Privacy Policy
Last updated:
This Privacy Policy explains how Maito ("we," "us," or "our") handles information when you use our website, web, desktop, and mobile applications, hosted services, and related features.
Maito connects clients to environments where conversations, files, credentials, and agent workflows are managed. How information is processed depends on whether you run your own environment, use a managed environment, and which providers and tools you connect.
About us
Maito is operated by MaitoAI, LLC, a Delaware limited liability company with an address at 1111b South Governors Ave STE 25502, Dover, DE 19904, United States. Contact us at support@maito.app.
Information we collect and process
We process information needed to operate Maito, secure accounts, run agent workflows, and support connected services.
- Account information, such as your name, email address, authentication identifiers, organization and workspace membership, invitations, and login activity.
- Workspace and agent data, such as prompts, conversations, outputs, code, files, repository data, documents, knowledge, memory, skills, task history, schedules, checkpoints, and attachments you provide or authorize an agent to access.
- Connection information, such as provider and integration identifiers, permission scopes, repository or channel metadata, authorization credentials, API keys, and secrets needed to act on your instructions.
- Billing information, such as subscriptions, invoices, credit purchases, usage totals, payment-related identifiers, and tax information. Payment card details are handled by our payment provider and are not stored by Maito.
- Technical and security information, such as IP addresses, device and browser details, connection metadata, logs, error traces, cookies, timestamps, and abuse-detection signals.
- Product analytics, where enabled, including feature usage, model choices, workflow outcomes, and pseudonymous identifiers.
- Support communications and feedback you send to us.
Self-hosted and managed environments
In a self-hosted environment, workspace data and credentials are primarily stored on the infrastructure you or your organization control. Running a local environment does not automatically upload all workspace content to us. Account services, remote connection services, optional analytics, and connected providers may still process information needed for those features.
In a managed environment, workspace data and credentials are processed on infrastructure operated for the Service by us and our hosting providers. Your organization's administrators control membership and access. Other authorized members may be able to access shared conversations, files, and workflow history according to their permissions.
Remote and relay connections transmit data between your client and environment. Information available to a connected client depends on its permissions and the environment's configuration.
How we use information
We use information to provide, maintain, secure, and improve the Service.
- Create and authenticate accounts, manage workspaces, and administer access.
- Connect clients to environments and operate managed hosting and remote access.
- Run agent tasks, process conversations and files, maintain workspace knowledge and history, and execute workflows at your instruction.
- Connect AI providers, repositories, Slack, MCP servers, and other authorized tools.
- Process billing, measure usage, enforce plan limits, and provide support.
- Monitor reliability, investigate suspicious activity, prevent abuse, and debug errors.
- Understand feature usage and improve clients, integrations, documentation, and workflows.
AI providers and connected tools
When you use an AI provider or connected tool, relevant prompts, context, code, files, outputs, account identifiers, and instructions may be sent to that service to complete your request. Agents may retrieve data from or send data to connected services using the permissions you grant.
Those services have their own terms, privacy policies, retention rules, and AI training practices. Your provider account settings and agreements may affect how they process information. Review those policies before sending sensitive information or enabling an integration.
Disconnecting an integration stops future authorized access through that connection, but does not automatically delete information already sent to a third party. Requests to delete that information may need to be made directly to the provider.
Product analytics
Where enabled, Maito sends product analytics such as feature counts, model choices, task outcomes, and connection or secret counts. Product analytics exclude prompts, messages, code, repository URLs, file paths, skill and tool names, and credential values. Analytics identifiers are pseudonymous; signed-in accounts may be recognized across their environments.
Environment administrators can disable product analytics by setting MAITO_TELEMETRY_ENABLED=false. Development environments do not send product analytics by default. Disabling product analytics does not disable information needed for account services, billing, security, or service operation.
Service providers and other disclosures
We share information with vendors that help provide authentication, payments, hosting, storage, networking, monitoring, analytics, security, email, and support. They may process information as needed to provide their services or as otherwise permitted by law.
We may also disclose information when required by law, to protect rights and safety, to investigate abuse, to enforce agreements, or as part of a merger, financing, acquisition, reorganization, or sale of assets.
No sale of personal information
We do not sell personal information. We do not use customer prompts, conversations, code, files, or credentials to train our own AI models. Connected AI providers process information under their own policies and your agreements with them.
Data storage and retention
Self-hosted data is stored wherever you operate your environment. Managed services and our vendors may process information in the United States and other countries where they operate. Privacy protections may differ from those in your country.
We retain information as needed to provide the Service, comply with legal obligations, resolve disputes, maintain backups, prevent abuse, and support security and billing records. Deleting a managed environment or ending paid access may permanently remove its files and backups; export information you need beforehand.
You may delete certain information through the Service or request deletion by contacting support. Backups, legal obligations, security needs, and billing records may require some information to be retained. We cannot delete data stored solely on infrastructure you control or information independently retained by connected providers.
Security
We use reasonable technical and organizational safeguards, including access controls, credential protection, and encryption in transit for hosted services. No internet service is perfectly secure. You are responsible for protecting your devices, credentials, self-hosted environments, and connected accounts, and for configuring access and permissions appropriately.
Cookies and local storage
We use cookies, local storage, and similar technologies for authentication, security, preferences, saved connections, and essential functionality. Analytics and operational tools may also process usage information. Browser controls can limit these technologies, but blocking essential storage may prevent parts of Maito from working.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export personal information, withdraw consent where processing relies on consent, or complain to a relevant supervisory authority. Send requests to support@maito.app. We may need to verify your identity and may limit a request where permitted by law.
For data controlled by your organization or a self-hosted environment administrator, contact that organization or administrator. You can manage connected services and permissions through Maito and the relevant provider's settings.
Children
Maito is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Do Not Track
Because browser Do Not Track signals do not have a consistent industry standard, we do not currently respond to them in a uniform way.
Changes
We may update this Privacy Policy from time to time. If we make material changes, we may notify you through the Service, by email, or by updating the date on this page. The revised policy applies from its effective date, subject to applicable law.
Contact
Questions or privacy requests can be sent to support@maito.app or mailed to MaitoAI, LLC, a Delaware limited liability company with an address at 1111b South Governors Ave STE 25502, Dover, DE 19904, United States.