Updated: September 8, 2026
1. About this policy
MacroMax, located in Singapore, is responsible for the personal data described in this policy. It applies to the MacroMax website, Windows client, MMaxLab, AI Agent, accounts, trials, downloads, support, and related online services.
2. Data we collect
- Account data: username, email address, securely hashed password, account status, trial and subscription status, and sign-in times.
- Device and security data: hashed device identifiers, device name, client and app versions, IP address, browser or client identifier, sessions, and security events. The original SMBIOS UUID or Windows MachineGuid is transformed into a hash on the client before transmission.
- Verification and contact data: email-verification status, CAPTCHA challenges and security logs, and information you submit in contact forms, support tickets, and attachments.
- Product and project data: project names and identifiers, package versions and hashes, permissions, and access-code status. A normal project export creates an encrypted package locally; the server registers package identifiers and authorization metadata.
- AI Agent data: to provide AI features, the client sends your instructions, conversation context, and necessary project context to MacroMax services for forwarding to the selected model provider. The server records operational metadata such as request identifiers, model, token usage, status, timing, and errors, but does not write prompt or response bodies to the AI usage record. Full chat history is stored locally in your project at ai-agent/chats.json.
3. How we use data
We use data to create and maintain accounts, verify identity, provide trials and subscriptions, enforce concurrent sign-in limits, deliver downloads and updates, operate the AI Agent, manage project authorization, provide support, prevent fraud and abuse, secure the service, calculate usage, and comply with legal obligations.
4. Basis and consent
We process personal data as necessary to provide our services, with consent, for reasonable security and business purposes, or to meet legal requirements. You may withdraw consent-based processing, without affecting earlier processing. If required data is unavailable, some services may no longer work.
5. Sharing and overseas transfers
We disclose data only as needed to hosting, email, infrastructure, support, and AI model providers. AI requests may currently be sent to Moonshot/Kimi or DeepSeek, depending on model availability and your selection. Providers may process data outside Singapore. We use contractual, technical, and organizational safeguards intended to provide protection comparable to Singapore data-protection standards. We do not sell personal data.
6. Retention
- CAPTCHA and verification security records: 30 days after use or expiry; login sessions: 30 days after expiry or revocation.
- Sign-in, device, IP, and client security logs: 12 months; general enquiries and closed support tickets: 24 months; support attachments: 12 months after closure.
- AI request and usage metadata: 24 months; email and device hashes used for trial eligibility: 5 years after the trial claim.
- Project, package, and authorization metadata: while active, then normally deleted or anonymized within 90 days after revocation or account deletion.
- Account data: while the account remains active; verified deletion requests are normally processed within 30 days, with backup copies removed through a 90-day rotation.
- Order, tax, and accounting records: normally at least 5 years where required by law.
We may retain records longer where reasonably necessary for disputes, fraud investigations, legal requests, or legal holds. When retention ends, data is deleted, de-identified, or anonymized.
7. Security
We use measures such as encryption in transit, password hashing, protected session tokens, access controls, and security logs. The Windows client stores login tokens in storage protected for the current Windows user. No system is completely secure; do not submit passwords, licence keys, or unnecessary sensitive information through contact forms.
8. Your choices and rights
Subject to applicable law, you may request access to or correction of personal data, withdraw consent, ask about our processing, or request deletion of your account and related data. The website and client do not yet provide automated deletion or export controls. Contact us at the address below; we may verify your identity and retain records required by law.
9. Minors
The services are intended for users aged 15 or older. Users aged 15–17 must have permission from a parent or legal guardian. A user under 18 must not purchase a paid subscription personally; the purchase must be completed by a parent or legal guardian.
10. Cookies
The website uses necessary access and refresh-session cookies to keep you signed in and protect your account. They use HttpOnly, Secure where applicable, and SameSite=Lax settings. Before the website enters formal promotion, Google Analytics 4 is enabled by default to measure page visits, traffic sources, device categories, and aggregate events such as downloads, registration, login, and contact. Turning analytics off does not affect core website functions, and you can disable or re-enable it through Cookie settings in the footer. We do not send usernames, email addresses, form contents, verification codes, account IDs, project names, or client device IDs to Google Analytics.
11. Contact and complaints
To exercise a right, ask a privacy question, or make a complaint, email milohwae@gmail.com. We will verify and respond within a reasonable time.
12. Changes
We may update this policy as our services or legal requirements change. Material changes will be explained through the website, an account notice, or another appropriate method, and a new effective date will appear here.