Privacy
Last updated to be completed — effective date
The short version
You sign in with GitHub. We read four things from your GitHub profile and ask for no OAuth scopes at all. Your organization's knowledge — its documents, decisions, records and run history — is stored by us, in Cloudflare, and mirrored to the GitHub repository you control. Questions you ask an agent, and the content it reads to answer them, are sent to Cloudflare's AI models. We do not sell anything, we run no analytics and we load no third-party scripts.
The part most services are vague about, stated plainly: today we mark records revoked rather than deleting them. There is no self-service account deletion. Section 8 says exactly what expires and what does not.
1. Who this is about
Mainmind is operated by to be completed — legal entity name, of
to be completed — registered address ("we", "us"). This page covers
mainmind.app, git.mainmind.app and the MCP connection your
agents use.
If you were invited into someone else's Mainmind organization, that organization decides what goes into it and who may read it. We process that content on their instructions.
2. Signing in
Mainmind uses a GitHub App, and the same App handles both identity and repository access. It requests no OAuth scopes. What it may reach is governed by the permissions you grant when you install the App on a repository, which GitHub shows you at install time.
When you sign in we read four fields from your GitHub profile: your login, your numeric account id, your display name, and your avatar URL. We store them together with your GitHub access and refresh tokens in a server-side session that expires 30 days after sign-in. That deadline is absolute — using the service does not extend it. The session cookie in your browser holds only an opaque identifier; your GitHub token is never sent to your browser.
Separately, your GitHub login is recorded against your membership of an organization, so that the right person can be recognised on their next visit.
What we do not collect
- No email address. There is no place in the product that
asks for one. Addresses of the form
you@members.mainmind.appthat appear in your Git history are synthetic commit-author addresses derived from your member name; they are not mailboxes and we do not send to them. - No IP addresses. The service does not read the connecting IP address anywhere. Cloudflare, which runs the network in front of us, keeps its own edge logs under its own policy.
- No analytics, no tracking pixels, no third-party scripts. Fonts are served from our own domain. There is no advertising identifier and nothing to opt out of.
3. Your organization's content, and where it actually lives
This is the section worth reading twice, because "your data stays in your repository" is a claim we cannot honestly make in that form.
| Copy | Where it sits | What it is |
|---|---|---|
| Canonical history | Mainmind Git, backed by Cloudflare R2 | Once an organization's custody has been migrated to Mainmind, this is the authoritative copy and your GitHub repository becomes the mirror that we push to. Before migration, your GitHub repository is the source. |
| Reading projection | Cloudflare D1 | The full text of every document, so agents can read and search it quickly. It is derived and could be rebuilt from Git, but the text is genuinely stored there. |
| Search embeddings | Cloudflare Vectorize | Numeric vectors computed from your documents. The stored metadata is the workspace, path, kind and commit — not the text — but the vectors are derived from the text. |
| Member views | Mainmind Git / R2 | A compiled per-person slice of the company file, reflecting what that member's role allows them to read. |
| Uploaded originals | Cloudflare R2 | Files you upload are kept byte-for-byte. Only a small manifest goes into Git, so Git alone is not a complete backup of them. |
Alongside the documents, we store the working record that makes the product useful: the run ledger of what each agent did, decisions and their reasoning, notes, comments, work assignments and events. That record contains whatever your team and your agents wrote into it.
4. What is sent to AI models
All model inference runs on Cloudflare Workers AI. We do not call Anthropic's, OpenAI's or any other model vendor's API directly from the service; where a model has a familiar name, it is the copy Cloudflare hosts.
- Asking an agent a question sends your question and the company-file content needed to answer it to a Cloudflare-hosted model.
- Plain-language views of a document send that document to a Cloudflare-hosted model.
- Search sends document text for embedding, and your query for embedding and reranking.
- Voice: while the microphone control is on, the audio your device captures — including silence — is streamed to Cloudflare for turn detection and transcription. We do not save raw or generated audio, and the provider's own transcript store is switched off. The transcribed question and the answer are saved in your conversation.
- Uploaded PDFs and images are converted to text by a Cloudflare service.
An agent you connect from outside — Claude Code, Cursor, Grok, Muse or any other MCP client — is a separate matter. What that client reads through your Mainmind connection goes to whoever runs it, under their terms, not ours. Revoking a connection stops future reads. It cannot recall what was already sent.
5. Credentials for services you connect
If you connect an outside service — Zoho, Shopify, Amazon's Selling Partner API, or any HTTPS endpoint you nominate — we hold the credential so that your agents can use it.
Each credential is encrypted with its own AES-256 key before it is stored; that key is itself wrapped under a root key held outside the database. The encryption is bound to the organization and capability it belongs to, so a stored credential cannot be decrypted in another organization's context even by us. If the root key is unavailable the service refuses to store the credential rather than storing it unprotected.
Credentials do not pass through the agent that asks for them: an agent can create an empty connection and a one-time link, which a person with authority opens to paste the value in. Replacing a credential is write-only — nothing is read back.
What is not separately encrypted beyond Cloudflare's own at-rest encryption: your document text, decisions, notes, run history, uploaded originals, Git objects, and the stored session that holds your GitHub token.
6. Logging
Cloudflare's Workers observability is switched on, which records request metadata and anything the service explicitly logs. The service logs three events. Two carry only an organization identifier and a commit. The third, when generating a plain-language view fails, records the title of the document it failed on. No document body, credential or personal profile field is written to logs.
7. Who else receives data
Always
- Cloudflare — hosting, database, object storage, key-value storage, containers, search vectors and all AI inference. Cloudflare chooses which of its locations runs the service.
- GitHub — your company-file repository. We commit to it
under your member display name and a synthetic member address, with a message
naming the run and the member. Product feedback you send through the
feedbacktool opens a private issue on our own repository; that issue carries your free-text message but not your organization or your identity.
Only if your organization chooses it
- Zoho, Shopify, Amazon Selling Partner API, and any HTTPS endpoint you install as a connection. We pass requests to them on your agents' behalf.
to be completed — whether a data-processing agreement is in place with Cloudflare and GitHub
We do not sell personal data and we do not share it for advertising.
8. How long we keep things
Stated honestly, including where the answer is unsatisfying.
These expire on their own
- Browser sessions: 30 days from sign-in, absolute.
- Agent access tokens: 1 hour. Refresh tokens: 30 days.
- Invitations: 7 days. Machine enrolment tokens: 15 minutes.
- Conversations with the assistant, their turns and their usage counters: 30 days, then permanently deleted.
- Partial upload fragments: cleared hourly.
These do not
- Membership records, including the display name and GitHub login of a person whose access has been revoked.
- The run ledger, decisions, notes, comments, events and work records.
- Documents and their history, in Git and in the reading projection.
- Uploaded originals. A failed extraction never removes a saved original.
- Revoked connections, which are kept as the audit record of what was once connected. The stored credential of a revoked connection is retained in encrypted form.
What revoking actually does
Revoking a member sets their status to revoked and stops their access. It does not erase their record. Rotating a machine credential invalidates the old one immediately; only a one-way digest of any credential is ever stored. Deleting a conversation with the assistant is a true deletion — at the time of writing it is the only one you can trigger yourself.
There is no self-service account deletion or organization deletion today. To request erasure, write to us at to be completed — an address for privacy requests and we will tell you what we can remove and what we cannot.
9. Your choices
- Take your content with you. The company file is a Git repository of plain Markdown. You can clone it, and your uploaded originals can be exported. See export options.
- Disconnect an agent at any time from the client you connected it with, or by revoking the member.
- Remove our GitHub App from a repository in GitHub's own settings; we unbind it when GitHub tells us.
- Ask us anything about your data at to be completed — an address for privacy requests.
to be completed — which privacy laws apply, and the lawful basis for each, once the entity and jurisdiction are settled
10. Security
Agents authenticate with OAuth 2.1 using PKCE; only the SHA-256 challenge method is accepted, and the weaker plain method is refused. Clients may register dynamically. Access is decided fresh on every operation from your current role, so changing or revoking a role takes effect immediately rather than at the next token refresh.
Invitation codes, machine credentials and session leases are stored only as one-way digests. The Git bridge refuses to return anything that looks like a GitHub token, and mirrored history is scanned for credential patterns.
No service is immune. If we discover a breach affecting your data we will tell you. to be completed — the breach-notification window we commit to
11. Changes
If we change this page in a way that materially affects you, we will say so on the updates page and date the change above.
12. Contact
to be completed — an address for privacy requests — to be completed — legal entity name, to be completed — registered address.