Legal
Privacy Policy
Last updated: September 5, 2026
The short version
We collect the minimum we need to run MAINS — your email, your account, and the content you create. We don't sell your data. We don't train AI models on it. Your content lives in your private vault — MAINS staff do not read or access it except where required by a valid legal order. When you direct MAINS to send your prompts to Claude, ChatGPT, Gemini, or Grok, those providers receive what you sent them — that's how the Service works. Where you have not supplied your own key for a participant, we dispatch on our provider accounts rather than yours; see section 4. You can export or delete your data at any time.
1. Who we are
MAINS (“we,” “us”) operates the multi-AI orchestration platform at mains-ai.app. Contact us at hello@mains-ai.app for any privacy question.
2. What we collect
We collect three categories of information:
- Account data — your email address, authentication tokens, and any profile information you provide.
- Your content — the scope cards, threads, prompts, decisions, and AI responses you create while using MAINS. This content is stored in your private vault. MAINS staff do not read, review, or access it in the course of normal operations. The sole exception is a valid legal order (such as a court order or formal law enforcement request), in which case we will notify you in advance wherever the law permits us to do so.
- Usage and device data — IP address, browser type, pages visited, and basic interaction events. We use this for security, debugging, and improving the Service.
3. Why we collect it
- To create and authenticate your account
- To deliver the Service — store your projects, route your prompts to AI providers, return responses
- To bill you for paid plans (if you upgrade)
- To send essential account email (security alerts, billing receipts, important policy changes)
- To detect and prevent fraud, abuse, and security incidents
- To comply with our legal obligations
We rely on the legal bases of contract performance, legitimate interest, and your consent — depending on the activity and your jurisdiction.
4. AI providers and your prompts
MAINS sends your prompt to the AI providers you select — Claude (Anthropic), ChatGPT (OpenAI), Gemini (Google), Grok (xAI). Where the response is then kept depends on where you asked. In a thread, it is stored in your project vault. In MAINS Council, it is not: the transcript lives in your own browser on the device you had the conversation on, and we store no prompt or reply from it at all — not even when the round runs on our keys. Those providers are independent data processors with their own privacy policies and data handling practices. We encourage you to read theirs:
There are three ways a prompt reaches a provider. Two questions separate them: whose account it travels on, and whether it passes through our servers on the way.
- Your key, saved to this device. Used by MAINS Council. Your browser calls the provider directly, so the key and the prompt never reach our servers at all, and provider terms apply between you and them.
- Your key, saved to your MAINS account. Used by threads, Klaustrum and Deep Research, which run server-side. We read the key back from storage and make the call for you, so your prompt does pass through our servers — but it reaches the provider on your account, under your terms with them, and the usage is billed to you.
- Our keys (pooled). Within free-tier allowances, and anywhere you have not supplied a key of your own, we dispatch from MAINS's own provider accounts. Your prompt reaches the provider under our contract with them rather than yours, and is handled under the terms of those accounts.
When you enable Web Browsing on a thread, the AI participants you dispatch also receive a coarse, IP-derived approximate location (city/region/country and timezone) so they can answer “local” questions like weather or the current time without you typing your location every time. This is the same kind of approximate location any website can infer from your network connection — not GPS, not precise tracking. It's sent only to the AI providers you've dispatched on that thread, the same way your prompts are, and is never stored separately from that request.
5. Service providers we use
We use a small number of vetted infrastructure providers to run the Service. They process data on our behalf under contract:
- Google Firebase — authentication, database (Firestore), and hosting
- Netlify — site delivery and edge functions
- Fastmail — receives email you send to hello@mains-ai.app
- LemonSqueezy (when paid plans launch) — payment processing and checkout
6. What we don't do
- We don't sell your personal data
- We don't use Your Content to train any AI models
- We don't read, review, or access the content of your vault (except where required by a valid legal order — see Section 2)
- We don't share Your Content with anyone other than the providers you direct
- We don't use third-party advertising or marketing tracking on the platform
7. How long we keep data
We keep account data and Your Content for as long as your account is active. If you delete your account, we delete or anonymize your data within 30 days, except where we're required to retain it for legal, tax, or security reasons (typically up to 7 years for billing records).
Backups roll off on a 30-day cycle.
8. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and your data
- Export Your Content in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on it
- Lodge a complaint with your local data protection authority
Email hello@mains-ai.app to exercise any of these rights. We'll respond within 30 days.
9. Security
We use industry-standard measures to protect your data — encryption in transit (TLS) and at rest, access controls, and regular review of our infrastructure. No system is perfectly secure; if we discover a breach that affects your data, we'll notify you and the relevant authorities as required by law.
10. Cookies and similar technologies
We use a small number of strictly necessary cookies to keep you logged in, remember your preferences, and protect against abuse. We don't use advertising or analytics cookies that follow you across sites.
11. International data transfers
MAINS infrastructure runs on providers with global data centers. Your data may be transferred to and processed in countries other than your own, including the United States. Where required, we rely on Standard Contractual Clauses or equivalent safeguards approved by your jurisdiction's regulator.
12. Children
MAINS is not intended for children under 16. We don't knowingly collect data from anyone under that age. If you believe a child has provided us with personal data, email hello@mains-ai.app and we'll delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or in-app notice at least 14 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
14. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
© 2026 MAINS. All rights reserved.
See also our Terms of Service.
