Privacy Policy
Last updated August 2026
8x Social, Inc., a Delaware C Corporation (“Mate”, “we”) operates the Mate service at mate-ai.chat. This privacy policy explains what we collect, why, and what we do not collect.
The short version: Mate queries your databases live and does not copy your records. We keep metadata — table names, column names, what they mean and how they relate — plus a log of the questions asked and the queries they became. The rows those queries return are used to answer and are not stored by us.
1.Who this covers
Mate is sold to organisations. Two kinds of people appear in this privacy policy: administrators, who hold an account on the Mate dashboard and connect data sources, and members, who never sign in and only ask Mate questions from Slack or Microsoft Teams.
Where your organisation is the customer, it is the data controller for the business data Mate reads on its behalf, and Mate is a processor acting on its instructions. For account data — the administrator’s email, the organisation record, billing — we are the controller.
2.What we collect
Account information
The email address an administrator signs up with, the organisation name and slug they choose, their selected time zone and dashboard language, and — if they sign in with Google — the account identifier Google returns. We request only openid and profile from Google and from Microsoft: enough to know who signed in, and nothing that reads your mail, files or calendar.
Connection details for your data sources
Host, port, database name, username and the credential itself. Credentials are stored encrypted and are used only to open the connection that answers a question.
Schema metadata
Table and column names, types, relationships, and the descriptions your administrator writes or approves. This is what lets Mate turn a plain-language question into a correct query, and it is the category of data we deliberately do keep.
Questions and the queries they became
Each question, the SQL or pipeline Mate generated from it, which models answered, timings, token counts and the outcome. This is the audit trail your administrator can read on the dashboard, and it is what usage and billing are calculated from.
Chat platform identifiers
The Slack or Microsoft Teams user, channel and tenant identifiers attached to a question, and — where the platform supplies it — the display name, so the dashboard can say who asked rather than showing a raw identifier.
Files Mate generates
Reports, spreadsheets and images Mate is asked to create are stored in a private bucket so the link in the chat keeps working. These contain whatever the answer contained, so they are the one place your business data does come to rest with us. Anyone holding the link can open the file.
3.What we do not collect
We do not store the contents of your databases. Every question runs as a live, read-only query against your system. The rows it returns are held in memory long enough to compose an answer and are not written to our storage — the exception being a file you explicitly asked Mate to generate, described above.
We do not copy, replicate, mirror or warehouse your data, and we do not use your business data, your schema or your questions to train any model.
4.How we use it
- To answer questions, which is the service.
- To show your administrator what was asked, what it cost and whether it worked.
- To calculate usage against your allowance and to bill you.
- To operate and secure the service — diagnosing failures, preventing abuse, and meeting legal obligations.
- To contact administrators about the service. We do not sell personal data, and we do not share it for advertising.
5.Sub-processors
Mate is built on a small number of vendors. Each receives only what it needs to do its part:
- Google (Gemini) or OpenAI — language models. They receive the question, your schema metadata and the query results needed to compose the answer. They do not receive your credentials. We use their APIs under terms that do not permit training on submitted content.
- Supabase — the Mate database and the private file bucket, holding everything in section 2.
- Vercel — hosting for the dashboard and the API.
- Pipedream — the connection layer for third-party apps, where your organisation has connected any.
- Slack and Microsoft — the chat platforms Mate answers in.
- Google (Analytics and Tag Manager) and PostHog — product analytics, in the browser only, and only on the live site. They receive page views and a fixed list of product events — an account created, an app connected, a plan bought — with the plan or app each one is about. Once you are signed in, PostHog also receives your Mate user id and your workspace id, so that those events can be counted per workspace rather than per browser. Neither receives your name, your email address, your business data, or anything Mate reads on your behalf.
Your own database provider is not our sub-processor: Mate connects outward to a system you already run and control.
6.Who can see what, inside your organisation
This is the part of the privacy policy worth reading twice, so it is stated plainly rather than as a clause. In the current version, anything Mate can read is answerable to anyone in your workspace who asks. Mate does not yet map your database’s own row-level permissions onto the person asking in chat. Your administrator acknowledges this during setup, and controls it by choosing which tables Mate may read at all.
Answers to direct messages stay in that direct message. Per-user and role-based permissions are planned; until they ship, treat Mate’s access as organisation-wide and scope the connected account accordingly.
7.Retention
Everything this privacy policy says we keep — schema metadata, questions and query logs — is kept for as long as your organisation has an account, because they are the audit trail and the basis of your bill. Generated files are kept until deleted or until their retention period ends.
Deleting a data source deletes its stored credential and its metadata. Closing your account deletes your organisation’s data from our systems; backups age out on their own cycle. Write to privacy@mate-ai.chat to request deletion.
8.Security
Every credential this privacy policy describes is encrypted at rest, and data in transit is encrypted with TLS. Access to a customer’s data within Mate is restricted by row-level security keyed on the organisation, and the file bucket is private with no public read path.
Mate asks you to connect it with a read-only database account and checks the grant where the engine allows it, so the database itself refuses writes rather than relying on us to. Report a vulnerability to security@mate-ai.chat.
9.International transfers
Mate is operated from the United States and every sub-processor named in this privacy policy operates globally. Where personal data is transferred out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards.
10.Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Under the GDPR our legal bases are performance of a contract, our legitimate interest in operating and securing the service, and consent where we ask for it.
Under the CCPA/CPRA and comparable US state laws, we do not sell or share personal information as those laws define it, and we do not discriminate against anyone who exercises a right.
If you are a member rather than an administrator, your organisation controls the data Mate holds about your questions — ask them first, and we will help them help you.
Exercise any right in this privacy policy at privacy@mate-ai.chat.
11.Age
Mate is a workplace product and is not directed at children. Nothing in this privacy policy is an invitation to anyone under 16, and we do not knowingly collect their data.
12.Changes to this privacy policy
We will update this privacy policy when the service changes, and the date at the top will change with it. Material changes will be notified to administrators by email.
13.Contact
Questions about this privacy policy, and any request under it, go to the address below.
8x Social, Inc., a Delaware C Corporation
1111B S Governors Ave STE 47647, Dover, DE 19904, United States Directions
Privacy: privacy@mate-ai.chat
Security: security@mate-ai.chat
Support: support@mate-ai.chat