1. Who we are
The service is operated by RealAdvisor SA, Route de Saint-Julien 198, 1228 Plan-les-Ouates, Switzerland, UID CHE-373.280.297(“Mako”, “we”). We are the data controller for account, billing and usage data. For the contents of the databases you connect, you are the controller and we act as your processor: we only ever run the queries you or your agent ask us to run, and only return results to you.
Privacy questions: privacy@mako.ai.
2. What we collect
Account and workspace data
- Name, email address and avatar from the sign-in provider you choose (Google or GitHub) or from email sign-up.
- Workspace membership, roles, invitations, API keys (stored hashed) and MCP OAuth grants.
- Billing details handled by Stripe: plan, invoices, and the last four digits and expiry of a card. We never receive full card numbers.
Connection credentials
Hostnames, usernames and passwords or service-account keys for the databases and SaaS sources you connect. They are encrypted at rest with AES-256, decrypted only inside our API to execute your requests, and never sent to AI providers, agents, apps or your browser.
Your content
- Saved queries, notebooks, dashboards, app source code and data bindings — stored in your workspace repository and database.
- Query results and materialized data extracts (parquet files) that you or a schedule produce. They are stored so apps and dashboards can serve them; you can delete them at any time.
- Schema metadata (table and column names, types, sample rows you request) used by the AI agent to write correct queries.
- Conversations with the in-product agent, including the prompts, tool calls and tool results in them.
Usage and technical data
- Server logs (IP address, user agent, timestamps, request paths, error details) kept for security and debugging.
- Product analytics events (which features are used, when) tied to your account.
- On the marketing website: aggregated analytics and, if you consent, marketing tags via Google Tag Manager.
3. Why we process it
- To provide the service (contract): run your queries, host your apps, sync your sources, bill your plan.
- AI features (contract): when you use the agent, the relevant prompt, schema metadata and the query results you choose to share are sent to the model provider selected for your workspace. Providers are contractually barred from training on this data.
- Security and abuse prevention (legitimate interest): logs, rate limiting, read-only enforcement for agents.
- Improving the product (legitimate interest): aggregated usage analytics; agent traces reviewed to fix failures. We do not use your database contents to train models.
- Communication (contract / consent): transactional email always; product news only if you opt in.
4. Where it lives and who processes it
The hosted service runs on Google Cloud Platform in europe-west1 (Belgium, EU); the primary database is MongoDB Atlas in the EU. Some sub-processors are in the United States; transfers rely on the EU–US Data Privacy Framework or standard contractual clauses.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting of the API, app builds and published apps; artifact storage | EU (europe-west1) |
| MongoDB Atlas | Primary database (workspaces, users, saved queries, encrypted connection credentials) | EU |
| Vercel | Marketing website hosting; AI Gateway routing model requests | US / global edge |
| OpenAI, Anthropic, Google | Large-language-model inference for the in-product agent (prompts, schema metadata and query results you choose to share with the agent) | US |
| Langfuse | LLM observability — traces of agent conversations for debugging and quality | US |
| E2B | Isolated sandboxes that build and preview apps and run notebook kernels | US / EU |
| Inngest | Background job orchestration (syncs, scheduled refreshes, deploys) | US |
| Stripe | Billing and payments (we never see full card numbers) | US / EU |
| SendGrid (Twilio) | Transactional email — invitations, verification, password resets | US |
| GitHub | Sign-in (OAuth), optional connected repositories, source hosting | US |
| Google (Sign-in, Tag Manager) | Sign-in (OAuth); website analytics tags | US |
5. AI agents and the MCP server
When you connect an external agent (Claude, Cursor, Codex, ChatGPT or any MCP client) to Mako, that agent runs under youraccount with the permissions you grant at sign-in — read-only by default. What the agent sends to its own model provider is governed by that provider’s policy, not this one. Mako only collects the requests it needs to serve the tool calls; it does not read your conversation with the agent.
6. Retention
- Account and workspace data: for the life of the account, then deleted within 30 days of closure.
- Connection credentials: until you remove the connection.
- Query results and materialized extracts: until replaced by a refresh or deleted by you.
- Agent conversations and traces: 90 days, then deleted or anonymised.
- Server logs: 30 days. Billing records: as long as tax law requires.
7. Your rights
You can export or delete your data from the app, or ask us at privacy@mako.ai to access, correct, delete, restrict or port it, and to object to processing based on legitimate interest. Under Swiss and EU law you may also complain to your data protection authority. We answer within 30 days.
8. Cookies
The app uses a session cookie and local storage strictly to keep you signed in and remember preferences. The website sets analytics and marketing cookies only with your consent.
9. Changes
We will announce material changes by email or in the app at least 14 days before they take effect. The date at the top is the version in force.