Privacy Policy
Who we are: Good Machines (“we,” “us”), the maker of Mitamaton, an iOS app with a built-in assistant. Contact: justin@goodmachines.ai.
This policy explains what Mitamaton collects, why, where it goes, and how you delete it. The short version: your data is used only to run the features you turn on. Nothing is sold. Nothing is used for advertising.
What we collect and why
| Data | When | Why |
|---|---|---|
| Email address | When you create an account (Sign in with Apple or Google) | To sign you in and keep your data attached to you |
| Messages and notes | When you type or dictate to the assistant | So it can understand you and reply |
| Calendar events | Only if you allow calendar access | To build your daily brief and spot conflicts |
| Email content | Only if you connect Gmail | To surface what matters in your inbox and draft replies you approve |
| Contacts (names, email addresses, phone numbers) | Only if you allow contacts access | To resolve who you mean when drafting messages |
| Health data (sleep and activity, via Apple Health) | Only if you allow Health access | To tune your morning brief |
| Approximate location (kilometer-level, captured once) | Only if you allow location access | To set a home base for weather and commute context |
| Reminders | Only if you allow reminders access | To surface what you said you’d do today |
| Purchase status | If you subscribe | To unlock paid features |
Every one of these is optional except the account email. Nothing is read until you grant the matching permission, and the app asks before the first time your data leaves your device.
Where your data goes
Mitamaton runs on servers we operate, with a small set of service providers:
- Supabase — sign-in and database hosting (United States).
- Fly.io — application servers (United States).
- OpenRouter — the service that connects the assistant to the AI models that power replies. Your messages, and relevant context from sources you’ve connected, are sent to OpenRouter and processed by the AI model providers it routes to, solely to generate the assistant’s responses.
- RevenueCat — subscription management.
- Apple — push notifications and App Store purchases.
- Google — only if you connect Google Calendar or Gmail, via Google’s official APIs with your OAuth consent.
We do not sell your data. We do not share it with advertisers or data brokers. We do not use it to track you across other apps or websites.
Health data
Data read from Apple Health is used only to power the features described above. It is never used for advertising or marketing, never disclosed to third parties for their own purposes, and never sold.
Google user data
Mitamaton’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide the features you see (calendar briefs, email triage, drafts you approve), is not used to develop or train generalized AI models, and is not transferred except as necessary to provide those features.
Retention and deletion
Your data is kept while your account is active so the assistant can remember context between days. You can:
- Withdraw data-sharing consent at any time in Settings — the app stops sending anything off-device.
- Disconnect any source (calendar, email, health, contacts) at any time.
- Delete your account in Settings → Delete Account. This deletes your account, your conversation history, your stored context, and revokes the connection tokens for every service you linked. Deletion is permanent.
Security
Data travels over encrypted connections (TLS). Access tokens for connected services are stored server-side in an encrypted vault, not on third-party analytics platforms. We follow the principle of least access: each feature can read only what it needs.
Children
Mitamaton is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes in a way that matters, we’ll say so in the app before the change applies. The current version always lives at this URL.
Contact
Questions or requests: justin@goodmachines.ai.