Scope and our role
This Privacy Policy explains how Imitation AI Ltd handles personal data through Macrosona’s website, hosted workspace, APIs, integrations, support and related services.
We are a controller when we decide how to use account, website, security and business-contact data. For conversations, transcripts, documents and other content placed in a customer workspace, the customer normally decides why that data is used. In that situation the customer is the controller and we act as its processor.
If your data appears in a workspace operated by your employer, client or another Macrosona customer, contact that organisation first to exercise your rights. We will support it in responding. An applicable data processing agreement governs our processing of Customer Content on a customer’s behalf.
Who we are
Macrosona is operated by Imitation AI Ltd, registered in England and Wales under company number 13215177. Our registered office is 167–169 Great Portland Street, Fifth Floor, London, England, W1W 5PF.
For privacy questions or rights requests, email info@imitation-ai.com. We have not appointed a statutory data protection officer; privacy enquiries are handled through that address.
Personal data we handle
Account and relationship data
Name, email address, organisation, workspace, role, invitation and verification status, authentication identifiers, support messages, contractual details and preferences. We do not receive your password from Firebase Authentication.
Customer Content and derived memory
Material you or an authorised connection provides, including conversations, visible human and assistant messages selected for capture, meeting recordings or transcripts, documents, notes, decisions, commitments, feedback and instructions. We also process derived concepts, summaries, evidence links, relationships, embeddings, provenance, confidence signals and revision history. Customer Content may contain information about people who do not have a Macrosona account.
Connections and credentials
Connector identifiers, authorisation status, source metadata, sync history and encrypted or otherwise protected access tokens for services you choose to connect, such as Plaud or Granola. Personal access tokens for agent connections are stored using a one-way verifier where supported; the secret is shown to you when created.
Technical and usage data
IP address, browser and device information, request timestamps, service events, authentication events, diagnostic logs, feature use, error data and security signals. The application also stores limited authentication and session state in your browser.
Optional development traces
For accounts explicitly enabled as development samples, selected AI requests and responses, token usage, call type, workspace and user identifiers may be sent to our evaluation service so we can test quality. This is disabled for other users and can be switched off by an administrator.
Where data comes from
We receive data directly from you, your workspace owner or administrator, your use of the Service, and services you intentionally connect. Workspace content may also come from colleagues, meeting participants, documents, connected AI tools or other sources selected by the customer.
Customers are responsible for providing required privacy information to people whose data they place in Macrosona and for ensuring they have an appropriate lawful basis.
How and why we use data
| Purpose | Typical data | Lawful basis when we are controller |
|---|---|---|
| Provide accounts, workspaces, capture, retrieval, integrations and support | Account, Customer Content, connections and service events | Performance of our contract; legitimate interests in providing requested business services |
| Authenticate users, enforce permissions, prevent abuse and protect the Service | Account, credential, device, network and security data | Contract; legitimate interests in security; legal obligation where applicable |
| Operate, debug and improve reliability and quality | Usage, diagnostic and, only for enabled development samples, evaluation trace data | Legitimate interests in maintaining and improving the Service |
| Respond to enquiries and manage our customer relationship | Contact, support and contractual data | Contract; legitimate interests in customer service and business administration |
| Meet legal, regulatory and accounting duties and establish or defend claims | Relevant account, transaction, log and correspondence data | Legal obligation; legitimate interests in protecting legal rights |
| Send requested product or service communications | Name, email and communication preferences | Consent where required; otherwise legitimate interests. You can opt out of marketing at any time |
Where we act as processor, we use Customer Content on the customer’s documented instructions to provide the Service and as required by law.
AI processing and model training
Macrosona uses AI models to extract evidence, form experiences and concepts, maintain connected memory, generate summaries and answer retrieval requests. Relevant Customer Content may be sent through OpenRouter to approved model providers for these functions.
Our production requests are configured to deny provider data collection and to use providers that support zero-data-retention handling. We do not use Customer Content to train general-purpose AI models or permit model providers to use it for their own training. We may use de-identified or aggregated operational information that does not identify a person or expose Customer Content to understand service performance.
Macrosona does not make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. Customers must not use generated memories as the sole basis for such decisions.
International transfers
Our primary production services are deployed in Google Cloud’s Europe region. Some suppliers or their support operations may process data outside the United Kingdom. Where personal data is transferred internationally, we rely on a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or another approved safeguard, and apply additional measures where appropriate.
You may contact us for more information about safeguards relevant to your data.
How long we keep data
Macrosona is designed to create durable memory, so Customer Content and its evidence, provenance and revision history are normally retained for the life of the workspace unless the customer deletes it, instructs us to delete it, or an agreement specifies another period. This durability does not override a verified legal deletion obligation.
Account and relationship data is kept while the account or customer relationship is active and afterwards only as reasonably needed for closure, security, dispute handling, legal or accounting obligations. Connector credentials are kept until the connection is revoked, expires or is removed. Security and diagnostic logs are kept for periods proportionate to troubleshooting, fraud prevention and legal needs.
When data is deleted, residual copies may remain temporarily in protected backups until overwritten under our backup cycle. We may retain a restricted record where law requires it or where necessary to establish, exercise or defend legal claims. We determine periods by considering the nature and sensitivity of the data, the reason it was collected, contractual requirements, risk and applicable law.
Your privacy rights
Depending on the circumstances, you may have the right to ask for access to your personal data, correction, deletion, restriction, portability, or to object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
You have the right to object to processing based on our legitimate interests and to object at any time to direct marketing.
Send requests to info@imitation-ai.com. We may need to verify your identity. If a customer controls the workspace containing your data, please contact that customer; we will assist it as required.
You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint or to your local supervisory authority. We would appreciate the opportunity to address your concern first.
Security
We use measures designed to protect personal data, including encryption in transit, managed cloud security, workspace-scoped access controls, restricted service identities, hashed token verifiers, secrets management, audit and operational logging, and access limited to authorised personnel and suppliers.
No system is completely secure. Please protect your devices and credentials, use appropriate workspace permissions and tell us promptly if you believe your account or data has been compromised.
Children
Macrosona is intended for adults and organisational use and is not directed to children under 18. Do not create an account for a child or intentionally submit children’s data unless this is expressly agreed with us and you have completed all required safeguarding and data-protection assessments.
Changes and contact
We may update this policy as the Service, our suppliers or the law changes. We will publish the updated version with a new effective date and notify account holders of material changes where appropriate.
Contact: info@imitation-ai.com
Imitation AI Ltd
167–169 Great Portland Street, Fifth Floor
London, England, W1W 5PF