Privacy notice
This notice explains what happens to personal data when you use Talk to MAIA. It is given under Article 13 of the General Data Protection Regulation, Regulation (EU) 2016/679, as applied in Malta by the Data Protection Act, Chapter 586 of the Laws of Malta.
A link to it is shown before you start a conversation, and it applies from that moment. Nothing on this page asks you to agree to anything; it tells you what happens if you go on.
Who is responsible
The controller is MAIA Brain P Ltd, a private limited liability company registered in Malta, with its registered office at 2, Spinola Road, St Julians STJ 349, Malta.
You can reach us about anything in this notice by email at info@maiabrain.com or by telephone on +356 2010 2020.
The notice at www.maiabrain.com/privacy covers our website and our email. This page covers Talk to MAIA only.
You are talking to an AI
MAIA is an AI system, not a person. Language models from OpenAI write most answers and compose the page on the left from our knowledge base; the service itself supplies a few fixed replies, described below. It can be wrong. Check anything that matters to you against the sources it cites under its answers.
There is no person behind the answers, and no one at MAIA Brain answers in MAIA's place. This notice speaks for MAIA Brain P Ltd, as "we".
What we collect
No sign-in. The service runs in a mode with no sign-in: before a conversation starts, your browser passes a bot check run by AWS WAF, which can ask you to solve a short puzzle. In this mode the service does not ask for your name, email address or phone number. Its code also contains sign-in by a code sent by email or text message, but in this mode that path cannot be reached: the service does not accept an email address or phone number, sends no code, and gives nothing to our text-message provider (Twilio) or our email provider, although both are configured on our server. If we ever switch sign-in on, we will change this notice first.
- The network address you connect from. Every connection carries it. It is used by AWS for its bot check, and by our service to limit how many sessions one address can start in an hour (two hundred, unless we configure otherwise) and how many connection reports it can send in a minute.
- Your conversation. The questions you type or say and MAIA's answers, typed or spoken, in order. A spoken turn is kept as a written transcript and marked as spoken.
- What MAIA notes about you. When a question speaks about yourself (it contains words such as "I", "my", "we" or "our"), that question alone is sent, beside the answer, to an OpenAI model that picks out what you said about yourself. Only six things can be noted: your company, sector, role, size, location and concern, each in at most 120 characters, in your own terms; a newer note replaces an older one on the same point. How the notes are used is set out below.
- Your voice, if you use voice. While a voice session is open, the sound from your microphone is streamed to OpenAI so that MAIA can hear you, and anything you type during the voice session is sent to the voice model too. A written transcript is made of what you say and of what MAIA says, and both are added to your conversation. A voice session on GPT-Live stays open until you stop it or until two minutes pass without you speaking or typing into it; a voice session on the fallback voice model (see below) ends about a minute after it starts. A pass can have one voice session open at a time.
Please do not tell MAIA anything about your health, beliefs or other sensitive matters, or personal details about other people. Nothing in the service detects or removes them: whatever you type or say is stored with your conversation and sent to OpenAI with it.
How your notes are used. Within your conversation, what MAIA notes about you is shown to you on the page; is used to compose the page; is given to the conversation check described below; and is used by the checks on MAIA's own answers, so that a figure or a name you gave yourself is not refused as unsupported when MAIA repeats it. The checks on typed answers also use the questions you asked earlier in the conversation in the same way.
Images. Images on the page are stored files served from our server. The service picks an image topic from a fixed, closed list; your words and notes can decide which topic is picked, on our server. When no stored image fits that topic, the service may ask OpenAI's fixed image model, gpt-image-2, to make one from a fixed description written by us for that topic; your words are not part of that description. The description tells the model not to include text, numbers, faces, people, logos or trademarks. Generated image files have names derived from their contents, are not linked to you or your pass, are reused for later visitors, and are not deleted automatically. A manifest records the topic tag, display topic, tags, original dimensions, colour palette, output dimensions, file names and byte sizes, model, quality, generation mode and time, request latency, calculated cost, usage returned by OpenAI, and OpenAI request identifier.
Who else is involved
Amazon Web Services and OpenAI process personal data for the live service as set out here. Twilio and an SMTP email provider are configured, but the live no-sign-in mode does not send them a phone number, email address or sign-in code.
- Amazon Web Services
- Receives the service runs on AWS EC2 in Frankfurt (region eu-central-1), so the server records listed under the next heading are held there. Your connection reaches it through Amazon CloudFront and AWS WAF. AWS receives your network address and request details; the complete signed session pass passes through CloudFront and WAF in the WebSocket URL and, when the browser renews it, in the
X-Talk-Renewalrequest header. AWS WAF runs the bot check and puzzle. - Why hosting, delivery, and protecting the service from automated abuse.
- How long what AWS keeps as a provider is set out in its privacy notice.
- OpenAI
- Receives everything the service sends to its models to answer you, keep the notes, compose the page and check the conversation. The configurable defaults and the model names fixed in the code are identified below.
- Answers. MAIA's text answers are usually written by an OpenAI realtime model (by default gpt-realtime-2) in one conversation kept open for your pass. It receives MAIA's instructions, material from our knowledge base, each question, and your conversation so far. The conversation is sent in full while it is short; once it passes about six thousand tokens (roughly 24,000 characters), the oldest turns are replaced by a summary made on our server, not by a model, by shortening each earlier line to at most 280 characters and keeping the summary to about 3,600 characters. That open conversation is closed about a minute after your page disconnects, after five minutes without use, when the service restarts, or when your pass's records are deleted, and it is replaced every fifty-five minutes. If it is unavailable, the answer is written by an ordinary call to an OpenAI model (by default gpt-5) with the same instructions, material and conversation. A few fixed replies are written by the service itself, without a model: for example when you only ask for the page to be built, or after the conversation check has stopped the conversation.
- Notes about you. A question that speaks about yourself is sent on its own to an OpenAI model (by default gpt-5.6-luna), with OpenAI's option not to store it (store: false).
- The page. The page on the left is composed from your conversation by a second realtime conversation using the fixed model gpt-realtime-2, kept for your pass. With each question, typed or spoken, it receives the question, the knowledge-base material fetched for it, MAIA's previous answer, what MAIA has noted about you, the headings of the page on screen, and a short interest profile: some words from your questions, up to four questions that state a goal, and your last six questions. If it fails, the same material is sent with store: false to the model set by
TALK_PAGE_MODEL, whose default is gpt-5.6-luna. A separate facts-mode page writer uses that same setting first and, if the model is unavailable, the model set byTALK_PAGE_FALLBACK_MODEL, whose default is gpt-5. - Voice. A voice session is led by OpenAI's GPT-Live model (by default gpt-live-1), opened with store: false. It receives the sound from your microphone, anything you type during the session, MAIA's instructions, your conversation so far (in the same full-or-summarised form as above), and the answers the service looks up for it. It makes the transcripts and speaks. When you ask something factual, the question is answered by the same knowledge-base lookup and ordinary model call as the text chat, and the answer is passed to GPT-Live to say. If GPT-Live cannot be started, that voice session uses an OpenAI realtime voice model (by default gpt-realtime-2.1), with your speech transcribed by an OpenAI transcription model (by default gpt-transcribe), and after three such failures within a minute all voice sessions use it for the next five minutes; that path receives your microphone's sound, anything you type during the session, MAIA's instructions, your conversation so far and knowledge-base material.
- The answer review. After a model-written text answer, or an answer spoken by GPT-Live, has been given, its text is usually (MAIA's words only, not your question) sent to the fixed OpenAI model gpt-5.6-luna, with store: false, to check it against our content rules. This happens in the background and never delays an answer; the log records the first ten characters of a SHA-256 fingerprint of the pass and the names of any rules it flags.
- The conversation check. After your fourth question, and then every three to ten questions, the fixed OpenAI model gpt-5.6-luna, with store: false, is sent your last ten questions, typed or spoken, without MAIA's answers; what MAIA has noted about you; and the seconds between those questions. It judges whether the conversation is a genuine one about MAIA and its field or misuse, such as gibberish, unrelated tasks or probing. It runs in the background after an answer. If it is confident that the conversation is misuse, or judges so twice in a row, MAIA says once that it will stop here, later questions with that pass get the same reply without any model being asked, a new voice session is not opened, and an open GPT-Live session closes the next time you speak or type.
- OpenAI does not receive your network address or the number of your pass.
- Why to write MAIA's answers, note what you say about yourself, compose the page, hear you and speak in voice, review answers against our content rules, and keep the service from being misused.
- How long what OpenAI keeps, and whether it may use it, is governed by its terms for its API, set out in OpenAI's data controls for the API. We have not arranged terms of our own with OpenAI beyond those.
Inside our server. The service also hands work to a knowledge-base process on the same server, over a local connection: lookups written by the models, your notes (to plan the page) and the text of the page being composed.
We do not sell personal data, we do not share it for advertising, and nothing from this service goes anywhere other than the two processors above, except to a public authority entitled to it.
How long we keep things
The session pass. Once the check is passed, the service gives your browser a signed session pass containing a version, a random number, its expiry and the time the conversation started; an HMAC signature follows that payload. The expiry is four hours after issue unless we configure otherwise. It carries no name, email address or phone number. Before it runs out, the page quietly obtains a new pass; the conversation record moves to the new random number, and the old database row and page-composer mappings are removed during renewal. A conversation can be carried over in this way for up to twenty-four hours from its start; after that, a new conversation starts, and the old one waits for deletion as below.
On the server's disk, in a small database, the service keeps against the number of your pass:
- your conversation, typed and spoken questions and MAIA's answers, the running summary described above, and how many turns it covers;
- what MAIA noted about you, and the last page composed for you with its revision number;
- the questions you asked, typed or spoken (a spoken one as transcribed, up to 4,000 characters), with its number in the conversation and the time it was asked, for the conversation check; and the check's state: its last verdict and confidence, how many genuine or misuse verdicts came in a row, the last question checked, when the next check is due, and whether the conversation has been stopped;
- a ledger of questions: for each typed question, a random question number chosen by your browser, its text, whether it was counted, whether it is running, finished or abandoned, when it was last updated, and, once answered, the answer sent to you. It lets a question be counted once and answered again after a dropped connection. On the fallback voice path, a lookup the voice model asks for is also entered, with a number made by the server, the words "voice delegation" in place of text, and an empty answer. The last twelve finished entries are kept;
- pass state: when the pass expires, when the conversation started, how many questions you asked, how many voice sessions you opened and whether one is open now, how many pages were composed, how many knowledge-base lookups voice made, how many connections the page made and how many reconnections in the current hour, the code with which the last connection closed, and what the model calls for your pass cost.
While the service is running, it also keeps a working copy of your conversation, notes and page in memory until the retention sweep removes it. That conversation state includes the network address from your connection and moves to the renewed pass with the conversation. During renewal the old pass number is also kept in memory, pointing to the new one, so that a turn in progress still reaches your conversation; it is followed for two minutes and removed by the next retention sweep after that. The chat and page realtime sessions are re-keyed to the renewed pass; when the retention time is reached, the retirement callback closes and removes them. The page composer also keeps pass-to-address, latest-question and notes-fingerprint mappings; renewal removes the old pass's mappings, and the retention sweep removes mappings for records that reach the deletion time below.
How long: all of this is deleted six hours after your last pass expires, by a sweep that runs when the service starts and every ten minutes. With the default settings, and while the service is running, a conversation is therefore gone at most about thirty hours and ten minutes after it began, and a conversation of one pass that is not carried over is gone at most about ten hours and ten minutes after it began. If the service is stopped at that moment, the records are deleted when it next starts.
Deleting sooner. The service has no control that lets you delete your conversation before then, and closing the tab does not delete it sooner. These records hold no name or account: on disk they are filed under the random number of your pass, although what you typed or said may itself identify you. In memory, the working conversation state keeps the network address until the retention sweep, including across renewal; shorter-lived page-composer and rate-limit records are described next.
Other records on the server:
- Your network address. In memory, the service keeps timestamp queues under the address to limit session starts over one hour and connection reports over one minute. Old timestamps and empty address entries are trimmed on later requests and by the ten-minute retention sweep. The page composer also keeps the number of your pass with your network address, the number of your latest question, and a SHA-256 fingerprint of your notes; those mappings are removed on renewal, at the retention deletion time, or when the service stops. The address is not written to the database.
- Images. To limit image making, the service keeps in memory the numbers of recent passes (with a page revision number) that asked for a new image, up to 2,048 of them, until the service restarts.
- A report token index. The page is given a signed token for connection reports (below). In memory, the server keeps an opaque handle derived from your pass number with a secret key, and the pass's expiry, so that it can check a report; it is removed after the pass expires, at the latest by the next sweep.
- Your voice is passed straight through to OpenAI. The server does not record the sound. The transcripts become part of your conversation and are kept and deleted with it.
- Spending records. While a model call, an image request or a voice session runs, the database holds a record of it: a random reservation number, the day, when it was made or last updated, which part of the service made it, the amount reserved and spent (for voice, the seconds used) and, when that call supplies one, the number of your pass. It holds no text. It is deleted when the call or session ends, or later by the sweep or when the service next starts.
- Totals. The same database keeps totals only: per day, how many questions, voice seconds, sessions, pages and lookups there were and what the model calls cost; per hour, the cost of each part of the service; and per day, how many conversations the check judged genuine, unclear or misuse, and how many it stopped. These rows hold no pass number, no network address and nothing anyone said, and they are not deleted automatically.
- Spending alerts. A spending monitor runs every five minutes and records short spending-alert lines, with their time. An alert about a single pass names it by the first ten characters of a SHA-256 fingerprint of the pass number and gives what it has spent. Alerts are kept in the database for twenty-four hours and are deleted on the next monitor run after that, and they are also written to the service log described below, which keeps them for at most thirty days, and less once it reaches 200 MB.
- Connection reports. When the page's connection closes, your browser sends a small report: the close code, a class from a fixed list, how long the connection had been open as a range, and how many times the page had reconnected, with the signed token, which does not contain your pass number. To ignore duplicates, the server keeps a one-way fingerprint of each report for about twenty-four hours.
- Our own checks. We can start sessions with a signed header that only our server can produce, to check that the service works. The one-time number each check uses is kept for about an hour so that it cannot be replayed.
The service log. The service writes a log of technical events: connections closing, voice sessions starting and ending, word and character counts, timings, errors, and the names of rules when a check refuses or flags output. Entries can carry random question numbers made by the browser or server, a random voice-session number, OpenAI call identifiers for voice lookups, the last twelve characters of OpenAI conversation-item identifiers on the fallback voice path, and, for the answer review and conversation check, the first ten characters of a SHA-256 fingerprint of the pass number. It does not write your questions or MAIA's answers as log fields, and it clears the session pass from the address of its connections before accepting them. It can, however, hold short pieces of text: when a part of the page is refused, up to 500 characters of what the page model wrote; when the page model's reply cannot be read, up to 160 characters of it; and error messages, which can quote what was being processed. This log is kept for at most thirty days, and less once it reaches 200 MB.
Why, and on what basis
We send your conversation, what you tell MAIA about yourself and, if you use voice, what you say, to OpenAI, and keep the conversation records until six hours after the last pass expires, because that is how the service you asked for answers you in context and composes the page for you. The legal basis is Article 6(1)(b), processing necessary to provide the service you request.
We use the bot check, limit sessions per network address, review answers against our content rules, measure what each pass costs and watch spending, keep the service log, and let the conversation check end conversations that misuse the service, because every answer costs us money and an open service of this kind is abused quickly. The legal basis is Article 6(1)(f), our legitimate interest in keeping the service available, accurate and its cost bounded.
MAIA makes no decision about you that has legal or similarly significant effects. What it notes about you is used only within your conversation, as set out above. The conversation check can end a conversation automatically; that affects only this free conversation. If you think it stopped you wrongly, start a new conversation in a new tab, or write to us.
Cookies and browser storage
AWS WAF, which runs the bot check and the puzzle, keeps its own token in your browser to show that the check was passed; according to AWS's documentation it does so in a cookie, and AWS decides what it holds and how long it lasts. Our service does not read it. The page loads AWS's script for the check and the puzzle from the address we configure for AWS WAF.
That token is strictly necessary to protect the service from automated abuse, and without it the service cannot be used. For that reason, under Regulation 5 of the Processing of Personal Data (Electronic Communications Sector) Regulations, Subsidiary Legislation 586.01, you are not asked to consent to it.
The page itself stores one item in your browser's session storage, maia-talk-pass-v1: your session pass and its expiry. It lets the conversation continue if you reload the page, since the server then sends your conversation back to the page. Session storage belongs to that tab only, and the page clears the item when you open the page afresh rather than reload it. The page's own code sets no cookie and writes nothing else to your browser's storage.
Where data goes
The service runs in Frankfurt. CloudFront carries your connection through AWS edge locations, which may be outside the European Economic Area. OpenAI is a United States company, and what it receives may be processed outside the European Economic Area. Those transfers rest on the mechanisms in Chapter V of the Regulation: adequacy decisions, including the EU–US Data Privacy Framework, where they apply, and the Standard Contractual Clauses in the processors' terms where they do not. You may ask us for information about the safeguards that apply.
Your rights
You may ask for access to your personal data, for it to be corrected or erased, for its processing to be restricted, and, where the conditions in Article 20 are met, for it to be given to you in a portable form.
Where we process on the basis of our legitimate interests, you may object at any time on grounds relating to your particular situation, and we will stop unless we can show compelling legitimate grounds that override your interests.
Write to info@maiabrain.com. We answer within one month, and we will tell you if we need longer and why. Because the service asks for no name or account and files conversation records under a random pass number, we will usually be unable to identify which conversation records are yours without information that links you to that pass. The pass is processed by our server and passes through CloudFront and WAF as described above; conversation records are deleted on the six-hour schedule, service logs can remain for up to thirty days or 200 MB, and aggregate totals are not deleted automatically. A request about what OpenAI holds, we will pass on to it.
If you are not satisfied
You may lodge a complaint with the Information and Data Protection Commissioner, the supervisory authority for Malta, or with the authority in the country where you live or work. Doing so does not affect any other remedy available to you.
Changes to this notice
This notice describes what the service does today, and it is written from the code that was running when it was published. If that changes, this notice changes with it.
MAIA Brain P Ltd · 2 Spinola Road, St Julians STJ 349, Malta · info@maiabrain.com · Back to the chat