This Privacy Policy describes how MAIA Decision OS ("MAIA," "we," "us") collects, uses, and protects information when you use our service.
1. Information We Collect
Account information: Email address, hashed password, payment information (processed by Stripe — we do not store card numbers).
Passkey credentials: Public key and credential metadata for biometric login. Private keys never leave your device.
Usage metadata: Session timestamps, rehearsal counts, and purchase transactions. We do not log decision content, uploaded document content, or rehearsal outputs.
2. Information We Do NOT Collect
Decision content: What you describe, upload, or discuss during a rehearsal is processed in memory only and never stored persistently.
Document content: Files you upload are extracted in Worker memory, used for the active session, and discarded. No file content is written to any database, object store, or log.
Rehearsal outputs: Decision Briefs, risk registers, dependency maps, and Visual Intelligence Packages are generated in your session and delivered to you. We do not retain copies.
3. Zero Data Retention (ZDR)
MAIA enforces Zero Data Retention for all rehearsal data:
- Documents processed in memory only — never written to persistent storage
- All session data purged on session close
- 24-hour hard TTL — sessions auto-expire regardless of close event
- No logging of document content, filenames, or extracted text
- Compliance audit logs record flag events only — never the flagged content itself
For six industries (Financial Services, Healthcare, Life Sciences, Energy, Manufacturing, Defense), ZDR is mandatory and cannot be loosened.
4. Third-Party Services
Stripe: Payment processing. Stripe's privacy policy governs payment data.
Anthropic (Claude): AI inference. MAIA sends decision context to Claude's API for analysis. Anthropic does not train on API inputs. See Anthropic's Privacy Policy.
Cloudflare: Infrastructure hosting. Session data resides in Cloudflare Durable Objects with TTL-based auto-expiry.
Resend: Transactional email (verification, welcome). Email addresses only — no decision content.
5. Data Connectors
When you connect external data sources (Salesforce, Google Drive, Slack, etc.), MAIA fetches data using read-only OAuth tokens scoped to the minimum required permissions. Connector data is processed in the active session and subject to the same ZDR policy — no persistent storage of fetched content.
6. Your Rights
You may request account deletion at any time by contacting [email protected]. Because MAIA does not retain rehearsal data, there is no decision content to delete — it was never stored.
7. Contact
Privacy questions: [email protected]
Last updated: March 2026