Effective date: 2026-09-05
Who we are: Good Machines LLC, a Maryland limited liability company (“Good Machines”, “we”, “us”), makes Mitamaton. Contact us at justin@goodmachines.ai.
This policy explains what Mitamaton collects, why we use it, who receives it, and how long we keep it. The short version is simple: we use your data to run the features you choose. We do not sell it, use it for advertising, or track you across other apps or websites.
| Data | When we collect it | Why we use it |
|---|---|---|
| Account, profile, and persona data | When you sign in, set up Mitamaton, or change preferences | To identify your account and personalize the service. This can include your email address, display name, time zone, assistant name and pronouns, tone or behavior preferences, derived profile fields, and dashboard layouts. Your name can come from what you type during setup or from the sign-in provider you chose. |
| Messages and durable memories | When you chat or ask Mitamaton to remember something | To answer, preserve conversation history, and use details across sessions. Conversation records include your message text and the assistant’s reply. |
| Captures and transcripts | When you save a note, meeting capture, or dictated capture | To organize what you captured and create summaries, action items, and keywords. We collect the title, text or audio transcript, duration, source, and generated results. Mitamaton does not upload or store the raw audio recording. |
| Capture searches | When you search your saved captures | To rank your own captures against what you typed. The words you search are sent to our service with your account’s token. The service scores the matches in memory and does not store the query, and our application server runs with request logging turned off. |
| Photos attached to a chat | When you choose photos for a message | To answer that message. The server sends the attachment to the selected AI route for that request, but does not add the image to server conversation history. |
| Calendar events and reminders | Only when you grant access or connect a calendar | To build briefs, find conflicts, provide commute context, and help with actions you approve. This can include titles, times, duration, location text, and reminder status. |
| Email data | Only when you connect Gmail | To read and triage messages, surface important threads, learn the writing style you request, and prepare app-local reply suggestions. This can include message and thread identifiers, sender details, subject, snippet, classifications, suggestion text, and action history. Mitamaton does not create, modify, or send Gmail messages. |
| Subscription charges named in your mail | Only when you connect Gmail, and only where we have enabled the trial watcher for your account | To warn you before a free trial turns into a paid charge. The watcher reads the subject, sender, and preview text of new mail, and where those are not enough it reads the full text of that one message once, to confirm the trial. It keeps a record when a message names a free trial together with a labeled end date, and it stores the conversion price as well when the message states one. That record holds a provider name taken from the sender, which is the display name on the message or, where the sender gave none, the sender’s email domain, together with the trial end date, the amount in cents where the message named one, the currency, a confidence score, and the Gmail message id. These records have two uses. One is a reminder in the three days before the charge. The other is the Gmail card you see when you first connect Gmail, which says how many of these trials end within the next thirty days and carries their provider, end date, and amount in the card’s own data. We do not read balances, statements, or account numbers. The app does not forward purchase data to any other service today. If that changes, this policy will say so before the change is enabled. |
| Writing style and routine profile | Only when you separately accept Writing and routines analysis | To make drafts sound more like you and make briefs fit the shape of your week. One bounded scan can analyze up to 300 messages from the previous 90 days (up to 200 from your mailbox and up to 100 from Sent, reading message metadata only, never bodies), the previous 90 days of connected Google Calendar history, and aggregate Apple Reminders completion patterns. We store derived writing descriptors, cadence statistics, relationship signals, reminder counts and rates, and later draft-edit refinements. This scan does not store raw email bodies, verbatim writing examples, calendar event records, reminder titles, or reminder notes in the profile. |
| Contacts | Only when you grant access | To resolve who you mean. We collect names, email addresses, and phone numbers, not contact notes, birthdays, postal addresses, organizations, photos, or relationships. |
| Health and activity data | Only when you grant Apple Health access and enable sharing | To provide health-aware context and briefs. This can include sleep minutes, heart rate variability (HRV), resting heart rate (RHR), workout type, date and duration, steps, active energy, and exercise minutes. |
| Approximate home location | Only when you grant location access and choose to set a home base | To provide weather and commute context. Your device rounds both coordinates to two decimal places before the app sends them, which is roughly a one kilometer grid, so the precise coordinate never reaches our servers. Our service rounds to the same two decimals again when it stores the value, and once more when it reads it back. A home base also carries a short label. That label is the city and region only, such as “Baltimore, MD”. It is never a street address and never a postal code, whether you set the spot from your current location or from your own contact card. |
| Connected-service credentials | When you connect Google, Microsoft, ChatGPT/Codex, or another available source | To access only the connected features you request. This can include encrypted OAuth access and refresh tokens, account identifiers, scopes, and expiration metadata. |
| Notifications | When you enable notifications | To deliver and manage alerts. We collect the Apple Push Notification service device token, environment, notification preferences, time zone, recent notification content, delivery status, and errors. |
| Account and device identifiers | Whenever the app talks to our service | To route a request to the right account and the right device. Our identifier for you is the account id issued at sign-in, which travels in the sign-in token on every request. The device-scoped identifiers are the Apple push token, a random per-install identifier the app generates and keeps on the device for setup measurement, and the vendor identifier iOS assigns to this app. Mitamaton does not use the iOS advertising identifier, does not ask for one, and never shows the app-tracking prompt. |
| Usage and purchase records | As you use the service or subscribe | To enforce plan limits, operate features, diagnose failures, and unlock paid access. This can include action type, task, units, model route metadata, timestamps, and current RevenueCat entitlement, product, and expiration status. Apple handles payment details. |
| Setup and product events | From first launch, including before you sign in | To measure how far people get through setup and where they stop. The app sends named events, such as opening the app or finishing a setup step, tagged with the random per-install identifier described above. This measurement is not covered by the cloud data-sharing setting and starts before an account exists. The app deliberately sends no sign-in token with these events, so they are recorded against the per-install identifier rather than your account. They are never used for advertising and are never joined to data from other apps. |
| Crash and performance diagnostics | Only on builds where we have switched crash reporting on | To find and fix crashes, hangs, and slow screens. See the Diagnostics section below for what a report contains and what is stripped out of it before it is sent. |
| Device-action history | When Mitamaton prepares or runs an action on your device | To show pending work, request review where required, and record completion or failure. This can include the action type, payload, source, review status, result, error, and timestamps. |
Account data is required for signed-in features. Every connected source and device permission is optional. For optional device sources, the app asks for the matching permission and data-sharing consent before it uploads the data. The two exceptions, both named in the table above, are the setup and product events, which start at first launch, and crash and performance diagnostics, which carry no account identity at all.
We use a small set of service providers:
store to false. OpenAI’s model-improvement handling follows your OpenAI
plan and data controls.Each recipient must protect personal data to the same or an equal level as this policy and Apple’s requirements, and may use it only to provide the service we asked it to provide.
We do not sell personal data or share it with advertisers or data brokers.
AI requests can contain your message and only the context needed for the task, such as a relevant calendar item, email, health observation, or saved memory. OpenRouter and its downstream model provider process that data to generate the requested result.
When an OpenRouter request can contain Google-sourced data, Mitamaton sets
OpenRouter’s per-request provider.data_collection control to deny and its
zero-data-retention flag to true. This restricts routing to providers that do
not collect or retain the request data. We use these controls to enforce that
Google-sourced data is not used to develop or train generalized AI models.
That OpenRouter control does not govern the separate, optional ChatGPT/Codex
route. The route sets store to false, but OpenAI says content from consumer
ChatGPT and Codex plans may be used to improve models unless the user opts out
through OpenAI’s data controls. You can review OpenAI’s data-use explanation
and disconnect ChatGPT/Codex at any time.
The trial watcher described above is deliberately not an AI feature. It matches fixed patterns on the device text it is given and never sends that mail to a model.
Mitamaton’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide the features you request, such as calendar briefs, email triage, and app-local reply suggestions. Good Machines does not use Google API data to develop or train generalized AI models.
Health data is used only for the health-aware features described here. We do not use it for advertising or marketing, sell it, or give it to another party for that party’s own purposes.
Crash reporting is off in every build unless we supply a reporting key when we build it. Where it is on, the app sends crash reports, app-hang and unexpected-termination reports, and one in five of its performance traces, to Sentry. A performance trace covers an event such as app start or a screen load, and the network calls made during that event are recorded as steps inside it.
These reports are not linked to your account, and that is a property of what the app sends rather than a promise about what Sentry does with it:
What a report does still carry is the device model, the operating system version, and the app version and build, which are the same for every install of a given build.
Separately, iOS gives the app aggregate power and performance metrics about itself. Those are shown on the device and are never uploaded.
| Category | Retention rule |
|---|---|
| Account, profile, persona, and generated service records | Kept until you replace them or delete your account. Database rows tied to your account are deleted when the account is deleted. |
| Conversation text | Kept until account deletion. Chat photo attachments are processed for the request and are not stored in server conversation history. |
| Durable memories | Kept as active until you ask Mitamaton to forget them or delete your account. A forgotten memory stops being used, but its inactive record remains until account deletion. |
| Captures | The service keeps up to the 500 most recent captures. A capture remains until you delete it, it rolls out of that limit, or you delete your account. Raw audio is not kept by Mitamaton. |
| Capture search queries | Not kept. The query is used to rank the results of that one request. |
| Contacts | Each full sync replaces the prior contact snapshot. The snapshot remains until the next sync, you clear contacts from the service, or you delete your account. |
| Calendar, reminder, and email records | Daily device-source snapshots and server-side email records remain until account deletion unless a feature replaces or explicitly removes them. Disconnecting a source stops future access but does not by itself promise removal of records already derived or saved. |
| Trial watch records | One record per source message, replaced rather than duplicated if that message is scanned again. Records remain until account deletion. |
| Writing style and routine profile | Kept until you withdraw this separate consent or delete your account. Withdrawing clears the derived profile and refinement notes while retaining the consent status and audit timestamps. |
| Health and activity | Stored sleep, heart rate variability, resting heart rate, and workout observations are updated by date and type and remain until account deletion. Live steps, active energy, and exercise minutes may be sent as current context without becoming a durable health row. |
| Approximate home location | Kept until you replace it or delete your account. |
| OAuth credentials | Kept until you disconnect the source, the credential is replaced, or you delete your account. |
| Push token and notification data | The token and preferences remain until replaced or account deletion. The service keeps up to the 100 most recent notification-history entries. |
| Usage and purchase status | Daily usage records remain until account deletion. The current plan snapshot is replaced when subscription status is synchronized and is deleted with the account. |
| Setup and product events | Deleting your account deletes these rows. Our service removes every row that carries your account id and, on current app versions, also the rows written on that phone before you signed in, which the app identifies by sending its per-install identifier with the deletion request. Both removals have to succeed before the account itself is deleted, and rows recorded on the same phone under a different account are left alone. Older app versions send no install identifier, so on those only the rows carrying your account id are removed. The app generates a new per-install identifier as soon as our service confirms the deletion, so what is measured on that phone afterwards cannot be joined to what came before. Where we have configured PostHog, a copy of these events already forwarded to it is held on that service’s own schedule and is not reached by deleting your account. |
| Crash and performance diagnostics | Held by Sentry under its own retention schedule. Because these reports carry no account identity, we cannot look one up by account and deleting your account does not reach them. |
| Device actions | Pending actions remain until completed, failed, or account deletion. Completed and failed actions become eligible for removal after seven days and are pruned on a later device poll. If no later poll occurs, they remain until account deletion. |
You can:
Account deletion deletes the account, account-linked database rows, files on our application server, and our copies of linked-service credentials. It deletes our stored tokens and revokes provider authorization where supported. This now includes the setup and product events described above: the rows carrying your account id are deleted, and on current app versions so are the rows written on that phone before you signed in. The app generates a new per-install identifier the moment our service confirms the deletion, so measurement on that phone starts over. Deletion is permanent. What deletion does not reach is named in the retention table: crash reports, which never carried your identity, and any copy of setup and product events already forwarded to PostHog, which is held on that service’s own schedule. Deleting a Mitamaton account does not cancel an App Store subscription. Billing continues through Apple until you cancel it in your Apple Account settings.
If the Maryland Online Data Privacy Act applies to your request, you may ask to:
Email justin@goodmachines.ai with the subject Privacy Request. Include the account email, the right you want to exercise, and enough information for us to verify the request. An authorized agent may submit a request with proof of authority. We will use the request information only to verify and answer the request. We will respond within 45 days of receiving a verifiable request, and may extend that period once by 45 days when reasonably necessary, with notice to you.
If we refuse to act, email the same address with the subject Privacy Appeal and explain why you want the decision reviewed. We will answer the appeal in writing within 60 days and, if we deny it, provide a way to contact the Maryland Attorney General.
We will not discriminate against you for exercising a privacy right. We do not sell personal data or use it for targeted advertising, so there is no sale or targeted-advertising opt-out needed today.
Data travels over encrypted connections. Connected-service credentials are stored server-side in an encrypted vault. We limit each feature to the access needed to provide it. No security measure is perfect, but we work to protect data from unauthorized access, use, and disclosure.
Mitamaton is not directed to children under 13. We do not knowingly collect personal data from a child under 13. Contact us if you believe a child provided personal data so we can review and delete it.
Mitamaton is currently offered only in the United States.
If this policy changes in a material way, we will give notice in the app or by email before the change applies. The current version will remain at this URL with its effective date.
Privacy questions and requests: justin@goodmachines.ai.