Legal

Privacy & Terms

How we handle your account data, and the basics of using iMake. Contact legal@imake.lol if you need a signed DPA or formal policy pack.


Privacy

Effective and last updated: July 25, 2026

This Privacy Policy explains what iMake collects, how the information is collected and used, and when it is shared. It applies to the iMake Agents apps, the iMake website, the cluster service, and connected iMake runtimes. We do not sell personal data or use it for targeted advertising.

Information we collect and how we collect it

  • Account information: account ID, name, email address, and sign-in provider identifiers received when you sign in with Apple or Google.
  • Content you choose to submit: prompts, instructions, custom system prompts, conversation history, and files, images, screenshots, clipboard content, or voice transcriptions you attach or send.
  • Workspace and session content: the working directory you select, relevant code and files read from your connected computer to complete your request, agent responses, generated artifacts, session titles, status, and runtime logs.
  • Connected-device information: device and node identifiers, device names, online status, operating system, app version, push-notification token, and connection information.
  • Usage and technical information: model selection, token and feature usage, timestamps, IP address, diagnostic events, and security or abuse-prevention logs. We collect this information automatically when the service is used.
  • Support information: contact details and the content of messages you send to iMake support.

How we use information

We use the information above only as needed to:

  • authenticate your account and keep sessions, computers, and devices associated with it;
  • route requests, maintain conversation context, execute requested work, and return results;
  • sync sessions and artifacts across your devices and send requested service notifications;
  • measure usage, administer service limits, and support billing and account operations;
  • secure, debug, maintain, and improve the reliability of the service;
  • respond to support requests and comply with legal obligations.

AI processing and your permission

iMake Agents asks for your explicit permission in the app before the first request that shares data for third-party AI processing. Until you allow it, iMake blocks new AI prompts and attachments from being transmitted. You can decline or withdraw permission in Settings; withdrawing permission blocks future AI requests but does not undo processing that already occurred.

When you allow AI data sharing, iMake routes the request through iMake's cluster service to your connected computer. The request can include your prompt, the conversation history needed to continue the session, the custom system prompt, and any files, images, screenshots, clipboard content, or voice transcription you chose to send. The connected runtime may also provide relevant code and file content from the working directory you selected so the agent can perform the requested task.

AI requests are processed by Cursor, operated by Anysphere, Inc. Cursor may route content to one or more model-inference providers, including Anthropic, OpenAI, Google, Fireworks AI, or xAI, depending on the selected model and Cursor's internal routing. Cursor describes these inference providers and its data flow on its security page. Their processing is used to generate responses, supply relevant context, execute requested work, prevent abuse, and maintain service security.

iMake does not use your prompts, files, or generated results to train iMake models. We do not authorize AI providers to use that content for advertising. Provider-side security review, feedback you explicitly submit, or a separate provider opt-in may be handled under the applicable provider's terms. See the Cursor Privacy Policy, Anthropic Privacy Center, OpenAI Privacy Policy, and Google Privacy Policy.

When we share information

We disclose information only in the following circumstances:

  • Connected computers: to the computer or node you select so it can execute the session.
  • AI processors: to Anysphere/Cursor and the model-inference providers identified above, only after you grant in-app permission.
  • Infrastructure and account providers: to hosting, network, storage, notification, authentication, monitoring, and support providers—including Cloudflare, Apple, and Google—only as needed for their service.
  • Legal and safety: when required by law or reasonably necessary to protect users, prevent fraud or abuse, enforce terms, or defend legal rights.
  • Business transfers: in connection with a merger, financing, acquisition, or sale, subject to continued confidentiality and notice where required.

We require every service provider and AI processor that receives personal data to use it only for the authorized service and to maintain confidentiality, security, and privacy protections that are the same as or materially equivalent to the protections described in this Policy. We review the applicable contractual terms and published security commitments before using a provider.

Retention and deletion

Account, session, and artifact data is retained while your account or the relevant session remains active so the service can sync and continue work. You may delete sessions in supported clients and may request account-data deletion by contacting us. Usage, billing, security, and diagnostic records are kept only as long as reasonably necessary for the purposes described above, legal obligations, dispute resolution, and abuse prevention. Backups are removed on their normal rotation schedule. Providers may retain limited information under their applicable terms for security, legal, or operational reasons.

Security and international processing

We use access controls, encryption in transit, authentication, and operational safeguards designed to protect personal data. Information may be processed in the United States and other countries where iMake's providers operate. When required, transfers use lawful safeguards, and providers must continue to apply the protections described in this Policy.

Your choices and rights

You can decline or withdraw AI data-sharing permission in the iMake Agents app. Depending on your location, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent. To exercise a privacy right or ask a question, email legal@imake.lol. We may need to verify your identity before completing a request.

Changes to this Policy

We may update this Policy as the product or its providers change. We will update the date above and provide additional notice when a material change requires new consent. A new in-app consent version will be required before further AI processing when the disclosed AI data sharing changes materially.

Terms

By using iMake you agree to use the service lawfully, keep your account credentials private, and not abuse shared infrastructure. You are responsible for what you run on machines you connect.

Software and services are provided as available. We may update clients and cluster behavior over time. If you need a formal agreement for your company, contact legal@imake.lol.