MyAISE
Product Use cases Pricing Marketplace Blog Docs
Sign in Download
Product Use cases Pricing Marketplace Blog Docs
Sign in Download
// legal

Privacy policy

What we collect, why, and how to delete it. Written in plain language because legal pages shouldn't need a translator.

Last updated · August 24, 2026
// contents
  • Overview
  • The desktop app
  • Cloud sync & teams
  • Viewer sessions
  • AI providers
  • Cookies & analytics
  • Your rights
  • Contact
Questions?
legal@myaise.com

Overview

MyAISE Studio is a local desktop app. Your rulesets, demo configurations, and intercepted traffic stay on your machine unless you explicitly opt into cloud sync, AI generation, or a viewer session. This policy explains what we collect in each case, why, and how to delete it.

Plain summary: the desktop app collects nothing without a feature you turned on. The cloud collects what you put into it. No advertising data, no third-party tracking pixels.

The desktop app

MyAISE Studio runs entirely on your local machine. Out of the box it sends nothing to our servers.

It does store the following locally, in ~/.har-capture-proxy/:

  • Rulesets — the demos and rules you create. Stored as JSON.
  • Preferences — theme, LLM provider choice, recent demos, etc.
  • Encrypted LLM API keys, when you provide them. Encrypted at rest using your OS keychain.
  • The CA certificate needed for HTTPS interception. Installed in your login Keychain on macOS.

All of the above can be removed by deleting ~/.har-capture-proxy and running security delete-certificate -c "har-capture-proxy CA".

Error reporting (opt-in)

If you opt in during onboarding, the app sends anonymized crash reports to Sentry. The payload includes a stack trace, app version, and OS — no ruleset content, no demo content, no LLM keys. You can toggle this off in Settings.

Cloud sync & teams

If you sign in with a MyAISE Cloud account (Solo / AI SE / Enterprise plans), the following data is stored on our servers:

  • Your account profile — email, name, billing details handled by Stripe.
  • The rulesets you sync, plus full version history.
  • Team membership and shared-ruleset assignments, for AI SE plan accounts.
  • Operational logs — minimized API request timestamps and error rates — retained for 30 days. Immutable security-audit events are retained for 365 days.

Rulesets are encrypted at rest. Only you (and members of your team workspace) can access them via the cloud API. We do not read rule contents to train models, target ads, or any other secondary purpose.

Viewer sessions

When you start a viewer session, we provision a single-use, private GPU task running a sandboxed browser. The proxy engine runs inside that task and applies your ruleset to every HTTP response. Streamed pixels and input events transit the service over WebRTC and TURN when relay is required. The task and its temporary state are destroyed after use.

What we store about a viewer session:

  • Session metadata — start time, duration, ruleset version, and workspace. Analytics retention is owner-configurable to 7, 30, or 90 days (90 by default).
  • Normalized analytics paths and interaction coordinates, only when session tracking is enabled. Query strings, fragments, typed values, DOM contents, cookies, and headers are excluded.
  • Recordings, only when the workspace owner enables recording and the viewer is shown a recording indicator. Media retention is owner-configurable to 7, 30, or 90 days (30 by default).
  • Auto-healing baselines, if self-healing is enabled — minimized screenshots associated with the demo and purgeable from demo settings.

What we do not store:

  • Typed input values, cookies, request/response headers, URL query strings, or fragments. Session tracking never records DOM contents; self-healing baselines and drift findings can include element names, labels, and short text snippets from the rule-transformed page, and are purgeable from demo settings.
  • Reusable plaintext credentials. Submitted credentials are encrypted for one-time retrieval by the assigned task and then erased.
  • Rendered pixels unless recording was explicitly enabled as described above.

AI providers

MyAISE sends content to LLM providers under two scenarios:

  1. AI rule generation — when you click "Suggest", we send page HTML, intercepted API responses, and a prompt to your chosen LLM provider (OpenAI, Anthropic, or Google).
  2. Self-healing (AI SE) — when an anchor drifts, we send stored baseline metadata (selector candidates, role, accessible name, and geometry) plus a bounded set of structural descriptors from the live, rule-transformed page — element tags, roles, labels, and short text snippets — to Anthropic Claude to ask for a new selector. Viewer-session healing can also include the stored baseline and current screenshots; scheduled runner healing uses descriptors. Neither path sends raw DOM.

On the Studio and Solo plans (BYOK), requests use your API key and go directly from the desktop app to the provider — we don't proxy or log them. On the cloud LLM tier (included with Solo/AI SE), requests transit our infrastructure under our enterprise contract with the provider; we don't retain prompt content, and the provider's enterprise terms include no-training guarantees.

Cookies & analytics

The marketing site uses a single first-party cookie for authentication on signed-in pages. No advertising cookies, no third-party tracking pixels, no Facebook Pixel, no Google Tag Manager.

The marketing site does not currently load a third-party analytics service. If that changes, this policy will be updated before collection begins.

Your rights

Regardless of where you live, you can:

  • Export your data — every ruleset, version history entry, and account record is exportable as JSON from the dashboard.
  • Delete your account — from the dashboard. Deletion removes all rulesets, viewer-session metadata, and account profile within 7 days.
  • Object, restrict, or correct processing — email privacy@myaise.com.

Live account data is removed from the database, object storage, and analytics service within 7 days. Encrypted immutable recovery copies cannot be selectively edited and expire within 35 days. They are isolated from normal product use and restored only for disaster recovery.

EU/UK residents have GDPR rights. California residents have CCPA rights. We honor both globally.

Contact

MyAISE Inc. · 100 Pine St, Suite 1250, San Francisco CA 94111 · USA.

Data Protection Officer: privacy@myaise.com.

For security disclosures, see our security policy on GitHub.

MyAISE

The AI Sales Engineer that demos your real product on demand.

demos on demand·source available
Product
  • AI Sales Engineer
  • Studio for Mac
  • Knowledge base
  • Live sessions
  • Use cases
  • Pricing
  • Changelog
Resources
  • Docs
  • MCP guide
  • Blog
  • For SEs
  • har-capture-proxy
  • Source available
Company
  • About
  • Support
  • Privacy
  • Terms
© 2026 MyAISE — your AI sales engineer. made for sales engineers everywhere