1. Controller
The data controller is MinborAI. For any question or request: [email protected]
2. Data we process
- Account data: email address, username, display name, profile picture (from Discord/Google if you sign in with them).
- Authentication: your password is stored only as a one-way hash (bcrypt); your 2FA secret is encrypted (AES-256-GCM) and backup codes are stored only as hashes.
- Security logs: sign-in times, IP addresses, failed sign-in and 2FA attempts, password/2FA changes.
- Abuse prevention: a random device id stored in your browser and a one-way hash of browser properties (screen, time zone, graphics card, etc.). At sign-up, your IP address is checked against VPN/proxy/Tor/data-center lists and the proxycheck.io service. These are used only to prevent abuse of free credits through multiple accounts.
- Content: your projects, source code, version history, build outputs and your conversations with the AI assistant.
- Your own API keys: stored encrypted (AES-256-GCM); never sent back to the browser, only the last 4 characters are shown.
- Credit activity: spending and grants (when payments are added, payment details stay with the payment provider; we never store card data).
3. Purposes and legal bases
- Providing the service (accounts, projects, builds, AI assistant) — performance of a contract.
- Account security and preventing abuse and fake accounts — legitimate interest and legal obligation.
- Verification, password reset and security notification emails — performance of a contract.
- Responding to lawful requests — legal obligation.
5. Retention
- Account and project data: as long as your account exists. When you delete your account, your projects, files and build outputs are deleted immediately.
- Database backups: daily backups are kept for 14 days and weekly backups for 8 weeks, then deleted automatically.
- Security logs: kept for a reasonable period to detect abuse and meet legal obligations.
7. Security
- All traffic is encrypted with HTTPS; the server is only reachable through Cloudflare.
- Optional two-factor authentication (2FA), rate-limited sign-in, email alerts on password/2FA changes and the ability to sign out all sessions.
- User code and test servers run in containers isolated from the server and from other users.
8. Your rights
You can request access to, correction or deletion of your data, object to processing, and ask which parties it was shared with. You can delete your account yourself under Settings → Account; for other requests write to [email protected]. We respond within 30 days.
9. Age
MinborAI is not intended for children under 13. If you are under 18 you should use the service with a parent's or guardian's knowledge.
10. Changes
This policy may change; for significant changes we notify your registered email. The current version is always on this page.