Login
Maidaname · Legal

Privacy Policy

Version 1.1 · draft, pending legal review
Three kinds of people this covers

Most privacy policies are written for one person: the one who signed up. This product has three. If you made an account and started a naming project, you're the first kind. If someone invited you to weigh in on names for their project, and you never made an account at all, you're the second. If you're just looking at the site, before either of those, you're the third, and the lightest touch of all. All three are covered below, lightest touch first.

If you're just visiting the site, and haven't signed up or been invited to anything

If you land on this site without an account, and without an invitation to someone else's project, we may record that visit. This only happens on a small set of pages: the homepage, the sign-up, sign-in, password reset, and email verification pages, and the terms, privacy, and support pages. We never record anything on the page where an invited participant answers a naming round, and never once you've signed in.

We ask before we record anything. A banner on the page tells you what we'd track and lets you say no. Until you answer it, nothing is recorded. If you say no, nothing is ever recorded for that visit, or any later one, until you clear your own browser's storage; your answer is remembered on your device, as a simple yes-or-no, not as anything that identifies you.

If you say yes, what we record for each page is the page itself, how long you spent on it, how far you scrolled down it, and whether you clicked or typed anything at all. That's the whole list. We don't record your IP address, your browser, where you came from, or anything you typed into the page itself, like the free-text prompt on the homepage.

There's no cookie involved, and nothing that recognizes you on a later visit. The identifier for your visit exists only for as long as the browser tab stays open; close it, and there's nothing left to connect one visit to the next.

This is kept in its own separate record, apart from anything about accounts or invited participants; nothing joins the two automatically. If you later create an account, your earlier anonymous visits aren't linked to it. We don't sell this, and we don't share it with advertisers.

Visitor analytics run only if you say yes in the on-page banner. Nothing is recorded before you answer, and we remember if you say no.

If you were invited to a round, and never made an account

You didn't type your name or email into anything. The person running the project entered them, when they invited you, so the product would know who to send the link to and whose answers belong to whom. That's the only reason we have them.

What we have: your name, your email, and whatever you say in the round itself, your rankings, comments, and answers to any questions the facilitator asked. Opening your invite link only asks you for a short access code, not your name or email again.

What happens to it: your answers get sent to whichever AI provider is generating or evaluating names for that project, labelled only with a number, like "Participant 2", so the tool can tell your input apart from anyone else's. Your name and email are never sent to an AI provider. Your answers go as you wrote them, so anything you put in an answer yourself goes with it. See "who sees it" below for exactly which providers and what else they get. Nothing about you is sold, and nothing is used to advertise to you.

How to stop being in it: the facilitator can remove you from a round, which stops you being asked for anything further, but doesn't erase what you already said; that stays on the record. The only thing that deletes your name, email, and everything you said is the facilitator deleting the whole project, which removes it permanently, for everyone in it, along with the rest of the project. You can ask a facilitator to do that, or contact us directly (see "contact," below), though we'd still need to go back to them, since we don't delete someone's project without them.

If you have an account
What we collect

When you sign up or sign in. Your name and email address. If you set a password, we store it hashed, not in plain text. If you sign in with Google instead, we get your name, email, and profile photo from Google, and hold the tokens Google issues so you can stay signed in. Either way, we keep a record of your login sessions: a session token, the time it started and expires, and the IP address and browser the session came from, which is standard practice for keeping a login secure.

When you run a project. The project's title, the kind of thing being named, and anything you write into it: briefs, framing, positioning, notes, the names generated and your reaction to them.

When you invite participants. Their name and email, which you give us. See the section above for what happens to it on their end.

If you submit feedback. What you wrote, plus some technical context that comes along automatically: the page you were on, your browser, screen size, language, and timezone. This helps us understand a report without having to ask you to repeat yourself.

When you pay. We don't collect or see your card number. Stripe handles that directly; we only get back a confirmation that a payment went through, and store the ledger of your balance and what it's been spent on.

How we use it

To run the product: sign you in, verify your email, send a password reset if you ask for one, keep your projects and their invited participants straight, and keep a record of what your balance is and what it's been spent on.

To generate and evaluate names: your project's brief, framing, and any participant answers get sent to the AI provider handling that request. We route between five: Anthropic, OpenAI, Google, Moonshot, and DeepSeek, depending on what the task needs. None of them gets your payment details. All of them can see the project content and any participant answers you've brought into the project. Participants appear there only as numbered labels, like "Participant 2", so the AI can tell one person's input from another's; no participant's name or email is sent. DeepSeek stores and processes what it receives in the People's Republic of China, and its own privacy policy allows it to use that data to train its models.

To check a candidate name: if you run a domain or reference check, we send the candidate word or name itself to the relevant registry or dictionary lookup, and to a search provider if a web search is run. None of these ever receive your name, your email, or anything else about you, only the word being checked.

To process payment: your balance refills in $10 increments, handled by Stripe. We hold a record of the transaction (amount, status, Stripe's own reference for it), never the card itself.

Who sees it
  • Stripe, to process payment. We never touch your card details.
  • Anthropic, OpenAI, Google, Moonshot, and DeepSeek, whichever is handling a given AI request, to generate or evaluate names. They see project content and participant answers, with each participant shown only as a number, never by name or email. DeepSeek keeps what it receives in the People's Republic of China.
  • Resend, to deliver the emails the product sends: verification, password reset, and round invitations.
  • The domain registry, a dictionary lookup, and a search provider, when you run a check on a candidate name. They only ever see the candidate word, never you.

Nobody else. We don't sell data, we don't share it with advertisers, and we don't work with data brokers. Visitor analytics run only with your consent and never after you sign in. We collect error reports from your browser and our server to find and fix bugs. Before storing them, we redact personal identifiers and sensitive information, such as email addresses, IP addresses and access tokens. These reports are visible only on our internal admin page. We don't sell them or share them with third parties.

Cookies

Two, and nothing else. One keeps you signed in, set by the login system. The other, for someone who was invited to a round, remembers for 30 days that you already entered the access code once, so you're not asked again; it doesn't do anything on its own beyond that. No advertising or analytics cookies.

How long we keep it, and how to have it removed

Deleting a project deletes everything in it, permanently and completely: the project itself, everyone's answers, and any participants' name and email that were only ever tied to that project. There's no undo. That's by design.

Outside of a deleted project, we don't yet have a fixed period after which data is automatically removed.

If you want your account closed, contact us. This isn't a self-serve feature yet, and closing an account currently requires first deleting every project you own, participants' data included; we can't yet close an account that still owns projects.

Contact

[privacy contact address, not yet set. The product doesn't have its real domain or sending address yet (decisions 1.1 to 1.3 are still open); this needs a real, monitored address before publishing.]

We record anonymous usage of this page — which pages you visit, how long, and how far you scroll — to see what does and doesn’t work. No account, no cookie, nothing that follows you between visits.