Privacy
Data collected through mikaelbuilds is held by Syneron Technologies Limited, a company registered in Hong Kong under company number 79999193, registered office 3906, 39/F, The Center, 99 Queen's Road Central, Hong Kong. Questions about any of this go to hello@mikaelbuilds.com.
What we hold
- Your brief. Everything you tell the onboarding interview: what your business does, what you sell, your prices, how you want to sound, who your customers are, and what the agent may do without asking you.
- Your site content. The text, photos, logos and files you give us, and the pages we build from them.
- Your agent's working data. The enquiries that come in, the conversations it handles, the drafts it writes, the prospects it researched, and the record of what it did. This is your operational data and it belongs to you.
- Your billing identity. Your Stripe customer reference and the email on your receipt. Card numbers are handled by Stripe and never reach us.
- Your X profile, if you claimed a spot on the wall. Your X user id, your handle, your display name and avatar, and the link you posted. All of it is already public on X.
What we never keep in the database
Two things are treated differently from everything above, because a copy of either one is a copy of your business:
- Your AI key.
- Your mailbox app password.
Both are submitted through a plain form, never through a chat with an agent and never through any text that reaches a language model. They are encrypted the moment they arrive, with a key our database does not have. They are pulled exactly once, by the machine that sets your agent up, and deleted from the database at that point. They never appear in a log line, a transcript, an error report or a support message.
What we will not claim is that they stop existing. From that moment they live inside your own agent's isolated instance, on the server described under "Where it lives" below, because the key is what the agent authenticates with every time it calls a model and the app password is what it sends your mail with. We operate that server. So the accurate statement is: they are not in our database, nobody reads them back to you, nobody needs to, and you can revoke either one yourself at any time from the provider that issued it — for a Google mailbox, at myaccount.google.com/apppasswords. If either needs replacing, you submit a new one the same way.
What the agent does with your mailbox: an app password grants full mailbox access at most providers and cannot be narrowed down, so the limit is what the agent is built to touch. It reads the threads it started itself and one dedicated label; it writes replies and follow-ups on those threads; it does not read or summarise the rest of your inbox, and it never deletes anything. If you would rather not hand over a mailbox credential at all, we send through our own provider from your domain instead and never hold IMAP access.
Your X account
Signing in with X asks for read access only, and the scopes are exactly
users.read and tweet.read. No posting scope is ever
requested, from anyone, at any point. We never post from your account,
and the permission that would allow it is one we deliberately do not hold. You
can revoke the connection from X at any time and keep your number on the wall.
Where it lives
- Cloudflare hosts this site, your site, and the database behind both.
- Your agent's own server. Your agent does not run on Cloudflare. It runs on a server we rent from Hetzner and operate ourselves, in its own isolated instance with its own user account, its own gateway and its own secrets, not shared with another client. Its working memory and the record of what it did — the enquiries, the conversations, the drafts, the researched prospects — live there. The country that server is in is named in your onboarding brief before anything is provisioned on it.
- Stripe handles payments and holds your card details.
- Your AI provider, under your own key, processes what your agent sends it. Unless you chose another one, that is OpenRouter, and the account and the bill are yours. Their terms apply to what passes through them.
- Telegram carries the messages between you and your agent.
- Your own mail provider sends your agent's email, because it sends from your mailbox rather than ours. If your provider makes that impossible, or you would rather not give mailbox access, we fall back to our own sending provider using your domain.
Who sees it
We do, to build your site and your agent, to answer your support requests, and to fix things when they break. Nobody else. Your data is not sold, not shared with advertisers, and not used to train anything.
Your customers' data
Your agent handles information about the people who contact you. That information is yours and we treat it as yours: it stays inside your agent's own isolated instance, it is not pooled with any other client's, and it leaves with you when you go.
Keeping and deleting
- We keep your data while you are a subscriber, because the agent is using it.
- When you cancel, your working data is exported to you.
- Ask us to delete it and we delete it, including the brief and the site content. Billing records stay with Stripe, which is a legal obligation on their side and not a choice on ours.
- Wall entries are a public, numbered record and are not deleted on request, but you can ask us to unlink your X profile from your number.
Cookies
All of them, named, because a list that is shorter than the code is worse than no list:
- A sign-in cookie and a profile cookie, if you signed in with X, for 30 days.
- Two short-lived cookies during the X sign-in round trip itself, which exist for ten minutes and secure that exchange.
- A referral cookie for 30 days if you arrived through someone's referral link, so their number on the wall gets the credit for your claim.
- A short-lived cookie after a successful checkout, so the onboarding page knows a payment happened.
None of them are advertising cookies, none of them follow you to other sites, and there are no analytics trackers on this site.
Reaching us
hello@mikaelbuilds.com, whether or not you are a customer. Asking your agent or replying to the email address on your Stripe receipt works too. Requests about your data are answered by a human within one business day.