Privacy Policy
This policy describes what NativeMojo LLC ("we", "us") collects when you use Maestro — the maestromojo.com website, the Workspaces portal, the MCP server and API, and site hosting (the "Service") — and how we handle it.
1. What we collect
Account information
- Your email address (used for sign-in codes and notifications), display name, and optional avatar.
- Authentication artifacts: hashed API keys, session tokens, sign-in timestamps.
Content you store or publish
- Workspace content: boards, items, comments, documents, milestones, and knowledge entries.
- Code and repository content you choose to index, and the embeddings generated from it.
- Sites content you publish, which is public by design.
Usage information
- Service logs (requests, errors, IP addresses) and aggregate activity metrics (for example, items created and closed) used for features like board insights.
- Hosted-site analytics are cookieless and aggregate — they do not identify individual visitors to your sites.
2. How we use it
- To provide and operate the Service: hosting your workspaces, running AI features you invoke, sending sign-in codes and notifications you subscribe to.
- To process content through AI model providers (such as Amazon Bedrock) when you use features like semantic search, embeddings, or agent runs. We do not use your content to train our own models.
- To secure the Service: abuse detection, debugging, and audit trails.
- We do not sell your personal information.
3. Cookies and local storage
The portal stores your session token and interface preferences (theme, board view settings) in your browser's local storage. The marketing site sets no tracking cookies. Analytics for hosted sites are cookieless.
4. Sharing
- Workspace members see the content of workspaces they belong to; publicly published boards and sites are visible per the visibility you choose.
- Service providers process data on our behalf: cloud infrastructure and email delivery (Amazon Web Services), AI model inference (Amazon Bedrock), and SMS delivery where you use phone features.
- Legal: we may disclose information when required by law or to protect the Service and its users.
5. Retention and deletion
- Content you delete (including permanently deleted board items and their activity) is removed from the live database; residual copies in backups age out on our backup rotation.
- You may request account deletion at support@nativemojo.com; we will delete your account and associated personal information except where retention is required by law.
6. Security
All traffic is encrypted in transit (TLS). API keys are stored as one-way hashes. Access to production systems is restricted. No system is perfectly secure — use strong, unique credentials and rotate exposed keys immediately.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Contact us at support@nativemojo.com and we will honor applicable requests.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
9. Changes
We may update this policy; material changes will be announced on this page with an updated date above.
10. Contact
Privacy questions: support@nativemojo.com.