Privacy Policy
MAI holds some of the most personal material you own — your voice, your meetings, your unfinished thinking. This explains exactly what happens to it, in plain terms, without hiding the parts that matter.
Last updated 4 September 2026
1. Who we are
MAI (“MAI: Second Brain Notes”) is operated by Inteli Seko EOOD, a company registered in Bulgaria under company number 208085848 (VAT BG208085848), with its registered address at 5 Ivaylo Petrov Street, Sofia, Bulgaria.
We are the data controller for the personal data described here. For anything about your data, write to privacy@maicontext.com. For help with the product, write to ivo@maicontext.com.
2. What this covers
This policy covers the MAI apps for iPhone, Apple Watch and Mac, the website at maicontext.com, our checkout at quiz.maicontext.com, and the connector that lets an AI assistant such as Claude read your brain.
3. What we collect
Your account
Your email address, and a display name if you give one. MAI has no passwords — you sign in with a six-digit code sent to your email.
What you put into your brain
This is the heart of the product and the most sensitive data we hold: voice recordings and their transcripts, dictated audio, typed notes, photos you capture and the text read out of them, links you save and their contents, meeting recordings and transcripts, and everything derived from those — summaries, tasks, projects, themes and the numerical embeddings that make search work. We also keep a weekly count of dictated words per account (the number only, used to apply the free plan’s allowance).
You decide what goes in. We would rather you knew now than later: if you dictate something into MAI that is confidential — health details, a client matter, anything about a named third party — it is stored and processed exactly like any other note, and passes through the AI providers listed below.
Device permissions
MAI asks for the microphone (to record and dictate), speech recognition (to turn speech into text), the camera and photo library (only for images you choose to capture), notifications, and — if you connect one — your calendar. On the Mac it also asks for Accessibility access, so dictated text can be typed into the app you are using, and for system audio capture if you record a meeting locally. Each is requested when the feature needs it, and each can be refused or revoked in your system settings without disabling the rest of the app.
Payments
If you subscribe, we receive a record of what you bought and whether it is active. We never see or store your card number. Payments on the web are handled by Stripe, and purchases in the app by Apple; each collects your payment details directly.
Usage and marketing data
With your consent, pseudonymous product analytics (which features get used, never your note content) and website advertising measurement. If you decline, neither runs. See Analytics, cookies and ads.
4. Why, and on what legal basis
- To provide the service — storing your notes, transcribing your voice, generating summaries and tasks, running search, syncing across your devices, and taking payment. Legal basis: performance of a contract with you.
- To send you the emails the product depends on — sign-in codes, receipts, and notices about changes. Legal basis: contract, and our legitimate interest in administering it.
- Optional features you switch on — the meeting notetaker, a connected calendar, an AI connector, spoken summaries. Legal basis: consent, and you can withdraw it by turning the feature off.
- Product analytics and advertising measurement. Legal basis: consent, asked for separately and refusable without losing any functionality.
- Keeping the service secure and preventing abuse — rate limiting, fraud and abuse detection, diagnostic logs. Legal basis: legitimate interests.
- Meeting our legal obligations — tax and accounting records for purchases. Legal basis: legal obligation.
MAIdoes not ask you for special-category data (health, beliefs, biometrics and the like) and does not knowingly seek it out. Because the product records open-ended speech, such information may end up in a note if you say it. We treat whatever you record with the same protections described here, but we cannot classify it in advance — so please think before recording other people’s sensitive information.
5. Meetings and other people
This section matters more than any other, because it is the one place where MAI processes data about people who never agreed to anything with us.
MAI can record a meeting two ways: by sending a notetaker bot into a video call, or by capturing audio locally on your Mac. Either way, the recording and transcript will contain the voices and words of everyone present, and under data protection law that is personal data about each of them.
When you record a meeting, you are responsible for having the right to do so. You are the one who decides to record, who is in the room, and what is discussed — so in relation to those other participants, you act as the controller of their data and we act as your processor. In practice this means you must tell participants they are being recorded and obtain their consent where the law requires it. That requirement is real and varies: twelve US states require the consent of every party to a conversation, and in the EU and UK a recording of an identifiable person is personal data regardless of where your company is based. Where participants are in different places, assume the strictest rule applies.
If someone recorded in your meeting asks us to delete their data, we will usually direct them to you, because it is your brain and we cannot judge your relationship with them. We will help you act on the request.
6. AI processing and model training
Turning speech into structured notes requires sending your content to AI providers. Voice and meeting audio go to OpenAI or ElevenLabs for transcription; the resulting text goes to OpenAI to produce titles, summaries, tasks and the embeddings behind search. Photos you attach go to OpenAI so the text in them can be read; so do documents and links you attach, and calendar event titles when a Focus Brief is generated.
How long the providers keep it. OpenAI keeps API inputs for up to 30 days for abuse monitoring and then deletes them; we use only endpoints that do not store conversations. Every transcription request to ElevenLabs is sent in its zero-retention mode. Recall.ai is involved only when you send the notetaker into a call, and deletes its copy 72 hours after that call ends — the recording and transcript you keep live with us, not with them. A meeting you record yourself on the Mac never reaches Recall.ai at all.
We do not use your content to train AI models, and we do not sell it. We use these providers through their business APIs under terms that exclude API content from training their models. We do not build models of our own from your data.
Separately, you can connect an AI assistant of your choice — Claude, ChatGPT, or any other MCP client — to your brain through our connector. A connected assistant can read the notes, meetings and tasks it requests and write new notes and tasks back, always signed in as you and only after you approve the connection. What that assistant’s provider does with the content it reads is governed by your agreement with them, not by this policy — so connect assistants you trust. Every connector request is logged, and you can revoke access at any time from the app.
AI output can be wrong. Summaries can miss things, transcripts can mishear, and extracted tasks can invent an emphasis you did not intend. Treat what MAI produces as a draft of your own thinking, not a record of fact.
7. Who else handles your data
We use the following processors. Those marked optional are only involved if you turn on the feature that uses them.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Supabase | Application database, file storage, authentication | Your account, notes, transcripts, tasks, projects and uploaded audio, images and files | European Union (Stockholm) |
| OpenAI | Speech-to-text, summarisation, task extraction, embeddings for search, text extraction from photos | Voice recordings, dictation audio, note text, meeting transcripts and participant names, photos and documents you attach, the text of links you save, and calendar event titles when a Focus Brief is generated | United States Standard Contractual Clauses |
| ElevenLabs | Speech-to-text for long recordings, spoken audio summaries when you ask for one, and the live voice conversation feature | Voice and meeting recordings above the size handled by OpenAI, requested in ElevenLabs' zero-retention mode; summary text you choose to have read aloud; live microphone audio while you talk to MAI by voice | United States Standard Contractual Clauses |
| Recall.ai optional | The meeting notetaker only — the bot you send into a call. Never involved when you record a meeting yourself on the Mac, or in anything else you capture | Audio, video and transcripts of calls the notetaker joined, including the voices of other participants. Its copy is deleted 72 hours after the call; the transcript you keep lives with us | United States Standard Contractual Clauses |
| Anthropic optional | Only if you connect Claude to your brain. Claude then reads the entries it requests through the connector | Whatever the connector returns for your requests — notes, tasks, meeting content | United States Standard Contractual Clauses |
| Google optional | Only if you connect a calendar. Reads your event list so the notetaker knows which calls to join | Calendar events: titles, times, attendees, meeting links | United States Standard Contractual Clauses |
| Supadata | Fetching the contents of links you save | The URLs you share into MAI | United States Standard Contractual Clauses |
| RevenueCat | Subscription and entitlement management | Your account identifier, purchase and subscription status | United States Standard Contractual Clauses |
| Stripe | Payment processing for purchases made on the web | Payment and billing details. Stripe collects these directly — we never see or store your card number | United States and European Union Standard Contractual Clauses |
| Apple | App distribution, in-app purchases, and push notifications to your devices | Purchase records for App Store subscriptions, device push tokens | United States and European Union Standard Contractual Clauses |
| Resend | Sending transactional email — sign-in codes, receipts, notices | Your email address and the contents of those messages | United States Standard Contractual Clauses |
| Vercel | Hosting maicontext.com and its traffic analytics | Website request data, including IP address | United States and European Union Standard Contractual Clauses |
| Mixpanel optional | Product analytics — which features get used | Usage events tied to your account identifier, only if you opt in. Never your note content. App versions before September 2026 also attached your name and email address to that profile; current versions send neither | European Union |
| Sentry | Error reporting — when something breaks, a report of the error | Error type, message and stack trace, tagged with your account identifier. Never a note, transcript, recording or request body — our reporter is hand-written to make that impossible | European Union (Germany) |
| Meta optional | Advertising measurement on our website and, in the iOS app, only if you allow tracking when iOS asks | Website events; in the app, sign-up and purchase events with your advertising identifier, only after you allow tracking | United States Standard Contractual Clauses |
We may also share data where the law requires it, or with professional advisers under confidentiality. If MAI is ever sold or merged, your data may transfer to the buyer — you will be told before that happens and it will remain subject to a policy no less protective than this one.
8. Where your data lives
Your account, notes, transcripts and files are stored in the European Union, on infrastructure hosted in Stockholm.
Several processors above operate in the United States, so using MAI involves transferring some data there — principally the AI providers that do transcription and summarisation. Those transfers rely on the European Commission’s Standard Contractual Clauses, or on the provider’s certification under the EU–US Data Privacy Framework where it holds one.
9. How long we keep it
- Your content — until you delete it, or until you delete your account. We keep it while you have an account because the entire point of a second brain is that it does not forget.
- Deleted items — removed from live systems promptly, and from encrypted backups within 30 days.
- Recordings — kept so you can play them back, until you delete the note. With the next app update (Mac 1.20, iPhone 3.2), deleting a note deletes its recording, photos and attachments with it, and a “Delete recordings after transcription” setting removes the audio from our servers the moment the transcript is ready. Until then, write to us and we delete recordings on request.
- Diagnostic logs — contain no note content, and are deleted after 30 days.
- Your account — deleting it removes your notes, recordings, transcripts, tasks and profile.
- Purchase and tax records — retained as long as accounting law requires, which in Bulgaria is generally up to 10 years, even after account deletion.
- Analytics events — retained in pseudonymous form and not used to reconstruct your notes.
10. Analytics, cookies and ads
Our website sets only what it needs to function until you choose otherwise. We ask before loading Meta’s advertising tools, and if you decline, the site works exactly the same.
In the apps, product analytics are off until you agree to them, and can be switched off again at any time in settings. Analytics tell us which features get used; they never carry your note content. On iPhone, Apple’s tracking prompt governs advertising identifiers separately, and declining it is respected.
11. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can withdraw consent at any time, which does not affect what we did before you withdrew it.
You can delete your account and its contents from inside the app at any time — no email required. For a copy of your data, write to privacy@maicontext.com and we will send it in a portable format.
We answer within one month. If you think we have handled your data badly, please tell us first — but you have the right to complain to a supervisory authority, and ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), Sofia, Bulgaria — cpdp.bg. You may also complain to the authority where you live.
12. Security
Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated, and the database enforces row-level rules so one account cannot read another’s content. Direct database access by our own team is logged. Error reports and diagnostic logs never contain your content. Sign-in uses a one-time emailed code rather than a password, which removes an entire category of breach. The full picture — who can read what, which provider sees which data, and what we do not have yet — is on the security page.
No system is perfectly secure. If a breach ever affects your rights, we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.
13. Children
MAI is not for children. You must be at least 16 to use it, or older if your country sets a higher age for consenting to online services. We do not knowingly collect data from children; if you believe a child has given us data, write to us and we will delete it.
14. Changes
We will update this policy as the product changes. The date at the top always reflects the current version, and we will tell you in the app or by email before any material change takes effect.
15. Contact
Inteli Seko EOOD, 5 Ivaylo Petrov Street, Sofia, Bulgaria
Privacy and legal: privacy@maicontext.com
Support: ivo@maicontext.com
See also our Terms of Service.