Scope
This Privacy Policy explains how Finna Labs Inc. collects, uses, shares, and protects information when you visit matrix-os.com, sign in to Matrix OS, use a hosted Matrix OS workspace, use the Matrix OS iOS or Android app, connect integrations, or contact support.
Matrix OS is designed so your workspace data is owner-controlled rather than casually mixed into the platform. This policy describes the service as operated by Finna Labs Inc.; self-hosted deployments may be controlled by the person or organization running them.
Finna Labs Inc. is the US service provider and the controller of personal data used to operate our website, accounts, billing, support and marketing. For personal data that a business customer puts into its workspace on behalf of others, our role depends on that customer's instructions and the applicable data-processing agreement. This policy does not replace that agreement.
Data We Collect
Depending on how you use Matrix OS, we may process:
- account and authentication data, such as name, email, session, and login details handled through Clerk;
- workspace data, such as prompts, files, apps, settings, terminal activity, agent memory, messages, and generated output;
- structured app and workspace records stored in a local Postgres database for your Matrix environment;
- integration metadata, OAuth connection status, provider identifiers, and data returned from connected services through Pipedream or similar providers;
- usage, diagnostics, error, device, browser, IP, campaign and advertising click attribution, purchase value, and performance information from Matrix OS, Vercel, PostHog, Google Ads, Reddit Ads, Stripe, and server logs; and
- support communications and feedback you send to support@matrix-os.com.
We receive data directly from you, from your use of the service, from people you collaborate with, and from the payment, authentication and integration providers you use. Required account and billing information enables us to supply the service; optional integrations and marketing subscriptions are your choice.
Mobile Apps
The Matrix OS iOS and Android apps connect to your hosted or self-hosted workspace. Account details, prompts, files, messages and terminal activity are processed to authenticate you and carry out the work you request.
- Notifications: when you enable push notifications, we register a device push token and platform with your workspace. Expo, Apple Push Notification service and Google’s Firebase Cloud Messaging deliver notification payloads and routing information. Disable notifications in App settings or your device settings to stop delivery.
- Product analytics: when configured, the app uses PostHog for screen views, interactions, device and app diagnostics, and session replay. Events may be associated with your account identifier. Replay is configured to mask text inputs, images, terminal output, chats and file views, and to exclude console logs and network telemetry.
- Device storage: authentication tokens, workspace connection details and preferences use protected device storage. Analytics identifiers and pending events may use local app storage. A bounded terminal scrollback cache is held in memory and cleared on sign-out. Signing out or removing the app does not delete your hosted account or workspace.
- Biometric lock: Face ID, Touch ID or other device authentication is checked locally by the operating system. Matrix receives the authentication result, not your face, fingerprint or biometric template. You can disable the lock in App settings.
- App updates: the app checks for updates through Expo; these requests can include IP address, platform, app version and update-channel information needed to deliver a compatible update.
The current mobile app has no advertising SDK and does not access Apple’s advertising identifier (IDFA). This does not exclude server-side advertising measurement: the hosted billing service can send account signup and first-payment conversion events to Reddit, including for accounts used in the mobile app. Those events can contain a hashed account identifier, transaction value and currency, and available campaign attribution. Website Cookie preferences control this website’s optional trackers; they do not act as a mobile analytics control or withdraw attribution already stored by the billing service.
Where Data Lives
In the hosted service, an active user may receive a customer VPS. Your Matrix home stores inspectable files such as apps, settings, exports, agent instructions, icons, and project material. Your local Postgres database stores structured app records, canvas/workspace state, social state, and other records that need reliable querying.
The platform keeps control-plane data needed to authenticate users, route requests, provision workspaces, manage integration metadata, recover service state, prevent abuse, and provide support. Backup and recovery systems may store snapshots or metadata so your workspace can be restored.
How We Use Data
We use information to:
- provide, secure, monitor, and improve Matrix OS;
- authenticate accounts and route users to the right workspace;
- provision, operate, update, back up, and recover customer VPS environments;
- run AI agents, generated apps, terminal sessions, and approved integrations at your direction;
- debug errors, measure reliability, understand product usage, and prevent abuse;
- communicate about support, security, service changes, and account activity; and
- comply with legal obligations and enforce service terms.
Legal Bases
Where the GDPR applies, our purposes and corresponding legal bases include:
- Contract: creating your account, delivering your paid workspace, processing payments and answering service requests.
- Legitimate interests: proportionate security, abuse prevention, troubleshooting and business administration, balanced against your rights.
- Legal obligations: tax and accounting records, lawful requests, and compliance duties.
- Consent: optional communications and other processing for which you give a specific consent. You can withdraw that consent without affecting earlier lawful processing.
A contractual permission to use Matrix OS is separate from consent to cookies or advertising. The website's current advertising behavior is described in Cookies and Advertising below.
AI Providers
Matrix OS can route prompts, context, files, tool results, code, and other workspace data to AI model providers or user-configured agents when you ask Matrix OS to perform an agentic task. The exact provider can depend on your configuration, credentials, model selection, and the feature being used. Supported providers include Anthropic, OpenAI, OpenRouter and Cloudflare Workers AI. OpenRouter may route requests to the underlying model provider you select; other providers may be available through agents you configure.
AI processing can transmit your task instructions and relevant workspace context to the selected provider to generate a response or perform the task. Review the provider and context before sending. You can stop a task, change providers or disconnect a provider account to stop subsequent requests; this does not recall data already sent. These are service requests, separate from website advertising consent.
You should not provide sensitive information to an AI task unless you want that information processed for the requested task. User-provided model keys or connected accounts may also be governed by the relevant provider's terms and privacy policy.
International Transfers
Finna Labs Inc. is based in the United States. Your selected workspace region does not necessarily determine where account, support, payment, analytics or connected-provider data is processed. Providers may process data in the United States, the EEA and other countries with different data-protection laws.
Where the GDPR applies, transfers outside the EEA are subject to its transfer requirements, including applicable adequacy decisions or appropriate safeguards such as approved contractual clauses. Contact us for the recipient countries and safeguards relevant to your data, or to request a copy where available.
Integrations
If you connect external services, Matrix OS uses the permissions you grant to perform requested actions such as reading context, creating or updating work items, sending messages, or synchronizing connection status. Provider credentials and tokens are handled through the platform-owned integration flow and scoped service routes.
You can disconnect integrations when you no longer want Matrix OS to use them. Some data from external services may remain in logs, backups, generated output, or workspace records until ordinary retention or deletion processes remove it.
Retention
We keep information for as long as needed to provide Matrix OS, maintain security, comply with legal obligations, resolve disputes, enforce terms, and support backup or recovery. Our retention period for residual backups, logs and analytics is up to 12 months after account or workspace deletion, unless a specific legal obligation or legal hold requires longer retention.
- Workspace and account data: while your service is active. When your deletion request is completed, we delete your account and hosted workspace data, including its files and structured database records. Residual backups, logs and analytics are deleted or de-identified within 12 months, subject to legal retention obligations.
- Billing and transaction records: the periods required by applicable tax, accounting and financial laws.
- Support and security records: the period needed to resolve the request or incident and handle related claims.
- Marketing records: while relevant to the stated purpose, with minimal suppression information where needed to respect an unsubscribe or objection.
Backup copies are not used for ordinary product or marketing activity. If a backup is restored for recovery, deletion requests must be reapplied. We also send applicable deletion instructions to our service providers. Records that must be retained for tax, fraud prevention or legal claims are restricted to those purposes; we explain any relevant exception in our response.
Account and Workspace Deletion
You can access account management from the mobile app’s Settings → Account → Manage account, which opens your account portal. To request deletion of your Matrix account and hosted workspace, email support@matrix-os.com from your account email. Specify whether you want one workspace or the entire account removed. We verify account ownership, explain any legally required retention and confirm completion.
Deleting your account, deleting a workspace, cancelling a subscription, disconnecting an integration and uninstalling the app are different actions. Export anything you need before requesting deletion. Deleting Matrix data does not automatically delete your accounts at connected providers or content you already sent to them. The 12-month residual retention limit above applies to backups, logs and analytics after deletion.
Security
Matrix OS uses technical and organizational safeguards intended to protect the service, including authentication, isolated runtime design, scoped APIs, access controls, auditability, backups, logging, and operational monitoring.
No online service can guarantee absolute security. You are responsible for protecting your account, reviewing connected integrations, and limiting what you choose to provide to AI agents or third-party services.
Your Rights and Choices
Depending on where you live, you may have rights to request access, correction, deletion, export, restriction, objection, or withdrawal of consent for certain personal information. You can make privacy requests by emailing support@matrix-os.com.
Under the GDPR, these rights include access, rectification, erasure, restriction, portability where applicable, objection to legitimate-interest processing and direct marketing, and withdrawal of consent. You can complain to your local supervisory authority; in Sweden, that is IMY. We respond within one month, subject to lawful extensions with notice.
Where applicable US state privacy laws cover our processing, you may have rights to know or access, correct, delete and obtain a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, and appeal a denied request. You may use an authorized agent where allowed and will not be discriminated against for exercising protected rights. We may reasonably verify your identity for access or deletion requests and apply the response deadlines required by law.
Our current website tags are not configured to automatically honor Global Privacy Control or Do Not Track signals. You can send privacy requests to the contact above. This describes current behavior and does not limit rights you have under applicable law.
You can also control many data flows directly by changing workspace settings, disconnecting integrations, deleting files or app data, or choosing what context to give an AI task.
Children
Matrix OS accounts are intended for adults aged 18 or older. We do not knowingly collect personal information from children under 13. If you believe a child provided us personal information, contact support@matrix-os.com.
Changes
We may update this Privacy Policy as Matrix OS changes. The updated policy will include a new effective date. Material changes will apply prospectively unless required sooner for legal, security, or abuse-prevention reasons.
Contact
Privacy questions or requests can be sent to Finna Labs Inc. atsupport@matrix-os.com or by post to 1908 Thomes Avenue, Cheyenne, WY 82001, United States.