudhawilabs.com to ask what is held about you, to correct it, or to have it deleted, subject to any record the engagement letter or applicable law requires the lab to keep.
03 / connected accounts
The lab’s tooling reads one person’s accounts.
Mudhawi Labs operates private internal tooling, MUSA, which connects to Google accounts belonging to the lab’s founder in order to surface her own mail, calendar and files to her. It is single-operator tooling. It is not a product, it is not offered to clients or to the public, and no third party is invited to connect an account to it. If you are reading this because a Google consent screen sent you here, that screen was shown to the account owner authorising access to her own data.
What it reads.
Read-only access to Gmail messages and to Google Drive files, and the ability to create drafts. Access is limited to the scopes granted at consent and nothing wider.
What it cannot do.
It cannot send mail. Sending is disabled in the software itself, which refuses the request regardless of what the granted scope would permit. It does not delete mail or files.
Where it lives.
On a private server operated by the lab in Helsinki. Credentials are held on that host with file-level access restrictions and are not stored in the site, in any repository, or on any third-party platform.
Limited use.
Google user data obtained through these scopes is used only to provide features to the account owner. It is never sold, never transferred for advertising, credit assessment or resale, and never used to train generalised AI models. Use complies with the Google API Services User Data Policy, including its Limited Use requirements.
Model providers.
Content the operator asks the tooling to work on may be processed by third-party AI model providers through their APIs, under their commercial terms, solely to produce output for the operator. It is not contributed to model training.
Revoking it.
The account owner can withdraw access at any time at myaccount.google.com/permissions, which invalidates the stored credentials immediately.
04 / changes and contact
If this changes, the date changes.
This page is revised when the practice changes, not on a schedule. The effective date at the top is the date of the current version. Material changes to how connected-account data is handled are made here before they are made in the tooling.
Questions about anything on this page go to contact@mudhawilabs.com and are answered by a person.