What we collect
When your team uses Matilda, we collect the data you send us, meaning the prompts, files, and context your team submits to the model and to Matilda Code. We collect the operational context that surrounds them: workspace name, member identities, billing details, and the configuration you save.
We collect basic product usage data so we can keep the service reliable, covering page paths, client versions, browser type, and the shape of your interactions. We do not collect the contents of pages you visit outside Matilda.
What we use it for
We use your data to run the model, power Matilda Code, and return results to your team. We use it to bill the workspace, contact account owners, and notify you when something touches your data.
We never sell your data. We never use the contents of your prompts or files to train shared models. We do not look at your data unless you ask us to, or unless we have to in order to keep the service running.
Where it lives
Your data is encrypted in transit and at rest. Each workspace's data is isolated at the storage layer. We retain it for the window your plan specifies and delete it on schedule; older data is not waiting in a backup tape somewhere.
We host on SOC 2 Type II infrastructure in the regions you select at workspace creation. Member access is logged; engineering access requires a paired review and an audit trail.
Your rights
You can export, redact, or delete any data your workspace has sent us. Account owners can do this from their settings; member-level requests route through the workspace admin. Deleted workspaces purge within 30 days, including from cold storage.
If you operate in the European Economic Area, the United Kingdom, or Australia, you have additional rights of access, portability, restriction, and objection. Write to security@maincode.com and we'll route it to a human within two business days.
Cookies & analytics
The marketing site uses essential cookies for sign-in and a small set of privacy-respecting analytics cookies for traffic shape. The product uses session cookies only, with no third-party advertising trackers, ever.
You can refuse non-essential cookies on your first visit and change your mind from the footer of any page.
Subprocessors
We rely on a short list of vetted infrastructure providers for cloud compute, transactional email, payments, and error tracking. Each one is bound by a data processing agreement that mirrors the protections in this policy. The current list is published at maincode.com/legal/subprocessors and updated at least 30 days before any addition takes effect.
Children
Matilda is built for engineering teams. We do not knowingly collect data from anyone under 16. If a workspace contains data that should not be there, write to security@maincode.com and we'll remove it.
Changes
We update this policy when we change how we handle data. Material changes get an in-product notice and an email to workspace owners 30 days before they take effect. Continued use after that date constitutes acceptance.
Contact
Privacy questions, deletion requests, and data export tickets: security@maincode.com. Postal mail: Maincode Pty Ltd, Melbourne, Victoria, Australia.