When you authorize a data source, MAIA gets permission to search it — not to download everything in it.
How Connector Access Works
When you connect a source (Google Drive, Salesforce, Slack, etc.), you go through a standard OAuth authorization flow. You grant MAIA read-only access. MAIA receives an access token — a limited-permission key that lets it search and fetch relevant content.
MAIA uses key terms from your decision description to construct targeted search queries. If you're rehearsing a market expansion decision, MAIA searches for market analysis, competitive intelligence, and financial projections — not your team's vacation photos or unrelated files.
Data Handling
- Fetched content is cached for a maximum of 24 hours, then permanently deleted
- Before any fetched content enters the rehearsal pipeline, MAIA's compliance scan screens it for personally identifiable information, protected health information, and material non-public information
- Flagged content is excluded and never reaches the analysis — it is discarded immediately
- All connector data follows the same Zero Data Retention policy as everything else in MAIA
Revoking Access
You can disconnect a source at any time. When you disconnect:
- MAIA's access token is deleted
- Any cached content from that source expires within 24 hours (or sooner if the session closes)
- You can also revoke access from the source itself (e.g., Google Account → Security → Third-party apps)
What MAIA Does NOT Do
- MAIA never writes to, modifies, or deletes anything in your connected sources
- MAIA never downloads your entire Drive, CRM, or inbox
- MAIA never shares fetched content across sessions or accounts