Effective date: September 16, 2026
Last updated: September 16, 2026
This Privacy Policy explains how AI MadeBy LLC ("MadeBy,"
"we," "us," or "our"), collects, uses, discloses, and protects personal information when you
visit or use MadeBy's websites, applications, artificial-intelligence features, and related
services (the "Service").
1. MadeBy's role
MadeBy serves organizations that purchase the Service or sponsor access (each a "Customer").
An "Authorized User" is an individual the Customer permits to use the Service. A
"Participant Organization" is an outside organization whose personnel receive
Customer-sponsored access as part of the Customer's services or other offering. These labels
describe access roles; they do not determine ownership of information or create a contractual
relationship between MadeBy and a Participant Organization. The Customer determines why and how
content is submitted to and used within its Workspace and is responsible for its Authorized Users.
- For documents, prompts, chats, recordings, transcripts, Space content, and other personal
information processed for a Customer ("Customer Content"), MadeBy generally acts as the
Customer's processor or service provider. The Customer is responsible for its instructions,
notices, permissions, and responses to individual rights requests. If you use MadeBy through a
Customer, contact that Customer first about its privacy practices or a request concerning
Customer Content.
- MadeBy acts as an independent controller or business for account administration, our direct
relationship with Customers and users, billing, service security, support, legal compliance, and
limited product-operations data.
If a Customer's privacy notice conflicts with this Policy concerning the Customer's own purposes,
the Customer's notice controls those purposes. If MadeBy and a Customer enter into a Data
Processing Addendum, that addendum governs MadeBy's processing of Customer Content for the
Customer to the extent stated in it.
2. Personal information we collect
The information we collect depends on how you interact with the Service.
Information you and Customers provide
- Account and professional information: name, email address, organization,
Workspace, role, and account status.
- Invitation and access information: inviter, invitee email address, invitation message,
invitation status, Workspace and Space memberships, and permission records.
- Agreement and notice records: the legal-document type and exact version presented, acceptance
statement and status, server-recorded date and time, account email snapshot, and related request
and authentication metadata.
- Customer Content: uploaded or imported documents, filenames, Knowledge Layer sources,
instructions, Space documents, prompts, chats, AI Outputs, starter questions, and content you
choose to share. Permitted Customer Content may include ordinary business and professional
information and incidental workplace information in meeting notes.
- Recordings: microphone audio, recording metadata, transcripts, edited key points, and saved
recording documents when you use the recording feature.
- Support and communications: messages, feedback, attachments, and other information you send
to MadeBy.
- Billing and transaction information: Customer plan, invoices, payment status, and transaction
details associated with paid features.
Information collected automatically
- Authentication and device data: essential session cookies and related authentication data,
IP address, browser and device type, operating system, request timestamps, and similar server-log
information.
- Usage and performance data: feature interactions, Workspace/Space and conversation
identifiers, model used, token counts, costs, request outcome, response timing, provider request
identifiers, and diagnostic events. MadeBy's current performance traces are designed not to store
prompt text, answer text, retrieved passages, filenames, cookies, or credentials.
- Browser storage: local storage for interface preferences and IndexedDB for recording chunks
and recovery state while a recording is in progress.
- Cookies and similar technologies: MadeBy currently uses technologies necessary to sign users
in, maintain sessions, remember interface state, secure the Service, and enable requested
features. The current application does not use advertising pixels or cross-site behavioral
advertising trackers.
Information from other sources
- Customers and other users: a Customer administrator or inviter may provide your email, name, role, organization, access permissions, or a note to invite you.
- Cloud-file providers: when you select a file from Google Drive, MadeBy
receives the selected file and basic metadata needed to import it. The import is a one-time copy.
Provider access tokens are kept in the browser for the import flow and are not stored in MadeBy's
database.
- Service providers: authentication, hosting, security, email, payment, and support providers
may provide operational, delivery, fraud-prevention, or transaction information.
3. How we use personal information
We use personal information to:
- provide, host, operate, maintain, and support the Service;
- authenticate users, deliver invitations, administer accounts, and enforce permissions;
- store, index, retrieve, transcribe, summarize, and generate responses from Customer Content at
the direction of Customers and users;
- enable user-directed imports and sharing;
- calculate usage, enforce limits, administer plans, invoice Customers, and process payments;
- monitor reliability and performance, debug errors, prevent abuse, and secure the Service;
- respond to requests, provide support, and communicate about the Service;
- comply with law, enforce agreements, and establish, exercise, or defend legal claims; and
- evaluate and improve Service functionality using operational data and Feedback.
MadeBy may create and use aggregated or de-identified operational information for these purposes
and to publish general benchmarks or trends in marketing. MadeBy will not use it to identify a
Customer or individual, reveal Customer Content or a protected methodology, or attempt
reidentification.
MadeBy currently sends transactional and service communications, such as invitations, security
notices, support messages, and material Service or policy updates. MadeBy does not currently send
promotional or newsletter email.
For ordinary analytics, MadeBy uses usage, cost, reliability, and performance metadata rather than
the text of private chats or documents. MadeBy does not routinely read private chats for product
analytics or general quality review. The limited circumstances in which authorized personnel may
access content are described in Section 6.
MadeBy does not use Customer Content or AI Outputs to train generalized AI models and does not opt
in to allow OpenAI to use MadeBy's API data to train its models. OpenAI processes API data under
its applicable business terms and data controls, which may include limited retention for abuse
monitoring and application functionality.
Where a law requires a legal basis, we process personal information as necessary to perform our
contract, follow a Customer's documented instructions, comply with legal obligations, protect
legitimate interests in operating and securing the Service, or based on consent where required. A
Customer determines the legal basis for Customer Content it directs MadeBy to process.
4. How we disclose personal information
We may disclose personal information as follows:
- To the Customer and authorized users. Customer administrators and authorized Collaborators
may access information within their Workspace. Documents in a Space may be available to
authorized Collaborators. A chat shared with a Space is available to users who can access that
Space. A user's private chat is not made available to other ordinary users unless the user shares
it. Removing a user does not make that user's private chats visible to Customer administrators;
the chats remain Customer Content under the Customer's retention lifecycle unless deleted.
- To service providers and subprocessors. Providers process information for hosting,
authentication, database and file storage, AI inference and retrieval, transcription, email,
security, support, payment processing, and similar operations. Current core providers include
Vercel, Supabase, OpenAI, and Resend.
- To third-party services you direct us to use. For example, Google may process
your sign-in and file-selection activity when you choose a cloud import. Their independent
processing is governed by their policies.
- For legal and safety reasons. We may disclose information if reasonably necessary to comply
with law or legal process; protect rights, safety, and security; investigate fraud or abuse; or
enforce agreements.
- For a business transaction. Information may be disclosed to advisers, counterparties, and a
successor in connection with financing, diligence, merger, acquisition, reorganization,
bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
- With consent or at your direction. We may disclose information for another purpose that is
disclosed when you provide it or with appropriate permission.
MadeBy does not sell personal information for money or share it for cross-context
behavioral advertising. MadeBy does not disclose personal information to third parties for their
own direct marketing. If these practices change, we will update this Policy and provide legally
required choices before the change applies.
5. AI processing
When you use an AI feature, MadeBy sends the prompt, relevant conversation context, retrieved
Customer Content, instructions, and related metadata to OpenAI to provide the requested feature.
Uploaded documents may be stored as OpenAI files and indexed in vector stores until MadeBy deletes
them. OpenAI may retain API data and application state according to MadeBy's account settings, the
endpoint used, and OpenAI's business terms and data controls.
The instructions sent with a request may include non-public MadeBy platform instructions,
Customer-configured Workspace, Knowledge Layer, or Space instructions, retrieval rules, and safety
or security controls. They shape or limit how the AI responds and may take priority over a user's
prompt. MadeBy does not disclose the contents of non-public platform instructions because they are
part of the Service's intellectual property and security controls. Their use does not constitute
model training.
AI Outputs can be inaccurate or reveal information included in the context supplied to the AI. Do
not submit information you or the Customer are not authorized to use. MadeBy does not use AI Outputs
to make solely automated decisions that produce legal or similarly significant effects about
individuals. Customers and users must not use the Service for that purpose.
6. Human and provider access to Customer Content
Customer Content is stored with providers that supply MadeBy's database, hosting, and AI services.
MadeBy and those providers therefore have the technical ability to process and, in limited
circumstances, access content. Technical capability does not mean that MadeBy routinely reads it.
MadeBy may allow specifically authorized personnel to access Customer Content only when reasonably
necessary to:
- provide support requested by a Customer or user;
- diagnose or correct a technical problem;
- investigate suspected security incidents, fraud, abuse, or prohibited use;
- comply with law or a binding legal request; or
- protect the rights, safety, or security of MadeBy, Customers, users, or others.
Access must be need-to-know, limited to the minimum content reasonably necessary, and subject to
confidentiality obligations. MadeBy does not use identifiable chat content for voluntary
product-quality research unless the Customer affirmatively opts in under separate terms. Service
providers may access content under their contracts and policies to operate, secure, and support
their services.
When practicable, MadeBy will notify the Customer of identifiable content access. If
Customer-requested support requires a private chat, MadeBy will seek the affected user's
authorization when practicable unless the Customer has established authority to request access or
an independent security, legal, or safety basis applies. A Customer administrator does not receive
access to a private chat merely because of the administrator role.
7. Recordings and transcripts
The recording feature captures microphone audio in small chunks. Chunks are first stored in your
browser for recovery, uploaded to private cloud storage while you record, and sent to OpenAI for
transcription. MadeBy stores the resulting transcript, summary or key points, and recording
metadata. If you save the work to a Knowledge Layer, the saved document includes the transcript and
is indexed as Customer Content.
MadeBy uses raw audio for transcription, in-progress recovery, troubleshooting, security, and legal
purposes as reasonably necessary. Raw audio is not intended to be the permanent record of a
meeting; transcripts, summaries or key points, and saved recording documents may remain as Customer
Content.
You are responsible for providing notice and obtaining consent from everyone recorded whenever
required by law. MadeBy does not use recordings to identify a person by voice or create biometric
voiceprints.
8. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described
in this Policy, including to provide the Service, follow Customer instructions, maintain security,
meet contractual and legal obligations, resolve disputes, and enforce agreements. The retention
period depends on the category and context.
- Account and membership records are retained while the account is active and as needed for
administration, security, audit, and legal obligations after deactivation.
- Customer Content is retained while the Customer account or applicable Workspace, Knowledge
Layer, Space, or chat remains active, subject to user controls and the Subscription Agreement.
- Files and vector stores held by AI providers may remain until deleted through the provider's API
and may then be subject to the provider's deletion and backup windows.
- Workspace-creation invitation links expire after 72 hours. Other invitation links expire
after seven days. MadeBy may retain invitation and acceptance records for security and
administration.
- Raw recording audio is retained based on the transcription, recovery, troubleshooting, security,
and legal purposes described in Section 7; transcripts and saved recording documents may remain
as Customer Content.
- Security, usage, billing, and audit records may be retained for a reasonable period after the
underlying activity to protect the Service and meet business and legal obligations.
Deletion from active systems may not immediately remove information from encrypted backups,
security logs, or records retained where legally permitted or required. We will isolate such data
from ordinary use and delete or anonymize it according to the applicable lifecycle.
9. Security
MadeBy uses administrative, technical, and organizational safeguards designed to protect personal
information. Current controls include invite-only access, server-side authorization, Workspace and
Space scoping, encrypted transport, private storage, and restricted database access. No method of
storage or transmission is completely secure, and we cannot guarantee absolute security.
If you believe your account or information has been compromised, contact legal@AIMadeBy.com
immediately.
10. Restricted Data
MadeBy necessarily collects limited personal information to provide the Service, including names,
contact details, account permissions, and usage records. Customer Content may contain
ordinary business and professional information and incidental workplace information in meeting
notes when reasonably necessary for a legitimate business purpose.
The Service is not designed or authorized for "Restricted Data." Do not submit:
- PHI or patient-level, claims, eligibility, clinical, or identifiable consumer health data,
whether or not HIPAA applies;
- government-issued identification numbers, financial-account credentials, full payment-card data,
account passwords, authentication secrets, or private keys;
- biometric identifiers or templates, genetic data, voiceprints, or face geometry;
- precise geolocation, information about children, or information concerning sensitive personal
traits such as race or ethnicity, religious beliefs, sexual life or orientation, disability,
immigration status, or criminal history;
- applicant files, background checks, compensation records, performance evaluations, disciplinary
records, medical or leave records, or other sensitive employment or human-resources information;
or
- personal information not reasonably necessary for a legitimate business purpose, or other data
subject to heightened safeguards that MadeBy has not expressly approved.
This restriction applies to documents, prompts, chats, recordings, transcripts, and imported files.
MadeBy does not currently offer a HIPAA-eligible Service or enter into BAAs. The fact that MadeBy or
a Customer works in healthcare does not make the Service HIPAA compliant.
11. Your privacy choices and rights
Depending on where you live and how MadeBy processes your information, you may have the right to
request access to, correction of, deletion of, or a copy of personal information; to object to or
restrict certain processing; to opt out of sale, sharing, or targeted advertising; to withdraw
consent; or to appeal a denied request. You may also have the right not to receive discriminatory
treatment for exercising a privacy right.
To make a request about Customer Content, contact the Customer that provided your access. MadeBy
will assist the Customer as required by contract and law. To make a request about information
MadeBy controls directly, email legal@AIMadeBy.com. We may need to verify your identity and authority.
An authorized agent may submit a request where permitted by law. To appeal MadeBy's denial of a
privacy request, reply to the denial or email legal@AIMadeBy.com with the subject “Privacy Appeal.”
MadeBy does not sell personal information or use it for targeted advertising, so there is
no sale or targeted-advertising opt-out needed for the current Service. Where legally required, we
will recognize an enabled Global Privacy Control signal for the browser or device sending it.
The Service does not track users across unaffiliated websites over time for advertising,
so we do not respond differently to browser "Do Not Track" signals.
You may complain to an applicable state or federal privacy regulator.
12. U.S. state disclosures
Where U.S. state privacy laws apply, the categories of personal information collected during the
preceding 12 months may include identifiers; professional or employment-related information;
commercial and subscription information; internet or other electronic network activity;
audio information; account credentials; and inferences reflected in AI Outputs. Restricted Data is
prohibited, although MadeBy may receive it contrary to its Terms. The sources, business purposes,
and recipients for these categories are described in Sections 2 through 4.
MadeBy retains each category under Section 8. MadeBy does not use or disclose sensitive personal
information to infer characteristics about individuals. MadeBy does not knowingly sell or share
personal information of anyone under 16.
13. International data transfers
The Service is currently offered only to Customers and Authorized Users located in the United
States. It is not currently offered to persons located in the EEA, United Kingdom, Switzerland, or
other countries. MadeBy and its providers are based in the United States, but providers or their
subprocessors may process information in other countries depending on the services used, account
configuration, and their subprocessor arrangements. Restricting Customer and Authorized User access
to the United States does not mean that all provider processing or support is geographically
limited to the United States.
14. Children
The Service is intended for business users age 18 or older and is not directed to children. MadeBy
does not knowingly collect personal information from children under 13. If you believe a child has
provided personal information, contact legal@AIMadeBy.com. Customers may not submit children's
personal information to the Service.
15. Changes to this Policy
We may update this Policy to reflect changes in the Service, our practices, or law. We will post the
updated Policy and revise the date above. If a change materially expands our use of personal
information, we will provide additional notice or obtain consent where required before the change
applies.
MadeBy records the version of this Policy presented during onboarding and when material notices are
delivered. That record shows which notice was provided; it does not turn this Policy into a contract,
waive a privacy right, or create consent where the law requires a separate choice.
16. Contact us
Privacy questions and requests may be sent to:
AI MadeBy LLC
8500 Normandale Lake Blvd, Suite 350 #1017
Bloomington, Minnesota 55347, United States
legal@AIMadeBy.com