Privacy

Last updated to be completed — effective date

Published while still being completed. Every highlighted to be completed — like this line is a value only the operator of this service can supply, and each one is outstanding. Everything else on this page is accurate: it was written from the service's source code rather than adapted from a template, so what it describes is what the software actually does. Describing software accurately is not the same as legal advice, and this page has not yet been reviewed by a lawyer.

The short version

You sign in with GitHub. We read four things from your GitHub profile and ask for no OAuth scopes at all. Your organization's knowledge — its documents, decisions, records and run history — is stored by us, in Cloudflare, and mirrored to the GitHub repository you control. Questions you ask an agent, and the content it reads to answer them, are sent to Cloudflare's AI models. We do not sell anything, we run no analytics and we load no third-party scripts.

The part most services are vague about, stated plainly: today we mark records revoked rather than deleting them. There is no self-service account deletion. Section 8 says exactly what expires and what does not.

1. Who this is about

Mainmind is operated by to be completed — legal entity name, of to be completed — registered address ("we", "us"). This page covers mainmind.app, git.mainmind.app and the MCP connection your agents use.

If you were invited into someone else's Mainmind organization, that organization decides what goes into it and who may read it. We process that content on their instructions.

2. Signing in

Mainmind uses a GitHub App, and the same App handles both identity and repository access. It requests no OAuth scopes. What it may reach is governed by the permissions you grant when you install the App on a repository, which GitHub shows you at install time.

When you sign in we read four fields from your GitHub profile: your login, your numeric account id, your display name, and your avatar URL. We store them together with your GitHub access and refresh tokens in a server-side session that expires 30 days after sign-in. That deadline is absolute — using the service does not extend it. The session cookie in your browser holds only an opaque identifier; your GitHub token is never sent to your browser.

Separately, your GitHub login is recorded against your membership of an organization, so that the right person can be recognised on their next visit.

What we do not collect

3. Your organization's content, and where it actually lives

This is the section worth reading twice, because "your data stays in your repository" is a claim we cannot honestly make in that form.

CopyWhere it sitsWhat it is
Canonical historyMainmind Git, backed by Cloudflare R2 Once an organization's custody has been migrated to Mainmind, this is the authoritative copy and your GitHub repository becomes the mirror that we push to. Before migration, your GitHub repository is the source.
Reading projectionCloudflare D1 The full text of every document, so agents can read and search it quickly. It is derived and could be rebuilt from Git, but the text is genuinely stored there.
Search embeddingsCloudflare Vectorize Numeric vectors computed from your documents. The stored metadata is the workspace, path, kind and commit — not the text — but the vectors are derived from the text.
Member viewsMainmind Git / R2 A compiled per-person slice of the company file, reflecting what that member's role allows them to read.
Uploaded originalsCloudflare R2 Files you upload are kept byte-for-byte. Only a small manifest goes into Git, so Git alone is not a complete backup of them.

Alongside the documents, we store the working record that makes the product useful: the run ledger of what each agent did, decisions and their reasoning, notes, comments, work assignments and events. That record contains whatever your team and your agents wrote into it.

4. What is sent to AI models

All model inference runs on Cloudflare Workers AI. We do not call Anthropic's, OpenAI's or any other model vendor's API directly from the service; where a model has a familiar name, it is the copy Cloudflare hosts.

An agent you connect from outside — Claude Code, Cursor, Grok, Muse or any other MCP client — is a separate matter. What that client reads through your Mainmind connection goes to whoever runs it, under their terms, not ours. Revoking a connection stops future reads. It cannot recall what was already sent.

5. Credentials for services you connect

If you connect an outside service — Zoho, Shopify, Amazon's Selling Partner API, or any HTTPS endpoint you nominate — we hold the credential so that your agents can use it.

Each credential is encrypted with its own AES-256 key before it is stored; that key is itself wrapped under a root key held outside the database. The encryption is bound to the organization and capability it belongs to, so a stored credential cannot be decrypted in another organization's context even by us. If the root key is unavailable the service refuses to store the credential rather than storing it unprotected.

Credentials do not pass through the agent that asks for them: an agent can create an empty connection and a one-time link, which a person with authority opens to paste the value in. Replacing a credential is write-only — nothing is read back.

What is not separately encrypted beyond Cloudflare's own at-rest encryption: your document text, decisions, notes, run history, uploaded originals, Git objects, and the stored session that holds your GitHub token.

6. Logging

Cloudflare's Workers observability is switched on, which records request metadata and anything the service explicitly logs. The service logs three events. Two carry only an organization identifier and a commit. The third, when generating a plain-language view fails, records the title of the document it failed on. No document body, credential or personal profile field is written to logs.

7. Who else receives data

Always

Only if your organization chooses it

to be completed — whether a data-processing agreement is in place with Cloudflare and GitHub

We do not sell personal data and we do not share it for advertising.

8. How long we keep things

Stated honestly, including where the answer is unsatisfying.

These expire on their own

These do not

What revoking actually does

Revoking a member sets their status to revoked and stops their access. It does not erase their record. Rotating a machine credential invalidates the old one immediately; only a one-way digest of any credential is ever stored. Deleting a conversation with the assistant is a true deletion — at the time of writing it is the only one you can trigger yourself.

There is no self-service account deletion or organization deletion today. To request erasure, write to us at to be completed — an address for privacy requests and we will tell you what we can remove and what we cannot.

9. Your choices

to be completed — which privacy laws apply, and the lawful basis for each, once the entity and jurisdiction are settled

10. Security

Agents authenticate with OAuth 2.1 using PKCE; only the SHA-256 challenge method is accepted, and the weaker plain method is refused. Clients may register dynamically. Access is decided fresh on every operation from your current role, so changing or revoking a role takes effect immediately rather than at the next token refresh.

Invitation codes, machine credentials and session leases are stored only as one-way digests. The Git bridge refuses to return anything that looks like a GitHub token, and mirrored history is scanned for credential patterns.

No service is immune. If we discover a breach affecting your data we will tell you. to be completed — the breach-notification window we commit to

11. Changes

If we change this page in a way that materially affects you, we will say so on the updates page and date the change above.

12. Contact

to be completed — an address for privacy requests — to be completed — legal entity name, to be completed — registered address.