Legal

Privacy Policy

Effective June 1, 2026 · Last updated June 15, 2026

Plain-language summary

We value your trust. Here is the distilled summary of our privacy practices:

  • Local-First Storage: Your raw screen recordings, audio files, transcribed text, and document indexes reside locally on your device, not on our servers.
  • Zero Training on User Content: We never train our algorithms, models, or any third-party models on your private workspace or meeting content.
  • GDPR & CCPA Aligned: You have full rights to inspect, export, or delete any data we hold about you.
  • Anonymized Telemetry: We only track essential usage data to improve app performance (which you can turn off at any time).

Table of Contents

  1. Introduction & Scope
  2. Information We Collect & Process
  3. How We Use Your Information
  4. Local-First Storage & Security Architecture
  5. Third-Party Large Language Models (LLMs)
  6. Data Sharing & Disclosure
  7. Your Rights & Choices (GDPR/CCPA/PIPEDA)
  8. Telemetry & Analytics Choices
  9. Data Retention & Deletion
  10. Changes to This Policy
  11. Contact Information & DPO

1. Introduction & Scope

This Privacy Policy explains how Maple AI ("Maple", "we", "us", or "our") collects, uses, protects, and discloses information when you use our desktop application (the "Application"), websites, and services (collectively, the "Services").

Maple is designed as a "local-first" application. This means our primary design goal is to keep your personal data and workspace indices on your own device. We do not run continuous cloud processing of your desktop screen or meeting audio. Please read this document carefully to understand how we minimize cloud transmission and keep you in complete control of your digital workspace footprint.

2. Information We Collect & Process

We process two categories of information: Account & System Operations Data (which goes to our servers) and Workspace Content Data (which stays locally on your device).

2.1 Account & Billing Data (Sent to Servers)

To access paid plans or features requiring authentication, we collect:

  • Profile Information: Name, email address, password hash, and account settings.
  • Billing & Transaction Details: Subscription tier, card type, last 4 digits of the card, billing address, and billing history. Payment processing is handled securely by Stripe; we do not store full credit card details.
  • Communication logs: Customer support requests, email feedback, and voluntary survey responses.

2.2 Workspace Content Data (Stays on Your Device)

The core functions of Maple involve indexing your activities to build a local vector database. The following data is processed and stored exclusively on your local hardware:

  • Screen Captures & OCR Content: Visual snapshots of your desktop screen and the text extracted from them via Optical Character Recognition (OCR).
  • Meeting & Audio Transcripts: System-level audio recordings and text transcripts generated from virtual meetings (e.g., Zoom, Google Meet, Slack) or microphone inputs.
  • Indexed Documents & Files: Metadata, text, and structure from folders, notes, markdown files, and integrated apps (Slack messages, Notion documents) that you explicitly authorize the Application to index.
  • Vector Embeddings: Mathematical representations of the text chunks stored in your local SQLite database to facilitate semantic search.

2.3 Technical Telemetry & Analytics (Optional)

To help us diagnose crashes and monitor application performance, we collect anonymous telemetry, including:

  • Operating system version, CPU type, memory availability, and crash report dump files.
  • Aggregated, non-identifiable usage statistics (e.g., number of semantic searches performed, hours of meeting audio processed, active features used).
  • Telemetry contains zero raw workspace text, screen images, transcripts, or personal credentials.

3. How We Use Your Information

We use the data we collect for the following specific purposes:

  • Providing the Services: Processing subscription changes, managing accounts, and enabling secure sync features when requested.
  • Local Computation: Building your local index, generating local OCR metadata, and completing text-to-speech or transcription workflows directly on your machine.
  • Third-Party Inference: Sending only the specific text snippets related to your active queries to our LLM providers to generate answers in the overlay chat interface.
  • Customer Support: Responding to help tickets, troubleshooting bugs, and communicating system updates.
  • Product Improvements: Analyzing anonymized telemetry to debug memory usage, optimize CPU execution during transcription, and identify feature usage patterns.

4. Local-First Storage & Security Architecture

Maple utilizes a security architecture designed to keep your workspace database inaccessible to anyone but you:

  • On-Device Encryption: The local database (SQLite) containing your transcripts and indexes is encrypted at rest using AES-256-GCM. The key is managed using your operating system's secure keychain (macOS Keychain or Windows Credential Manager).
  • Transport Security: When communicating with our servers or third-party APIs (e.g., Stripe, LLM APIs), all data is encrypted in transit using TLS 1.3.
  • Sandboxed Environments: The application does not expose local indexes or database ports to public network interfaces. Access to database folders is restricted to the Maple system process.

5. Third-Party Large Language Models (LLMs)

To answer questions about your workspace history in the Maple chat bar, we send targeted context snippets to AI providers (such as Google Gemini, Anthropic Claude, or OpenAI GPT-4). We protect your privacy under strict enterprise agreements:

  • Zero Data Retention (ZDR): Under our API contracts, providers do not store your transmitted text blocks or query prompts on disk. The data is processed in memory and discarded immediately after generating the response.
  • No Model Training: Your context chunks, prompts, and output responses are never used to train, tune, or improve models for Google, Anthropic, OpenAI, or Maple.
  • Context Filtering: We run local filters to minimize the transmission of high-risk text (like social security numbers or credit cards) prior to sending queries to the LLM APIs.

6. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We only share account details or anonymized telemetry in the following circumstances:

  • Service Providers: We use trusted third parties to handle billing (Stripe) and transactional emails (Postmark, SendGrid). These providers only access the minimal data required to perform their services.
  • Legal Compliance: We may disclose account details if required by a valid law enforcement request or court order. When legally permitted, we will give you notice before disclosing your information.
  • Business Transfers: In the event of a merger, acquisition, or sale of company assets, your account data may be transferred to the new owner, subject to the same privacy commitments outlined in this policy.

7. Your Rights & Choices (GDPR/CCPA/PIPEDA)

Regardless of your geographic location, we respect your rights to govern your own data under CCPA, GDPR, and other frameworks. You can:

  • Access & Export: Request a copy of your account data stored on our servers. (Note: Your workspace database is already on your device and can be copied or exported via the settings pane).
  • Correction: Update inaccurate account or profile info.
  • Deletion ("Right to be Forgotten"): Request that we delete your Maple account, subscription, and billing history from our servers. You can delete your local index and files by using the "Wipe Index" button in the app settings or by uninstalling the application.
  • Portability: Request that we transfer your account metadata to another service.

To exercise these rights, email us at mapledotso@gmail.com. We will process your request within 30 days and will verify your identity before releasing any information.

8. Telemetry & Analytics Choices

We collect anonymous telemetry to keep Maple fast and stable. However, we believe in user control:

  • You can disable telemetry completely in the Application Settings (under Settings > Privacy > Help Improve Maple).
  • Once disabled, no application logs, performance charts, error tracking, or usage statistics will be sent from your device to our servers.

9. Data Retention & Deletion

  • Account and Billing: Retained as long as your account is active, plus up to 7 years to comply with tax, corporate, and accounting laws.
  • Support Messages: Retained for up to 3 years to maintain historical support threads.
  • Workspace Content: Stays on your machine indefinitely until you clear your cache, delete the SQLite files, or uninstall Maple. We never see it and we cannot retrieve it for you.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the effective date and provide notices via our website or application updates. For major policy changes, we will notify you by email or show a modal in the desktop client prior to the change taking effect.

11. Contact Information & DPO

If you have any questions or concerns regarding this policy, or wish to file a request with our Data Protection Officer (DPO), please contact us:

  • Email: mapledotso@gmail.com
  • DPO & Founder Email: rishabh.maple@gmail.com