Privacy Policy

Last updated: June 5, 2026

1. What we collect

  • Account data: email, name, hashed password.
  • App data: app names, descriptions, product context, allowed domains.
  • Usage data: tutorial requests, anonymized session events, origin URLs.
  • Billing data: handled by our payment processor; we never store full card numbers.

2. How we use it

We use the data to provide the Service, generate tutorials, show analytics in your dashboard, and improve product quality. We do not sell personal data.

3. Sub-processors

We use Supabase (database/auth), Lovable AI Gateway (AI inference), Stripe (billing), and Cloudflare (edge hosting). Each is contractually bound to protect your data.

4. Cookies

We use strictly necessary cookies for authentication. No third-party advertising cookies.

5. Your rights (GDPR / CCPA)

You can request access, export, correction, or deletion of your personal data at any time by emailing privacy@mysia.app. We respond within 30 days.

6. Data retention

Analytics events are retained for up to 12 months. Account data is deleted within 30 days of account closure.

7. Security

Data is encrypted in transit (TLS) and at rest. API keys are hashed. Access to production data is restricted to authorized engineers.

8. Children

The Service is not directed at children under 16.

9. MYSIA Recorder browser extension

The MYSIA Recorder extension for Chrome has a single purpose: to record a workflow you perform on a web page and turn it into a help-center article.

  • What it captures: only while you have explicitly pressed Start recording, and only on the tab you started on — screenshots of the visible tab, the element you clicked (tag, role, accessible label, nearby text), the page title and URL, and text you type into non-password fields. Optional video mode records that same tab.
  • Where it is stored: recordings stay locally in the extension’s chrome.storage.local on your own device. Nothing leaves your browser automatically.
  • What is sent to MYSIA: only when you press Publish to MYSIA or export an AI-written article. The recording (steps and screenshots) is then sent over TLS to MYSIA’s API, authenticated with your API key, and processed by our AI provider to write step descriptions. It is stored against your workspace as a draft article.
  • What it never does: it does not run in the background, does not track your browsing, does not read pages you did not record, and does not sell, share, or use your data for advertising or for training third-party models.
  • Permissions: site access is requested at recording time for the site you are on; tabCapture is used only for video mode; downloads only for exports you trigger; storage only for your API key and local drafts.
  • Deleting data: delete individual drafts or use Clear all in the extension popup to erase local recordings, and delete published articles from your MYSIA dashboard. Uninstalling the extension removes all local data.

10. Changes

Material changes will be announced by email at least 14 days in advance.

11. Contact

Email privacy@mysia.app.