Privacy Policy

Last updated September 27, 2026

m’kay lets you talk, from a browser or phone, to the AI agent apps on your own Mac (Claude, ChatGPT/Codex and Cursor). It is operated by SaltedMango, Inc. (“we”). This policy explains what we collect, why, who processes it, and what we do not keep. Questions: max@mkay.ai.

In short

What we collect

Your account

When you sign up we keep your email address, an account ID, when you signed up and last signed in. Sign-in itself is handled by Google’s Firebase Authentication: your password (if you use one) is held by Firebase, not by us, and signing in with Google or GitHub goes through those services.

Credits

A record of the credits you received and used: one entry per started minute of a voice session, with the session’s ID and time.

Your linked Macs

For each Mac you link: its name (as your Mac reports it), when it was linked and last connected. Each Mac holds its own access token; we store only a one-way hash of it. You can unlink a Mac on your account page at any time.

Voice sessions

While you talk, the service needs to hear you, understand you, act on your Mac and answer. During a session:

These providers process this data to deliver the session, under their own terms and policies. We do not store audio, transcripts, messages or agent content. Our server logs record how sessions run (account ID, session times, which tools were used, errors, and the length of messages, not their text) and are kept for at most 30 days.

On your Mac

The connector you run on your Mac is open source (github.com/maxipesfix/mkay). It connects out to our server, and uses macOS Accessibility to read and operate the agent apps when a session of your account asks it to. It does not send anything else from your Mac. Nothing is sent to an agent unless you confirm it by voice after hearing it read back, and the connector’s --read-only option refuses sending altogether.

Cookies and browser storage

One cookie keeps you signed in (mkay_session, for 14 days). Firebase keeps sign-in state in your browser while you sign in, and the voice page remembers the voice you chose in your browser. We use no other cookies.

Where it is processed

Our server and database run on Google Cloud in the United States (Oregon). The providers above may process data in other countries under their terms.

Sharing

We share data only with the providers named above, to run the service, and when the law requires it. We do not sell or rent personal data.

How long we keep it

Account, credit and Mac records are kept while your account exists. Server logs are kept for at most 30 days. Database backups are kept for 7 days.

Your choices

You can unlink Macs and stop the connector at any time. To get a copy of your data, correct it, or delete your account and its data, email max@mkay.ai from your account’s address.

Security

Connections are encrypted (HTTPS and secure WebSockets), Mac tokens are stored only as hashes, the database is reachable only from our private network, and each voice session runs in its own process that can reach only your own Mac.

Children

m’kay is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We will post changes here and update the date above; for significant changes we will also tell you by email.

Contact

max@mkay.ai