Mafdet AI Help Center中文

Privacy Policy

Last updated: 2026-07-20

This Privacy Policy explains how Shanghai Jing'an District Mafdet Software Development Studio, doing business as Mafdet AI ("Mafdet," "we," or "us"), handles personal data when you visit mafdet.ai and its subdomains or use the Console, Playground, APIs, MCP Server, Agents, and related tools (collectively, the "Service"). The Service is intended for users aged 18 or older.

1. Our role

For account, platform-security, usage, and product-operations data, we generally act as the Service operator that determines why and how the data is processed. Paddle independently processes payment and tax data as merchant of record. Third-party model, search, email, and infrastructure providers may process data under their own terms.

If you use the Service for an organization, organization administrators can manage members, permissions, and organization resources and may view account and usage information relating to that organization.

2. Data we process

  • Account and organization data: email address, password hash, verification state, account status, organization membership, role, and preferences.
  • Authentication and security data: session cookie, registration and request IP addresses, user agent, login and security events, rate-limit records, correlation IDs, and machine-readable reasons for promotional-credit or risk decisions.
  • Billing and commercial records: wallet balances and transactions, order number, purchase amount, subscription state, plan, billing period, refund, and dispute state. Paddle handles full card and payment credentials; we do not store them.
  • API and Playground usage metadata: time, model/provider, request state, token counts, cost and charge, latency, error category, API-key ID, organization, billing mode, and service surface. API-key plaintext is shown only at creation; the server stores a one-way verification value and necessary prefix.
  • Playground content: session messages, settings, and generated artifacts that you choose to save so sessions can be reopened across devices. Deleting a session removes that content from the active database.
  • BYOK data: provider, label, key prefix, status, and encrypted provider credential. Plaintext credentials are decrypted server-side only when necessary to process a request and are never returned by list endpoints.
  • Support and feedback: feedback, refund requests, order numbers, support email, and our replies. Do not submit passwords, full API keys, or full payment-card information.
  • Local device data: the Console uses a necessary HttpOnly session cookie. Browser local storage may keep language, sign-in marker, and active-organization selection. We currently use no third-party advertising cookies and perform no cross-site advertising profiling.

3. How request content is handled

For API requests sent to api.mafdet.ai/v1/*, Mafdet does not write prompt or model-response bodies to the business database or application logs. During a request, content is forwarded through Mafdet to the provider you select and is not persisted in Mafdet's business systems after response delivery and metering.

Important distinctions apply:

  • Playground sessions you choose to save persist until you delete the session or close the account;
  • uploaded files are parsed in memory to construct a request; Mafdet does not persist the original file or extracted text;
  • when web search or an external tool is enabled, the query or necessary context is sent to that tool provider; Mafdet does not write the search-query body to business usage logs;
  • a provider may retain or review requests according to its product, account type, and policy. BYOK requests are governed by your provider contract; MANAGED requests use provider products configured by Mafdet.

Unless expressly agreed otherwise, we do not use API request bodies to train a Mafdet proprietary model.

We process data to:

  • create accounts, authenticate users, and provide the requested Service;
  • route model requests and operate metering, billing, subscriptions, and refunds;
  • prevent fraud, abuse, credential exposure, and unauthorized access;
  • troubleshoot, monitor reliability, provide support, and maintain audit records;
  • comply with tax, accounting, dispute-handling, and other legal obligations;
  • improve product experience, pricing, and capacity planning, generally using aggregated or de-identified data; and
  • obtain consent where required, such as before introducing optional cookies or certain marketing communications.

Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests, compliance with legal obligations, and consent. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

5. Recipients

We share data only as needed to provide the Service, comply with law, or protect rights:

  • model providers, which receive content and parameters needed to fulfill the selected model request;
  • your BYOK provider, which receives requests made using the credential you authorize;
  • Paddle, the merchant of record for checkout, taxes, receipts, subscriptions, refunds, and disputes;
  • Resend, for verification, billing, security, and operational email;
  • Cloudflare, for DNS, TLS, proxying, and network security;
  • cloud-hosting and database infrastructure, which hosts the Service and backups; the primary production Service currently operates in Tokyo, Japan;
  • search and tool providers, which receive necessary query or context only when you enable the relevant capability; and
  • professional advisers, regulators, or law enforcement, where legally required or necessary to handle a dispute or protect legal rights.

We do not sell personal data or share it for third-party cross-context behavioral advertising.

6. International processing

Model and other service providers may process data outside your country or region. We select and manage providers using available contractual, access-control, and security measures. Data-protection standards vary by location; review a provider's privacy policy and data-region options before selecting it.

7. Retention and deletion

We keep data only as long as needed for the purposes above:

  • account, organization, and configuration data generally remains until account closure;
  • Playground sessions remain until you delete the session or close the account;
  • usage, wallet, transaction, subscription, refund, audit, and security records are retained as needed for billing, fraud prevention, accounting, disputes, and legal obligations;
  • support and feedback records remain until resolution and for a reasonable period afterward to handle follow-up disputes; and
  • operational logs and backups follow operational rotation schedules. Data deleted from active systems may remain in restricted backups until those backups rotate, unless law requires longer retention.

When data is no longer needed, we delete, anonymize, or isolate it. Some billing, anti-fraud, and legal records cannot be deleted immediately on request.

8. Your choices and rights

Depending on applicable law, you may request to:

  • access or receive a copy of personal data;
  • correct inaccurate data;
  • delete data or close the account;
  • restrict or object to certain processing;
  • receive portable data;
  • withdraw consent; and
  • complain to your local data-protection authority.

Contact [email protected] from your account email. To protect the account, we may verify identity and organization authority. We generally acknowledge and handle requests within 30 days; complex requests or circumstances permitted by law may take longer.

9. Security

We use measures including TLS, HttpOnly session cookies, access controls, key hashing, encryption at rest for BYOK credentials, log redaction, rate limits, backups, and audit records. No system can guarantee absolute security. If you suspect an account or credential exposure, revoke the credential immediately and email us with [SECURITY] in the subject.

10. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their personal data. Contact us if you believe a child has provided data so that we can delete it.

11. Changes to this Policy

We may update this Policy. We will provide advance notice of material changes through the site, in-product notice, or your account email and update the date above. Where required by law, we will request consent.

12. Contact

The Service is provided by Shanghai Jing'an District Mafdet Software Development Studio under the Mafdet AI brand. Send privacy requests, complaints, or security questions to [email protected].