MIOSA MIOSA Trust
DocsDashboardStatusAPI health

Legal

Privacy Policy

This policy explains what personal data MIOSA collects, how we use it, who we share it with, and the rights you have over it. It replaces the earlier version published at miosa.ai/privacy, which now redirects here.

Last updated: October 10, 2026 Effective: October 10, 2026

1. Introduction and scope

1.1 MIOSA (“MIOSA,” “we,” “us,” or “our”) is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy describes how we collect, use, store, share, and protect information about you when you use the MIOSA platform, including all associated websites, applications, and services (collectively, the “Platform”).

1.2 This policy applies to all users of the Platform, including visitors who browse our marketing site without creating an account, registered users, and customers on paid plans.

1.3 This policy should be read together with our Terms of Service, which govern your use of the Platform and are incorporated by reference.

1.4 MIOSA operates as the data controller for personal data collected through the Platform as described in this policy.

2. Information we collect

2.1 Information you provide directly

Account registration data: your full name or display name, email address, password (stored as a salted cryptographic hash; we never store plaintext passwords), profile photo (if provided), organization name (for organizational accounts), and billing address and payment method details (collected and processed by our third-party payment provider).

Profile and preference data: account preferences and settings you configure, subscription and plan selections, and communication preferences such as marketing opt-in/opt-out.

Support communications: messages, emails, or chat logs you send to our support team, and bug reports, feature requests, or other feedback you submit.

2.2 Information collected through OAuth

If you register or log in using a third-party OAuth provider (currently GitHub or Google), we receive the following data from that provider, subject to the permissions you grant: your name and email address as registered with that provider, a unique provider-assigned user identifier, and a profile picture URL (if available). We do not receive your OAuth provider password, and we do not receive access to your private repositories, emails beyond the authenticated address, or any data beyond what is necessary for account creation and authentication.

2.3 Usage and analytics data

We automatically collect certain data about your interactions with the Platform:

  • Pages visited, features accessed, and buttons clicked (platform interaction data).
  • Workload metadata: creation time, last active time, workload type, template used, and resource consumption (CPU hours, storage used, network egress). This is metadata only, not the content of your workloads.
  • API request logs: timestamps, endpoints accessed, HTTP status codes, and response times.
  • Error logs and crash reports.
  • Session duration and frequency of use.
  • Browser type, operating system, screen resolution, and device type.
  • IP address at time of login and session establishment.

2.4 Information we do not collect

  • Workload content. We do not read, scan, or process the files, documents, code, databases, or other content stored within your Sandboxes, Computers, or other workloads. Your workload content is private to you.
  • Agent conversation content. We do not read or store the content of conversations between your AI agents and third-party model providers. Prompts and responses travel directly between your workload and the provider.
  • Keystrokes or screen captures. We do not record keystrokes, capture screenshots, or monitor your in-workload activity.
  • Third-party account passwords. We do not receive or store passwords to any third-party services you access from within a workload.
  • Sensitive personal data by default. We do not require or intentionally collect health data, financial account numbers, government identification numbers, or similar sensitive categories of personal data for Platform operation.

If you voluntarily include any of the above in a support request or feedback submission, it will be handled with appropriate care and not used for any purpose beyond resolving your inquiry.

3. How we use your information

3.1 Account management and service delivery: creating and managing your account, authenticating your identity, provisioning and managing your workloads, and delivering the features of your subscription plan.

3.2 Billing and payments: processing subscription payments through our payment provider, calculating usage-based charges, sending invoices and receipts, managing subscription upgrades, downgrades, and cancellations, and detecting and preventing fraudulent transactions.

3.3 Platform improvement: understanding how users interact with the Platform, identifying bugs and reliability issues, developing new features, and conducting internal research and analytics using aggregated, de-identified data where possible.

3.4 Security and abuse prevention: detecting and preventing unauthorized access, fraud, and abuse, enforcing our Terms and Acceptable Use Policy, investigating security incidents, and complying with law enforcement requests where legally required.

3.5 Communications: sending transactional emails (account confirmation, password reset, billing receipts, account alerts), service updates and security alerts, marketing communications only where you have opted in and which you may opt out of at any time, and responding to support requests.

3.6 Legal and compliance: complying with applicable laws, responding to valid legal process, establishing, exercising, or defending legal claims, and maintaining records required by law.

4. Legal basis for processing (GDPR)

For users in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases:

Processing activityLegal basis
Account creation and managementPerformance of a contract (Art. 6(1)(b) GDPR)
Service delivery and workload provisioningPerformance of a contract (Art. 6(1)(b) GDPR)
Billing and payment processingPerformance of a contract (Art. 6(1)(b) GDPR)
Security and fraud preventionLegitimate interests (Art. 6(1)(f) GDPR)
Platform analytics and improvementLegitimate interests (Art. 6(1)(f) GDPR)
Marketing communicationsConsent (Art. 6(1)(a) GDPR) — withdrawn at any time
Legal complianceLegal obligation (Art. 6(1)(c) GDPR)

5. Data storage and infrastructure

5.1 Own infrastructure. MIOSA runs customer workloads on bare-metal servers in data centers we operate and manage ourselves, in the United States. We do not resell a hyperscaler's infrastructure for customer workloads.

5.2 Encryption at rest. Sensitive values we hold, including credentials, secrets, API keys, and environment variables, are encrypted at rest before they are written. They are decrypted only at the boundary where they are needed and are never returned in plaintext through the API or UI.

5.3 Encryption in transit. All data transmitted between your devices and MIOSA services is encrypted using TLS. We enforce HTTPS for all Platform endpoints and do not support unencrypted HTTP connections.

5.4 Backups. Platform state and managed databases are backed up on a schedule, and restore paths are exercised. Backups are retained for a limited period and then purged.

5.5 Tenant isolation. Each workload runs in its own virtual machine with a dedicated kernel. One customer's workload cannot access another customer's data or processes.

6. Third-party services and data sharing

We share your data with third-party service providers only to the extent necessary to operate the Platform and deliver our services. We do not sell your personal data to any third party. The current list of subprocessors, with purpose and data category, is published at miosa.ai/legal/subprocessors.

6.1 Email delivery. We use a third-party provider to deliver transactional and account email. The data shared is your account email address and the content of the message.

6.2 Error tracking. We use a third-party error-tracking service to monitor application health. Sensitive fields are redacted before events are sent.

6.3 Payments. Subscription billing, payment processing, invoicing, tax handling, and fraud detection are handled by Commas (FanBasis, Inc. d/b/a Commas), our third-party payment provider, which acts as merchant of record. We share your name, email, billing address, and payment method details. MIOSA does not store your full card number or CVV; card data is handled exclusively by Commas. Commas' privacy policy is at commas.com/privacy-policy.

6.4 Authentication. “Sign in with Google” and “Sign in with GitHub” are optional OAuth providers. On login we receive your name, email address, and public profile data. You may register with email and password instead.

6.5 Model providers for AI inference. Agents and the documentation assistant can call third-party model providers, including Anthropic, OpenAI, Google (Gemini), Groq, Mistral, DeepSeek, OpenRouter and a local Ollama runtime. When you configure a provider, your prompts and context are transmitted to that provider for inference, using keys you provide. MIOSA does not log, store, or read the content of those prompts and responses. Your data is also governed by that provider's policy when you use it.

6.6 Legal disclosure. We may disclose your information to law enforcement, government agencies, or other third parties when required to do so by law, court order, or governmental regulation, or when we believe disclosure is necessary to protect the rights, property, or safety of MIOSA, our users, or the public, and where legally permitted.

6.7 AI and your data. MIOSA operates AI features on a bring-your-own-key (BYOK) basis: you supply the credentials, and you choose the model provider. Prompts and context are sent to the provider you select for inference and are governed by that provider's terms. We do not use your workload content to train AI models, and we do not sell or share it for that purpose. Model providers may have their own retention practices for the requests they receive; review their terms before you send them sensitive data.

7. Data retention

7.1 Active accounts. We retain your account data, including profile information, subscription history, and usage records, for as long as your account remains active.

7.2 Deleted accounts. When you delete your account, we will permanently delete or anonymize your personal data within a reasonable period, except as described below.

7.3 Retention exceptions. Certain data may be retained beyond that period where retention is required by applicable law (for example, financial records required for tax compliance), where the data is necessary to resolve an open support ticket, billing dispute, or legal claim, or where the data has been anonymized and aggregated such that it can no longer be associated with you.

7.4 Workload data. When you terminate a workload or delete your account, the workload's storage volumes are securely deleted on the platform's normal reclamation cycle.

8. Your privacy rights

8.1 All users have the right to access a copy of the personal data we hold about you, to request correction of inaccurate or incomplete data, to request deletion subject to legal retention requirements, to request your data in a structured, machine-readable format, and to opt out of marketing communications at any time.

8.2 EEA, UK and Switzerland. You additionally have the right to restrict processing, to object to processing based on legitimate interests, to withdraw consent where processing is based on consent without affecting the lawfulness of prior processing, and to lodge a complaint with your local supervisory authority.

8.3 California. Under the CCPA and CPRA you have the right to know what personal information we collect, use, disclose and sell, to delete it subject to exceptions, to correct it, to limit the use of sensitive personal information, and to non-discrimination. MIOSA does not sell personal information.

8.4 Other US states. If you are a resident of a US state with a comprehensive privacy law (for example, Virginia, Colorado, Connecticut, Utah, Texas and others), you have rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising and the sale of personal data. MIOSA does not sell personal data or use it for targeted advertising. We will honour verified requests under these laws.

8.5 How to exercise your rights. Contact us at privacy@miosa.ai with the subject line “Privacy Rights Request.” We will respond to verified requests within the time required by applicable law. We may request identity verification before processing a request, to protect your data from unauthorized disclosure.

9. Cookies and tracking

We use a small number of strictly necessary cookies to maintain your authenticated session and to complete SSO logins securely, plus browser local storage to remember preferences such as your theme. We do not use third-party advertising cookies, tracking pixels, social media trackers, or cross-site behavioural analytics. See our Cookie Policy for the full list and how to control them.

10. Children's privacy

The Platform is not designed for, directed at, or intended for use by children under the age of 13 (or under the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under 13. If we become aware that we have collected such data without verifiable parental consent, we will take steps to delete it promptly. If you are a parent or guardian and believe your child has provided personal information to MIOSA without your consent, contact us at privacy@miosa.ai.

11. International data transfers

11.1 MIOSA is headquartered in the United States. If you access the Platform from outside the United States, your personal data will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your home country.

11.2 For transfers of personal data from the European Economic Area or United Kingdom to the United States, we rely on the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, and adequacy decisions where applicable.

11.3 Our data processors operating in the United States either participate in applicable data transfer frameworks or are bound by Standard Contractual Clauses.

12. Security measures

12.1 Technical safeguards. MIOSA implements appropriate technical and organizational measures to protect your personal data, including encryption of sensitive values at rest, TLS encryption of data in transit, per-workload virtual machine isolation, access control on a least-privilege basis for internal systems, multi-factor authentication for administrative access, and ongoing security testing. Our controls are described in the Trust Center.

12.2 Organizational safeguards. We maintain internal security policies, train employees on data protection, and limit access to personal data to employees who need it to perform their job functions.

12.3 No absolute guarantee. Despite our efforts, no security system is impenetrable. We cannot guarantee that unauthorized parties will never be able to defeat our security measures.

12.4 Your responsibilities. You are responsible for maintaining the security of your account credentials. Use a strong, unique password and enable multi-factor authentication.

13. Data breach notification

13.1 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, MIOSA will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33 and applicable law.

13.2 Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users directly without undue delay, including a description of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address it.

13.3 Notification will be sent to the email address associated with your account, and, where contact information is unavailable, made publicly available through our status page at status.miosa.ai.

14. Privacy by design

14.1 MIOSA applies privacy by design: we consider privacy implications at the design stage of new features rather than as an afterthought.

14.2 We apply data minimization, collecting only the personal data we actually need to provide the service, and we use aggregated and anonymized data for analytics where possible.

15. Changes to this policy

15.1 We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements.

15.2 For material changes, we will notify you at least 30 days before the change takes effect by email to the address associated with your account and by a prominent notice in the dashboard.

15.3 For minor changes, we may update the policy without prior notice but will update the “Last updated” date at the top of this document.

15.4 Your continued use of the Platform after the effective date of any change constitutes your acceptance of the updated policy.

16. Contact

For questions, concerns, or requests regarding this Privacy Policy or our data practices:

MIOSA
Privacy Team
Email: privacy@miosa.ai

You also have the right to lodge a complaint with your local data protection supervisory authority: your national authority in the EU, the Information Commissioner's Office in the UK, and the California Privacy Protection Agency in California.

17. Definitions

  • Personal data means any information relating to an identified or identifiable natural person.
  • Processing means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • Data controller means the entity that determines the purposes and means of processing personal data. MIOSA is the data controller for data collected through the Platform.
  • Data processor means an entity that processes personal data on behalf of a data controller.
  • GDPR means the General Data Protection Regulation (EU) 2016/679.
  • CCPA/CPRA means the California Consumer Privacy Act and California Privacy Rights Act.
Questions? legal@miosa.ai All policies →
MIOSA MIOSA

Documentation for building, running and shipping on MIOSA.

Subscribe to updates

Get started

  • Introduction
  • Quickstart
  • Authentication
  • Learning paths
  • First production app

Products

  • Sandboxes
  • Computers
  • Agents
  • App Engine
  • Databases
  • Storage
  • Domains

Developers

  • SDKs overview
  • TypeScript
  • Python
  • Go
  • Rust
  • Elixir
  • Java
  • CLI
  • MCP
  • API reference

Platform

  • Workspaces
  • Members
  • White-label
  • Billing
  • Security
  • Benchmarks

Resources

  • Changelog
  • Docs for LLMs
  • Full context
  • Status
  • Pricing
  • GitHub
  • Discord
  • LinkedIn
  • Instagram
  • Contact support

Legal

  • Trust Center
  • Terms
  • Privacy
  • Acceptable use
  • DPA
  • Subprocessors
  • Cookies
  • Security
  • SLA
© 2026 MIOSA
PrivacyTermsTrust CenterStatus
Checking system status