Skip to content

Privacy Policy

Effective Date: February 23, 2026 Last Updated: February 23, 2026

MidOS Research (“we”, “us”) operates the MidOS knowledge infrastructure service at midos.dev. This policy explains how we handle your data.

  • Email address (for authentication and communication)
  • Hashed password (bcrypt, never stored in plaintext)
  • Tier and subscription status
  • API queries (tool name, timestamp, response status)
  • Rate limiting counters (per-key, per-IP)
  • Session metadata (session ID, duration, tool call count)
  • Feedback and ratings submitted via submit_feedback
  • Research requests (topic, context)
  • Episodic memory entries (if your tier supports write access)
  • We use Umami (privacy-first, cookie-free analytics) on midos.dev
  • Umami does not use cookies, does not track across sites, and does not collect personal data
  • We see aggregate page views and referrers only
  • Payments are processed by Paddle (Merchant of Record)
  • Paddle collects payment details (card, PayPal, etc.) directly
  • We receive only: transaction ID, subscription status, tier, and email
  • We never see or store your full card number
DataPurposeLegal Basis
EmailAuthentication, billing notices, service updatesContract performance
API queriesRate limiting, abuse prevention, service improvementLegitimate interest
FeedbackQuality improvement, knowledge validationConsent (you choose to submit)
Research requestsDelivering the research service you requestedContract performance
Episodic memoryProviding cross-session memory featuresContract performance
AnalyticsUnderstanding usage patterns, improving UXLegitimate interest
  • We do not track you across websites
  • We do not use advertising cookies or trackers
  • We do not sell or share your data with advertisers
  • We do not read the content of your source code or repositories
  • We do not use your queries to train AI models
DataRetention
Account dataUntil you delete your account + 30 days
API logs90 days, then aggregated (anonymized)
FeedbackIndefinite (used for knowledge quality)
Research requests1 year after delivery
Episodic memoryUntil you delete it or close your account
Payment recordsAs required by tax law (typically 7 years, held by Paddle)

We share data only with:

  • Paddle — payment processing (as Merchant of Record, they are the data controller for payment data)
  • Hetzner — infrastructure hosting (EU servers, GDPR-compliant)
  • Law enforcement — only when legally compelled

We do not sell data. We do not share data with analytics companies, ad networks, or data brokers.

You have the right to:

  • Access your data — request an export via [email protected]
  • Correct inaccurate data — update your profile or contact us
  • Delete your account and associated data — contact us or use the dashboard
  • Export your episodic memory and feedback — available via API or on request
  • Object to processing based on legitimate interest
  • Withdraw consent for optional data processing (e.g., feedback) at any time

We respond to rights requests within 30 days.

  • Passwords are hashed with bcrypt
  • API keys are generated with cryptographic randomness
  • All traffic is encrypted via TLS (HTTPS)
  • Infrastructure hosted on Hetzner (EU) with automated backups
  • Access to production systems is restricted and logged

Our servers are located in the EU (Hetzner, Germany). If you access the Service from outside the EU, your data is transferred to and processed in the EU under GDPR-level protections.

MidOS is not directed at children under 16. We do not knowingly collect data from children.

We may update this policy. Material changes are announced via email to paid subscribers and on the website. The “Last Updated” date at the top reflects the most recent revision.

For privacy questions or rights requests: [email protected]