Privacy Policy
Last updated: 2026-08-10 · v3
This policy explains what data Maegor collects when you use the website and the product (the AI-agent-assisted development platform, including the Builder and the ADE), what it is used for, and who it is shared with. Who operates the Service today, and the state of that entity's formalization, is described in Section 1 of the Terms of Use.
1. Data categories
Account data: name, email, and authentication credentials (including sign-in via OAuth providers, when you choose that option).
Billing data: Stripe identifiers, plan, subscription status, and invoice history. Maegor never receives the full card number.
Service and technical data: IP address, browser type, session identifiers, credit consumption metrics, task duration, model used, errors, and other diagnostic data collected automatically to operate and protect the Service.
Customer Content: prompts, instructions, source code, repositories, files, database schemas, documents, and other material you intentionally provide to agents to run a task. It is handled differently from the data above, as Section 6 explains.
2. How we use data
Account, billing, service, and technical data: authenticate your account, orchestrate AI agents, charge credits, keep the history of your missions and projects, answer questions, notify you of service changes, detect abuse, and prevent fraud.
Customer Content: processed solely to run the task you asked for (generating, reviewing, or testing code, for example). We do not use Customer Content to train Maegor's own models, or for any purpose other than running your task and supporting the Service.
3. Legal bases for processing
Performance of a contract: account creation, running agents, projects, and billing.
Legitimate interests: security, fraud prevention, service reliability, and limited aggregate product analytics.
Compliance with a legal obligation: tax and accounting records, judicial orders.
Consent: where specifically required, such as certain optional cookies or marketing communications, should those come to exist.
4. Maegor's role under the LGPD
For account, billing, service, and technical data, Maegor generally acts as controller: it decides how and why that data is processed.
When Maegor processes personal data contained in Customer Content on behalf of a customer, Maegor generally acts as operator ("processor"), handling that data only per that customer's instructions.
In limited circumstances, Maegor may act as controller for information derived from use of the Service where necessary for security, fraud prevention, abuse detection, billing, legal compliance, and operation of the platform.
5. AI providers and subprocessors
Maegor does not sell your data. We share data only with service providers (subprocessors) needed to operate the product, each under its own data-protection obligations. The current list, what each one processes, and each AI provider's data practices (including training) are on the Subprocessors page.
One point that belongs here, not only in that list: tasks processed through Anthropic's and OpenAI's commercial APIs are not used by those providers to train their models. DeepSeek is different and may use the content it processes to train its own. If Maegor's router sends your task to DeepSeek, that provider's data-use terms apply to that specific task.
We may also disclose data when required by law or to protect the rights, safety, or property of Maegor and its users.
6. International data transfers
Most of the subprocessors listed on the Subprocessors page operate outside Brazil, including DeepSeek, whose servers are located in China. That means your data may be transferred internationally to be processed.
These transfers rely on the mechanism available for each provider under Chapter V of the LGPD (an adequacy decision, ANPD standard contractual clauses, or equivalent contractual safeguards), varying by provider and jurisdiction.
We are reviewing, provider by provider, as Maegor formalizes its data processing agreements (DPAs), whether each one already has the right mechanism in place. Where that review is not yet complete, treat that provider's status as pending, not confirmed.
7. Retention and deletion
We keep account and usage data while your account is active. After account closure, Customer Content is scheduled for deletion from Maegor's active systems following the 30-day export window described in the Terms of Use.
Residual copies may remain temporarily in backups and disaster-recovery systems and are deleted according to those systems' normal retention cycle. Certain records may be kept longer where required for legal, tax, security, fraud-prevention, or dispute-resolution purposes (for example, billing records).
8. Cookies and similar technologies
We use cookies and local storage that are essential to keep your session authenticated and remember preferences like language and theme. We do not use third-party advertising trackers.
9. Your rights
Depending on applicable law, you may have the right to: confirm whether we process your data; access it; correct incomplete or inaccurate data; request anonymization, blocking, or deletion where applicable; request portability; obtain information about who your data was shared with; withdraw consent where processing relies on it; and lodge a complaint with the applicable data-protection authority (the ANPD, in Brazil). To exercise any of these, contact us through the channel below.
10. Security
We use reasonable technical and organizational measures to protect your data, including encryption in transit, sandboxed isolation for generated code execution, and credential-based access control. No system is entirely risk-free, and we will communicate relevant incidents where required by law.
This policy, and the security responsibility it describes for Maegor, cover data while processed on Maegor's own infrastructure. Protection of data you process in software you build and deploy using the Service, once it leaves Maegor's infrastructure, is your responsibility, as detailed in the Terms of Use.
11. Children
The product is not directed at anyone under 18. If we learn that we have collected personal data from a minor in violation of applicable law, we will take appropriate steps to delete it.
12. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated by email or an in-product notice before they take effect.
13. Contact
Questions about this policy or your data: founder@maegor.com.