All legal documents

Privacy

Privacy Policy

How Mateality Releases collects, uses, shares, retains, and protects personal data.

Effective and last updated July 28, 2026

1. Who we are and scope

Mateality Releases (“Releases”) is operated by the person or entity identified as the Mateality service provider in your order form, invoice, or account interface (“Mateality”, “we”, “us”). For account, website, billing, and direct customer-relationship data, Mateality acts as controller. Contact us at privacy@mateality.com.

This policy covers the Releases website, dashboard, APIs, hosted download pages, updater endpoints, support, and related communications. It does not govern a customer’s own application or independent websites linked from the service.

2. Data we collect

  • Account and identity data: name, email address, authentication credentials in protected form, passkey metadata, two-factor settings, organization membership, roles, and session records.
  • Customer and billing data: organization details, plan, entitlement and usage state, billing contact, transaction identifiers, subscription status, invoices, and limited checkout state. Payment-card data is collected by Polar and its payment partners, not stored by Mateality.
  • Release content and configuration: app names, slugs, icons, channels, versions, release notes, target platform, signatures, checksums, signed binaries, custom domains, and download-page settings.
  • Operational and security data: request timestamps, IP addresses processed transiently for security and rate limiting, hashed rate-limit subjects, API-key prefix and hash, user agent, error and audit information, and domain-verification results.
  • Distribution data: app, release, target, request source, timestamp, bytes delivered, and coarse country derived at the edge. Releases is designed not to retain raw downloader IP addresses in product analytics.
  • Support and communications: messages, attachments, diagnostic information, feedback, and communication preferences that you choose to provide.
  • Cookie and similar-technology data described in the Cookie Policy.

3. Why we process data

  • Contract: create and secure accounts; authenticate users; host, publish, and deliver releases; provide dashboards, domains, billing, support, and requested product features.
  • Legitimate interests: protect the service, prevent abuse, diagnose failures, maintain availability, measure plan usage, improve product reliability, and establish or defend legal claims, where those interests are not overridden by your rights.
  • Legal obligation: keep tax, accounting, compliance, sanctions, and transaction records and respond to lawful requests.
  • Consent: use optional cookies or send optional marketing communications. You can withdraw consent at any time without affecting earlier lawful processing.

4. Customer data and our processor role

A customer may upload or transmit personal data in release notes, application files, support materials, or other content. For that data, the customer is normally the controller and Mateality is its processor. The Data Processing Addendum applies to that processing.

Customers decide what they upload and must provide required notices, obtain a lawful basis, answer data-subject requests, and avoid including unnecessary personal or sensitive data in releases or metadata.

5. Who receives data

We disclose data only as needed to operate Releases, follow your instructions, complete billing, comply with law, protect rights and safety, or complete a corporate transaction subject to appropriate safeguards.

  • Infrastructure and storage providers, including Cloudflare and Supabase.
  • Billing and tax providers, including Polar, which acts as merchant of record for paid purchases and may act as an independent controller for checkout and payment data.
  • Email delivery providers, including Resend.
  • Professional advisers, auditors, insurers, authorities, or courts when necessary and lawful.
  • Other organization members and the public where you intentionally publish release pages, notes, domains, or downloadable artifacts.

6. International transfers

Providers may process data outside your country, including outside the EEA, Switzerland, or the UK. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK Addendum or other lawful safeguards, together with supplementary measures where appropriate. Contact privacy@mateality.com for information about applicable safeguards.

7. Retention

  • Account and organization records are retained while the account is active and for a reasonable period afterward for security, recovery, disputes, and legal obligations.
  • Published release metadata is retained until the customer deletes it or closes the account, subject to backups and legal holds. Artifact retention depends on the selected plan and any pruning date shown in the dashboard.
  • Distribution events and aggregated usage are retained only as long as needed for product reporting, capacity, billing, fraud prevention, and legal claims.
  • Security logs and hashed rate-limit records are kept for a limited operational window unless a longer period is needed to investigate abuse.
  • Billing and transaction records are retained for the period required by tax, accounting, and anti-fraud laws.
  • Backups age out on a rolling schedule. Deletion from active systems may not immediately remove data from encrypted, access-restricted backups.

8. Your rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, or a copy of your personal data; object to processing based on legitimate interests or direct marketing; and withdraw consent. You may also complain to your local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Send requests to privacy@mateality.com. We may verify your identity and, when we process data for a customer, direct the request to that customer. Rights can be limited where an exemption applies, including legal retention duties and the rights of others.

9. Security

We use organizational and technical safeguards designed for the nature of the data and risk, including transport encryption, encryption at rest for stored artifacts, hashed API credentials, scoped access, tenant authorization, short-lived download URLs, rate limits, backups, and monitoring. No system is completely secure, so customers must also protect credentials, signing keys, and endpoints.

10. Children, automated decisions, and changes

Releases is a business and developer service and is not directed to children. You must be at least 18 or the age of legal majority where you live to create a paid account. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects.

We may update this policy as the service or law changes. We will change the date above and provide additional notice when a change materially affects your rights. Continued use after an effective update is subject to the updated policy, but we will request new consent where law requires it.

Questions or notices

Start with the right contact.

Privacy requests: privacy@mateality.com. Security reports: security@mateality.com. Other legal notices: legal@mateality.com.

Contact legal
Next documentTerms and Conditions