Privacy Policy

What we collect, what we never do with it, and how your data stays yours.

Last updated: August 9, 2026

1. What this covers

This policy explains what BuildMidas collects, why, and what happens to it — across the marketing site, the dashboard, and the agent features.

2. What we collect

Account data

Email address, name, and a password hash (or your Google sign-in identity if you use Google login). Plan, credit balance, and billing history.

Content you provide

Prompts, chat messages, knowledge files, reference images, and the products the agents build in your workspace.

Credentials you connect (optional features)

Google service-account keys or OAuth tokens for Search Console / Analytics, app-store developer credentials for shipping, social-platform OAuth tokens for posting, and deploy targets (SFTP/SSH) for your own servers. Each is stored server-side, scoped to your account with database-level tenant isolation, used only to perform the action you connected it for, and never shared with other tenants.

Analytics data about your products

When you connect Google Search Console, Google Analytics, or store dashboards, we ingest performance data about your properties (queries, clicks, sessions, installs) to power reports and the optimization agents.

Usage data

Standard web logs and Google Analytics on our own pages (page views, referrers, approximate location from IP). We use this to understand what to improve.

3. What we do with it

  • Operate the Service: run agents you start, build and host your products, show your analytics.
  • Process payments through Stripe. Card details go to Stripe directly; we never store card numbers.
  • Send transactional email (receipts, important account or service notices).
  • Improve the platform, using aggregate usage patterns.

We do not sell your data. We do not use your private products, prompts, or connected-account data to market to anyone else.

4. Google user data — Limited Use

BuildMidas's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Search Console and Analytics data is used only to display your reports and drive the optimization features you invoke — never for advertising, and never transferred except as needed to provide those features.

5. Where data lives and how it's protected

  • Data is stored on our servers with per-tenant isolation enforced at the database layer (row-level security) — one tenant's queries cannot read another tenant's rows.
  • Agent workloads run in isolated environments with restricted network egress.
  • Access to production systems is limited to operators who need it.

6. Cookies and local storage

  • Authentication tokens are kept in your browser's local storage to keep you signed in.
  • Preferences — language, region, display currency — are kept in cookies/local storage so pages render the way you chose.
  • Google Analytics sets its own cookies on our marketing pages.

7. Retention and deletion

  • Your content and account data are retained while your account is active.
  • You can delete individual builds, connected credentials, and domains in the dashboard at any time.
  • To delete your account and its data, use Contact from your account email. We delete or anonymize within 30 days, except records we must keep (e.g. invoices, fraud prevention).

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us and we'll honor applicable requests.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

10. Changes

We may update this policy; material changes will be announced in the product or by email. The date above reflects the latest revision.

11. Contact

Privacy questions or requests: [email protected].