maestrly.

Privacy Policy

Last updated: September 7, 2026

Maestrly App is an open-source local desktop application. Its public privacy document describes the application’s data boundaries. This page also covers the website, voluntary contributions, and information you deliberately send to support.

1. Local application data

The app has no Maestrly account, hosted backend, license service, analytics, telemetry, automatic diagnostic upload, or automatic update channel. Workspaces, conversations, messages, settings, usage records, notes, and search metadata stay in the local profile and project files. Repositories and worktrees stay at their existing filesystem paths. Production, beta, and development profiles are separate; channels do not automatically import each other’s data.

2. Providers and network access

Selected AI providers and enabled integrations receive prompts and the context, attachments, tool information, and tool results approved for an operation. Authentication, retention, training choices, and processing locations follow the provider’s terms and your settings. Provider login does not create a Maestrly account.

Network access may also occur through Git hosts and GitHub operations, browser navigation and web fetch, configured remote MCP servers, model metadata from models.dev, skill searches, and explicit downloads of models, runtimes, skills, or editor components. A local MCP process can make its own network requests. Prepared local models execute locally; obtaining their assets can require internet access. Enabled ChatGPT Web uses an OpenAI tunnel client with a capability-protected loopback MCP bridge.

Providers, Git hosts, MCP services, registries, downloaded tools, and user-selected destinations apply their own privacy policies. Local storage does not mean that these third parties perform no processing. Review destinations and permissions before enabling them.

3. Credentials and diagnostics

App-managed persisted credentials are encrypted with Electron safeStorage using operating-system protection. If encryption is unavailable, persistence fails closed instead of falling back to plaintext. Provider CLIs, Git credential helpers, SSH agents, keychains, browsers, and remote services manage their own credential lifecycle outside the app database.

Diagnostics remain local unless you deliberately copy and share them. There is no automatic crash or log upload and no telemetry opt-in. Logs can contain sensitive metadata even with redaction. Before sharing, remove credentials, private paths, project names, conversation content, and identifying details; reproduce with synthetic data. The app does not add analytics to provider calls, but the providers still process their requests under their own policies.

4. Export, reset, and deletion

Use the in-app export before resetting if you need a recoverable copy. App-owned exports contain supported database state and app-owned assets with integrity metadata; they exclude credentials, repository/worktree files, search indexes, embeddings, and reproducible caches. An explicit reset preserves repositories and worktrees. Read the local data guide before moving profiles.

Removing the local profile removes app-owned state; it is not a secure-erasure guarantee for backups, snapshots, provider records, Git remotes, or operating-system credential stores. Manage those through their owning systems. There is no Maestrly account deletion request or grace period. Maintainers do not automatically receive local data and cannot export or delete your local profile through support.

5. Website, contributions, and contact

The website is separate from the desktop app. Vercel provides website hosting and can process request and operational data needed to deliver and protect the site under its own terms. The app’s lack of telemetry does not describe all website or third-party processing.

Optional contributions use Stripe, which processes payment-method and billing information under its privacy terms. Maestrly does not receive or store full card numbers or security codes. Limited contribution records, such as contact details, amount, currency, transaction identifiers, and recurring status, may be available for reconciliation, cancellation, refunds, and accounting. Contributions do not create a Maestrly app account or unlock features. See the Contribution & Refund Policy.

Historical Paddle payment and tax records may remain with Paddle and Maestrly for legally required periods. No new subscriptions are sold through Paddle. Canceling a contribution does not erase records required for accounting, tax, or disputes.

If you contact us or post to GitHub, the recipient processes what you send. Public issues and discussions are public. Share only sanitized information; use the confidential procedure in SECURITY.md for suspected vulnerabilities.

6. Rights, retention, and contact

For personal data actually held by the independent Maestrly operator in Brazil, such as correspondence and contribution records, contact privacy@maestrly.com to request access, correction, export, deletion, or other applicable rights. Applicable LGPD/GDPR rights and mandatory legal obligations remain in effect. This is not a channel for deleting a local app profile or provider account.

Processing depends on its purpose: handling requested correspondence or contributions, legitimate interests in website operation and security, legal accounting and tax obligations, and consent where required. Correspondence and transaction records are retained as needed for those purposes and applicable obligations. Providers and website or payment services set their own processing locations and retention; exercise rights over their records with them.

Policy changes are published here with an updated date. Questions: privacy@maestrly.com.