Privacy Policy
Last updated: July 30, 2025Introduction
We at Mupler, Inc. (“Mupler”, “we” or “us” ) are strongly committed to respecting your privacy and safeguarding any information you share with us.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Mupler’s software, platform, and related tools, including our website at www.mupler.com, and all services designed to help legal professionals send, share, and manage secure client intake forms and data.
It also explains how you can access, update, or delete your personal information, and describes the data protection rights that may be available under your jurisdiction’s laws (such as CCPA, ABA, and GLBA).
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
Please note: This Privacy Policy does not apply where Mupler acts as a data processor on behalf of its customers. In such cases, the processing of personal data is governed by the applicable customer agreement.
💡 By accessing or using Mupler, you agree to the collection and use of information in accordance with this policy
1. Information We Collect
Mupler only collects the information necessary to operate the service and keep your data secure.
A. Information You or Your Clients Provide Directly
- 1Account InformationYour name, email address, and any contact details you provide when creating an account or requesting information about Mupler
- 2Billing InformationIf you subscribe to a paid plan, payment processing is handled by our third-party provider (Stripe). We do not store your full payment details on our servers
- 3Client SubmissionsWhen your clients fill out forms, their responses are securely stored in your account in encrypted form
- 4Support RequestsWhen you contact our support team, we collect the information you provide (name, email, request content) to respond effectively
- 5FeedbackAny suggestions, comments, or reviews you submit about Mupler may be stored with your account
- 6Trial Abuse Prevention IdentifiersWhen you register, we generate and store a secure, non-reversible cryptographic hash (SHA-256) of your email address. This unique identifier does not contain your plaintext email and is used solely to verify eligibility for free trial periods
B. Information We Collect Automatically
- 1Device InformationWe receive details about your device type, browser version, operating system, and network provider when you use Mupler
- 2Log DataWe collect your IP address, login date and time, account activity, and pages visited within the platform
- 3Usage PatternsWe track how you interact with Mupler, such as creating forms, uploading files, or changing settings, to improve performance
- 4Cookies & Similar TechnologiesWe use cookies to maintain secure sessions, enhance navigation, and analyze platform performance. We do not use cookies for advertising or tracking purposes
- 5Approximate LocationDetermined by your IP address and used only for account protection, such as detecting unusual login activity
C. Information We Do Not Collect
- 1Sensitive Categories of DataMupler does not process medical information (HIPAA), biometric identifiers, genetic data, or religious information
- 2Electronic SignaturesWe do not collect or process e-signatures. Mupler is designed for secure data collection only
- 3Data from MinorsMupler is not intended for individuals under 18. If we discover that a minor has created an account, we will delete the account and its data
2. How We Use Personal Data
We may use personal data for the following purposes:
- 1Providing and Maintaining the ServiceIncluding form creation, secure storage, document sharing, and optional features that improve user experience
- 2Account ManagementCreating, managing, and administering your account, processing payments, and responding to your inquiries
- 3Service ImprovementImproving and developing Mupler, conducting research, debugging, and identifying or repairing issues that impact functionality
- 4CommunicationSending service-related updates, important notices, or information about new features when necessary
- 5Security and CompliancePreventing, detecting, and investigating fraud, abuse, security incidents, and violations of our Terms of Service
- 6Legal ObligationsComplying with applicable laws, ethical obligations (including ABA Rule 1.6), and protecting the rights, safety, privacy, and property of our users, Mupler, or third parties
- 7Dispute ResolutionInvestigating and resolving disputes, security incidents, or compliance issues
By default, Mupler employees do not have access to the contents of your forms or client submissions. We do not access your data for any other purposes, including advertising, analytics, or marketing. Access is only allowed if:
- 1Support AuthorizationYou explicitly request support and authorize us to review specific form content
- 2Legal RequirementAccess is required to comply with legal obligations or court orders
💡 By default, Mupler employees do not have access to the contents of your forms or client submissions.
3. Data Security & Compliance
Mupler is designed with strict legal and ethical requirements in mind, ensuring full support for attorney–client confidentiality, financial privacy, and consumer data protection.
A. ABA Rule 1.6 — Attorney–Client Confidentiality
- 1EncryptionAll form data is encrypted in transit (SSL) and at rest to protect sensitive client information
- 2Access ControlAccess is restricted to authorized account users with proper credentials
- 3SafeguardsWe maintain administrative, technical, and physical measures to prevent unauthorized access or disclosure
💡 Mupler is built to support compliance with ABA Model Rule 1.6 and uphold attorney–client privilege
B. GLBA — Financial Data Protection
- 1Secure StorageIndustry-standard security measures safeguard financial and related sensitive data
- 2Role-Based PermissionsAccess to financial information is limited to authorized team members as defined by your account roles
- 3Continuous MonitoringOur systems are updated regularly to address security vulnerabilities and ensure compliance
C. CCPA — Consumer Privacy Rights
- 1Data AccessCalifornia users may request access to the personal information stored about them
- 2Data DeletionCalifornia users may request deletion of their personal data
- 3No Sale of DataMupler does not sell or share personal information with third parties for commercial gain
D. Sensitive Personal Information
Because immigration and related intake forms may include sensitive details, such as immigration or citizenship status, we treat this information with additional care and use it only to provide the Service. Where applicable law provides such a right, you may ask us to limit the use of this sensitive information.
E. Data Breach Notification
We maintain safeguards designed to protect your data. In the unlikely event of a security incident affecting your personal information, we will take appropriate steps to address it and provide any notifications required under applicable laws.
F. Service Providers & Data Storage
Mupler relies on trusted third-party providers for services such as cloud hosting, payment processing, and email delivery. These providers are expected to maintain appropriate confidentiality and security protections, and your data is stored on servers located in the United States.
4. Data Retention & Deletion
Mupler retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, security, dispute resolution, and enforcement of agreements. Retention periods may vary depending on the type of data, its sensitivity, and applicable legal requirements.
- 1User-Controlled DeletionYou may delete your account and all associated data at any time via account settings
- 2Legal & Compliance RetentionSome records may be retained as required by law, billing obligations, or dispute resolution
- 3Automatic Removal After 5 YearsClient records - including form responses and uploaded documents - are automatically and permanently deleted after 5 years of inactivity (measured from the last activity on the client’s forms). When data is no longer needed, it is deleted, erased, or anonymized in compliance with applicable laws
- 4Retention for Trial Abuse PreventionUpon account deletion, we permanently remove your plaintext email, forms, and client data. However, to protect our legitimate business interests and enforce our single-trial policy, we retain the non-reversible cryptographic hash (SHA-256) of your email address and any connected Stripe customer tokens. This information cannot be used to reconstruct your email or identify you personally
5. Your Rights & Choices
Your privacy matters to us. As a Mupler user, you control the data in your account. You can manage, export, or delete it at any time. Depending on where you live, you may also have additional rights under your state’s privacy laws, such as the right to access, correct, delete, or limit the use of your personal information.
- 1Access Your DataYou can view all stored forms, templates, and client submissions in your account dashboard.
- 2Export Your DataYou can export completed forms and submissions in PDF format, and download a machine-readable copy of all data stored in your account from your profile settings.
- 3Delete Your DataYou may delete your account and all associated data at any time through account settings or by contacting our support team.
- 4Update Account InformationYou can correct or update your account details (e.g., name, email) at any time.
To make any privacy-related requests, please contact us at [email protected]. We may request verification to ensure your account’s security.
6. Cookies
We use cookies strictly based on user consent. We use essential cookies to:
- 1Keep you securely signed into your account
- 2Maintain platform session security and detect unauthorized access
- 3Improve platform performance and user interface stability
You may manage your choices via our cookie consent banner. You may also disable cookies in your browser settings, but some features of the Service may stop working properly.
7. Jurisdiction-Specific Disclosures
Some laws may require us to provide additional disclosures about how we handle personal data for users in certain regions. While Mupler is designed to comply with U.S. privacy laws (including ABA Rule 1.6, CCPA, GLBA, and other applicable U.S. state privacy laws), the principles below apply to all users.
- 1Purpose of Data CollectionWe collect only the information needed to provide and secure the Mupler service, support account management, and maintain compliance with legal obligations
- 2Type of Data CollectedAccount details (name, email), form structures, and client submissions (stored securely in encrypted form). We do not access client content unless explicitly authorized for support
- 3Legal BasisWe process personal data based on contractual necessity, compliance with legal obligations, and legitimate interests related to providing, securing the Service, and preventing trial abuse
8. EU Data Protection (GDPR)
If any client of our legal professional users resides in the European Union, their personal data is subject to the EU General Data Protection Regulation (GDPR). Mupler acts as a data processor only upon instructions from the legal professional user and does not independently determine the purpose or means of processing.
- 1Data ProcessingMupler processes client data solely to provide the Service as instructed by the legal professional. Users may instruct Mupler to limit or restrict processing of EU client data at any time
- 2Data TransfersAny transfer of EU personal data to servers outside the EU, including the United States, is conducted in compliance with GDPR requirements, using Standard Contractual Clauses or other legally recognized safeguards
- 3Client RightsEU clients have the right to correct, delete, or restrict the processing of their personal data. Mupler assists legal professionals in fulfilling these requests only upon the user’s explicit instruction
- 4Data RetentionEU personal data is retained only for as long as necessary to provide the Service, comply with legal obligations, or resolve disputes. Once no longer required, data is deleted or fully anonymized. For account administrators, minimal pseudonymized identifiers (such as cryptographic hashes) may be retained strictly for fraud and trial abuse prevention under our legitimate business interests
- 5Support RequestsWe may assist legal professionals in fulfilling EU client data requests (access, correction, or deletion) only upon the user’s instruction
- 6Security MeasuresWe implement appropriate technical and organizational measures to protect EU personal data against unauthorized access, loss, or disclosure
9. Privacy Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or security practices. When we make updates, we will post the revised version and update the effective date at the top of this page. Continued use of Mupler after these changes indicates your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy, our security measures, or how your data is handled, please contact us at [email protected].
