Data controller
The MAIT Team is currently operated by an individual, not a registered company — under GDPR Art. 4(7), a natural person is a valid data controller, and no legal entity formation is required for that role. This is a free, pre-incorporation initiative.
Contact email: privacy@mait.sh
Because of our current size, we do not have a formal Data Protection Officer, an EU representative, or a written Art. 30 record of processing activities. A DPO becomes required if our processing ever crosses into large-scale monitoring or special-category data (Art. 37(1)(b)/(c)). An EU representative (Art. 27) is required only for controllers with no EU establishment — as an individual operating from Italy, that does not describe us. The Art. 30 record exemption (Art. 30(5)) applies to controllers under 250 employees whose processing is occasional and low-risk; it lifts the moment our processing becomes regular or high-risk, at which point we will build that record even though it is not itself published here.
What data we collect
Everything listed here is data we actually store or process today, described specifically rather than in the broadest terms a policy could get away with.
When you sign in
- Email address — received from your identity provider (Google, GitHub, or Microsoft) when you sign in.
- Display name, and where the provider supplies them, your first and last name.
- Account identifier — the unique identifier your identity provider uses for you, plus the name of the provider itself. This is how we recognize you on your next sign-in.
- Sign-in activity — the time you last signed in and how many times you have signed in, counted both for your account as a whole and separately for each identity provider you have linked.
When you use your account
- Your preferences — your diagnostics choice, whether you have agreed to be emailed about your account, the date and time that email choice last changed, whether you have expressed interest in supporting or contributing to MAIT, and your click-tracking choice (see below for what this controls, and its current status).
- Licenses and entitlements — the product licenses and feature entitlements issued to your account, and their history. These are stored against your MAIT account identifier; our licensing service holds no name or email address at all.
- Service audit records — a record of the operations our own services perform on your account (for example "account created", "preferences updated", "account deleted"): the event name, which internal service made the request, your MAIT account identifier, your identity-provider account identifier, whether the operation succeeded, a short fixed error message if it did not, and when. We do not write your email address or your name into these records.
- Update checks, downloads, and license renewal — the MAIT command-line tools (the CLI, the aidcx launcher, and related tools) check for updates and renew your license certificate as a background part of running other commands, not only when you explicitly ask them to. This is strictly necessary to deliver the releases and license validity your account is entitled to, so we do not ask for separate consent for it. Each of these checks sends us the operation, the product, the version you are running, your MAIT account identifier, and a hashed identifier for the machine making the request — a one-way hash of your computer's hostname, not a randomly generated per-install token. We treat this hashed identifier as personal data, an "online identifier" that can be linked to the account it authenticates against, and cover it under the same rights and retention framework as any other personal data on this page. As of this writing this happens for nearly every command in these tools, with one exception:
aidcx doctoris local-only and sends nothing. We do not currently offer a way to turn this off. This happens in the tools, not on this website, and contains no name or email address. - Account activation — the first time you activate the command-line tools, they print a web address containing that same machine identifier for you to open in your browser to finish activation. Opening it sends the identifier to this website, where it can appear in our access logs.
- Faster package installs — if you use our optional package acceleration feature, usage statistics (which tool, which version, which platform, whether it was found) are recorded in aggregate and are not linked to your account or your machine. If a request is rejected because your license does not cover it, that rejection is logged against your MAIT account identifier so we can investigate access problems; a successful request is not.
Usage and error diagnostics in your browser
- Where diagnostics are enabled, our own telemetry agent (Grafana Faro, running on our infrastructure and sending only to our own servers) collects: the pages and in-app views you visit and their full URLs, page-performance measurements, JavaScript errors including their stack traces, browser console messages at information, warning, and error level, timings of the network requests the page makes, reports your browser makes when a page breaks our content-security rules, your browser and operating system and their user-agent string, your browser language, your window size, and a session identifier that lasts only as long as the browser tab. Separately, we have decided to also record which button you clicked for a short, fixed list of actions — starting sign-in, and the "Join waitlist" button on our homepage — nothing else about your on-page activity. Built, merged, and reviewed as of August 20, 2026, but not yet running on any channel; this section will be updated the moment it deploys. It can only ever happen for a visitor who has separately accepted diagnostics above — accepting diagnostics does not, by itself, opt you into this too; you get a separate say. We built that opt-out before turning click tracking on, not after; see our cookie policy for the full detail, or use the control below.
- None of this is sampled down. Where diagnostics are on, we collect every event, on every page, including this one.
- Before anything leaves your browser we strip the authorization codes and tokens that can appear in sign-in URLs. We do not filter free-form error and console text beyond that, which is one reason this data is kept for days rather than months.
- When you are signed in and have left diagnostics on, this data is linked to your MAIT account identifier — an opaque identifier that is not derived from your name or email, and is never sent alongside them. When you are signed out it is not linked to any account.
- Diagnostics are on unless you turn them off, and only a signed-in visitor can turn them off, from the account page. If you are not signed in there is no opt-out control for this data on the site today; blocking this site's scripts in your browser is the only way to stop the collection. We consider that a gap, not a design choice. (The separate click-tracking capability mentioned above does have an anonymous-visitor opt-out already — the two are independent, and this gap is specifically about the diagnostics described in this section.)
- Decided and built, not yet deployed: we have changed this. Before Faro loads on any page, everyone — signed in or not — is asked to accept or decline, replacing the opt-out default above with a real, upfront choice, built by extending our existing cookie banner. This is merged into our codebase but not yet running on any channel; until it is deployed, the two bullets above describe what visitors actually experience today.
- Diagnostics run across our Edge, Beta, and Stable channels alike; this is not limited to a single preview channel.
Both diagnostics and click-tracking are web-portal-only choices, and this page does not duplicate their controls. Change either on our cookie policy page (works for every visitor, signed in or not), or — if you are signed in — from an additional, advanced override on your account page.
Connection data
- IP address — as with any website, our servers see your IP address while your browser is connected to them. It is written to two request logs: the sign-in component in front of the site, and, separately, our edge proxy's own access log. It is not stored in your account record, we do not store it as part of your diagnostics data, and we do not currently use it to work out where you are. Both logs are deleted after 7 days.
What we do not collect
- We do not run advertising, marketing, or third-party analytics of any kind. There is no Google Analytics, no tag manager, no advertising pixel, and no third-party tracker anywhere in this site.
- We do not sell or rent personal data, and we do not use your data to build a profile of you or to make automated decisions about you.
- We do not use session recording or screen replay, and we do not attempt to identify you across other websites.
What we deliberately do not do
Because this page exists to be checked, not only read, here is what we verified is not true about our tools, alongside what is:
- No hardware fingerprinting. The only device identifier the tools use is the hashed hostname described above — no processor, disk, or motherboard serial number, no network hardware address, and no separate randomly generated identity file.
- No tracking via your software's version string. The identification string our tools send with every request states only the tool name and its version — nothing about your machine or operating system.
- The public install script sends nothing. Downloading and running our published one-line installer does not send any identifier; it only downloads the installer itself.
- "doctor" is not a send-us-your-logs feature. Our built-in diagnostic commands print their findings to your own screen. They do not assemble, save, or upload a report anywhere.
- Your license is tied to your account, not to your machine. The certificate itself carries no machine identifier, so it works on any machine you copy it to — the hashed machine identifier described above is a separate signal, not something your license depends on.
- No crash-reporting or analytics service is built into any of our tools. We checked; there is none.
- Your code and prompts stay yours. Nothing in our command-line tools sends your source code, files, or AI-assistant prompts to us or to any AI provider. The commands that print an AI briefing do so entirely from information already on your machine, offline.
- Our developer tools do not contact destinations of our own choosing. The tools we provide for browser automation, container management, and infrastructure access make outbound connections only to the destinations you configure or direct them to.
- Browser-automation session data stays on your machine by default. When our tools drive a browser for you, anything captured — cookies, saved page state, screenshots, recordings — is written to your own machine and cleaned up when the session ends. This describes the default, locally-launched mode; an advanced networked mode we also ship makes that data reachable over the network if you choose to expose it, which is a deployment choice, not a default.
Remote access sessions
If you use our remote-access tooling to connect to another machine, here is what that involves.
- We cannot see your session. The connection between the two ends is end-to-end encrypted using keys generated only on the two connecting machines; our relay server forwards the encrypted traffic between them without inspecting it, and has no way to decrypt it even in principle.
- We do not keep a record of your session. While a session is active, our relay briefly holds your MAIT account identifier and a temporary session identifier in memory, purely to connect the two ends to each other. This is discarded the moment the session ends; nothing about it is written to a database or kept afterwards. As of this pass, the temporary session identifier is also no longer written to our operational logs during session setup — an earlier gap, where it was, has been closed.
- If you record a session, you are responsible for who else is in it. Our tools let you optionally record a remote-access session; that recording is written only to your own machine and is never sent to us. If the machine or room you are recording includes other people who are not MAIT customers, obtaining their consent and respecting their own privacy is your responsibility as the person making the recording, not ours — we have no visibility into, and no control over, a recording that never reaches us.
Why we collect it (purposes and legal basis)
- Sign-in, your account, and your licenses — to provide the service you asked for. Contract performance (Art. 6(1)(b) GDPR).
- Service audit records — to keep the service secure, to investigate problems, and to be able to prove what was done to an account and when, including proving that a deletion request was carried out. Legitimate interest (Art. 6(1)(f) GDPR).
- Update checks, downloads, and license renewal — to deliver the releases and license validity your account is entitled to, and to know which versions are in use so we can keep supporting them. Contract performance (Art. 6(1)(b) GDPR) for the delivery, legitimate interest (Art. 6(1)(f) GDPR) for the record we keep of it.
- Usage and error diagnostics — to find and fix faults and to understand which parts of the product are used. Legitimate interest (Art. 6(1)(f) GDPR). Diagnostics are on by default; if you are signed in you can turn them off at any time from your account page without giving a reason. We have moved this to Consent (Art. 6(1)(a) GDPR), with a real accept/reject choice offered before diagnostics run for everyone — built, merged into our codebase, and not yet running on any channel.
- Click tracking — Consent (Art. 6(1)(a) GDPR): it rides on the diagnostics accept/reject decision above, not a separate one — it can never run for a visitor who has not accepted diagnostics, so accepting diagnostics is the operative consent. Accepting diagnostics does not, by itself, opt you into this as well; a further, separate opt-out is available and honored either way. Built, merged into our codebase, and not yet running on any channel.
- Emails about your account and licenses — Legitimate interest (Art. 6(1)(f) GDPR), scoped to MAIT's own product and service notices only — never third-party or broader "related products" marketing. On by default; you can turn it off at any time from your account page. We do not send any email yet, so this setting has no effect today — it only records your preference for when sending starts. Once it does, every message will carry a real, one-click unsubscribe.
How we store and protect your data
- Your name and email address are encrypted in our customer database with AES-256-GCM. Each record gets its own encryption key, generated fresh and wrapped by a separate key-encryption key that we can rotate without re-encrypting every record; the wrapping key is supplied to the service at runtime and never stored in the database, so a copy of the database on its own does not reveal them. Each record is cryptographically bound to its own account identifier, so an encrypted record cannot be moved onto another account.
- Your email is also stored as a keyed hash (a "blind index"), so we can look your account up by email address without keeping a readable copy for that purpose.
- Not everything is encrypted. Your identity-provider account identifiers, your sign-in counts and timestamps, your preferences and consent record, and the service audit records are stored unencrypted, in the same database file as the encrypted fields. They are protected by the access controls below, not by encryption.
- Access between our own services requires a client certificate. The service that holds your personal data is not a public website: every request to it must present a certificate issued by our own certificate authority and carrying the specific permission for the operation being attempted, and network rules restrict which of our services may reach it at all. That certificate is verified against our own certificate authority on every request, and travels only over network paths restricted to the specific services authorized to use them — an appropriate safeguard, given the low sensitivity of what it carries, for this internal hop. The certificate your account uses identifies you by your MAIT account identifier, lists the entitlements it grants, and reflects where your account sits within your organization's account structure with us, if it is part of one (an internal, business-facing structural identifier, not itself a personal-data disclosure); certificates used by our own operations staff and automation are separate and carry no personal data.
- Servers are in the EU — Hetzner Online GmbH. The machines that run the service and hold your data are in Falkenstein, Germany; some supporting infrastructure storage is in Helsinki, Finland.
- Diagnostics stay on our own infrastructure. Browser diagnostics are sent to a collector we run ourselves, and are stored in our own Grafana Loki and Tempo instances on the same EU infrastructure. They are not sent to Grafana Labs or to any other third party.
What stays on your own machine
Some of what the command-line tools use lives only on your own computer, and we would rather tell you where than leave you to wonder. None of the following is ever sent to us; it answers the practical question of what is still on your disk if you stop using the tools.
- Your license credential — a file containing your account identifier and the entitlements it grants, stored readable only by you. Renewing it leaves the previous copy on disk alongside the new one; we do not currently clean these up automatically.
- Sign-in credentials for optional third-party integrations — if you connect one of our tools to an external service on your behalf, the access token for that connection, and in some cases a saved browser sign-in session for that service, are stored locally, readable only by you, until you disconnect it.
- An activity log — our development-container tool keeps a local, append-only record of the commands it runs on your behalf, so you can review what it did. It is readable only by you, is not sent anywhere, and currently has no automatic size limit or expiry.
- The AI development environment can reuse your other AI tools' sign-in state. If you turn on that specific feature, our development-container tool makes the configuration and sign-in state of AI coding assistants already installed on your machine (for example Claude Code, Cursor, or similar tools) available inside the container it creates for you, so you do not have to sign in again inside it. This is a local file-sharing setting between two things running on your own computer; nothing is sent to us, and it only ever shares the specific tool-configuration folders involved, never your whole home folder.
- Uninstalling removes the software but not your account's server-side state. Uninstalling the tools deletes what is on your machine; it does not itself notify us, so your license certificate and the records described above remain valid and unchanged until they naturally expire or you delete your account (see "What deleting your account actually removes" below).
Who we share your data with
- Google LLC — Identity provider (OAuth login). Acts as an independent controller for authentication data. Data transferred to the US under the EU-US Data Privacy Framework. Governed by Google's Privacy Policy.
- GitHub, Inc. — Identity provider (OAuth login). Acts as an independent controller for authentication data. When you sign in with GitHub we also ask GitHub's API for your profile name. Data transferred to the US under the EU-US Data Privacy Framework. Governed by GitHub's Privacy Statement.
- Microsoft Corporation — Identity provider (OAuth login via Microsoft Entra ID). Acts as an independent controller for authentication data. Data transferred to the US under the EU-US Data Privacy Framework. Governed by Microsoft's Privacy Statement.
- Hetzner Online GmbH — Infrastructure provider and data processor (EU, Germany and Finland). Data Processing Agreement in place per Art. 28 GDPR, available at hetzner.com/AV/DPA_en.pdf.
- We share your data with no other third parties. In particular, your diagnostics data is not shared with anyone — we host the collection and storage software ourselves.
When you sign in, your identity provider necessarily learns that you signed in to mait.sh, and we ask it only for the sign-in identity itself: your identifier, your email address, and your basic profile name. We do not request access to your documents, contacts, repositories, or mailbox.
How long we keep your data
- Account data (your encrypted name and email, linked identities, sign-in counts, preferences and consent record) — kept until you delete your account. Deletion happens immediately when you use the button on this page; there is no soft-delete and no recovery window.
- Usage and error diagnostics — 7 days, then automatically deleted. This is enforced by the retention settings of the systems that store them.
- Server and application logs — 7 days. Everything our servers and sign-in components write to their logs is collected centrally and deleted on that schedule, including any log line that happens to contain your IP address or your account identifier.
- Operational metrics about our infrastructure — up to 7 days, and sooner if the metrics store reaches its size limit first.
- Service audit records, update checks, and downloads — records that identify you or your machine are deleted after 7 days, the same as the other records above. They exist to show what was done to an account and when, including proof that a deletion was carried out. They contain your account identifiers and timestamps, and no name or email address. Two things are kept permanently instead of being deleted: a day-by-day count of downloads by product, version, and platform, which contains no information about who downloaded them and is what lets us understand how the product is used over time; and, in our update-check service, the record that a product or release was taken down, kept as a permanent administrative trail of what was removed and when.
- Backups — we do not currently run scheduled backups of the customer database, so a deletion is not shadowed by an older copy waiting to be restored. If that ever changes, this policy will say so and will state how long a backup is kept.
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of your data. Your account page shows your email address, your name, which identity providers are linked, and your preferences. It does not show everything: for your sign-in counts, your licenses, and your audit records, email us and we will send them to you. There is no self-service export yet, so this is a manual process on our side.
- Right to rectification (Art. 16) — correct inaccurate data. Your name and email come from your identity provider; correcting them there and signing in again updates them here. Email us if that does not resolve it.
- Right to erasure (Art. 17) — delete your account and data. You can use the "Delete my account and data" button on this page when logged in, or contact us. See the next section for exactly what that removes.
- Right to restriction (Art. 18) — have us stop processing your data while a dispute about its accuracy or lawfulness is settled. Email us; we handle this by hand.
- Right to data portability (Art. 20) — receive your data in a structured, commonly used format. We do this on request by email; there is no self-service download yet.
- Right to object (Art. 21) — object to processing based on legitimate interest. For diagnostics, the "Share anonymous usage and error diagnostics" switch on your account page is that objection, and it takes effect immediately for your browser activity on this site (we have moved this to a consent model instead — see "Why we collect it" above — built and merged, not yet running on any channel). For the update-check and license-renewal traffic sent by the command-line tools described above, this is strictly necessary to deliver your releases and license validity, so we do not currently offer a way to opt out of it. For anything else, email us.
- Right to withdraw consent — you can withdraw consent at any time without affecting the lawfulness of prior processing. The email-consent toggle on your account page is the withdrawal mechanism for that consent.
What deleting your account actually removes
We would rather be exact about this than reassuring. Using the "Delete my account and data" button:
- Removes immediately: your encrypted name and email, the hash used to look you up by email, every identity provider linked to your account together with its sign-in counts and timestamps, and your preferences and consent record. After this, looking your account up by identifier, by email, or by provider returns nothing.
- Also removes: your customer record in our licensing service, and with it your licenses, the certificates issued to you, your activation codes and their renewal history. This is requested as part of the deletion but does not block it: if that service is briefly unavailable, the rest of the deletion still completes and those licensing records are left behind. Nothing retries automatically, so email us if you want them confirmed gone. Certificates already installed on your machines are not revoked; they stop resolving to an account.
- Kept: the service audit records described above — including a new record showing that your account was deleted — and the activation and renewal audit records from our licensing service, which also carry the hashed machine identifier described above. These hold your MAIT account identifier and, in the service audit records, the account identifier your identity provider gave us. They hold no name or email address, and once your account record is gone nothing in our systems maps those identifiers to a person. They are not irreversibly anonymous, though: if you sign in again with the same identity provider, the provider identifier in those older records is the same one, and the machine identifier in the licensing records is the same one on any machine you continue using. Ask us and we will delete them too.
- Two things deletion does not currently reach, stated plainly rather than glossed over: our update-check service keeps its own separate audit records of your downloads and update checks, and deleting your account does not remove those — they are a distinct system from the licensing records described above, and ask us if you want them removed too. Separately, uninstalling the command-line tools from a machine (see "What stays on your own machine" above) does not itself tell us anything — deleting your account is the only way to stop that machine's traffic being associated with you going forward.
- Not undoable: there is no recovery window. Signing in again afterwards creates a new, empty account.
If you want us to confirm in writing that a deletion completed, email us.
How to exercise your rights
- Email: privacy@mait.sh
- Use the "Delete my account and data" button on this page when logged in.
- Turn diagnostics or account emails on or off yourself from your account page. The two controls are "Share anonymous usage and error diagnostics" and "Email me about my account and licences".
Right to complain
You have the right to lodge a complaint with the Italian Data Protection Authority: Garante per la protezione dei dati personali, www.garanteprivacy.it.
You may also complain to the supervisory authority in the EU or EEA country where you live or work (Art. 77 GDPR).
International transfers
Authentication via Google, GitHub, and Microsoft involves data transfer to the US. All three providers participate in the EU-US Data Privacy Framework, which ensures an adequate level of data protection as recognized by the European Commission. These providers act as independent controllers for the authentication data they process — no separate Data Processing Agreement is required for OAuth login.
All other data processing — storage, encryption, licensing, and diagnostics — occurs exclusively within the EU on Hetzner infrastructure in Germany and Finland, governed by a Data Processing Agreement per Art. 28 GDPR.
Cookies and browser storage
We use cookies and browser storage that are strictly necessary to sign you in and to remember a few choices you have made, plus one short-lived entry used by the diagnostics described above. We set no advertising or third-party tracking cookies. For the full list, see our cookie policy.
Changes
We may update this policy from time to time. The updated version will be posted on this page, with the date below revised to match.
Last updated
August 20, 2026