Legal
Privacy Policy
Effective: August 1, 2026
1. Scope and controller
This policy explains how Yoon Indo, an individual business operator trading as OSB and providing Maho under the Maho product name, handles personal data through the Maho Browser, mahobrowser.com, account services, encrypted sync, managed AI, billing, waitlist, and related support channels.
The controller is located at 213-315, Gran City Xi 2nd Officetel, 17 Haeyang 5-ro, Sangrok-gu, Ansan-si, Gyeonggi-do, Republic of Korea. Business Registration Number: 150-32-00795. Privacy requests and questions may be sent to hello@mahobrowser.com. The mail-order sales registration number will be added after its exact registered form is verified.
2. Local-first design and service data
Maho is designed to keep browsing history and locally stored mailbox content on your device by default. Local-first does not mean that every feature operates only on your device. Optional account, authentication, encrypted sync, managed AI, billing, waitlist, abuse-prevention, and security features process limited data through Maho-operated or contracted infrastructure.
Encrypted sync stores ciphertext, room identifiers, ownership records, timestamps, device records, and encrypted snapshots on the relay. Maho does not receive the plaintext sync key through the normal pairing flow, but relay metadata and encrypted payloads are still service data processed on Maho infrastructure.
3. Data we process, why, and legal bases
| Category | Examples | Purpose | Typical legal basis |
|---|---|---|---|
| Account and authentication | Email address, password hash, display name, Google account identifier, email verification status, sign-in and token timestamps | Create and secure accounts, authenticate users, link sign-in methods, recover service state, and prevent abuse | Contract; legitimate interests in security and abuse prevention |
| Device and sync service data | Device name and type, client device identifier, room ID, last-seen time, encrypted messages and snapshots, room ownership | Provide optional cross-device encrypted sync, pairing, catch-up, storage limits, and retention maintenance | Contract; legitimate interests in reliable and secure service operation |
| Billing and entitlements | Subscription tier and status, period dates, credit balance and ledger, payment-method status, LemonSqueezy customer and event identifiers, refund records | Process purchases, provide paid access, prevent duplicate credits, handle refunds and disputes, and meet accounting obligations | Contract; legal obligation; legitimate interests in fraud and dispute prevention |
| Managed AI requests | Prompt and response bodies in transit, selected model and route, usage amount, quota and billing metadata | Return the requested AI output, enforce quotas, calculate usage, and protect the service | Contract; legitimate interests in security and service operation |
| Website and waitlist | Email, source, coarse request metadata, pseudonymous IP hash, pages or forms you choose to use | Operate the website, manage sign-ups, respond to messages, rate-limit abuse, and measure service demand from server-side operational records | Consent where requested; contract steps; legitimate interests in security and service operation |
| Security and administration | Session records, rate-limit and quota decisions, account activity day, administrative action and reason, error and abuse signals | Detect misuse, secure accounts, investigate incidents, enforce limits, and maintain an accountable audit trail | Legitimate interests; legal obligation where applicable |
Where local law requires consent for a particular activity, consent is the basis and may be withdrawn. Withdrawing consent does not affect processing already performed lawfully.
4. Google sign-in
If you choose Sign in with Google, Google provides Maho with a stable account identifier, your email address and verification status, and, where available, your display name. The Google ID token and a one-time nonce are transmitted to the relay so Maho can validate the sign-in. Maho uses this information to create or link your account, authenticate you, maintain account security, and prevent abuse. Maho does not receive your Google password.
Basic Google sign-in does not grant Maho access to your Gmail mailbox, Google Drive, Calendar, or other Google Workspace content. The stored Google identity is protected using the same access controls used for Maho account records and is disclosed only to infrastructure providers needed to run authentication, or where law requires it.
You may stop using Google sign-in by revoking Maho in your Google Account's third-party access settings. Revocation stops future Google authorization but does not itself delete your Maho account. To remove the linked identity and account data, use the authenticated account-deletion function or contact hello@mahobrowser.com.
5. Managed AI and BYOK
With Bring Your Own Key (BYOK), requests are sent from your device to the provider you select under that provider's terms. Maho does not receive your provider API key through the normal BYOK request path.
For managed AI, requests pass from the Maho client through Maho's Cloudflare-hosted billing proxy, OpenRouter, and the selected model provider. Maho does not intentionally persist managed-AI prompt or response bodies in its application database. Requests must still be processed in transit, and upstream providers may perform temporary retention, security review, or abuse monitoring. Their retention and training practices can vary by model and route, and legal-preservation exceptions may apply. Maho therefore does not promise universal “zero retention” or “no training” across every available route.
6. Recipients and service providers
- Cloudflare: website delivery, Workers, D1 databases, Durable Objects, rate limiting, encrypted sync relay, and the managed-AI proxy.
- Google: optional Google sign-in and verification of Google-issued identity tokens.
- LemonSqueezy: merchant-of-record checkout, payment processing, customer portal, invoices, taxes, subscriptions, refunds, and fraud controls.
- OpenRouter and selected AI providers: processing managed-AI requests for the model and route you select.
- Email and support providers: transactional verification messages and communications you request.
Maho does not sell personal data or share it for cross-context behavioural advertising. Google Analytics has been removed from the website; no Google Analytics tag is intentionally loaded by the public website.
7. International transfers
Providers may process data in countries other than your own, including the United States. Where required, Maho relies on provider contractual safeguards, adequacy decisions, or other lawful transfer mechanisms. Contact us if you need information about safeguards relevant to your location.
8. Retention and deletion
- Active account, device, session, OAuth identity, subscription, and credit records are retained while needed to provide the service.
- Expired sessions and old encrypted sync messages are pruned on service schedules. Activity-day records are designed for a rolling 90-day operational window.
- Waitlist records are retained until they are no longer needed for the requested launch communication, suppression, security, or legal purpose.
- Billing, refund, webhook-idempotency, tax, dispute, fraud-prevention, and administrative audit records may be retained for the period permitted or required by applicable law. Some such records do not contain a Maho account identifier.
When an authenticated account-deletion request is completed, Maho deletes account-linked users, sessions, devices, OAuth identities, encrypted sync rooms and content, activity records, jobs, credits, and matching waitlist records, and detaches retained administrative audit records from the account. Provider-side billing records and backups or caches may remain until their legal or scheduled deletion period expires. Deletion is therefore not promised as universal or immediate across every system.
9. Your choices and rights
Depending on where you live, you may have rights to access, obtain a copy of, correct, delete, restrict, or object to processing of personal data, and to data portability or non-discrimination. You may withdraw consent where consent is used and complain to your local data-protection authority. Send requests to hello@mahobrowser.com. We may verify your identity and may refuse or limit a request where the law permits.
Automated systems make rate-limit, quota, billing, replay-prevention, and abuse-control decisions. These controls may temporarily reject requests or restrict service access. If you believe a material restriction is incorrect, contact us for human review.
10. Security
Maho uses measures including encrypted transport, password hashing, hashed access and refresh tokens, one-time OAuth nonces, access controls, rate limits, encrypted sync payloads, and limited operational logging. No system is perfectly secure, and encrypted sync is not a substitute for a separate backup.
11. Children
Maho is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly create accounts for children who cannot lawfully consent or enter the applicable agreement. Contact us if you believe a child provided personal data without required authorization.
12. Google Workspace APIs and Gmail
Maho does not currently request Gmail or other Google Workspace content scopes through basic Google sign-in. If a future release enables those scopes, Maho will present the exact scopes and requested actions before authorization and update this policy before launch.
For such a future feature, the notice will identify whether Maho accesses email addresses and profiles; message headers, bodies, snippets, threads, labels, drafts, sent messages, deleted messages, attachments, or Calendar data; where access and refresh tokens are stored; whether content passes through Maho infrastructure; when a human can access it; and how to disconnect and delete it.
Limited Use: Maho's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Maho will not use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or ML models.
Maho will not automatically send Gmail content to an AI provider. If a future Gmail integration allows you to deliberately invoke an AI feature on an email, the selected content and necessary context may be transmitted only through the AI route presented to you at that time.
13. Changes and contact
Material changes will be posted here with a revised effective date and, when appropriate, announced in the product, by email, or before the changed processing begins. Questions, rights requests, legal notices, and account-deletion assistance may be sent to hello@mahobrowser.com or by post to Yoon Indo (OSB), 213-315, Gran City Xi 2nd Officetel, 17 Haeyang 5-ro, Sangrok-gu, Ansan-si, Gyeonggi-do, Republic of Korea.