Privacy Policy
Effective date
Malmoi is a localization tool: developers push the strings in their code to Malmoi, their teammates translate them here, and Malmoi opens a pull request back to the repository. This policy covers what Malmoi stores about the people who sign in, how it counts visits to its public pages, why, and how to have your data removed.
What we collect
Malmoi collects what it needs to sign you in, to decide what you can open, and to show your teammates who changed a translation. Separately, it counts visits to its public pages — the home page, sign-in, the docs and this policy — without cookies. Pages inside the app are not counted, and there is no advertising or cross-site tracking.
| What | Where it comes from | Why |
|---|---|---|
| Your name, email address and profile picture | GitHub or Google, when you sign in | Identifying you to your teammates |
| A keyed index of your email address | Derived from the address | Matching an invitation to the account that accepts it, without comparing addresses in the clear |
| Which GitHub or Google account you signed in with, as the account id at that provider | GitHub or Google, when you sign in | Recognizing you the next time. Malmoi keeps no sign-in tokens — the id is all it stores |
| A GitHub token for your own account, and when it expires | GitHub, when you connect a repository to a project | Reading which GitHub App installations you can choose a repository from. It is never used to write to a repository |
| Sign-in state: your session, and short-lived challenges for linking an account or signing other sessions out | Created by Malmoi | Keeping you signed in, and proving that a reply from GitHub or Google belongs to a round trip you started |
| Your project membership and any invitation sent to your address | The person who invites you | Deciding which projects you can open and what you can do in them, and emailing you the invitation link |
| The language you choose for Malmoi's screens | You, when you pick a language | Showing Malmoi in that language on every device you sign in on |
| The time zone you choose for dates and times | You, when you pick a time zone | Showing dates and times in that time zone on every device you sign in on |
| The theme you choose for Malmoi's screens | You, when you pick a theme | Showing Malmoi in that theme on every device you sign in on |
| When you last opened or viewed your Inbox | Malmoi, when you open the list or view the Inbox page | Marking which items in it are new since you last looked |
| Who last changed a translation, and who asked for a sync | Your own edits | Showing your teammates who changed what |
| A personal token for AI agents: a one-way hash of it (never the token itself), the actions and projects you allowed it, and when it was created, last used and expires | Created by Malmoi when you create or rotate a token on the MCP connector page | Letting an AI agent you run act for you, within what your project role already allows |
| An app you connect by signing in through your browser, such as Claude Code or Codex: the name and address it gives for itself, where it returns after you sign in, one-way hashes of the tokens Malmoi issued to it and of the refresh tokens it has already used (never the tokens themselves), the actions and projects you allowed it, and when it was connected, last used and expires | Created by Malmoi when you authorize the app on its connection screen | Letting an app you connect act for you, within what your project role already allows |
Names, email addresses and connection tokens are stored encrypted, and the keys are held outside the database. A profile picture you upload is re-encoded before it is stored, which drops the original file and the metadata in it; a picture that comes from GitHub or Google stays on their servers.
Visits to the public pages are counted by Vercel Web Analytics. For each page view it records the time, the page address with any query and fragment removed, the page you came from, your approximate location (country, region and city), and your device type, operating system and browser with their versions. It sets no cookies and stores nothing in your browser. Instead of an identifier, Vercel uses a hash created from the request, and that visitor session is discarded after 24 hours; the records are not tied to a person or an IP address. Malmoi sees only totals.
Why we use it
- Signing you in and keeping you signed in.
- Showing Malmoi in the language you choose.
- Showing dates and times in the time zone you choose.
- Showing Malmoi in the theme you choose.
- Marking which items in your Inbox are new since you last opened or viewed it.
- Deciding which projects you can open and what you can do in them.
- Showing your teammates who changed a translation and who asked for a sync.
- Writing translations back to the repository a project is connected to, as a pull request.
- Emailing an invitation link to an address a project owner enters. The email holds the link and the project it is for — the project's name, its picture if it has one, and the role you are invited with. It does not say who invited you, and it has no tracking.
- Keeping the service running, which includes looking at error logs when something fails.
- Counting visits to the public pages, to see whether people find Malmoi and which docs they read. Only totals are looked at.
- Letting an AI agent you connect — with your own token, or by signing in through your browser — do what you could do in the app. What it changes is recorded as your change.
Malmoi does not sell your data, does not share it for advertising, and does not use it to train anything. The repository coordinates a project is connected to are about the repository, not about you, and this policy does not treat them as personal data.
How long we keep it
How long something works and how long its row is kept are different, so this section says both.
- Your account and its connections: kept until you ask us to delete them.
- The language you choose: kept with your account until you choose another or ask us to delete your account. On a browser, the language cookie lasts a year from the last time you chose a language or signed in with a language saved to your account.
- The time zone you choose: kept with your account until you choose another or ask us to delete your account. It is not stored in a cookie.
- The theme you choose: kept with your account until you choose another or ask us to delete your account. On a browser, the theme cookie lasts a year from the last time you chose a theme or signed in with a theme saved to your account.
- When you last opened or viewed your Inbox — the list in the header or the Inbox page: one time per account, replaced each time you open the list or the page and kept until you ask us to delete your account. There is no record of which items you saw, and no cookie.
- A session stops working 24 hours after your last activity. Its row goes away when you sign out, or when that expired session is next presented.
- A challenge for linking an account or signing other sessions out stops working after 5 to 10 minutes. Its row goes away the next time you start the same step.
- An invitation stops working after 7 days, or as soon as it is accepted, revoked or sent again. The row is kept after that, including the address it was sent to, as the record that the invitation happened — ask us and we will delete it.
- An invitation email: Resend, which sends it, keeps a record of the message — the address, the subject and the email itself, with the link, the project's name, the address of its picture if it has one, and your role — for 30 days.
- Translations and the record of who changed them: kept for the life of the project.
- An AI agent token stops working when it expires (30, 90 or 365 days after you create it) or as soon as you rotate or revoke it. Its row is deleted when you rotate or revoke it, or with your account; until then an expired token stays listed so you can see what it allowed.
- An app connection stops working when it expires (30, 90 or 365 days after you authorize it) or as soon as you disconnect it or authorize the same app again. Its row, with the hashes of the refresh tokens it used, is deleted then, or with your account; an expired connection stays listed until it is deleted. The hand-off from the connection screen to the app lasts one minute and is deleted when the app uses it.
Who else sees it
Malmoi sends your data to five services and to no one else.
- GitHub — signing you in, and reading and writing the repository a project is connected to. Translations are committed and opened as a pull request by Malmoi's GitHub App, not under your own account.
- Google — signing you in, if you choose Google.
- Supabase — the database, hosted in Tokyo.
- Vercel — hosting for the app, storage for uploaded profile pictures and project pictures, and counting visits to the public pages (Web Analytics, described under What we collect). Vercel records requests to the service, including IP addresses, as part of running it.
- Resend — sending invitation emails, from Tokyo. It receives the invited address and the message: the invitation link, the project's name, the address of its picture if it has one, and the role you are invited with. Open and click tracking are off.
A profile picture that comes from GitHub or Google is loaded by your browser directly from their servers, so those requests reach them even though Malmoi sends them nothing.
If you connect an AI agent with your token or by signing in through your browser, what the agent reads through it — the translations, activity and members of your projects, and a project's push token when you ask for one — goes to that agent and to whichever AI service it uses. You choose and run that agent; Malmoi does not send it anything on its own and has no agreement with it. To show an app's name on the connection screen, Malmoi reads the app's public description from the address the app gives; that request carries nothing about you.
An invitation email shows a logo and the project's picture (or a placeholder icon when it has none), and your email app loads all of them from mal-moi.com — Malmoi fetches the picture from its own storage, so your email app reaches no one else. The logo and the icon are the same for everyone, and a project's picture is the same for everyone invited to that project, so none of them tells Malmoi who opened the email.
Deleting your data, and how to reach us
Write to ox501501@gmail.com to ask what Malmoi holds about you, to correct it, or to have it deleted. We answer within 30 days. Malmoi has no self-service delete screen, so the request goes through that address.
Deleting your data removes your account, your GitHub and Google connections, your sessions, your AI agent token and app connections, your project memberships, any invitation addressed to you that has not been accepted, and a profile picture you uploaded. Resend's record of an invitation email is not removed early; it expires on its own 30 days after the email was sent.
Translations stay. They are the project's output and are already in the repository, so removing them would delete work that belongs to the team — but the record of who wrote them stops pointing at you.
Cookies
Every cookie Malmoi sets is needed to sign you in, to finish a round trip to GitHub or Google, or to remember the language and theme you chose for Malmoi's screens and whether you collapsed the sidebar. There are no analytics, advertising or tracking cookies, so there is nothing here to consent to or turn off. All of them except the sidebar cookie are http-only, which means scripts cannot read them. The sidebar cookie holds only whether the sidebar is collapsed, so Malmoi's pages write it directly.
| Cookie | How long it lasts | What it does |
|---|---|---|
| Session | 24 hours from your last activity | Keeps you signed in |
| Sign-in request check | Until you close the browser | Checks that a sign-in was started from this site |
| Return address | Until you close the browser | Sends you back to the page you started from |
| Sign-in state | 15 minutes | Proves that the reply from GitHub or Google belongs to the sign-in you started |
| Repository connection state | 10 minutes | The same, for connecting a repository |
| Account link and sign-out challenges | 5 to 15 minutes | The same, for adding a second sign-in method to one address and for signing other sessions out |
| Language | 1 year from your last choice or sign-in | Shows Malmoi in the language you chose on this browser, even when you are signed out. Signing in copies the language saved to your account into it |
| Theme | 1 year from your last choice or sign-in | Shows Malmoi in the theme you chose on this browser, even when you are signed out. Signing in copies the theme saved to your account into it |
| Sidebar | 1 year from when you last collapsed or expanded it | Keeps the sidebar collapsed or expanded the way you left it on this browser |
Changes to this policy
The effective date at the top belongs to the text below it: whenever this policy changes, that date moves and the change is listed here.
- — the “Needs your attention” list in the header is now called Inbox, and it also has its own page. Viewing that page counts as looking at your Inbox, the same as opening the list in the header.
- — Malmoi remembers whether you collapsed the sidebar in a cookie on this browser. It is the only cookie that scripts can read, and it holds nothing else.
- — the “Needs your attention” list in the header marks items that are new since you last opened it. Malmoi keeps one time per account — when you last opened the list — and no record of which items you saw.
- — you can choose Malmoi's theme: System, Light or Dark. Malmoi remembers your choice with your account and in a cookie on this browser, and signing in copies the theme saved to your account into that cookie.
- — you can choose the time zone Malmoi uses for dates and times. Malmoi remembers your choice with your account only, not in a cookie. Public pages always use UTC.
- — you can choose the language of Malmoi's screens: English, Korean or Spanish. Malmoi remembers your choice with your account and in a cookie on this browser, and signing in copies the language saved to your account into that cookie. This policy is also published in Korean.
- — you can also connect an app such as Claude Code or Codex by signing in through your browser, with no token to copy. Malmoi keeps the connection — the app's name and address, the actions and projects you allowed, when it was used — and only hashes of the tokens it issued; you can disconnect it on the MCP connector page.
- — you can create a personal token for AI agents on the MCP connector page. Malmoi stores only a hash of it, with the actions and projects you allowed and when it was used.
- — invitation emails show the name and picture of the project you are invited to, and your role in it. They still do not say who invited you.
- — visits to the public pages are counted with Vercel Web Analytics, without cookies.
- — the product name is written Malmoi. No change to what we collect or share.
- — invitations can be sent by email through Resend.
- — first version.