1. What we collect
Your account. Email address, name if you give one, a password hash if you use one, and the identifiers of any external accounts (Google, GitHub) you sign in with. We never receive your password at those providers.
What you create. Everything you put into a workspace - products, decisions, documents, logs, tasks, integrations, and the settings around them.
How the service is used. Sign-in times and the IP address a session was created from, so you can see and revoke your own sessions. Records of what agents did through the API, kept under a retention and redaction policy you control per workspace.
Payment. We do not see or store your card. Paddle.com Market Ltd takes the payment and tells us that a subscription exists, which plan it is on, and its status.
2. Why we have it
To run the service you asked for - performing our contract with you. To keep it secure and to investigate abuse - our legitimate interest, and yours. To meet legal obligations, including tax records for a purchase. Where we ever rely on consent, you can withdraw it.
We do not sell your data, we do not run advertising, and we do not use your content to train models.
3. Who else processes it
- Paddle.com Market Ltd - payments, invoicing and tax.
- Resend - transactional email such as invitations. Only the address and the message.
- Our hosting provider - the servers and database the product runs on.
- Google and GitHub - only if you choose to sign in with them, and only to establish who you are.
The semantic search model runs on our own infrastructure. Your content is not sent to an external AI provider by the product.
4. Cookies
We set one cookie: the session cookie that keeps you signed in. There are no advertising cookies, no analytics cookies and no third-party trackers, which is why you are not being asked to accept anything.
5. How long we keep it
Your content stays until you delete it. Deleting a product archives it first, so it can be recovered; a purge may physically remove archived data after 180 days, and we warn before that happens.
Telemetry about agent activity follows the retention policy set for the workspace, which can be shortened or switched off. Records we must keep for tax or legal reasons are kept for as long as that requires.
6. Your rights
You can see and correct your data in the product. You can export a whole workspace at any time in a restorable format - this is built in, not a request you have to make. You can delete your account, which starts deletion of what it owns.
Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a data protection authority. Write to privacy@makermap.io and we will answer within 30 days.
7. Where the data is
The service runs on servers in Europe. Sub-processors listed above may process data elsewhere under their own safeguards.
8. Security
Passwords are hashed with argon2id. Stored credentials are encrypted with a key held outside the database, so a database dump alone does not reveal them. Access to production is limited to people who operate the service.
No system is perfectly secure. If a breach affects you, we will tell you.
9. Contact
Write to privacy@makermap.io.