Privacy Policy
Last updated: March 19, 2026
This Privacy Policy explains how Mosaiqo Software Development SLU ("Mosaiqo", "we", "us", or "our"), a company registered in Spain, collects, uses, and protects your personal data when you use Magia and its associated cloud services (collectively, the "Service").
Magia is an agent-first desktop coding environment. We are committed to protecting your privacy and handling your data transparently in compliance with the General Data Protection Regulation (GDPR) and applicable Spanish data protection laws.
Contents
1. Data We Collect
Account Data
When you create an account, we collect your name, email address, and avatar image through GitHub or Google OAuth. We do not store your OAuth provider passwords.
Usage Telemetry
Official builds of Magia collect anonymous usage telemetry by default to help us improve the product. This includes feature usage patterns and general interaction data. Telemetry is entirely opt-out — you can disable it in the application settings at any time. Self-compiled builds have telemetry disabled by default.
Desktop Heartbeat
The desktop application periodically sends a lightweight heartbeat signal containing your app version, operating system, and architecture. This helps us understand our user base and prioritize platform support.
Payment Information
Payment processing is handled entirely by Stripe. We never see, store, or have access to your full credit card numbers. We only receive confirmation of payment status and basic transaction metadata from Stripe.
Session and Workspace Data
Your coding sessions, workspace configurations, and project data are stored locally on your device. We do not upload, access, or process the contents of your local sessions or code.
2. How We Use Your Data
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To process payments and manage subscriptions
- To send important service-related communications
- To monitor and fix errors and crashes (via opt-out error tracking)
- To understand usage patterns and improve the product (via opt-out analytics)
- To comply with legal obligations
3. Data Retention
Telemetry and heartbeat data is retained for 90 days in identifiable form, after which it is aggregated and anonymized. Account data is retained for as long as your account is active. When you delete your account, we remove your personal data within 30 days, except where retention is required by law (e.g., financial records).
4. Third-Party Services
We use the following third-party services to operate Magia:
Stripe
Payment processing. Subject to Stripe's Privacy Policy.
Sentry
Error tracking and crash reporting. Opt-out available in settings.
PostHog
Product analytics. Opt-out available in settings.
GitHub
OAuth authentication and repository integration.
OAuth authentication.
DigitalOcean
Cloud hosting and CDN infrastructure.
6. Data Location
All cloud data is stored and processed within the European Union, specifically on DigitalOcean infrastructure located in Amsterdam, the Netherlands, managed through Laravel Forge. Your local session and workspace data remains on your device and is never transmitted to our servers.
7. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of access — Request a copy of the personal data we hold about you
- Right to rectification — Request correction of inaccurate or incomplete data
- Right to erasure — Request deletion of your personal data
- Right to data portability — Request an export of your data in a machine-readable format
- Right to restrict processing — Request that we limit how we use your data
- Right to object — Object to processing of your data for certain purposes
- Right to withdraw consent — Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at privacy@magia.sh. We will respond within 30 days. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
8. Children
Magia is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at privacy@magia.sh and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice in the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at: