← Mahanu

Privacy Notice

Pre-launch draft · not effective. Complete the controller identity, contact routes, supported jurisdictions, legal bases, transfer mechanism, retention schedule, effective date, and version before publication. This notice is the canonical privacy statement for the hosted service.

1. Who is responsible

[Mahanu Operator legal name], [registered address], is the controller or equivalent responsible party for the Mahanu hosted service. Contact [email protected]. Add the appointed data-protection contact, EU/UK representative, and supervisory-authority details here if applicable.

This notice covers the hosted Mahanu service, not self-hosted deployments or third-party services a project deliberately chooses. Those operators publish their own notices.

2. Data we process and why

Category Examples Purpose
Account and authentication email for an independent account, invitation/vouch relationship, adult attestation timestamp, session-token hash, approved-device credential authenticate access, prevent abuse, recover accounts, and enforce the adult/guardian model
Project access and public data project card, listing status, roles, invite and join-request records, intentionally published work operate collaboration, enforce permissions, render the public directory, run an owner-requested support match against the public card, and handle reports
Project content sync payloads, files, assets, and change history provide storage, sync, recovery, and features the project enables; in encrypted mode, team-private payloads are ciphertext to Mahanu
Service, security, and support records rate-limit, error, security, report, refusal, billing, and support records secure and operate the service, investigate abuse, meet legal duties, and provide support
Optional feature data selected assistant context, usage needed to bill an enabled AI route, grant applications, a search query, or selected material used for a related-support search provide the specific feature you request; the feature UI identifies the additional disclosure or provider boundary
Bot and conduct records bot registration, operator identity, granted permissions, and the conduct-bot flags and serious-category escalation signals described in the Bot & Automation Policy operate bot features, enforce the Acceptable Use Policy, protect supervised members, and make decisions reviewable

Where a project must run the conduct bot, the bot evaluates the project’s conduct surfaces within the project boundary — on the members’ devices in an encrypted project — and retains no copy of unflagged content; only a flag or a serious-category escalation becomes a record. This is safety processing under the Bot & Automation Policy, not behavioural profiling.

We do not require a birthdate, government ID, facial estimate, behavioural profile, public follower graph, or advertising profile for ordinary use. A supervised account is linked to its guardian for consent, recovery, and controls; it does not require a child’s independent email account.

3. How we use and disclose data

We use data only for the purposes above, to comply with law, and for other compatible purposes disclosed before we use them. Before launch, counsel must record the appropriate legal basis or equivalent for every purpose and jurisdiction.

We disclose data only to: project members according to project permissions; the public when an owner publishes a card or work; processors in the Subprocessor Register that operate the hosted service under written obligations; authorities or others when law requires it; and a recipient you deliberately choose, such as an external assistant provider, the operator of a third-party bot a project adds (which receives only what its granted permissions allow), or a grant sponsor. A grant sponsor receives only the application material the project owner submits.

No account-level enforcement decision is made by automation alone: a conduct-bot flag or escalation is reviewed by a person before an account is suspended or terminated, and the decision is reviewable under Reporting & Appeals.

Mahanu does not sell, rent, license, trade, or provide paid access to user or project data. It does not run behavioural advertising, offer sponsor tracking, or disclose selected related-search material, vectors, inferred topics, project identity, audience data, or performance data to a sponsor. The detailed support boundary is here.

4. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, receive a portable copy of, or complain about the processing of your personal data. You may also withdraw consent where processing relies on consent. Use [email protected] or the in-product request path [URL]. We will verify a request proportionately, respond within the period required by applicable law, and explain any lawful limitation.

Project members control their own content subject to shared-project permissions. An owner cannot delete another member’s independent account. A guardian exercises the applicable rights for a supervised account as explained in the Guardian Addendum.

5. Retention, security, and transfers

Our retention rules are in the canonical Retention & Deletion Policy. We protect data with measures appropriate to its sensitivity, including access controls, encrypted transport, key management for encrypted projects, and backups. No security measure is absolute.

If data is processed outside your country, we will use the transfer mechanism and safeguards required for the relevant jurisdiction. The final effective notice must name the countries or regions, processors, safeguards, and how to obtain further information.

6. Children and changes

Independent accounts are adult accounts. A guardian creates and manages a supervised account; the applicable guardian notice, consent record, and withdrawal/deletion route are mandatory before that flow launches. Mahanu does not use a child’s content or use for advertising, profiling, paid placement, or AI training. The Guardian Addendum has the product-specific rules.

We will publish an effective date, version, and material-change summary for this notice. Material changes follow the notice and consent rules in the legal index.