Macro Automation Inc, a Delaware corporation (“Macro Automation”, “we”, “us”), makes Macro Automation Studio (MAS): the website at automationmacro.com, the MAS desktop app for Windows and Apple Silicon Mac, MAS cloud devices, MAS Agent, the MCP server, the REST API and the marketplace (together, the “Service”). This policy explains what personal data we collect through the Service, why, who receives it, how long we keep it, and the rights you have. It does not cover data collected by third parties you connect to the Service, such as the apps you automate, the proxy you bring, or the AI clients you attach.
Who is responsible
Macro Automation Inc is the controller of the personal data described here. Questions, requests and complaints go to legal@automationmacro.com. For product help use support@automationmacro.com or our Discord server, which is run by Discord under its own privacy policy.
What we collect
The table lists each category, what it contains, why we process it, our legal basis where one is required, and how long we keep it. “Contract” means the processing is needed to provide the Service you asked for; “legitimate interest” means we have a business reason that does not override your rights; “consent” means you can withdraw it at any time; “legal obligation” means a law requires it.
| Category | What it contains | Why | Basis | Retention |
|---|---|---|---|---|
| Account | Name, email address, avatar, sign-in method, referral code, role, the identifier your sign-in provider gives us | Create and secure your account, send service email; if a partner referred you, show that partner your account status, plan and payment status | Contract | Life of the account, then deleted on request or after closure |
| Sign-in and app sessions | IP address, browser or app user agent, sign-in method, last seen time | Security, abuse prevention, session management | Legitimate interest | Life of the account |
| Downloads | IP address, referring page, installer version, referral link clicks and the partner code and channel label they carried | Distribution statistics, crediting partner referrals | Legitimate interest | 24 months |
| Partner program | For partners: name, email address, country, PayPal email, commission and payout records. For referred customers: the partner code, how the referral was captured, the channel label | Run the partner program, pay commissions, meet tax reporting duties | Contract, legal obligation | Payout and tax records as long as tax law requires; referral records for the life of the account |
| Billing | Stripe customer id or PayPal payer id, plan, device count, billing cycle, payment amounts and status, invoice references, credit ledger | Charge you, issue invoices, handle disputes, keep accounts | Contract, legal obligation | As long as tax and accounting law requires after the last transaction |
| Devices and groups | Device names, emulator ports, group membership, settings profiles, run arguments | Run macros where you point them | Contract | Until you delete them |
| Code and macros | Your projects in git repositories on our servers, code snapshots uploaded for cloud runs, image library templates, marketplace listings you publish | Store, sync and run your macros; publish what you choose to publish | Contract | Until you delete the project; listings until you unpublish them |
| Runs and logs | Macro name, device, start and end time, exit code, error message, script output shipped from cloud runs, proxy exit IP and country | Show run history, deliver webhooks, support | Contract | Run records for the life of the account; cloud run output until you delete the run or the account |
| Cloud devices | Device configuration, state, the Android data on the device’s disk, an archive of that disk, files and APKs you upload, stream session tokens | Provide the cloud device | Contract | Deleted when you delete the device; archives removed at the same time |
| MAS Agent sessions | Your prompt, the device used, provider and model, the event log of the session, screenshots you opt in to keep, the compiled project, screen maps of the app | Build the macro you asked for, let you review the session | Contract | Until you delete the session; screen maps may be kept without personal data to speed up later sessions |
| API keys, webhooks, MCP | Hashed API keys, key scopes, webhook URLs and signing secrets, delivery records, MCP token issue times | Let your tools call the Service on your behalf | Contract | Keys until revoked; webhook deliveries 30 days |
| Proxies | Proxy host, port and credentials (encrypted at rest), traffic volume, exit IP and country per run | Route device traffic where you asked | Contract | Until you delete the proxy; usage records for the life of the account |
| Support and community | Emails you send us, the content of support conversations | Answer you | Legitimate interest | 24 months after the conversation ends |
| Diagnostics | Error reports from the backend and, when enabled, the desktop app: error text, stack traces, app version, operating system | Keep the Service reliable | Legitimate interest | 90 days |
| Website analytics | Google Analytics cookies and identifiers, pages viewed, approximate location from IP, referring site | Understand how the site is used | Consent | Per the Google Analytics retention setting, 14 months |
We do not collect special-category data, and we do not want it. If a screenshot or a file you process through the Service contains such data about you or anyone else, that is your choice and your responsibility.
Waitlists. If you join a waitlist on the site, for example for physical devices, we store the email address you enter, the product you asked about, the page language and the IP address of the request. We use it to send one email when that product opens and to block abuse of the form.
How we collect it
You give us data when you sign up, sign in, subscribe, add devices, write or upload code, start an agent session, create keys, webhooks or proxies, publish to the marketplace, or write to us. The desktop app and the backend collect data automatically when you use the Service: sign-in events, run records, error reports and the technical data listed above. Stripe, PayPal and Google send us the identifiers and status information described in the sections below. We do not buy data about you from data brokers.
Sign in with Google
When you sign in with Google we request the email, profile and openid scopes only: your email address, name and profile picture. We use them to create and identify your account and for nothing else. We do not read your Gmail, Drive, contacts or any other Google data. Our use of data received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
AI features and what leaves your device
MAS Agent and the MCP authoring tools work by looking at the screen. When you start an agent session or ask an AI client to author a macro, the Service sends to a third-party AI model provider: screenshots of the connected device (batched and pruned as the session goes on), your prompt and answers, the app package name, relevant macro code, and OCR text read from the screen. The providers we use are Anthropic, OpenAI and models reached through OpenRouter; the app shows which provider and model a session used. If you supply your own provider key, the requests go directly from your machine to that provider under your own agreement with it.
Screenshots can contain personal data about other people who appear on the screen, such as names in a chat app. You must not use the agent on screens you have no right to share.
We do not use your prompts, screenshots, code or macros to train models of our own, and we do not permit our providers to train on them where the provider offers that choice. Providers keep inputs for a short period for abuse monitoring under their API terms, after which they delete them. The event log and result of a session are stored with your account so you can review what the agent did; keyframe screenshots are kept only when you opt in from the session view, and you can delete a session at any time. Deleting a session never deletes the macro it produced.
You are interacting with an AI system whenever you use MAS Agent or an AI client through the MCP server. Generated macros can be wrong. Review them before running them on anything you care about.
Cloud devices
A cloud device is an Android instance that runs on our infrastructure on Amazon Web Services in the United States. Everything you do on it, install on it or sign in to on it stays on the device’s disk and in an archive we keep so the device can be rebuilt on another host. We do not look inside a device except to operate the Service, investigate abuse, or as the law requires. When you delete a device we delete its disk and its archive. A running device with no active run is stopped automatically after a period of inactivity.
If you enable Google apps on a cloud device you sign in with your own Google account. That account, and any app account you use on the device, is yours and governed by its provider’s terms; we never receive those passwords.
Proxies
If you attach a proxy, device traffic for that device is routed through it. For a bring-your-own proxy we store the host, port and credentials encrypted at rest. For our managed gateway, traffic passes through a third-party proxy network provider on our account, and we record the traffic volume for metering. For every run we record the exit IP address and country the proxy reported. We do not inspect the content of proxied traffic.
Cookies and analytics
The website uses Google Analytics to measure visits, which sets cookies and sends your IP address and page views to Google. It does not load until you accept it in the cookie banner shown on your first visit; declining keeps the site fully usable. Your choice is stored in your browser for twelve months and can be changed at any time through “Cookie settings” in the footer. Google’s advertising features are switched off for this site. You can also block the cookies with a browser setting or Google’s opt-out add-on. Videos on the site are embedded from YouTube in privacy-enhanced mode, which sets no cookie until you press play. Fonts load from Google Fonts. When you open the site through a partner link, it sets one first-party cookie, mas_ref, holding the partner code and a click identifier for 60 days so the download and your sign-up can be credited to that partner; it is needed for the program to work, contains no analytics identifier, is not shared with anyone, and does not depend on the banner. The desktop app stores your sign-in tokens on your computer so you stay signed in; it sets no advertising cookies.
We do not use advertising cookies, do not run retargeting, and do not sell or share personal data for cross-context behavioral advertising.
Who receives your data
We share personal data only with the service providers that run the Service, with people you tell us to share it with, and when the law requires it. Our providers act on our instructions under written contracts.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, databases, file storage, cloud device hosts, sign-in service (Cognito), content delivery | All service data | United States (Oregon) |
| Stripe | Card payments, invoices, subscription billing | Name, email, billing details, payment method (held by Stripe) | United States and worldwide |
| PayPal | PayPal payments and subscriptions | Name, email, PayPal account id | United States and worldwide |
| Sign in with Google, Google Analytics, YouTube embeds, fonts | Sign-in profile, analytics identifiers, IP address | United States and worldwide | |
| Anthropic, OpenAI, OpenRouter | AI model processing for MAS Agent and MCP authoring | Screenshots, prompts, code, OCR text | United States |
| Mailgun | Transactional email | Name, email, email content | United States |
| Sentry | Error reporting | Error reports, app version, technical identifiers | United States |
| Proxy network provider | Managed proxy gateway | Traffic metadata and volume | Worldwide exit locations |
| Discord | Community support, at your choice | Whatever you post there | Under Discord’s policy |
Data you direct outward is shared with the recipient you chose: webhook payloads go to the URLs you configure, MCP clients you attach receive what their tools return, and marketplace listings you publish are public along with your publisher name.
If you came to MAS through a partner link or a partner code, the partner who referred you can see your name, email address, plan, device counts, subscription status, renewal date and payment dates, amounts and status in their partner portal, so they can support you and see what they have earned. They cannot change your account, see your payment method, or see your macros, devices or other content, and they are bound by the Partner Program Terms to keep that information confidential. Partners are paid through PayPal, so the PayPal row above also covers partner payouts.
We may disclose personal data to comply with a law, court order or lawful request, to enforce our Terms, to protect the rights, property or safety of Macro Automation, our users or the public, or in connection with a merger, sale or reorganization of the company, in which case this policy continues to apply.
International transfers
We are a United States company and process data in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred there. For transfers to our providers we rely on the EU-US Data Privacy Framework and its UK extension where a provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, with a transfer risk assessment. You can request a copy of the relevant safeguard from legal@automationmacro.com.
How long we keep data
Retention periods are in the table above. In general we keep data for as long as your account exists and for a short period after it closes so we can restore it if the closure was a mistake, resolve disputes and meet legal obligations. Billing records are kept for as long as tax and accounting rules require. Backups roll off on their own schedule after the live copy is deleted.
Waitlist entries are deleted after the product they concern launches, unless you have become a customer by then, and at any time on request.
Your rights
Wherever you live, you can ask us to tell you what personal data we hold about you, correct it, give you a copy, delete it, or stop a particular use. Write to legal@automationmacro.com from the email address on your account; we may ask you to confirm your identity and we answer within 30 days. We will not treat you differently for exercising a right.
European Economic Area, United Kingdom and Switzerland. You have the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent at any time without affecting earlier processing, and the right to complain to your supervisory authority; in the UK that is the Information Commissioner’s Office. Where we rely on legitimate interests you may object and we will stop unless we have compelling grounds. We do not make decisions with legal or similarly significant effects on you by automated means alone.
United States. Depending on your state you may have the right to know what personal data we collect and how we use and share it, to access, correct or delete it, to obtain a portable copy, to opt out of sales, sharing for targeted advertising and profiling, and not to be discriminated against for exercising these rights. We do not sell personal data or share it for targeted advertising. If we ever did, we would honor opt-out preference signals such as Global Privacy Control. You may appeal a decision we make on a request by replying to our answer; we will explain the outcome of the appeal in writing.
Children
The Service is not directed at children. You must be at least 18 years old, or the age of majority where you live, to create an account. We do not knowingly collect personal data from anyone under 16, and if we learn that we have, we delete it. If you believe a child has given us personal data, write to legal@automationmacro.com.
Security
Data travels over TLS. Passwords are handled by Amazon Cognito; we never see or store them. API keys are shown once and stored as a one-way hash. Proxy credentials are encrypted at rest. Webhook deliveries are signed so you can verify them. MCP access tokens expire after one hour and cloud run tokens after a fixed period. The API applies rate limits and every request is tied to an account. No system is perfectly secure; if we learn of a breach affecting your data we will tell you and the authorities as the law requires.
Changes to this policy
When we change this policy we update the dates at the top and the version history at the bottom of this page. If a change materially reduces your rights or expands how we use data, we email account holders at least 30 days before it takes effect.
Contact
Macro Automation Inc, a Delaware corporation. Privacy requests and questions: legal@automationmacro.com. Product support: support@automationmacro.com.
Version history
- First version for the current Macro Automation Inc service.
- Rewritten to cover cloud devices, MAS Agent and the AI model providers, the MCP server, API keys, webhooks, proxies, the marketplace, a data table with retention periods, and EU, UK and US state rights.
- Partner program added, including what the partner who referred you can see, the referral cookie, and partner payout and tax records.