MadeByLog in

MadeBy Privacy Policy

2026-09-16-workspace-invitations

Website waitlist privacy notice

Version: 2026-09-28-waitlist-v1

This notice applies to the waitlist at aimadeby.com and supplements the MadeBy Privacy Policy below. If the two differ about the waitlist, this notice governs that activity.

AI MadeBy LLC collects your email address, optional name, signup date and the version of the notice you agreed to. We use them to manage your request for MadeBy access and, with your consent, contact you about availability and launch updates. Joining the waitlist does not create an account or grant product access.

Vercel hosts the website and submission service. Supabase stores waitlist records. These records are kept separate from product accounts and customer workspaces. We do not sell waitlist details or use them to train AI models.

To reduce abuse, the submission service uses a keyed hash of your network address and email for short-lived rate limits. It does not store your raw network address in the waitlist database. Hosting providers may process technical request information under their own service arrangements.

We retain waitlist details while managing your access request. You may withdraw consent or request removal by emailing legal@aimadeby.com. We may retain a limited suppression record to honor a request not to be contacted. Any future waitlist email will include a way to unsubscribe. Automated waitlist emails are not currently enabled.

For other privacy rights, safeguards and contact information, see the MadeBy Privacy Policy below.

Effective date: September 16, 2026
Last updated: September 16, 2026

This Privacy Policy explains how AI MadeBy LLC ("MadeBy," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit or use MadeBy's websites, applications, artificial-intelligence features, and related services (the "Service").

1. MadeBy's role

MadeBy serves organizations that purchase the Service or sponsor access (each a "Customer"). An "Authorized User" is an individual the Customer permits to use the Service. A "Participant Organization" is an outside organization whose personnel receive Customer-sponsored access as part of the Customer's services or other offering. These labels describe access roles; they do not determine ownership of information or create a contractual relationship between MadeBy and a Participant Organization. The Customer determines why and how content is submitted to and used within its Workspace and is responsible for its Authorized Users.

  • For documents, prompts, chats, recordings, transcripts, Space content, and other personal information processed for a Customer ("Customer Content"), MadeBy generally acts as the Customer's processor or service provider. The Customer is responsible for its instructions, notices, permissions, and responses to individual rights requests. If you use MadeBy through a Customer, contact that Customer first about its privacy practices or a request concerning Customer Content.
  • MadeBy acts as an independent controller or business for account administration, our direct relationship with Customers and users, billing, service security, support, legal compliance, and limited product-operations data.

If a Customer's privacy notice conflicts with this Policy concerning the Customer's own purposes, the Customer's notice controls those purposes. If MadeBy and a Customer enter into a Data Processing Addendum, that addendum governs MadeBy's processing of Customer Content for the Customer to the extent stated in it.

2. Personal information we collect

The information we collect depends on how you interact with the Service.

Information you and Customers provide

  • Account and professional information: name, email address, organization, Workspace, role, and account status.
  • Invitation and access information: inviter, invitee email address, invitation message, invitation status, Workspace and Space memberships, and permission records.
  • Agreement and notice records: the legal-document type and exact version presented, acceptance statement and status, server-recorded date and time, account email snapshot, and related request and authentication metadata.
  • Customer Content: uploaded or imported documents, filenames, Knowledge Layer sources, instructions, Space documents, prompts, chats, AI Outputs, starter questions, and content you choose to share. Permitted Customer Content may include ordinary business and professional information and incidental workplace information in meeting notes.
  • Recordings: microphone audio, recording metadata, transcripts, edited key points, and saved recording documents when you use the recording feature.
  • Support and communications: messages, feedback, attachments, and other information you send to MadeBy.
  • Billing and transaction information: Customer plan, invoices, payment status, and transaction details associated with paid features.

Information collected automatically

  • Authentication and device data: essential session cookies and related authentication data, IP address, browser and device type, operating system, request timestamps, and similar server-log information.
  • Usage and performance data: feature interactions, Workspace/Space and conversation identifiers, model used, token counts, costs, request outcome, response timing, provider request identifiers, and diagnostic events. MadeBy's current performance traces are designed not to store prompt text, answer text, retrieved passages, filenames, cookies, or credentials.
  • Browser storage: local storage for interface preferences and IndexedDB for recording chunks and recovery state while a recording is in progress.
  • Cookies and similar technologies: MadeBy currently uses technologies necessary to sign users in, maintain sessions, remember interface state, secure the Service, and enable requested features. The current application does not use advertising pixels or cross-site behavioral advertising trackers.

Information from other sources

  • Customers and other users: a Customer administrator or inviter may provide your email, name, role, organization, access permissions, or a note to invite you.
  • Cloud-file providers: when you select a file from Google Drive, MadeBy receives the selected file and basic metadata needed to import it. The import is a one-time copy. Provider access tokens are kept in the browser for the import flow and are not stored in MadeBy's database.
  • Service providers: authentication, hosting, security, email, payment, and support providers may provide operational, delivery, fraud-prevention, or transaction information.

3. How we use personal information

We use personal information to:

  1. provide, host, operate, maintain, and support the Service;
  2. authenticate users, deliver invitations, administer accounts, and enforce permissions;
  3. store, index, retrieve, transcribe, summarize, and generate responses from Customer Content at the direction of Customers and users;
  4. enable user-directed imports and sharing;
  5. calculate usage, enforce limits, administer plans, invoice Customers, and process payments;
  6. monitor reliability and performance, debug errors, prevent abuse, and secure the Service;
  7. respond to requests, provide support, and communicate about the Service;
  8. comply with law, enforce agreements, and establish, exercise, or defend legal claims; and
  9. evaluate and improve Service functionality using operational data and Feedback.

MadeBy may create and use aggregated or de-identified operational information for these purposes and to publish general benchmarks or trends in marketing. MadeBy will not use it to identify a Customer or individual, reveal Customer Content or a protected methodology, or attempt reidentification.

MadeBy currently sends transactional and service communications, such as invitations, security notices, support messages, and material Service or policy updates. MadeBy does not currently send promotional or newsletter email.

For ordinary analytics, MadeBy uses usage, cost, reliability, and performance metadata rather than the text of private chats or documents. MadeBy does not routinely read private chats for product analytics or general quality review. The limited circumstances in which authorized personnel may access content are described in Section 6.

MadeBy does not use Customer Content or AI Outputs to train generalized AI models and does not opt in to allow OpenAI to use MadeBy's API data to train its models. OpenAI processes API data under its applicable business terms and data controls, which may include limited retention for abuse monitoring and application functionality.

Where a law requires a legal basis, we process personal information as necessary to perform our contract, follow a Customer's documented instructions, comply with legal obligations, protect legitimate interests in operating and securing the Service, or based on consent where required. A Customer determines the legal basis for Customer Content it directs MadeBy to process.

4. How we disclose personal information

We may disclose personal information as follows:

  • To the Customer and authorized users. Customer administrators and authorized Collaborators may access information within their Workspace. Documents in a Space may be available to authorized Collaborators. A chat shared with a Space is available to users who can access that Space. A user's private chat is not made available to other ordinary users unless the user shares it. Removing a user does not make that user's private chats visible to Customer administrators; the chats remain Customer Content under the Customer's retention lifecycle unless deleted.
  • To service providers and subprocessors. Providers process information for hosting, authentication, database and file storage, AI inference and retrieval, transcription, email, security, support, payment processing, and similar operations. Current core providers include Vercel, Supabase, OpenAI, and Resend.
  • To third-party services you direct us to use. For example, Google may process your sign-in and file-selection activity when you choose a cloud import. Their independent processing is governed by their policies.
  • For legal and safety reasons. We may disclose information if reasonably necessary to comply with law or legal process; protect rights, safety, and security; investigate fraud or abuse; or enforce agreements.
  • For a business transaction. Information may be disclosed to advisers, counterparties, and a successor in connection with financing, diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
  • With consent or at your direction. We may disclose information for another purpose that is disclosed when you provide it or with appropriate permission.

MadeBy does not sell personal information for money or share it for cross-context behavioral advertising. MadeBy does not disclose personal information to third parties for their own direct marketing. If these practices change, we will update this Policy and provide legally required choices before the change applies.

5. AI processing

When you use an AI feature, MadeBy sends the prompt, relevant conversation context, retrieved Customer Content, instructions, and related metadata to OpenAI to provide the requested feature. Uploaded documents may be stored as OpenAI files and indexed in vector stores until MadeBy deletes them. OpenAI may retain API data and application state according to MadeBy's account settings, the endpoint used, and OpenAI's business terms and data controls.

The instructions sent with a request may include non-public MadeBy platform instructions, Customer-configured Workspace, Knowledge Layer, or Space instructions, retrieval rules, and safety or security controls. They shape or limit how the AI responds and may take priority over a user's prompt. MadeBy does not disclose the contents of non-public platform instructions because they are part of the Service's intellectual property and security controls. Their use does not constitute model training.

AI Outputs can be inaccurate or reveal information included in the context supplied to the AI. Do not submit information you or the Customer are not authorized to use. MadeBy does not use AI Outputs to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers and users must not use the Service for that purpose.

6. Human and provider access to Customer Content

Customer Content is stored with providers that supply MadeBy's database, hosting, and AI services. MadeBy and those providers therefore have the technical ability to process and, in limited circumstances, access content. Technical capability does not mean that MadeBy routinely reads it.

MadeBy may allow specifically authorized personnel to access Customer Content only when reasonably necessary to:

  • provide support requested by a Customer or user;
  • diagnose or correct a technical problem;
  • investigate suspected security incidents, fraud, abuse, or prohibited use;
  • comply with law or a binding legal request; or
  • protect the rights, safety, or security of MadeBy, Customers, users, or others.

Access must be need-to-know, limited to the minimum content reasonably necessary, and subject to confidentiality obligations. MadeBy does not use identifiable chat content for voluntary product-quality research unless the Customer affirmatively opts in under separate terms. Service providers may access content under their contracts and policies to operate, secure, and support their services.

When practicable, MadeBy will notify the Customer of identifiable content access. If Customer-requested support requires a private chat, MadeBy will seek the affected user's authorization when practicable unless the Customer has established authority to request access or an independent security, legal, or safety basis applies. A Customer administrator does not receive access to a private chat merely because of the administrator role.

7. Recordings and transcripts

The recording feature captures microphone audio in small chunks. Chunks are first stored in your browser for recovery, uploaded to private cloud storage while you record, and sent to OpenAI for transcription. MadeBy stores the resulting transcript, summary or key points, and recording metadata. If you save the work to a Knowledge Layer, the saved document includes the transcript and is indexed as Customer Content.

MadeBy uses raw audio for transcription, in-progress recovery, troubleshooting, security, and legal purposes as reasonably necessary. Raw audio is not intended to be the permanent record of a meeting; transcripts, summaries or key points, and saved recording documents may remain as Customer Content.

You are responsible for providing notice and obtaining consent from everyone recorded whenever required by law. MadeBy does not use recordings to identify a person by voice or create biometric voiceprints.

8. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow Customer instructions, maintain security, meet contractual and legal obligations, resolve disputes, and enforce agreements. The retention period depends on the category and context.

  • Account and membership records are retained while the account is active and as needed for administration, security, audit, and legal obligations after deactivation.
  • Customer Content is retained while the Customer account or applicable Workspace, Knowledge Layer, Space, or chat remains active, subject to user controls and the Subscription Agreement.
  • Files and vector stores held by AI providers may remain until deleted through the provider's API and may then be subject to the provider's deletion and backup windows.
  • Workspace-creation invitation links expire after 72 hours. Other invitation links expire after seven days. MadeBy may retain invitation and acceptance records for security and administration.
  • Raw recording audio is retained based on the transcription, recovery, troubleshooting, security, and legal purposes described in Section 7; transcripts and saved recording documents may remain as Customer Content.
  • Security, usage, billing, and audit records may be retained for a reasonable period after the underlying activity to protect the Service and meet business and legal obligations.

Deletion from active systems may not immediately remove information from encrypted backups, security logs, or records retained where legally permitted or required. We will isolate such data from ordinary use and delete or anonymize it according to the applicable lifecycle.

9. Security

MadeBy uses administrative, technical, and organizational safeguards designed to protect personal information. Current controls include invite-only access, server-side authorization, Workspace and Space scoping, encrypted transport, private storage, and restricted database access. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

If you believe your account or information has been compromised, contact legal@AIMadeBy.com immediately.

10. Restricted Data

MadeBy necessarily collects limited personal information to provide the Service, including names, contact details, account permissions, and usage records. Customer Content may contain ordinary business and professional information and incidental workplace information in meeting notes when reasonably necessary for a legitimate business purpose.

The Service is not designed or authorized for "Restricted Data." Do not submit:

  • PHI or patient-level, claims, eligibility, clinical, or identifiable consumer health data, whether or not HIPAA applies;
  • government-issued identification numbers, financial-account credentials, full payment-card data, account passwords, authentication secrets, or private keys;
  • biometric identifiers or templates, genetic data, voiceprints, or face geometry;
  • precise geolocation, information about children, or information concerning sensitive personal traits such as race or ethnicity, religious beliefs, sexual life or orientation, disability, immigration status, or criminal history;
  • applicant files, background checks, compensation records, performance evaluations, disciplinary records, medical or leave records, or other sensitive employment or human-resources information; or
  • personal information not reasonably necessary for a legitimate business purpose, or other data subject to heightened safeguards that MadeBy has not expressly approved.

This restriction applies to documents, prompts, chats, recordings, transcripts, and imported files. MadeBy does not currently offer a HIPAA-eligible Service or enter into BAAs. The fact that MadeBy or a Customer works in healthcare does not make the Service HIPAA compliant.

11. Your privacy choices and rights

Depending on where you live and how MadeBy processes your information, you may have the right to request access to, correction of, deletion of, or a copy of personal information; to object to or restrict certain processing; to opt out of sale, sharing, or targeted advertising; to withdraw consent; or to appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

To make a request about Customer Content, contact the Customer that provided your access. MadeBy will assist the Customer as required by contract and law. To make a request about information MadeBy controls directly, email legal@AIMadeBy.com. We may need to verify your identity and authority. An authorized agent may submit a request where permitted by law. To appeal MadeBy's denial of a privacy request, reply to the denial or email legal@AIMadeBy.com with the subject “Privacy Appeal.”

MadeBy does not sell personal information or use it for targeted advertising, so there is no sale or targeted-advertising opt-out needed for the current Service. Where legally required, we will recognize an enabled Global Privacy Control signal for the browser or device sending it.

The Service does not track users across unaffiliated websites over time for advertising, so we do not respond differently to browser "Do Not Track" signals.

You may complain to an applicable state or federal privacy regulator.

12. U.S. state disclosures

Where U.S. state privacy laws apply, the categories of personal information collected during the preceding 12 months may include identifiers; professional or employment-related information; commercial and subscription information; internet or other electronic network activity; audio information; account credentials; and inferences reflected in AI Outputs. Restricted Data is prohibited, although MadeBy may receive it contrary to its Terms. The sources, business purposes, and recipients for these categories are described in Sections 2 through 4.

MadeBy retains each category under Section 8. MadeBy does not use or disclose sensitive personal information to infer characteristics about individuals. MadeBy does not knowingly sell or share personal information of anyone under 16.

13. International data transfers

The Service is currently offered only to Customers and Authorized Users located in the United States. It is not currently offered to persons located in the EEA, United Kingdom, Switzerland, or other countries. MadeBy and its providers are based in the United States, but providers or their subprocessors may process information in other countries depending on the services used, account configuration, and their subprocessor arrangements. Restricting Customer and Authorized User access to the United States does not mean that all provider processing or support is geographically limited to the United States.

14. Children

The Service is intended for business users age 18 or older and is not directed to children. MadeBy does not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact legal@AIMadeBy.com. Customers may not submit children's personal information to the Service.

15. Changes to this Policy

We may update this Policy to reflect changes in the Service, our practices, or law. We will post the updated Policy and revise the date above. If a change materially expands our use of personal information, we will provide additional notice or obtain consent where required before the change applies.

MadeBy records the version of this Policy presented during onboarding and when material notices are delivered. That record shows which notice was provided; it does not turn this Policy into a contract, waive a privacy right, or create consent where the law requires a separate choice.

16. Contact us

Privacy questions and requests may be sent to:

AI MadeBy LLC
8500 Normandale Lake Blvd, Suite 350 #1017
Bloomington, Minnesota 55347, United States
legal@AIMadeBy.com