Privacy Policy

Last updated: February 25, 2026

1. Introduction

Welcome to Maxi.io (“we,” “our,” or “us”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web and mobile applications (our “Services”).

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when you:

  • Register for an account (name, email address, password)
  • Complete your profile (avatar, timezone, language preferences)
  • Use our services (goals, habits, journal entries, action items, and interactions with our AI features)
  • Communicate with us (support requests, feedback)
  • Make purchases (payment information)

2.2 Automatically Collected Information

When you use our services, we automatically collect:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, time spent)
  • Authentication data (session tokens, login timestamps)

2.3 Analytics Information

We use PostHog for analytics to understand how users interact with our services. PostHog collects anonymized usage data, session recordings (with sensitive data masked), and feature usage statistics. This helps us improve our product and user experience.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain our services
  • Improve, personalize, and expand our services
  • Communicate with you about updates, support, and promotional content (you may opt out at any time)
  • Process your transactions and manage subscriptions
  • Analyze usage patterns to improve our services and user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

4. Data Storage and Security

Your data is stored on secure servers located in Amsterdam, Netherlands (EU region), in compliance with GDPR requirements. We use industry-standard security measures including:

  • Encryption in transit (TLS/SSL) and at rest
  • Secure authentication via Supabase Auth
  • Row Level Security (RLS) policies to protect your data
  • Regular security audits and updates
  • Access controls and monitoring

While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

5.1 Essential Cookies

Required for authentication and core functionality. These cannot be disabled as they are necessary for the service to work.

5.2 Analytics Cookies

PostHog analytics cookies help us understand usage patterns. You can opt out of analytics tracking in your account settings.

5.3 Preference Cookies

These remember your settings like language preference, timezone, and theme.

6. Third-Party Services

We use the following third-party services:

  • Supabase: Database hosting and authentication
  • PostHog: Analytics and product insights
  • OpenAI: AI-powered features for goal setting and reflection
  • DeepSeek: AI-chat features
  • OAuth Providers: Google for authentication
  • Stripe: Payment processing
  • Railway: Deployment on EU servers (Amsterdam, Netherlands)

Each third-party service has its own privacy policy. We select our partners carefully and encourage you to review their policies to understand how they handle your data.

7. AI Data Sharing

To provide AI coaching features, we send certain data to third-party AI providers. Here is exactly what is shared and with whom:

7.1 What We Share

  • Your goals, habits, and tasks
  • Chat messages you send to the AI coach
  • Progress reviews and journal entries
  • Contextual data needed for personalized coaching

7.2 Who We Share With

  • OpenAI — for goal planning, reflections, and coaching features
  • DeepSeek — for AI chat conversations

7.3 What We Never Share with AI Providers

  • Your email address or account credentials
  • Passwords or payment information
  • Personal identification numbers

7.4 How We Protect Your Data

All data sent to AI providers is transmitted over encrypted connections (TLS/SSL). We anonymize requests where possible, and your personal account details are not included in AI requests. Your conversations are not used to train AI models.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal compliance, dispute resolution, or enforcement of our agreements.

9. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), if you are a resident of the European Economic Area (EEA), you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing of your data
  • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your information
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection authority

To exercise these rights, please contact us at [email protected]. We will respond to your request in accordance with applicable data protection laws.

10. International Data Transfers

Your data is primarily stored and processed in the European Union (Amsterdam, Netherlands). However, to provide our services, we may need to transfer your data to third-party services located outside the EEA, such as the United States.

Specifically, services like OpenAI, DeepSeek, PostHog, Stripe, and Google are based in the US. When we transfer your data to these services, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognized transfer mechanisms, to protect your data.

11. Children's Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last updated” date. For significant changes, we will provide more prominent notice or request your consent as required by law.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

  • Service: Maxi.io
  • Business Name: Thomas Maximini
  • Data Protection Contact: [email protected]
  • Address: Praceta Antonio Vicente Campinas 1-3A, Faro, Faro 8005-214, Portugal