Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how Maestrly ("Maestrly", "we", "us"), an independent product operated from Brazil, collects, uses and protects personal data when you use the Maestrly desktop application and website. We follow Brazil's LGPD and the EU's GDPR where applicable.
Local-first by design
Third-party AI coding tools and their credentials run and are stored locally on your machine. Your source code, prompts and agent responses are not sent to our servers.
1. Who is the data controller
The data controller is the operator of Maestrly. For privacy requests or questions, contact privacy@maestrly.com.
2. What data we collect
| Data | Why |
|---|---|
| Account data — email, name, avatar and provider account ID from Google or GitHub sign-in | To create, authenticate and protect your account |
| Service data — device identifier, app version, platform, release channel and legal-acceptance records | To operate the desktop service, updates and account lifecycle |
| Optional contribution records — contact details, amount, currency, transaction or recurring-contribution status, processed by Stripe | To process, reconcile, cancel or refund voluntary contributions and meet accounting obligations |
| Basic technical and security data | Fraud prevention, abuse prevention and service reliability |
| Usage statistics and error reports — opt-in, off by default. Feature usage, app version, platform, release channel and crash diagnostics, associated with anonymous device and account identifiers | To improve the product and fix crashes, only when you opt in |
We do not collect source code, prompts, agent outputs, file paths, repository names, conversation content or access tokens through telemetry.
3. Payments and card data
Optional contributions are processed by Stripe. Stripe collects and processes payment-method and billing information under its own privacy terms. Maestrly does not receive or store full card numbers or security codes. We may access limited contribution records through Stripe, such as payer contact information, amount, currency, transaction identifiers and payment or recurring status, when needed for support, reconciliation, refunds or accounting.
4. Third parties and service providers
We share only the minimum data needed with:
- Google LLC — OAuth sign-in and profile data.
- GitHub, Inc. — OAuth sign-in and email.
- Supabase, Inc. — authentication, account backend and update-file hosting.
- Stripe, Inc. and its affiliates — payment processing for optional contributions.
- Vercel Inc. — website hosting, aggregate website analytics and performance monitoring.
- Functional Software, Inc. (Sentry) — opt-in error reporting in the EU region, with diagnostics minimized before sending.
- Aptabase — opt-in privacy-focused usage analytics using anonymous identifiers.
Paddle.com Market Ltd. is no longer used for new payments. Paddle and Maestrly may retain limited records of historical Maestrly subscriptions and their tax or payment documents for the period required by applicable law.
5. Legal bases (LGPD and GDPR)
- Performance of a contract — account authentication and delivery of the Service.
- Legitimate interests — security, fraud prevention, service reliability and minimal operational analytics.
- Legal obligation — accounting, tax and transaction-record retention for contributions and historical payments.
- Consent — optional usage statistics, crash diagnostics and, where applicable, marketing communications.
6. Your rights
You may request access, correction, export, deletion, objection or restriction of personal-data processing. Email privacy@maestrly.com from the address linked to your account.
- GDPR: we respond within 1 month, extendable by up to 2 further months for complex requests with notice.
- LGPD: we respond to access requests within 15 days and to other requests within applicable legal periods.
Because your code, prompts and AI outputs stay local, they are not part of data held by us.
7. Data location and retention
Account data is stored with our backend provider in the region recorded in our infrastructure configuration. We retain it while your account exists.
When you request account deletion, the account enters a 30-day grace period. During this window it is deactivated and can be restored by signing in and reactivating it. If not restored, the account and associated personal data are permanently deleted after the grace period, subject to records we must retain by law.
Stripe contribution records and historical Paddle payment or tax records are retained for the periods required for accounting, tax, dispute and legal compliance. Canceling a monthly contribution stops future charges but does not erase legally required transaction records.
8. Security
AI-tool credentials are stored in your operating system's keychain or keyring. Data sent to our servers is encrypted in transit. We use reasonable technical and organizational safeguards, while no system can guarantee absolute security.
9. Children
Maestrly is a professional developer tool and is not directed to children under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy. Material changes will be reflected here with a new date and, where appropriate, communicated through the Service.
11. Contact
Questions or requests: privacy@maestrly.com.