Privacy Policy

This explains what mythos collects, why, who we share it with, and what choices you have. We wrote it in plain language because legal language shouldn’t be the reason you don’t know what we do with your data.

Last updated · September 4, 2026

The short version

If you only have a minute, here is what you need to know:

  • We collect what is needed to run your account and nothing more.
  • We do not sell your data. We do not run advertising trackers.
  • We do not use your Builder prompts, code, or project files to train AI models. The optional public documentation assistant has a separate provider boundary described below.
  • Payment is a direct on-chain stablecoin transfer on Solana — we never see a card number or bank account.
  • You can export or delete your data at any time, and you own the code you generate.

The rest of this page explains exactly what we collect, why, and who we share it with.

What we collect

Account information

When you sign up we store the identifier returned by our authentication provider (usually an email address and a provider-issued user ID), an automatically assigned username, and any profile details you choose to add: a display name, bio, location, website, profile photo, and cover image. Profile images are stored privately and delivered through short-lived signed links. We never see or store your password.

Project data

Everything you build through mythos — prompts, generated files, commit history, preview URLs, and metadata such as project name and created date. Project files live in a private internal source repository and are mirrored to our database so the workspace UI can load them quickly.

Collaboration and messaging also store membership and invitation records, human project-room and direct messages, contact relationships created through project membership, your read, archive, and block choices, and named Share Preview links. Mythos Updates is a platform-authored product feed; we store only your personal read position for it. While a signed-in member has a project open, Mythos keeps a short-lived presence session so other members can see who is currently there.

Shared previews

A person opening a Share Preview can view the latest working preview without a Mythos account. The preview link is a bearer credential: anyone who receives it can open that preview until it expires or the project owner revokes it. Share Preview no longer collects guest names or new comments. Historical preview-comment records created before retirement remain dormant only for the retention, export, correction, and deletion obligations described in this policy.

Usage data

Infrastructure access logs can record request metadata such as IP address, browser and operating-system strings, timestamp, path, and request outcome for security, debugging, and capacity planning. These access logs are separate from published-site Analytics. They are not sold or shared with advertisers.

Job applications

If you apply for a role, we store the contact details, location, links, resume URL, work samples, application answers, availability, referral source, and basic browser information you submit so we can review and respond to the application.

AI interactions

When you explicitly start voice dictation, your browser records a bounded audio clip and sends it through Mythos to OpenAI for transcription. Mythos does not persist the audio. The returned text is inserted into the composer for you to review and is not submitted automatically.

Prompts you send to the Builder, along with the working-copy files it reads during a session, are transmitted to OpenAI so it can generate code. For oversized document attachments, a separate bounded OpenAI extraction call may receive selected document chunks and pseudonymous source-reference identifiers before the Builder runs; it does not receive the repository, backend credentials, secrets, or runtime evidence and cannot write code. Your prompt remains in your project chat. We keep the bounded task classification when the optional profiler is enabled, immutable routing decision, per-stage token/cost totals, and sanitized outcome evidence needed to investigate failed runs and bill credits accurately. Operational logs and traces exclude prompts, code, file contents, tool payloads, and private model reasoning.

If you use the optional public documentation assistant, Mythos sends its provider your current question, earlier questions in that browser conversation, and the published Mythos documentation corpus. The conversation is kept in your browser's session storage and is not written by Mythos to an account or project record. The server keeps only short-lived abuse-prevention counters and body-free operational logs. Do not include personal data, source code, credentials, or other secrets in a documentation question.

On-chain payment data

When you top up credits using USDT on Solana or USDC on Solana, we record the selected asset and network, displayed receive address, scanner watch account when it differs, exact amount, Solana invoice reference when applicable, transaction hash, payment-intent ID, and credit pack purchased. Public chain data may expose a sending address or other transfer payload. This data is used to match the transfer, credit the balance, and investigate payment disputes.

Connected services

If you connect GitHub, we store the credentials needed for that connection (encrypted at rest) and a record of what was connected when. If you previously connected Supabase through the retired flow, we may retain its encrypted legacy credentials and connection record for compatibility and safe cleanup. An ordinary frontend Build for that already-connected project may receive only the stored project URL and public anon key; provider tokens and service-role credentials are not given to the agent.

Published sites

When you publish a project, its static build is copied to our hosting provider and served publicly on your chosen subdomain. Whatever you put in the site becomes public; visitors to it are served directly by the hosting edge (see the sub-processor list).

Published-site visitor analytics

Visitor analytics is enabled by default for a project, starts only while that project is published and live, and never runs in Preview. A project owner can turn it off under More → Project settings → Publishing; disabling it or unpublishing stops new events immediately without deleting earlier history.

For each accepted page view we store the project, event time, a random 30-minute session identifier, the pathname without its query or fragment, an external referrer hostname or “Direct”, a coarse Desktop/Mobile/Tablet class, and a two-letter country code derived from the browser’s IANA time zone (or XX when unavailable). We do not store the time-zone identifier or the visitor’s IP address, full user-agent, full referrer or URL, query or UTM parameters, fingerprint, Mythos account identity, or a profile that follows the visitor across separate sessions.

Why we collect it

  • To sign you in and keep your session alive.
  • To generate, store, and serve the projects you build.
  • To provide project owners with aggregate traffic metrics for their published sites when Visitor analytics is enabled.
  • To account for credit spend and honour refunds.
  • To detect abuse, fraud, and infrastructure issues, and to keep the sandbox safe for everyone.
  • To let you contact support and to contact you about security, legal, or service-critical matters.
  • To review and respond to a job application you submit.
  • To comply with legal obligations when we receive a valid request.

That is the full list. We do not use your data to build advertising profiles, and we do not sell it to data brokers.

AI training

We do not use your prompts, your generated code, or any other content from your projects to train or fine-tune AI models.

We send explicitly recorded voice audio to OpenAI only to produce the transcript placed in your composer. We also send Builder prompts and the working copy of your project files to OpenAI so it can generate a response. If the separately activated oversized-document path applies, a bounded OpenAI extraction call receives selected chunks and pseudonymous source-reference identifiers (content hashes and chunk IDs) from those attachments to create a source-referenced brief. It does not receive attachment filenames or MIME types, the current user goal or repository, and it cannot write code. OpenAI's business API service is configured for processing, not model training. See the subprocessors section for the complete provider boundaries.

The public documentation assistant is separate from the Builder. It sends the question and earlier questions in the browser conversation to an external AI provider. The provider's published Privacy Policy says inputs may be used to improve or train its services unless the account opts out. This repository does not evidence an account-level opt-out, so Mythos does not promise that documentation questions are excluded from provider training. Do not submit project data, personal data, credentials, or other secrets to that assistant. The provider's Open Platform Terms also apply.

Who we share data with

mythos is a small layer of code on top of several specialist providers. To operate the service we must share certain data with them. Here is the current list and what each one receives. Their legal roles can differ; not every provider necessarily acts as our processor:

  • No advertising trackers
  • No intentional model training on Builder project data
  • No payment cards or bank data
  • Connected backends stay in your account
Sub-processors mythos shares data with
ProviderRegionRole
Core platform
SupabaseGermany, EU (eu-central-1, Frankfurt)Germany, EU (eu-central-1, Frankfurt)Authentication, Postgres database, and Storage. Verifies identity, issues sessions, and stores account data, project metadata, prompts/chat messages and payloads, payment/credit records, generation logs, connection metadata, bounded published-site analytics events, and uploaded/artifact storage. Encrypted in transit and at rest.
GitHubUSAUSAPer-project private git repository hosting (our internal org). Receives every commit and its history. Also processes OAuth tokens you authorise when connecting your own GitHub account.
Google CloudEU / USAEU / USACloud Run hosts the app and every project sandbox in europe-west3 (Frankfurt). Secret Manager and Cloud Logging support the runtime; Cloud Scheduler/control-plane services may process operational metadata in US regions, including us-central1.
AI and build assistance
OpenAIUSAUSAAI inference through one OpenAI Agents SDK Builder over the Responses API. Receives your prompt, selected attachments, and the isolated working copy needed to plan or edit code. The Builder may also ask OpenAI Images to create bounded original site imagery or an explicitly requested favicon; those calls receive only the image description and a pseudonymous safety identifier. For oversized document attachments, a separate bounded OpenAI extraction call may receive selected text chunks and source-reference identifiers before the Builder runs. When you explicitly use voice dictation, one completed recording is sent to OpenAI for transcription; Mythos does not persist that audio or automatically submit the returned text. API data is handled under OpenAI business data controls and is not used to train models by default.
Documentation assistant providerPeople's Republic of ChinaPeople's Republic of ChinaAnswers questions submitted to the optional public documentation assistant. Receives the current question, earlier questions kept in that browser conversation, and the published Mythos documentation corpus. It does not receive your account identity, project, repository, attachments, or Builder conversation unless you put that information into a question yourself. The provider's published Privacy Policy says inputs may be used to improve or train its services unless the account opts out; this repository does not evidence an account-level opt-out, DPA, transfer basis, or fixed provider retention period. Do not submit personal data, source code, credentials, or other secrets to the documentation assistant.
Operations and delivery
ResendNot asserted; see provider terms and DPANot asserted; see provider terms and DPAProcesses authentication email submitted through Supabase custom SMTP. If platform invitation email is enabled, Resend also receives the recipient address, sender, workspace and project names when applicable, requested role, inviter identity, invitation message, exact invitation or project action URL, and bounded delivery tags. It returns delivery, delay, bounce, complaint, failure and suppression events. Mythos does not send project source, prompts, payment data or backend credentials to Resend.
CloudflareUSAUSADNS and CDN/security proxy for mythos.new, and edge hosting for published sites. Static builds are stored in Cloudflare R2 and served on *.r21.dev or a connected custom domain. When a project owner leaves Visitor analytics enabled, Cloudflare also serves the first-party analytics script, receives its same-origin page-view request, derives a coarse device class, converts the browser time zone to a two-letter country code, and forwards only the bounded event to Mythos. Cloudflare sees ordinary network metadata such as IP and user-agent while handling the request; Mythos does not store those raw values or the time-zone identifier in the analytics table.
SentryGermany, EUGermany, EUError monitoring. When something breaks, receives the technical error report (stack trace, browser/OS, request id) from our app and servers so we can fix it. Events travel via our own domain; no Sentry cookies, session replay disabled, and personal data is not attached by default.

If you previously connected your own Supabase project, your app’s backend — its database, its users, its files — remains in your Supabase account under Supabase’s terms, not ours. New BYO-Supabase onboarding and the workspace Cloud console are retired. We retain legacy connection credentials encrypted only for the fenced cancellation, authorization-revocation, export, deletion, and compatibility handling described in this policy; retiring the UI does not delete or change an external Supabase resource. Separately, if you leave Visitor analytics enabled for the published site, Mythos acts as your processor for the bounded traffic dataset described in this policy.

If this list changes we update the date at the top of this page and, for significant changes, announce it in-product. Data-processing terms (DPAs) are used where available. Questions: privacy@mythos.new.

How long we keep it

  • Account records. Kept while the account is open, and for up to thirty days after deletion to handle re-activation and support tickets, except for the minimal security tombstone described below.
  • Project files and git history. Kept until you delete the project or transfer the repository out of our organisation. Database mirrors are removed in the same operation.
  • Collaboration and messaging. Memberships, invitations, project-room messages, and Share Preview link metadata follow the project/account deletion boundary. A direct conversation, its shared message history, contact relationship, archive/read state, and block choice are not deleted merely because project access ends; they remain until an affected account is deleted. Your Mythos Updates read position follows your account deletion boundary, while the platform-authored update itself is global product content. Dormant historical preview-comment records follow the project boundary and are retained only for compatibility with export, correction, and deletion requests. Share Preview access capabilities are short-lived, and an expired, replaced, or revoked link can no longer open the preview. Presence sessions are temporary: they stop being shown after sixty seconds without a heartbeat, become eligible for deletion after twenty-four hours, and are removed by the next daily retention sweep.
  • Generation logs. Terminal records are deleted once they are more than ninety days old. If a run has not reached a safe terminal state, we retain its limited delivery and credit-recovery record only until that outcome is reconciled, then apply the same deletion rule. Prompts and chat content remain governed by the project-retention rule above.
  • Failed remix request identity. After a refunded remix, we keep a minimal record containing opaque request, project, run, and account identifiers—but no prompt, repository, or failure text—to prevent the same browser request from being charged again. Records without a client request key are deleted after ninety days; keyed records remain while the account is open and are deleted with the account.
  • Message identity security tombstone. After project or account deletion removes chat content, we retain the random message UUID, its former random project UUID, semantic role, opaque workflow binding and, for a human turn, the former random account UUID only when an immutable source proved the author. Older uncorrelated human turns keep an explicit unknown-author binding instead; we do not infer the author from the project owner. This content-free record is kept permanently so a deleted identity cannot be reassigned across accounts, projects, roles, or trusted assistant workflows. It contains no prompt, response, profile, email, repository, or chat payload. We use it only for anti-replay and provenance-spoof prevention under our security legitimate interest.
  • Access logs. Kept for up to thirty days for security and abuse investigations.
  • Documentation assistant. Completed questions and answers are kept only in that browser tab's session storage until you clear the conversation or the browser session ends. Mythos does not write them to an account or project record. The per-address abuse counter stores the validated IP address, or IPv6 /64 bucket, in a service-only database key and is swept after its window expires. The provider's own retention is purpose-dependent under its published Privacy Policy; this repository does not evidence a fixed provider retention period.
  • Published-site analytics. Raw page-view events are kept for up to ninety days. Deleting the project or account removes them earlier. Turning Visitor analytics off or unpublishing stops new collection immediately but keeps existing history until that retention or deletion boundary.
  • Job applications. Deleted once they are more than two years old. You may ask us to delete yours earlier, subject to any legal obligation to retain it.
  • Credit and payment ledger. Kept for as long as applicable tax and accounting rules require, currently around seven years.
  • Backups. Encrypted backups may contain data for up to thirty days after you delete it from live systems, after which they roll over.

International transfers

mythos runs the app and project sandboxes on Google Cloud Run in europe-west3 (Frankfurt, Germany). Cloud Scheduler and some Google control-plane/operational metadata may use us-central1 (Iowa, USA). The Postgres database (Supabase) is hosted in eu-central-1 (Frankfurt, Germany). The providers named above process data in the regions shown in the register where those regions are published. Where a provider offers a DPA, transfers outside your region use its Standard Contractual Clauses or other stated mechanism.

How we protect it

  • TLS is required on every connection. Plain HTTP is rejected.
  • Secrets are stored in a managed secret store and rotated on a schedule.
  • Database access is scoped with row-level policies so one user cannot read another user’s projects.
  • The preview sandbox that runs your code is isolated per project, scales to zero when idle, and is torn down when the project is deleted. Agent tool calls are whitelisted; arbitrary shell access is blocked.
  • Error payloads are scrubbed of common secret patterns before they are sent to error tracking.

If we confirm a breach that affects your personal data, we will notify you without undue delay — within 72 hours where GDPR requires it — with what happened, what was affected, and what we are doing about it.

No system is perfectly secure and we do not claim otherwise. If you discover a vulnerability, please report it to support@mythos.new so we can fix it before disclosure.

Your rights

Depending on where you live — including under GDPR in the EU/UK, the CCPA and CPRA in California, and equivalent regimes elsewhere — you have the right to:

  • Access the personal data we hold about you.
  • Correct anything that is inaccurate.
  • Request deletion of your data.
  • Restrict or object to certain kinds of processing.
  • Receive your data in a portable format and move it elsewhere.
  • Withdraw consent where processing relies on consent.
  • Lodge a complaint with your local data-protection authority if you believe we are handling your data incorrectly.

Export and deletion are self-service: Account → Export data downloads a portable JSON archive that identifies any incomplete slices and excludes credentials, OAuth tokens, and other secrets. The archive includes your direct-conversation identities and message history, messages you authored in project rooms, your own contacts, read/archive state and outgoing block choices, your own Share Preview link actions, historical authored review content where applicable, and short-lived project-presence records. It does not include a contact’s unrelated profile or content, another person’s block choice, or the global Mythos Updates content. The portable archive also excludes the internal message-identity anti-replay registry described above. Requests to access, correct, or object to that permanent security record require verified manual review. Account → Delete account starts account closure and removal of associated project resources; legal records and encrypted backups follow the retention periods above. For anything else email privacy@mythos.new. We respond within thirty days. We may ask you to confirm identity so we do not hand your data to an impostor.

If you visited a site published by a Mythos customer, contact that site owner first: they are the controller for the site’s visitor data. We assist project owners with valid access, restriction, and deletion requests for the bounded analytics data we process for them.

If you previously commented as a guest on a Share Preview before that feature was retired, contact the project owner or privacy@mythos.new. We may ask for the exact preview link and sufficient evidence to verify authorship before disclosing, correcting, or deleting the historical record.

What we do not collect

mythos does not intentionally collect:

  • Payment card numbers, bank details, or SSNs.
  • Precise GPS or geolocation beyond IP-level region.
  • Biometric identifiers, health information, political views, religious beliefs, or trade-union membership.
  • Data from third-party ad networks, tracking pixels, or data brokers.

If you share any of the above with us accidentally (for example inside a prompt) we will delete it on request and we will not act on it.

Cookies

We use a small number of first-party cookies to keep you signed in and remember UI preferences. A published site with Visitor analytics enabled also sets one host-only random session cookie with a sliding 30-minute lifetime so page views can be grouped into a visit; it is not reused to follow a visitor across expired sessions or hostnames. We do not set third-party advertising cookies or embed tracking pixels from marketing networks. The full inventory — every cookie and storage key, with lifetimes — lives in the Cookie Policy.

Because we do not sell or share personal data for advertising, there is nothing to opt out of — browsers sending a Global Privacy Control signal are already getting the behaviour it asks for.

You can clear or block cookies from your browser at any time. Clearing Mythos account cookies signs you out; clearing the analytics cookie starts a new anonymous visit if you later return while the project owner still has Visitor analytics enabled.

Children

mythos is not intended for anyone under eighteen, or the age of majority in your jurisdiction. We do not knowingly collect data from children. If you believe a minor has created an account, contact privacy@mythos.new and we will remove the account and associated data.

Changes to this policy

When we update this policy we change the “Last updated” date at the top. For material changes — a new category of data, a new kind of sharing, a new subprocessor that touches user content — we notify active users by email or in-product banner at least thirty days before the change takes effect.

Contact

Privacy and data-rights requests: privacy@mythos.new
Everything else: support@mythos.new or the support page