MMARW / LEGAL / PRIVACY
Privacy Policy
We are committed to protecting your personal data and respecting your privacy in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and applicable US state privacy laws. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our landing page or the MMARW App (the “Service”). The landing page is an informational offer; the MMARW App provides free and paid account-based services.
1. Data Controller & Contact Information
The Data Controller responsible for the processing of your personal data under the GDPR is:
Thomas Bechtold (Einzelunternehmer)
Nikolaus-Fey-Straße 6
97241 Bergtheim
Germany
Contact Email for Privacy Inquiries: mail@mmarw.com
Phone: +49 (0) 1525 9870943
Legal Notice: Legal Notice
Competent Supervisory Authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Where no Data Protection Officer has been appointed, please use the contact details above for all privacy-related inquiries. If the legal requirements for appointing a Data Protection Officer become applicable, this Privacy Policy will be updated accordingly.
2. Personal Data We Collect & Provision Requirements
When you interact with MMARW, we collect specific categories of personal data.
Mandatory Data: Providing your email address, name, and a password is a contractual requirement to create an account. Without this data, we cannot provide the Service to you.
Account & Registration Data: Email address, name, hashed password, email verification status, and account status flags.
Profile & Preference Data (Optional): Preferred AI name, primary use case/specialization, specific position, UI preferences (dark/light mode), enabled/disabled AI models, and explicit consent choices for product updates and marketing/newsletter emails.
Authentication Data: Security cookies, session tokens, and optional Two-Factor Authentication (2FA) verification codes.
Content & AI Interaction Data: Direct chats and Heavy projects, user inputs, prompts, chat histories, selected model and tool settings, uploaded files (including images, PDFs, TXT, and Markdown files), AI-generated outputs, and modified outputs in the workspace.
Log & Error Data: Depending on the request, Cloudflare and our infrastructure providers may process technical metadata such as IP address, country or region, browser or user-agent information, timestamps, request metadata, and error diagnostics for security, reliability, abuse prevention, and debugging. Retention depends on the relevant log type and configured provider or account setting and is limited to what is necessary for those purposes or required by law.
Support & Bug Reports: Bug report submissions (which may include chat content only if you voluntarily toggle "include chat content") and support email communications.
Payment & Subscription Data: Subscription plan status and limited payment metadata received via Stripe webhooks. (Note: Full payment and credit card details are processed directly and securely by Stripe; we do not store them).
Communication Data: Transactional emails and security notifications sent through Amazon Simple Email Service (AWS SES). AWS SES is used for delivery and necessary delivery metadata, such as acceptance, bounce, and complaint status. We do not use AWS SES or another email provider for open-rate or click-through tracking at the current launch.
Contract and Withdrawal Data: Where you create an MMARW App account or use a paid service, we may process account and contract references, cancellation or withdrawal declarations, timestamps, communication records, and refund or payment-status information needed to administer the contract and comply with legal duties.
Analytics Data: For visitors outside the EU/EEA, Cloudflare Web Analytics may be used to understand website-performance and usage metrics. Cloudflare describes this service as cookie-free and as not tracking individual end users across its customers’ websites.
Important Notice Regarding Special Categories of Data (Art. 9 GDPR)
MMARW is not intended for the processing of special categories of personal data within the meaning of Article 9 GDPR, such as health data, biometric data, genetic data, or other particularly sensitive personal data. Please do not upload or submit such data through the Service. If such data is nevertheless submitted, it may be processed to the extent technically necessary to provide the requested functionality, operate the Service, maintain security, or comply with applicable legal obligations. We do not intentionally request or encourage the submission of such data.
3. Legal Basis and Purposes for Processing
We process your personal data based on the following legal grounds under Art. 6(1) GDPR:
Performance of a Contract (Art. 6(1)(b)): To provide the core MMARW service, manage your account, authenticate logins, process subscriptions, facilitate multi-agent AI workflows (including transmitting prompts/files to selected AI providers), and provide customer support.
Legitimate Interests (Art. 6(1)(f)): To ensure platform security, prevent fraud, maintain system stability, and diagnose software errors (using bug reports, server logs, and AI Gateway logs).
Consent (Art. 6(1)(a)): For optional profile fields and voluntary subscriptions to product updates and newsletter emails. These communications are opt-in during signup and can be disabled at any time in the MMARW App settings.
Legal Obligation (Art. 6(1)(c)): To comply with tax, accounting, and legal retention obligations (e.g., keeping payment records or commercial support correspondence), and to administer statutory consumer rights such as cancellation and withdrawal.
4. Data Sharing, Processors, and International Transfers
To operate our Service, we use specialized third-party service providers. Depending on the functionality you use, your personal data may be processed in the United States and other countries outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we implement appropriate safeguards in accordance with Chapter V GDPR, including, where applicable, an adequacy decision, the EU-US Data Privacy Framework for a recipient that is currently certified for the relevant service, and/or the European Commission’s Standard Contractual Clauses. The safeguard used depends on the recipient and the transfer route in question.
Infrastructure & Operations
Cloudflare, Inc. (USA): Hosts our infrastructure (Workers, D1 Database, R2 Storage, AI Gateway, Workflows, Queues). Cloudflare also provides Web Analytics. Depending on the transfer route, the applicable safeguard may include the EU-US Data Privacy Framework (DPF), an adequacy decision, or Standard Contractual Clauses (SCCs).
Amazon Web Services, Inc. (USA): Used for sending transactional and security emails (AWS SES) via their US-East-1 region. Depending on the transfer route, the applicable safeguard may include the EU-US Data Privacy Framework (DPF), an adequacy decision, or Standard Contractual Clauses (SCCs).
Stripe, Inc. / Stripe Payments Europe, Ltd.: Handles all payment processing. Data transfers are safeguarded, depending on the transfer route, by the EU-US Data Privacy Framework (DPF), an adequacy decision, or Standard Contractual Clauses (SCCs).
Artificial Intelligence (AI) Providers
To provide AI functionality, MMARW routes the content needed for a request (for example, prompts, relevant chat context, and attached files) through Cloudflare AI Gateway or a comparable secure routing layer to the AI provider or inference provider selected for that request. The provider used depends on the selected model, enabled tool, task type, and service availability. We do not use customer prompts, files, or outputs to train MMARW's own models.
We use API and commercial configurations intended for business use. Provider-specific retention, training, and onward-transfer practices can differ by provider and model. We maintain contractual and technical safeguards appropriate to the route in use. Do not submit special-category data or other highly sensitive information unless you have assessed that use for your organisation and have an appropriate legal basis to do so.
DeepInfra (USA): Provides AI inference for selected models, including internal orchestration, context processing, and selected coding or reasoning tools. Requests routed to DeepInfra can include the content necessary to generate the requested output. As described in DeepInfra's current API privacy documentation, standard inference inputs and outputs are processed in memory and are not used for training by DeepInfra, subject to the provider's documented model- specific exceptions and service terms.
OpenAI, LLC (USA): Models via API (Cloudflare AI Gateway). International transfers are safeguarded, where applicable, by the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
Google LLC (USA): Gemini models via API (Cloudflare AI Gateway). International transfers are safeguarded, where applicable, by the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
Anthropic PBC (USA): Claude models via API (Cloudflare AI Gateway). International transfers are safeguarded, where applicable, by Standard Contractual Clauses (SCCs) and other appropriate safeguards as required.
xAI Corp (USA): Grok models via API (Cloudflare AI Gateway). International transfers are safeguarded, where applicable, by Standard Contractual Clauses (SCCs) and other appropriate safeguards as required.
Cloudflare Workers AI (USA): Models hosted on Cloudflare’s infrastructure or edge network. International transfers are safeguarded, where applicable, by the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
A current model catalogue can include models developed by third parties, for example NVIDIA, Google, Moonshot AI, or DeepSeek, where they are made available through an inference provider such as DeepInfra. The service provider that receives a request is determined by the active route, not only by the developer of the underlying model. We will update this policy before a new recipient or a material new processing route is used for personal data.
5. Data Retention and Deletion
We store your personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by law.
Unverified Accounts: If you register but do not verify your email address, your account and associated data will be automatically deleted 7 days after creation.
Account Deletion: You can delete your account at any time. We apply a 14-day grace period during which you can log back in to cancel the deletion. After 14 days, your account data is permanently deleted from our active databases.
System Backups: Deleted data may remain in encrypted system backups (e.g., Cloudflare D1 snapshots) for up to 90 days before being completely overwritten.
Bug Reports & Support: Bug reports, support correspondence, and voluntarily shared chat logs attached to bug reports are generally retained for up to 12 months after the issue has been resolved. In individual cases, retention may extend up to 24 months where this is strictly necessary for security investigations, the analysis of recurring system vulnerabilities, the prevention of abuse, or the establishment, exercise, or defense of legal claims. Where specific records are subject to statutory commercial or tax retention obligations, they may be retained for the legally required period.
Server Logs: Standard server access logs collected by Cloudflare are retained for a maximum of 90 days.
6. Your Rights Under the GDPR
As a data subject, you have the following rights regarding your personal data:
Right of Access (Art. 15): You can request information about the personal data we hold about you. You can trigger an automated export in your settings, and within a few minutes, you will receive an email containing a secure download link valid for 24 hours.
Right to Rectification (Art. 16): You can update or correct inaccurate data in your account settings.
Right to Erasure (Art. 17): You can request the deletion of your account and personal data at any time via your account settings.
Right to Data Portability (Art. 20): You have the right to receive your data in a structured, commonly used format. You can trigger an automated export in your settings, and within a few minutes, you will receive an email containing a secure download link valid for 24 hours.
Right to Restrict Processing (Art. 18): You may request that we limit the processing of your data under certain circumstances.
Right to Object (Art. 21): You can object to data processing based on legitimate interests.
Right to Withdraw Consent (Art. 7): You can withdraw your consent for optional features, including newsletter and product-update communications, at any time. These communication preferences can be changed in the MMARW App settings. Landing-page cookie preferences can be changed through the “Cookie settings” link in the footer.
To exercise any of these rights, you can use the built-in features in your dashboard or contact us at mail@mmarw.com.
Contractual cancellation or withdrawal declarations can be submitted through the clearly labelled withdrawal function in the MMARW App or by email. We process the declaration, account and contract reference, receipt timestamp, and any required payment or refund details only to handle the request, provide the legally required confirmation, and comply with applicable legal obligations.
7. US State Privacy Rights
If you are a resident of a US state whose privacy law applies to our processing, you may have additional rights, subject to statutory exceptions and applicable thresholds. Depending on the law, these may include the right to know or access personal information, correct inaccurate information, request deletion, obtain a portable copy, limit certain uses of sensitive information, appeal a denied request, and not be discriminated against for exercising your rights.
At the current launch, MMARW does not sell personal information for money and does not share personal information for cross-context behavioural advertising. We do not use personal information for profiling that produces legal or similarly significant effects. If these practices change, we will update this policy and provide any opt-out mechanism required by applicable law, including a recognised global privacy signal where required.
You may submit a privacy request by contacting mail@mmarw.com. We may verify your identity and request additional information where reasonably necessary to protect your account. We will respond within the time required by the law that applies to your request. You may use an authorised agent where permitted by applicable law. We do not discriminate against you for exercising a legally protected right.
8. Cookies & Local Storage
We distinguish between our Landing Page and our MMARW App:
MMARW App (Logged In, https://app.mmarw.com): We use only strictly necessary cookies and local storage to keep you securely logged in, manage your active session, and save your UI preferences (e.g., dark/light mode).
Landing Page (Logged Out, https://mmarw.com): We use a first-party session cookie only for the user-selected theme. At the current launch, the landing page does not write marketing identifiers to browser storage or pass signup attribution parameters to the app without confirmed analytics consent. If optional analytics is enabled in the future and you consent, limited signup attribution (such as page path, CTA location, and campaign parameters) may be passed to the signup flow; it is not used to build a persistent advertising profile. For visitors outside the EU/EEA, Cloudflare Web Analytics may be used as described above. If a consent choice is made, the first-party
mmarw_consent_v1cookie stores that choice for up to 180 days. It records the preference only and does not itself activate optional analytics or marketing technologies.
9. No Automated Decisions
We do not use automated decision-making with legal or significant impact on you (Art. 22 GDPR). The AI assistant provides information only and does not replace your own judgment.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Service, legal requirements, or technical developments. Before a material change to our processing, such as a new recipient of user content or a new international transfer route, takes effect, we will provide clear notice by email or in the Service where required. The "Last Updated" date at the top will reflect the current version.