MAISIGHT REV 01

BLUEPRINT · LEGAL / PRIVACY

Privacy Policy

Effective 2026-08-15. Back to the legal pack.

This document has not yet been reviewed by counsel and is not legal advice.

It is drafted from a standard SaaS template and states our actual practice. The governing legal entity name and notice address are still to be finalized. Contact for anything in this policy: codeblackwell@gmail.com.

The short version, for the reviewer who has twenty more of these to read today: mAiSight sets no cookies, retains no IP addresses, stores no raw User-Agent or Referer, builds no cross-site profile, and sells nothing to anyone. There is a one-page version of this at /privacy.

1. Who this covers

This policy covers two different groups of people, and the distinction matters throughout.

2. What we collect from customers

Data Why Basis
Account details — name, work email, organization, password credentials To create and secure your account and to contact you about the Service Performance of a contract
Billing details — plan, billing contact, payment status To charge you and meet accounting obligations Contract; legal obligation
Documentation you submit and the glossaries built from it To deliver the Service Contract
Support correspondence To answer you and to keep a record of what was said Contract; legitimate interests
Server and application logs To keep the Service running and to investigate abuse Legitimate interests

Card numbers are handled by our payment processor. We never see or store a full card number.

3. What we do not collect from readers

This section is the point of the policy. When the mAiSight widget runs on a page, it does not collect any of the following:

What is recorded is behavior about the document: that a given term was hovered, that a definition was opened, roughly how long a section held attention. Events are aggregated as they are written, and the customer dashboard can only read aggregates — it has no path to individual events.

Both properties are enforced by automated tests in our public repository rather than by policy alone: one asserts that no personal data reaches an analytics event, the other that the dashboard cannot read raw events. A change that broke either would fail the build.

mAiSight adds no cookies and collects no personal data, so it adds nothing to your consent banner.

That sentence is about our software. It is deliberately not a claim that your overall deployment complies with GDPR, ePrivacy, CCPA, or anything else — that depends on the rest of your site, which we know nothing about. Treat it as one line removed from your data map, not as a compliance certificate.

4. Cookies

The widget uses none. The mAiSight application itself uses only what is strictly necessary to keep a signed-in customer signed in. There is no analytics cookie, no advertising cookie, and no third-party tag anywhere in the product.

5. Language models

Building a glossary requires sending document text to a language model. By default this is a hosted model used under a zero-retention arrangement, meaning the provider does not retain the text after the request. Customers may instead configure extraction against any OpenAI-compatible endpoint, including a model running inside their own network — in that configuration no third-party model provider receives the text at all.

We do not train any model on customer documentation.

6. Sharing

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it for anyone else's marketing. We share data only with the service providers listed on the subprocessors page, each under contract and only as needed to run the Service; where a law or valid legal process compels disclosure, and we will notify you unless we are prohibited from doing so; and with a successor in a merger or acquisition, under this same policy.

7. Where data is stored

Application data — documents, glossaries, aggregates, account records — is hosted in the European Union (Falkenstein, Germany). Some subprocessors operate in the United States; the subprocessors page names each one and its region. Transfers out of the EEA and UK rely on Standard Contractual Clauses with the relevant provider.

8. Retention

9. Security

Data is encrypted in transit. Customer-issued credentials for connected sources are encrypted at rest, held separately from their decryption key, rotated on a fixed cadence, and destroyed when the source is deleted. Our threat model, and what it explicitly does not cover, is published on the security page. We hold no third-party security certification and do not claim one.

10. Your rights

Depending on where you live you may have rights to access, correct, delete, port, or restrict the personal data we hold about you, to object to processing based on legitimate interests, and to complain to a supervisory authority. Exercise any of them by emailing codeblackwell@gmail.com; we will respond within 30 days.

For readers there is a structural answer rather than a process: we hold nothing keyed to a person, so there is nothing to retrieve or erase. A reader request that reaches us about content on a customer's site is forwarded to that customer, who is the controller.

11. Children

The Service is for organizations and is not directed at children. We do not knowingly collect personal data from anyone under 16.

12. Changes

We will update this policy when our practice changes. Material changes get at least 30 days' notice by email or in the product, and the effective date at the top always reflects the current version.

13. Contact

codeblackwell@gmail.com. A dedicated compliance address and a formal notice address will be published here once the operating entity is finalized.