Privacy Policy
Mafold (“we”, “us”) operates the Mafold chat application. This policy explains what we collect and how we use it.
Information we collect
- Account — the username and password you register with.
- Messages & content — the messages, images, and files you send, so we can deliver them to your conversations.
- Bots you create — their configuration and any credentials you choose to provide (stored encrypted).
- Device tokens — an Apple Push Notification token, used only to deliver notifications.
- Basic technical data — connection metadata needed to operate the service.
- Product usage events — coarse actions such as opening a product surface, completing onboarding, or successfully sending a message, plus automatic page navigation and interaction events such as clicks, form changes, and submissions. Element text and free-form attributes are masked; structural tags and CSS classes may be retained. These events do not include message or prompt content, form values, copied text, usernames, bot names, filenames, credentials, conversation identifiers, or full URLs and query strings.
How we use it
To operate and improve Mafold: authenticate you, deliver your messages, run the bots you configure, send notifications, and understand whether key product flows work. We do not sell your data or use it for advertising.
Sharing
We do not sell your personal data, and we do not share it with third parties except as required to run the service (e.g. Apple for push delivery) or to comply with the law.
Product analytics.We use PostHog to process the limited product usage events described above. After sign-in, PostHog receives a one-way hashed account identifier rather than your Mafold username. Automatic interaction and page navigation capture are enabled to support retrospective product analysis. Element text and free-form attributes are masked, and dynamic URLs are reduced to route templates. Session replay, console capture, and automatic error capture remain disabled. Our client also respects the browser’s Do Not Track preference.
AI assistants — what is sent, to whom, and only after you agree. We ask for your permission inside the app before any message is sent to an AI model, and nothing is sent until you tap Allow. The permission is asked separately for each assistant, and you can withdraw it at any time in Settings › Privacy; withdrawing stops any further sending immediately. This is enforced on our servers, not only in the interface — the model is not called without the permission.
What is sent. The text of the messages in that conversation — the conversation so far, not only your newest message, because a model needs the thread to answer it. In a group conversation that therefore includes messages written by other people in that group.
What is not sent. Your username, display name, email address, avatar, profile fields, password, device tokens and phone number are not sent to AI providers. Only the words in the conversation are.
Who receives it.For Mafold’s official assistants the provider is currently DeepSeek; some metered assistants route to Anthropic. For bots you create with your own API key, the recipient is the provider you configure (for example Anthropic or OpenAI) — we cannot name it for you, and the in-app notice says so rather than guessing. These providers process the messages only to return a response, under their own privacy terms, and we select providers that offer protections equivalent to those described in this policy.
Retention & deletion
We retain your data while your account is active. You can delete individual messages, bots, and conversations in the app at any time. You can also permanently delete your entire account and all associated datadirectly in the app: open Settings and tap “Delete Account”. This is immediate and cannot be undone. If you need help, contact support@mafold.com.
Security
Connections use TLS. Bot credentials are stored encrypted at rest.
Children
Mafold is not directed to children under 13.
Contact
Questions or deletion requests: support@mafold.com.