Last updated: 5 October 2026
1. Who we are
This policy explains how Mestra Labs Pty Ltd (ABN 73 702 936 356) of Sydney, New South Wales, Australia ("Mestra", "we", "us") handles personal information. "Mestra by Thirty Oars" is our brand byline.
Mestra is a service for businesses. It turns an advertising master in Adobe InDesign, Figma or Canva into every format a campaign needs. This policy covers our website (withmestra.com), the web app (app.withmestra.com) and the Mestra apps for InDesign, Figma and Canva.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Questions? Email privacy@withmestra.com.
2. What we collect
Account information. Your name and email address. If you sign in with Google or Microsoft, the identifier that provider gives us for you. Your role in each organisation (owner, editor or viewer). Your sessions and app sign-ins: we store a scrambled form (a hash) of each token, never the token itself, together with your browser's user agent and the times it was used. When you connect a design app, we record the approximate location of the sign-in (country, and later city), worked out by our network provider from your connection, and include it in a security email to you. We don't store your IP address.
Organisation information. Your organisation's name and members. Your brands, formats, format sets, campaigns and campaign copy, and uploaded logos. When you sign up, the domain of your email address (for example example.com.au), or a note that it's a free-mail address.
Your content. When you run Mestra, our apps read the structure of your master: copy, fonts, positions, and image link names and paths. For a review, the app also sends a rendered image of the built format. Your content may include personal information if, for example, your copy names a person or an image shows one. If your organisation turns on the optional file library, we also store your exported files.
Usage information.
- Run records: who started a run, when, the brand, campaign and app used, and each format's status and flags. These hold no artwork or copy.
- A usage ledger: a record of each AI request (model, token counts, timing, outcome and cost), with no content.
- An audit log: sign-ins and changes, recording who did what and when. It never holds content, email addresses or tokens.
- Operational logs: request lines (method, path with sensitive parts removed, status and timing), with no content. Our app's logs don't record your IP address.
Sign-up and anti-abuse information.
- When you sign up, an automated check (Cloudflare Turnstile) confirms you're human, and we use your IP address for a short time to apply rate limits.
- To enforce one trial per domain, per email address and per card, we keep a keyed, one-way hash (an HMAC) of your work domain, your normalised email address and, if you add a card, the card's fingerprint from Stripe. We also keep an HMAC of the network your sign-up came from. These hashes don't show the domain, address, card or IP address in readable form.
Billing information (through Stripe). If your organisation subscribes or adds a card, Stripe collects the billing contact's name, email and address, any tax ID, and card details. Card details are entered only on Stripe's pages and never reach Mestra. We keep Stripe's reference numbers, your subscription status and the card-fingerprint hash described above. We never store a card number, its last four digits or its expiry date.
Support emails. If you email support@withmestra.com, privacy@withmestra.com or security@withmestra.com, we keep your email address, your message and our reply.
Website enquiries. If you use a form on our website (for example "Talk to us"), we collect your name, email address, company, role and message, and the country your request came from (worked out from your IP address, which we don't keep).
Website analytics. Our website uses Cloudflare Web Analytics, which counts visits and pages viewed without cookies and doesn't track you across other sites.
Cookies.
- The web app uses a session cookie to keep you signed in. It's first-party and essential: the app can't work without it.
- If you sign in with Google or Microsoft, a short-lived cookie keeps that sign-in secure.
- Cloudflare, which delivers and protects our app and website, sees your IP address when you connect. Its Turnstile check, on sign-up and on our website forms, may set its own cookie or storage for that check.
- The web app also keeps two small items in your browser's storage: the page to return to after you sign in, and which notices you've dismissed. Our design-app plugins keep a sign-in token in the app's own storage.
- We don't use advertising or cross-site tracking cookies.
We don't ask for sensitive information (such as health or political information) and you shouldn't put it into Mestra.
3. How we collect it
We collect personal information:
- from you, when you sign up, use Mestra, contact us or fill in a form on our website;
- from your organisation, when an owner invites you (they give us your email address and role) or a member starts runs that include your information;
- from the Mestra apps, which send us the structure of a master while a format is being built;
- automatically, through the session cookie, logs, the audit log and analytics;
- from Stripe, about the status of your payments and subscription;
- from Google or Microsoft, if you choose to sign in with them.
You can deal with us without giving your name only for general website enquiries. To use Mestra, we need your email address.
4. Why we use it
We use personal information to:
- provide Mestra: create accounts, sign you in, build and review formats, and deliver files;
- run your organisation: invites, roles, settings and the optional file library;
- run trials and bill for plans and overage, including through Stripe;
- enforce our trial rules and limits, and prevent fraud and abuse. Some of these checks are automated: for example, whether a domain, email address or card has already had a trial decides whether a new trial can start;
- keep Mestra secure, investigate incidents and keep the audit log;
- send service emails, such as sign-in links, trial reminders, billing notices, read-only and deletion warnings, and security notices;
- answer support requests and website enquiries;
- understand how Mestra and our website are used, mostly from counts with no content, so we can improve them;
- meet our legal obligations, such as tax records.
We don't sell personal information, and we don't use it for advertising.
If one person at your organisation's domain already has Mestra and you ask to join, we email that organisation's owners your name and email address so they can invite you. We never show you their names or addresses.
5. AI processing
Mestra uses an AI model to plan each format's layout and review the result. Our AI provider is Anthropic, PBC, and the processing happens in the United States. More detail is on our sub-processors page.
For each request we send:
- the composition read from your master: copy, fonts, positions, and image link names and paths;
- your format and brand settings;
- for a review, a rendered image of the built format.
What Mestra keeps. We don't store this working data, our prompts or the AI's replies after the request finishes.
What Anthropic keeps.
- Anthropic deletes API inputs and outputs within 30 days by default.
- Content flagged for a usage-policy breach may be kept for up to 2 years, and classification scores for up to 7 years, or longer where the law requires.
- Under Anthropic's commercial terms, customer content isn't used to train its models.
We don't claim zero data retention at our AI provider.
6. Who we share it with
We share personal information only as this policy describes.
Within your organisation. Members can see each other's names, email addresses and roles, and who started each run. Owners see billing details and usage.
Our sub-processors. These providers process personal information for us to run Mestra:
| Provider | What they do | Where |
|---|---|---|
| Fly.io, Inc. | Runs the Mestra application server; operational logs, kept 7 days | Server in Sydney, Australia. Log storage location not published: United States or elsewhere. |
| Neon, LLC (part of Databricks, Inc.) | Database: accounts, settings, logos, run records, usage, audit log | Sydney, Australia (AWS) |
| Cloudflare, Inc. | Network security and delivery, file storage (R2), website hosting and analytics, sign-up checks (Turnstile), and routing for our support, privacy and security email | Global network. File storage uses an Oceania location hint, which Cloudflare describes as best effort, not a guarantee. |
| Anthropic, PBC | AI layout planning and review (section 5) | United States |
| Postmark (AC PM LLC) | Sending service emails | United States |
| Stripe Payments Australia Pty Ltd | Payments, subscriptions, invoices and tax | United States and other countries |
Stripe. We use Stripe Payments Australia Pty Ltd and its affiliates to process subscription payments. For payment processing on our behalf, Stripe acts as our processor (service provider). Stripe also acts as an independent controller for its own purposes, including fraud prevention, regulatory compliance and product improvement, under the Stripe Privacy Policy.
The current list, with more detail, is at withmestra.com/trust/subprocessors. We give at least 30 days' notice before adding or replacing a sub-processor that handles customer data. To be told about changes, email privacy@withmestra.com.
Mailbox provider. Emails you send to our support, privacy and security addresses are delivered to our Microsoft 365 mailbox, which stores mail in Australia.
Others, only when needed.
- Professional advisers, such as lawyers and accountants, who must keep it confidential.
- Our AI provider (Anthropic), if we need to investigate possible misuse under its usage policy, sharing only what that investigation needs.
- Police, regulators or courts, where the law requires or allows it.
- A buyer or successor of all or part of our business, who must handle it under this policy.
7. Overseas disclosure
Some personal information is sent to, or stored by, providers outside Australia:
| Country | Who | What |
|---|---|---|
| United States | Anthropic | Your content during AI processing (section 5) |
| United States | Postmark | Your name and email address, and the content of service emails |
| United States and other countries | Stripe, and its affiliates and sub-processors | Billing contact details, tax ID and card details |
| United States and other countries | Cloudflare | Traffic as it passes through Cloudflare's global network; support email in transit |
| United States or elsewhere | Fly.io | Operational logs |
Our service and database run in Sydney, and stored files use an Oceania location hint. We choose providers with published security practices and data processing terms, and we take reasonable steps to make sure they handle personal information consistently with the APPs.
8. Storage and security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include:
- HTTPS for all traffic, and encrypted connections between our server and its providers;
- library files encrypted by us before they're stored, with a separate key for each organisation;
- storing only hashes of sign-in links, sessions and app tokens;
- every request limited to one organisation, with owner, editor and viewer roles;
- multi-factor authentication on our hosting and infrastructure accounts;
- support access limited to Mestra staff, time-limited, with a recorded reason, and visible to owners on the Activity page;
- an audit log that can't be edited.
More detail is on our trust site, withmestra.com/trust. Our security policies were adopted on 4 October 2026 and are available on request.
9. How long we keep it
| Information | How long |
|---|---|
| Working data sent by the apps (composition, plans, AI notes) | Not stored after the request finishes. Anthropic's retention is in section 5. |
| Account (name, email) | While you're a member of an organisation. Removing you from an organisation doesn't delete your account. Ask us to delete it, or it's deleted when you no longer belong to any organisation and the last one is deleted. |
| Sessions | Up to 30 days of use. Expired or revoked sessions are deleted 30 days later. |
| Sign-in links and app sign-in codes | Deleted 24 hours after use or expiry |
| App sign-ins | Expire after 90 days without use |
| Approximate location of a design-app sign-in | Up to 7 days, then deleted. A copy stays in the security email we sent you. |
| Organisation settings, campaign copy and logos | Until you delete them, or your organisation is deleted |
| Library files (optional, off by default) | 30, 90 or 365 days, as an owner chooses. Then deleted by an hourly clean-up. |
| Run records and usage ledger | For the life of your organisation. After deletion, the usage and billing ledgers are kept only as anonymous counts. |
| Audit log | 1 year |
| Operational logs | 7 days |
| Sign-up domain | Until your organisation is deleted |
| Trial hashes (domain, email, card, network) | Kept indefinitely, including after your organisation is deleted, to enforce one trial each. They don't show the underlying details in readable form. |
| Stripe event records | 30 days |
| Billing records at Stripe (customer and invoices) | Kept by Stripe after your organisation is deleted, for Australian tax records |
| Database backups | Up to 7 days after deletion |
| Stored files, as a safety net | No file is kept more than 400 days |
| Website enquiries | 12 months, or until the enquirer becomes a customer |
| Support emails | 2 years after the last contact |
When an organisation stops paying. If a trial ends without a subscription, a subscription ends, or an invoice is 14 days unpaid, the organisation becomes read-only. We keep its data for 60 days, and email its owners about 7 days before we delete it. Then we delete its brands, campaigns, formats, settings, logos, run records, library files, invites, app sign-ins and memberships, and any member who no longer belongs to an organisation.
10. Access and correction
You can ask to see the personal information we hold about you, or ask us to correct it, by emailing privacy@withmestra.com.
- You can update your own name in the app. Owners can change members' roles.
- We'll check your identity before we act.
- We don't charge for a request.
- We'll respond within a reasonable time. If we refuse, we'll tell you why in writing, unless that would be unreasonable, and how to complain.
11. Deletion and export
Deleting.
- Owners and editors can delete settings, logos and library files in the app at any time.
- Owners can remove members and revoke app sign-ins.
- To delete your own account, or your whole organisation sooner than the 60-day process in section 9, email privacy@withmestra.com. We'll confirm the request with an owner before deleting an organisation.
- We may keep information we need for tax, legal or security reasons, as section 9 describes.
Exporting.
- Your editable outputs stay in your design tool and folders.
- Library files can be downloaded one at a time or a run at a time as a zip.
- Brand, format and campaign settings can be read in the app or through the API.
- For a copy of your account or audit records, email privacy@withmestra.com.
12. Marketing
We only send emails about your account and the service. We don't send marketing emails unless you've opted in, and every marketing email will have an unsubscribe link.
13. Children
Mestra is a business service. It isn't directed at children, and users must be at least 18. We don't knowingly collect personal information from children. If you think we have, email privacy@withmestra.com and we'll delete it.
14. Complaints
If you have a complaint about how we've handled your personal information:
- Tell us first. Email privacy@withmestra.com with the details. We'll acknowledge it, look into it, and reply in writing within a reasonable time.
- If you're not satisfied, you can also contact the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, phone 1300 363 992.
15. Data breaches
We treat the Notifiable Data Breaches scheme in the Privacy Act as applying to us. If we suspect a data breach:
- we assess it promptly, within 30 days at most;
- if it's likely to cause serious harm, we notify the OAIC and the people affected as soon as practicable;
- we tell affected customers' owners without undue delay, and aim to do so within 72 hours of confirming an incident that affects their data, whether or not the law requires it;
- we post updates at status.withmestra.com where customers are affected.
To report a security issue, email security@withmestra.com.
16. Changes to this policy
We may update this policy, for example when our service or providers change. We'll post the new version here with a new date. If a change materially affects how we handle your personal information, we'll email organisation owners before it takes effect.
17. Contact
Mestra Labs Pty Ltd (ABN 73 702 936 356), Sydney NSW, Australia.
- Privacy: privacy@withmestra.com
- Security: security@withmestra.com
- Support: support@withmestra.com
Our service emails come from an address that doesn't accept replies, so please use the addresses above.