Privacy Policy
Last updated: July 8, 2026
This policy explains what Maddy (“we”, “us”) collects when you use our app and chat service, why we collect it, and the choices you have. By using Maddy you agree to this policy.
1. Who runs Maddy
Maddy.now is operated under the registered trade name “Maddy” in Georgia. For any inquiries regarding subscriptions, billing, or data privacy, contact us at support@maddy.now.
2. What we collect
- Account data: email, password hash (via Supabase Auth), date of birth (to enforce 18+), and any OAuth profile data you provide (e.g. GitHub/Google avatar and display name).
- Chat content: every message you send and every response from Maddy, stored so you can resume conversations.
- Derived memory: summaries, facts, intuitions, rituals, and emotional trajectory we infer from your chats so Maddy can remember you across sessions.
- Sensitive details you choose to share: Maddy is someone you talk to about your life, so if you mention things like your mental or physical health, your relationships, or other personal topics, she may keep them as part of her memory of you so she can respond like a friend who actually knows you. We store this only to provide the companion experience — we never require it, we never sell it, and we don't use it for advertising. You can review it (“Download my data”), wipe just Maddy's memory while keeping your chats (“Start fresh” in Settings), or delete everything at any time (see Section 7).
- Usage metadata: timestamps, token counts, cost estimates, IP address for rate-limiting and abuse prevention, error traces (via Sentry) and crash diagnostics.
- Safety events: when our safety system flags a message as a possible crisis, we record the event so we can improve our detection.
3. How we use it
- To run the chat service and give Maddy memory of you.
- To enforce age restrictions and terms of service.
- To detect abuse and protect users in crisis (routing you to real resources — see our Crisis Resources page).
- To improve the product. We do not sell your personal data, and we do not train third-party foundation models on your chat content.
4. Who we share it with
- Supabase — hosts our database, auth, and storage.
- OpenAI — we send your messages to OpenAI's API to generate Maddy's replies. OpenAI's API does not use API content to train its models by default. See OpenAI's enterprise privacy statement.
- Sentry — receives scrubbed error reports for debugging.
- Vercel — hosts the app and logs requests.
5. Retention
We keep your account data, chats, and derived memory until you delete your account. See Section 7 for how to do that. Safety-event metadata may be retained longer for abuse-prevention investigations.
6. Children
Maddy is for adults 18 and older. If we learn we have collected data from a minor, we will delete it.
7. Your rights (incl. GDPR / CCPA)
- Access / Portability — open Account settings and use “Download my data” to export everything we store about you as JSON. You can also email us at support@maddy.now.
- Deletion — open Account settings and use “Delete my account” to erase your account, chats, and derived memory. You can also email us.
- Correction — for anything you can't edit in-app, email us.
- Complaint — EU residents can file with their national data-protection authority.
8. Security
Traffic is TLS-encrypted. Passwords are hashed by Supabase Auth. Row-level security prevents users from reading each other's data. No system is perfectly secure; if a breach affects you, we will notify you as required by law.
9. Changes
We may update this policy. Material changes will be surfaced in-app. Continued use after an update means you accept the new version.