Trust

Sub-processors

Mestra Labs Pty Ltd, ABN 73 702 936 356. Last updated 4 October 2026.

These are the third parties that process customer data so that Mestra can run.

Sub-processors that handle customer data

VendorPurposeData processedLocationMore
Fly.io
(Fly.io, Inc.)
Runs the Mestra application serverRequest data while it's processed, including working data in memory. Operational logs, kept for 7 days (storage location not published by Fly.io).Sydney, AustraliaSecurity
Neon
(Neon, LLC)
Managed Postgres databaseAccounts, organisation settings, logos, run records, usage, audit log, sealed keysAWS ap-southeast-2, Sydney, AustraliaSecurity
Cloudflare
(Cloudflare, Inc.)
Edge TLS and rate limiting, tunnel to the app, R2 file storage, staff access control, DNS, support email routingAll traffic in transit. Library files at rest, always encrypted by Mestra first. Inbound support email.Global network. R2 uses an Oceania location hint (best effort, not a guarantee).Trust hub
Anthropic
(Anthropic, PBC)
AI layout planning and review (Claude API; currently Claude Opus 5.5)Composition read from your master (copy, fonts, positions, image link names and paths), format and brand settings, and preview images for reviewUnited States (inference)Trust, commercial terms
Postmark
(AC PM LLC)
Transactional email: sign-in links, invites and noticesRecipient name and email address, and the email content (links, organisation name)United StatesPrivacy
Stripe
(Stripe Payments Australia Pty Ltd)
Checkout, customer portal, subscriptions, invoices and tax.Billing contact, address and tax ID. Card details are entered only on Stripe-hosted pages.United States and other countriesSecurity
Microsoft 365
(Microsoft Corporation)
Support mailbox for support@, privacy@ and security@ emailSupport, privacy and security emails: the sender's address, the message and our repliesAustraliaTrust Center
Grafana Labs
(Raintank, Inc., trading as Grafana Labs) Planned
Operational log search and monitoring (Grafana Cloud). Not yet in use; we will give at least 30 days' notice before it starts.Operational logs only: request method, route, status and timing, IP addresses shortened to the network (not the full address), and service event types. No content, emails, tokens or headlines.Australia (Sydney)Security

Providers that don't process customer data

VendorPurposeData processedLocationMore
GitHub
(GitHub, Inc.)
Source code hosting and CISource code onlyUnited StatesSecurity
UptimeRobot
(UptimeRobot s.r.o.)
Uptime monitoring and the status pageNo customer data. It probes public health and sign-in endpoints.EU, with a secondary site in the United StatesSecurity

AI provider data use

Under Anthropic's commercial terms, customer content isn't used to train models. Anthropic deletes API inputs and outputs within 30 days by default. Content flagged for a usage-policy violation may be kept for up to 2 years (classification scores up to 7 years), or longer where the law requires. Mestra doesn't claim zero data retention.

This website

withmestra.com runs on Cloudflare Workers. Entries from the Talk to us form are stored in Cloudflare and emailed to us. Analytics use Cloudflare Web Analytics, without cookies.

Changes

We'll give at least 30 days' notice before adding or replacing a sub-processor. Organisation owners are emailed automatically, and anyone else can email privacy@withmestra.com to be added. Questions about any vendor are welcome there too. Service status is at status.withmestra.com.