Privacy policy
Last updated: September 25, 2026
This policy explains what data Main AI collects, where it goes, how long it is kept, and what controls you have. It describes what the service does today.
Document handling
When you open a document, its text is read in your browser and, for PDFs, also on our server. The original file stays in your browser; we do not keep it on our servers. If you are signed in, the extracted text (up to 400,000 characters) and the analysis are saved to your account automatically so your documents are there next time.
Account data
We process your email address, plan status, authentication tokens, and workspace activity to operate the product, manage billing, and provide support.
AI processing
To produce an analysis, we send DeepSeek the document’s file name, its type, our own findings, and an excerpt of its text. That is the only AI model provider we use today. We do not use your documents to train AI models, and how DeepSeek handles what it receives is governed by its own terms.
Security
The site is served only over HTTPS. Sign-in is handled by Firebase Authentication. Access to saved documents is limited to your account.
Retention
We have not set automatic deletion periods. What you save stays until you delete it or ask us to. You can delete a document from your dashboard; to delete your account and everything in it, email mainaihelp@gmail.com.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your data. Email mainaihelp@gmail.com to exercise any of them.
Main AI is not designed for processing highly regulated sensitive data (HIPAA, PCI-DSS, etc.) unless agreed in writing. Please do not upload documents containing full financial account numbers, SSNs, or similarly sensitive identifiers without understanding the risk.
Data we collect
- Email address and authentication credentials (via Firebase Auth)
- Document text and analysis, saved to your account when you are signed in. Original files are kept only in your browser.
- Plan and billing status (via Stripe — we do not store card details)
- Usage events: which pages and buttons are used, the page path, a session id, the referring page and campaign tags, and for some tools the state you chose. These events do not contain what you type.
- If you ask for a deadline reminder or a report link by email: your email address and what the reminder is about (for a deposit reminder, the state and the deadline). Reminder records are currently kept after the reminder is sent.
- If you bought a security deposit letter before September 25, 2026: the case details you gave us (names, addresses, amounts and notes), kept to complete that order.
- Support communications if you contact us
- Browser extension (if installed): page text you choose to analyze, source URL and page title of analyzed pages, your extension authentication session (stored locally in your browser only)
What stays in your browser
- Documents you open, including the original file, are kept in your browser’s storage so you can come back to them.
- When you sign out, Main AI clears the documents and analysis it stored in that browser for your account.
- If you use Main AI without signing in, that data stays in your browser until you clear your browser storage.
- The free security deposit letter is drafted on our server and not stored there. The page keeps what you typed in your browser for up to 30 minutes so you can come back to it.
Browser extension
The Main AI browser extension adds document analysis directly to your browser. Here is exactly what it does and does not do:
- Page reading — on demand only. The extension reads the text content of a page only when you explicitly click "Analyze this page" in the extension popup or right-click and choose an analyze option. It does not read pages automatically or in the background.
- Sign Intercept — e-signature platforms only. On supported e-signature platforms (DocuSign, HelloSign, Adobe Sign, PandaDoc, SignNow, Ironclad), the extension injects a "Review with Main AI" button near the sign button. No page content is read until you click that button.
- What is sent to your dashboard. When you trigger analysis, the visible text of the page is extracted and sent to your signed-in Main AI account for analysis. The source URL and page title are also recorded so you know where the document came from.
- What is never sent. Passwords, payment card numbers, form field values, cookies, and browser history are never read or transmitted. The extension only reads visible page text.
- Authentication. The extension authenticates using your Main AI account (Firebase Auth). Your session is stored locally in
chrome.storage.localand is namespaced to your user ID. Signing out wipes all locally stored extension data immediately. - Cross-user isolation. All extension storage keys are namespaced by user ID. A different user signing in on the same browser cannot access the previous user's data. Signing out triggers a full
chrome.storage.local.clear(). - No persistent background activity. The extension does not run continuously in the background, does not track your browsing history, and does not send data to Main AI unless you explicitly trigger an analysis.
- Local storage only. Recent analysis history displayed in the extension popup is stored locally in
chrome.storage.localand never leaves your browser independently of an analysis action.
Service providers
These are the providers that receive data from the service today, and what each one receives:
- DeepSeek — the AI model that generates analyses. Receives the document’s file name, type, our findings and an excerpt of its text.
- Tavily — web search, used to look up public sources for an analysis. Receives search queries that can include the document type, your question and short excerpts of findings (up to 380 characters), and, for contract watch checks, the names of the other parties.
- Firebase (Google) — sign-in, the account database where saved documents live, and file storage.
- Amazon Web Services (S3) — stores shared report links (they expire after 30 days), finding status for saved documents, and plan records.
- Resend — sends the emails you receive from us (sign-in and account messages, reminders you asked for, and invitations).
- Supabase — stores website usage events, and your email address if you ask us to email you a report link.
- Stripe — payment processing (no card data touches our servers)
- Netlify — hosting, serverless functions and their logs
Not in use today, although our code can call them: Anthropic’s Claude models, OpenAI and Voyage AI (text embeddings for search), and AWS Textract (text recognition for scanned files). If we start using any of them, we will update this page first. Google Analytics is not loaded.
Each provider processes data under its own terms, only as needed to deliver the service.
Contact for privacy matters
For access requests, deletion, correction, or any privacy concern: mainaihelp@gmail.com