Privacy Policy
Effective:
1. Overview
This Privacy Policy explains what information Maskura (formerly S4), referred to as "the Service", operated by 231self ("we", "us", "our"), collects, how we use it, and the choices you have. We are committed to minimizing data collection and protecting your privacy.
2. Information We Collect
- Account information — email address and authentication details you provide when signing up (via Supabase Auth).
- Usage metadata — request counts, data volumes processed, and workspace/API-key identifiers, used for metering and billing.
- Analytics — product usage events via PostHog (page views and feature events, with person profiles enabled only for identified users).
3. How We Handle Object Data
In the general hosted bring-your-own-storage mode, Maskura does not provide durable object storage. Your object data is processed and forwarded to the backend you configure. Most object data streams through the Service without local persistence. When a transformed read cannot be streamed safely, Maskura may temporarily write an encrypted local spool before disclosing response bytes. Hosted transformed reads are capped at 64 MiB; text records and complete JSON documents are capped at 8 MiB. All spool data shares a 256 MiB process quota. Spool artifacts are ephemeral and stale artifacts are removed within a bounded cleanup window.
4. How We Use Information
- To provide, operate, and secure the Service;
- To meter usage and process billing (via Paddle);
- To communicate with you about your account and the Service;
- To improve the Service through aggregate, non-identifying analytics.
5. Third-Party Services
We rely on the following third parties to operate the Service:
- Supabase — authentication and database;
- Paddle — payment processing (merchant of record);
- PostHog — product analytics;
- Cloudflare — hosting and content delivery.
Each processes data under its own privacy policy. We share only the minimum information required for each service to function.
6. Analytics & Cookies
We use PostHog for product analytics. This may set cookies or local storage on your device. You can disable cookies in your browser, though some features may not work as expected.
7. Data Retention
We retain account and usage metadata for as long as your account is active and for a reasonable period thereafter for billing and legal purposes. Analytics events are retained under PostHog's retention settings. Temporary encrypted read spools follow the bounded cleanup behavior described above and are not durable object storage.
8. Your Rights
Depending on your jurisdiction (including the GDPR and CCPA), you may have the right to access, correct, or delete your personal information, and to object to or restrict processing. To exercise these rights, contact us athello@231self.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date.
10. Contact
Questions or concerns? Contact us athello@231self.com.