Legal

Privacy Policy

Last updated: September 14, 2026

This policy explains what data Maax processes, what we deliberately never keep, and the controls you have. It covers the Maax web application at app.maax.app, the Maax desktop application, and this website. Maax is operated by BOOTHIC SMPC, a single-member private company incorporated in Greece, VAT No. EL801264656 ("we", "us").

The short version

  • Audio is never stored. It is transcribed as it streams and discarded. There is no recording — not on your computer, not on ours.
  • Transcripts are never stored. They exist in your window while a session runs and in the transient requests that detect and answer questions. When you press Stop, they are gone.
  • What is kept: your account, the knowledge you give your agents, the gaps (questions your agent could not answer), and a ledger of the credits each request used — never the request's content.
  • Nothing joins your calls, we sell no data, we run no ads, and your content is never used to train AI models.

Our two roles

For the knowledge you give your agents and the calls Maax listens to, you — or the organization you work for — decide why and how that data is processed. Under the GDPR you are the controller and we are your processor: we handle that data only on your instructions, under our Data Processing Agreement. If you took part in a call a Maax user was on and want to exercise rights over your data, the quickest route is that person or organization — and we help them respond.

For a smaller set of data — accounts, billing, usage metering, support messages and this website — we decide how and why, and we are the controller. The rest of this policy covers both roles and says which is which where it matters.

What we process

  • Account data — your name, email address and sign-in method, handled through Clerk, our identity provider; the date you signed up and when you were last seen.
  • Agent knowledge — the Q&A pairs, context paragraph, uploaded files and website pages you add to an agent. Files and pages are indexed for search with Google's File Search; the index and the source records live for as long as the agent does.
  • Call data, in transit only — while a session runs, the audio your computer plays and your microphone stream to Soniox for transcription and are discarded; the transcript is sent, chunk by chunk, to Google's Gemini models to detect questions and hard moments and to produce answers from your agent. None of it is stored by us. What other participants say is included in these transient streams.
  • Gaps — the questions your agent could not answer, saved on the agent with a count of how often they came up, until you answer or delete them.
  • Chat messages — what you type to your agent and its replies, processed transiently and not stored.
  • Usage and metering — a credit ledger with one row per request: the kind of request, the credits it used and when. No content.
  • Billing data — your plan and its status, mirrored from Polar, our merchant of record. Payments happen with Polar; we never see full card numbers.
  • Log data — IP address, browser or app version, timestamps and security logs, kept briefly to run and protect the service.
  • Messages you send us — by email or through the contact form on this site.

What we never do

We never store call audio or transcripts. No bot joins your calls and nothing announces itself to the other side — capture happens on your own computer. We do not sell personal data. We do not use your content, your calls or your gaps to train AI models — ours or anyone else's — and our providers are contractually bound not to. This website carries no advertising and no cross-site tracking.

Why we process it

As your processor, we process agent knowledge and call data on your documented instructions: pressing Start, building an agent, asking a question. Where we are the controller, we rely on: performance of a contract (Art. 6(1)(b) GDPR) to run accounts, credits and billing; legitimate interests (Art. 6(1)(f)) to secure the service, prevent abuse, measure aggregate usage and improve Maax; legal obligations (Art. 6(1)(c)) for tax and accounting records; and consent (Art. 6(1)(a)) where the law requires it — which you can withdraw at any time.

Subprocessors and recipients

We share personal data only with the providers needed to run Maax. Each is bound by a data processing agreement and processes data only to provide its service to us:

  • Clerk (US) — sign-in and account management.
  • Convex (US) — the database holding accounts, agents, Q&A, gaps and the credit ledger.
  • Cloudflare (US / EU) — hosting of the application, its network edge, and storage of the desktop installer.
  • Soniox (US) — real-time speech-to-text; receives the live audio solely to return the transcript.
  • Google (US / EU) — Gemini models that detect questions and generate answers, Q&A and context; File Search, which indexes your uploaded files and crawled pages.
  • Exa (US) — fetches the web pages you ask us to crawl; receives the page addresses.
  • Inngest (US) — runs the crawl and upload pipelines in durable steps; handles page digests transiently while an agent is being built.

For this website only: Web3Forms delivers contact-form messages to our inbox, and Umami Cloud, when enabled, provides cookieless, aggregate analytics.

Polar, our merchant of record, acts for itself rather than for us: it is the seller at checkout and an independent controller of payment data under its own privacy policy.

We update this list on this page and notify you at least 30 days before adding a new subprocessor; you can object as our Data Processing Agreement sets out. We may also disclose data where the law requires it; and if we are ever part of a merger or acquisition, this policy continues to protect the data that transfers.

International transfers

Our subprocessors are mainly in the United States. When personal data leaves the EEA, we rely on the safeguards the GDPR provides for: the EU–US Data Privacy Framework where the provider is certified, and the European Commission's Standard Contractual Clauses otherwise, alongside measures such as encryption in transit and at rest.

Retention

  • Audio and transcripts: not retained at all.
  • Agent knowledge and gaps: until you delete the pair, the page, the file or the agent — or your account.
  • Credit ledger: for the life of your account. Invoices and payment records are held by Polar for as long as tax law requires.
  • Account data: while the account is active. Deleting your account purges your agents, their sources and search indexes, your Q&A, gaps and ledger; the account record at our identity provider is deleted with it.
  • Log data: briefly, on rolling windows, for security and troubleshooting.
  • Contact and support messages: as long as needed to help you.

Deleted data also disappears from backups on their rolling replacement cycle.

Security

Data is encrypted in transit and at rest across the entire pipeline. Sign-in is handled by Clerk; the desktop application keeps your session in its own profile on your computer. Our infrastructure providers hold SOC 2 Type II attestations, and access to production data is limited to the few people who need it to run the service. No system is perfectly secure — if a breach ever puts your rights at risk, we will notify you and the supervisory authority as the GDPR requires.

Cookies

The web application sets only the strictly necessary cookies needed to keep you signed in; the desktop application stores the same session in its own profile. This website sets none: analytics, when enabled, are cookieless, and there are no advertising or cross-site tracking cookies anywhere — which is why you don't see a cookie banner.

Your rights

You can ask for access to your personal data, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent at any time. Most of this you can do yourself: edit or delete any agent content in the app, and delete your account from the Account page. For anything else, write to support@maax.app; we may need to verify your identity, and we respond within one month. If the data lives in a user's agent — for example a gap recorded on a call you took part in — we may refer you to that user, since they control the data, and we will help them respond. You can also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local EU supervisory authority. If you are in California or another jurisdiction with its own privacy law, we honor those rights too — and we do not "sell" or "share" personal information as the CCPA defines those terms.

Children

Maax is a tool for work. It is not directed to anyone under 18, and we do not knowingly process children's data.

Changes

If we make material changes to this policy, we will notify you — by email or in the app — before they take effect.

Contact

BOOTHIC SMPC — single-member private company incorporated in Greece
29 Tavoulari Str., Greece · GEMI No. 153029403000 · VAT No. EL801264656
Operating Maax · support@maax.app