Privacy Policy
Last updated: September 9, 2026
1. Scope
This policy explains how MadoHub ("we", "our", or "us") collects, uses, retains, and protects data when you use the MadoHub apps for macOS, iPhone, and iPad, MadoHub Cloud, and the MadoHub website.
2. Information We Collect
We collect only the information needed to provide, secure, bill, and support MadoHub. Depending on the features you use, this may include:
- Account information — your email address, display name provided through a sign-in service, internal account identifier, password hash, email-verification status, and authentication records. We never store your plaintext password.
- Local application data — canvas layout, connections, local chat history, agent definitions, and Mac Companion data remain on your device unless you submit a task or choose a Cloud feature that transmits specific content. The current iPhone and iPad apps do not accept user-supplied AI provider API keys.
- Cloud content — prompts, relevant conversation context, task instructions, files, images, or audio you choose to include, and generated responses you send through MadoHub Cloud. We share only the content needed for the requested task with contracted model inference providers.
- Service, diagnostic, and usage records — account ID, request time, request category, processing route, token counts, request status, duration, IP address, user agent, Cloud runtime seconds, and Credit amount. We use these records for billing, abuse prevention, reliability, and support. These records do not contain ordinary prompt or response text.
- Purchase history — product ID, transaction or subscription identifier, environment, purchase status, and entitlement history from Apple or Stripe. We do not receive full payment-card details.
- Website analytics — page views, referrer, browser type, and approximate country/region through Google Analytics 4 and PostHog. Website analytics are not linked to your MadoHub account, prompts, file paths, or application workspace content.
3. How We Use Information
- Create and secure your account
- Deliver AI responses and operate remote Cloud Agents
- Calculate allowances, Credits, and Cloud runtime usage
- Validate purchases, subscriptions, restores, and refunds
- Prevent fraud, abuse, and unauthorized access
- Diagnose failures and keep the service reliable
- Send verification codes and critical account notices
We do not sell personal data, show third-party advertising, or use app data to track you across other companies' apps or websites.
4. Cloud Content
Before the first AI task is sent, the iPhone and iPad apps show the current AI-processing disclosure and ask for your explicit permission. If the disclosure cannot be loaded or you do not allow it, the task is not sent. You can withdraw permission in Settings; this blocks new AI tasks, although a task already accepted for processing may finish.
Every AI request submitted from the current iPhone and iPad apps goes through MadoHub Cloud. MadoHub may route a request, or fail it over when needed, among contracted model inference providers to generate the result. We do not identify a specific provider or model in this policy because that routing can change while the disclosed data categories and purposes remain the same.
To recover replies after a network interruption or when the app returns from the background, MadoHub temporarily stores encrypted requests (including prompts and context) and response events (including generated text and proposed actions) in Google Cloud. Recovery expires 24 hours after the request is created. Request content is cleared when processing ends; expired recovery content is removed by periodic cleanup. Prompt and response text is not stored in the Credit ledger. Model providers process task content under their applicable terms and retention policies; the 24-hour recovery window is not a provider retention guarantee.
Remote Cloud Agents exchange messages and events through an encrypted relay. Mac Companion can connect directly over a local network or through MadoHub Cloud when remote access is enabled. The remote connection relays commands, workspace state, and terminal content between your devices. Relay content is encrypted at rest, expires after 24 hours, and is removed by periodic cleanup.
5. Purchases and Subscriptions
Purchases made in the iPhone or iPad app are processed by Apple exclusively through In-App Purchase. The iOS app does not direct users to an external purchase method. Apple sends signed transaction and subscription status information so we can grant Credits and Cloud allowances, restore purchases, and process refunds.
Website and macOS purchase flows are processed by Stripe. Stripe stores payment-card details; we receive customer and transaction identifiers, purchase status, price, currency, and limited card metadata such as brand and last four digits when available.
Purchased Credits do not expire. Subscription allowances reset each paid billing period. You can manage or cancel MadoHub Pro through Apple subscription settings or the Stripe Customer Portal, depending on where you subscribed.
6. Storage and Retention
Account, entitlement, Credit, and Cloud usage records are stored in Google Cloud. Transactional emails are delivered through Resend. We retain account and purchase records while your account is active and as required for security, tax, accounting, fraud prevention, or legal compliance.
- Message recovery content: encrypted; recovery expires 24 hours after request creation, with expired content removed by periodic cleanup
- Cloud Agent and remote Mac Companion relay content: encrypted; expires after 24 hours and is removed by periodic cleanup
- Message execution identifiers, status, and request fingerprints may remain after recovery content is removed to prevent duplicate execution; these records do not contain the prompt or reply body
- Model provider retention: governed by the applicable provider terms and policies, separately from MadoHub recovery storage
- Linked request metadata, including IP and user agent: up to 30 days
- Product telemetry and uploaded client diagnostic logs: up to 30 days
- Infrastructure logs: retained under our Google Cloud log policy
- Local canvas and chat history: retained on your device until you delete it
7. Service Providers
- Google Cloud — Cloud API, database, encrypted relay, and remote agent runtime
- Contracted model inference providers — process the task content needed to generate requested outputs and may provide failover
- Apple — iOS and iPadOS distribution and In-App Purchase processing
- Stripe — website and macOS payment processing
- Resend — transactional email delivery
- Google Cloud and Cloudflare — website hosting, delivery, and network security
- Google Analytics 4 and PostHog — website analytics
8. Security
We use encryption in transit, encrypted storage for message recovery and relay content, restricted service accounts, hashed passwords, short-lived access tokens, rate limits, and production backups. No security measure is perfect, but we continuously reduce the amount of sensitive data we retain and limit access to it.
9. Your Choices and Rights
Depending on applicable law, you may:
- Access, correct, export, or delete personal data
- Object to or restrict certain processing
- Withdraw consent where processing relies on consent
- Manage or cancel subscriptions through the purchase provider
In the iPhone and iPad apps, you can review or withdraw AI data permission in Settings. Withdrawing permission blocks new AI tasks from being shared with model inference providers.
Email [email protected] to exercise a privacy right. We may need to verify your account before fulfilling the request.
10. International Processing
MadoHub and its service providers may process data outside your country. Where required, we use contractual and technical safeguards intended to protect data during international transfers.
11. Changes and Contact
We may update this policy as the product or law changes. We will post the revised date here and provide additional notice when a material change requires it. Questions can be sent to [email protected].