MacrosonaLiving intelligence
Terms of ServiceGet started
Back to Macrosona

Legal

Privacy Policy

How Macrosona protects account data, source material and the living memory created from it.

Effective 18 August 2026

On this page
01Scope and our role02Who we are03Personal data we handle04Where data comes from05How and why we use data06AI processing and model training07Who receives data08International transfers09How long we keep data10Cookies and browser storage11Your privacy rights12Security13Children14Changes and contact
01

Scope and our role

This Privacy Policy explains how Imitation AI Ltd handles personal data through Macrosona’s website, hosted workspace, APIs, integrations, support and related services.

Two different roles

We are a controller when we decide how to use account, website, security and business-contact data. For conversations, transcripts, documents and other content placed in a customer workspace, the customer normally decides why that data is used. In that situation the customer is the controller and we act as its processor.

If your data appears in a workspace operated by your employer, client or another Macrosona customer, contact that organisation first to exercise your rights. We will support it in responding. An applicable data processing agreement governs our processing of Customer Content on a customer’s behalf.

02

Who we are

Macrosona is operated by Imitation AI Ltd, registered in England and Wales under company number 13215177. Our registered office is 167–169 Great Portland Street, Fifth Floor, London, England, W1W 5PF.

For privacy questions or rights requests, email info@imitation-ai.com. We have not appointed a statutory data protection officer; privacy enquiries are handled through that address.

03

Personal data we handle

Account and relationship data

Name, email address, organisation, workspace, role, invitation and verification status, authentication identifiers, support messages, contractual details and preferences. We do not receive your password from Firebase Authentication.

Customer Content and derived memory

Material you or an authorised connection provides, including conversations, visible human and assistant messages selected for capture, meeting recordings or transcripts, documents, notes, decisions, commitments, feedback and instructions. We also process derived concepts, summaries, evidence links, relationships, embeddings, provenance, confidence signals and revision history. Customer Content may contain information about people who do not have a Macrosona account.

Connections and credentials

Connector identifiers, authorisation status, source metadata, sync history and encrypted or otherwise protected access tokens for services you choose to connect, such as Plaud or Granola. Personal access tokens for agent connections are stored using a one-way verifier where supported; the secret is shown to you when created.

Technical and usage data

IP address, browser and device information, request timestamps, service events, authentication events, diagnostic logs, feature use, error data and security signals. The application also stores limited authentication and session state in your browser.

Optional development traces

For accounts explicitly enabled as development samples, selected AI requests and responses, token usage, call type, workspace and user identifiers may be sent to our evaluation service so we can test quality. This is disabled for other users and can be switched off by an administrator.

04

Where data comes from

We receive data directly from you, your workspace owner or administrator, your use of the Service, and services you intentionally connect. Workspace content may also come from colleagues, meeting participants, documents, connected AI tools or other sources selected by the customer.

Customers are responsible for providing required privacy information to people whose data they place in Macrosona and for ensuring they have an appropriate lawful basis.

05

How and why we use data

PurposeTypical dataLawful basis when we are controller
Provide accounts, workspaces, capture, retrieval, integrations and supportAccount, Customer Content, connections and service eventsPerformance of our contract; legitimate interests in providing requested business services
Authenticate users, enforce permissions, prevent abuse and protect the ServiceAccount, credential, device, network and security dataContract; legitimate interests in security; legal obligation where applicable
Operate, debug and improve reliability and qualityUsage, diagnostic and, only for enabled development samples, evaluation trace dataLegitimate interests in maintaining and improving the Service
Respond to enquiries and manage our customer relationshipContact, support and contractual dataContract; legitimate interests in customer service and business administration
Meet legal, regulatory and accounting duties and establish or defend claimsRelevant account, transaction, log and correspondence dataLegal obligation; legitimate interests in protecting legal rights
Send requested product or service communicationsName, email and communication preferencesConsent where required; otherwise legitimate interests. You can opt out of marketing at any time

Where we act as processor, we use Customer Content on the customer’s documented instructions to provide the Service and as required by law.

06

AI processing and model training

Macrosona uses AI models to extract evidence, form experiences and concepts, maintain connected memory, generate summaries and answer retrieval requests. Relevant Customer Content may be sent through OpenRouter to approved model providers for these functions.

Our production requests are configured to deny provider data collection and to use providers that support zero-data-retention handling. We do not use Customer Content to train general-purpose AI models or permit model providers to use it for their own training. We may use de-identified or aggregated operational information that does not identify a person or expose Customer Content to understand service performance.

Macrosona does not make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. Customers must not use generated memories as the sole basis for such decisions.

07

Who receives data

We disclose personal data only where needed for the purposes above:

  • Google Cloud and Firebase provide hosting, storage, databases, authentication, secret management and service infrastructure.
  • OpenRouter and approved AI model providers process bounded content needed for AI functions under our privacy configuration.
  • Braintrust receives evaluation traces only for explicitly enabled development-sample accounts.
  • Services you connect, including Plaud, Granola, AI agents or other integrations, exchange data at your instruction and operate under their own privacy terms.
  • Professional advisers, insurers and authorities may receive data where reasonably necessary to obtain advice, protect rights, complete a corporate transaction or comply with law.

We do not sell personal data and do not share Customer Content for third-party advertising.

08

International transfers

Our primary production services are deployed in Google Cloud’s Europe region. Some suppliers or their support operations may process data outside the United Kingdom. Where personal data is transferred internationally, we rely on a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or another approved safeguard, and apply additional measures where appropriate.

You may contact us for more information about safeguards relevant to your data.

09

How long we keep data

Macrosona is designed to create durable memory, so Customer Content and its evidence, provenance and revision history are normally retained for the life of the workspace unless the customer deletes it, instructs us to delete it, or an agreement specifies another period. This durability does not override a verified legal deletion obligation.

Account and relationship data is kept while the account or customer relationship is active and afterwards only as reasonably needed for closure, security, dispute handling, legal or accounting obligations. Connector credentials are kept until the connection is revoked, expires or is removed. Security and diagnostic logs are kept for periods proportionate to troubleshooting, fraud prevention and legal needs.

When data is deleted, residual copies may remain temporarily in protected backups until overwritten under our backup cycle. We may retain a restricted record where law requires it or where necessary to establish, exercise or defend legal claims. We determine periods by considering the nature and sensitivity of the data, the reason it was collected, contractual requirements, risk and applicable law.

10

Cookies and browser storage

Macrosona currently uses cookies and browser storage needed for authentication, security and core session functionality, including Firebase Authentication and short-lived interface state. We do not currently use third-party advertising cookies or behavioural advertising trackers on the Service.

If we introduce optional analytics or marketing technologies that require consent, we will provide an appropriate choice before using them. A connected sign-in provider, such as Google, may use its own cookies when you choose that sign-in method.

11

Your privacy rights

Depending on the circumstances, you may have the right to ask for access to your personal data, correction, deletion, restriction, portability, or to object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

Your right to object

You have the right to object to processing based on our legitimate interests and to object at any time to direct marketing.

Send requests to info@imitation-ai.com. We may need to verify your identity. If a customer controls the workspace containing your data, please contact that customer; we will assist it as required.

You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint or to your local supervisory authority. We would appreciate the opportunity to address your concern first.

12

Security

We use measures designed to protect personal data, including encryption in transit, managed cloud security, workspace-scoped access controls, restricted service identities, hashed token verifiers, secrets management, audit and operational logging, and access limited to authorised personnel and suppliers.

No system is completely secure. Please protect your devices and credentials, use appropriate workspace permissions and tell us promptly if you believe your account or data has been compromised.

13

Children

Macrosona is intended for adults and organisational use and is not directed to children under 18. Do not create an account for a child or intentionally submit children’s data unless this is expressly agreed with us and you have completed all required safeguarding and data-protection assessments.

14

Changes and contact

We may update this policy as the Service, our suppliers or the law changes. We will publish the updated version with a new effective date and notify account holders of material changes where appropriate.

Contact: info@imitation-ai.com
Imitation AI Ltd
167–169 Great Portland Street, Fifth Floor
London, England, W1W 5PF

MacrosonaLiving intelligence

Organisational intelligence, made durable.

SecurityPrivacyTermsDocumentation
© 2026 Imitation AI Ltd