Privacy Policy
MAP Agents lets a business publish an AI agent that answers questions about it, and lets people and other AI systems ask those agents things. This policy explains what happens to personal data on the way through — including the part most services leave vague: exactly what a business sees when your question reaches it.
1. Who is responsible
The controller for the personal data described here is:
Meddow GmbHMarie-Curie-Straße 153359 RheinbachDeutschlandFor anything about personal data, including any of the requests in Your rights, write to info@meddow.de. Full company details are in the Imprint.
We have not appointed a data protection officer. Requests go to the address above and are answered by the company directly.
1.1 What this policy covers
- the website at
www.map-agents.com - the business dashboard at
app.map-agents.com - MAP Open at
open.map-agents.com - our API and MCP endpoints at
api.map-agents.com, including the public agent endpoints businesses publish through us
It does not cover what a business does with information after it reaches them, what your calendar provider does with a booking, or what an AI assistant you used to reach us does with your conversation. Those organisations decide those things for themselves, and their own privacy notices apply. Where we can tell you who they are, we do — see who else receives data.
1.2 Who this policy is about
The service brings several different people into contact, and they are not all in the same position. Where it matters below, we say which of these we mean.
- Account holders
- someone who signs up, usually on behalf of a business, and publishes an agent.
- MAP Open users
- someone signed in to MAP Open to search for and talk to businesses.
- Anonymous callers
- someone who uses our public search endpoint without an account. We do not know who you are, and we cannot find out.
- Visitors to a business agent
- someone who asks a published business agent a question, whether directly or through another AI assistant.
- People named in a booking
- whoever an appointment is for, including when somebody else books on their behalf.
- People named in business content
- staff or contacts a business chooses to publish in its own agent's knowledge.
2. The short version
- The service is free. We do not sell personal data, we run no advertising, and there is no analytics or tracking product anywhere on these sites.
- This website sets no cookies at all. The signed-in apps store a session and your theme choice, and nothing else.
- When a search contacts a business, that business receives the question as our agent phrased it and your language — not your identity, your address, or anything else. Most searches contact nobody.
- A business can read the conversations people have with its own agent, in full. That is the point of the product, and it is worth knowing before you type.
- We send text to OpenAI to generate answers, configured so that OpenAI does not store the responses and does not train on them.
- Most things are deleted on a schedule, and every period in How long we keep things is enforced by a job that runs every fifteen minutes. The exception is a business's record of its own customer conversations, which it keeps while it has an account — and can delete at any time.
3. What we collect
Grouped by what you are doing, because almost nobody encounters all of it.
3.1 If you have an account
- your email address, and a display name and avatar if you set one
- authentication data held by our identity provider — a password hash, sign-in timestamps, and the session your browser holds
- where you have got to in setup, including the website address you gave us to read when your agent was created
3.2 What you publish about your business
Your agent's name, public address, description, category, locations, service areas, opening details, instructions and knowledge documents. This is public by design: it is what your agent answers with, and both people and other AI systems can read it. We also compile it into a search profile — units, facets, locations and numerical embeddings — so that it can be found.
3.3 Conversations
- With your own agent, while building it: the messages you and the Builder exchange, the steps it took, and any action it proposed to you.
- With a published business agent: the questions visitors ask and the answers given.
- In MAP Open or through our public search: your messages, the answer, which businesses were considered, why each was kept or set aside, and the messages exchanged with any business that was contacted.
Alongside a conversation with a business agent we keep a short record for the business's own statistics: the topic, whether it was resolved, whether a booking was attempted, how long the answer took, and a redacted excerpt of the question. The excerpt is erased on the schedule in How long we keep things; the counts derived from it survive, so a business's historical figures do not change when the text goes.
3.4 If you make a booking
The name, email address, timezone and any answers the business asks for, plus the appointment type and time. While the booking is being confirmed we hold these encrypted, tied to that one booking so the same confirmation cannot be replayed at a different business. They are sent to the business's calendar provider when — and only when — you confirm.
3.5 Technical and security data
We do not store your IP address. Where we need one — to limit request rates, or to investigate abuse — we store a one-way hash of it instead, and on the public search endpoint even that is erased after a day. Server logs record request timing and errors.
One narrow exception is worth naming because it involves an address leaving our edge: when a request arrives claiming to be an AI crawler, and our built-in address ranges cannot settle whether that is true, we ask our own API to verify it and pass the address and user agent to do so. It happens only for requests whose user agent already claims to be a crawler, never for ordinary browsing, and nothing is stored.
3.6 If you connect a calendar or a data source
The provider, the account identifier, the permissions you granted, your appointment types and availability, and the access credentials themselves — which are stored encrypted and are never shown back to you or to anyone else. If you connect your own data endpoint we store its address, its schema, and its secret in the same way.
3.7 If you write to us
The contact form asks for your name, email address and message, and sends them to our mailbox by email. We keep the correspondence so we can follow it up. The form also carries a hidden field that people never see and automated submitters usually fill in; when it is filled in we discard the message, and we do not keep what was in it.
4. Where it comes from
- from you, when you type it or connect something
- from an account holder, when they publish content about their business that names somebody
- from whoever is arranging an appointment, when they enter somebody else's details
- from your website, if you asked us to read it during setup — we fetch it the way a search engine does, and we honour
robots.txt - from a calendar or data provider you connected, with the permissions you granted
- from a business we contacted on your behalf, in the form of its agent's reply
- generated by our own systems — search rankings, topics, and model output
5. Why we process it, and on what legal basis
| What for | Legal basis (GDPR Art. 6) | Kept for |
|---|---|---|
| Creating and running your account | Contract, Art. 6(1)(b) | While the account exists |
| Publishing your agent and answering questions put to it | Contract, Art. 6(1)(b) | While it is published |
| Answering a question you ask in MAP Open or through public search | Contract, Art. 6(1)(b) when you are signed in; legitimate interests, Art. 6(1)(f), for anonymous use — providing the answer you asked for | 30 days, or 7 anonymous |
| Contacting businesses so we can compare real answers | Legitimate interests, Art. 6(1)(f) — giving you a grounded answer | With the conversation |
| Preparing and completing a booking you confirm | Contract, Art. 6(1)(b) | 7 days after it settles |
| Giving a business statistics about its own agent | Legitimate interests, Art. 6(1)(f) — a business understanding its own service | Text 90 days; counts kept |
| Keeping the service up, limiting request rates, and investigating abuse | Legitimate interests, Art. 6(1)(f) — security and availability | 1 day to 14 days |
| Answering your email | Legitimate interests, Art. 6(1)(f) — replying to someone who wrote to us | While relevant |
| Meeting legal obligations and defending legal claims | Legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f) | As long as required |
Where we rely on legitimate interests we have weighed them against your interests and rights, and you can object — see Your rights. We do not rely on consent for anything described here, because nothing here is optional in a way that consent would be the honest basis for. If that changes we will ask you properly, and separately.
6. When your question reaches a business
This is the part of the service most worth understanding, so it gets its own section rather than a line in a list of recipients.
When you search, we first look through what businesses have already published. Most searches end there and contact nobody. We contact a business's agent only when answering you needs something only that business can confirm — a current price, whether they cover your area, whether a time is free.
When we do contact a business, this is exactly what it receives:
- a question written by our agent, drawn from what the conversation has established — usually not your words verbatim
- the language you are working in
And this is what it does not receive: your name, your email address, your account, any identifier we hold for you, your IP address, your browser, or anything from your conversation beyond the question we asked. A business we contact cannot tell whether you were signed in. Businesses contacted in the same search never see each other's replies.
There is one deliberate exception, and it happens only after you have chosen a business and are confirming something with it — a booking, typically. At that point your own words are passed on, because a confirmation has to be yours and not a paraphrase of yours.
6.1 What a business can see about its own agent
If you ask a published business agent something directly — on its page, or through an AI assistant — the business that owns that agent can read that conversation in full, exactly as you wrote it. Nothing is redacted. This is deliberate: it is how a business finds out what its customers are asking and where its agent is getting things wrong.
A business cannot see your MAP account, conversations with any other business, or anything from the wider search that produced its reply.
7. AI, ranking and automated decisions
Every answer the service produces is generated by an AI system. It can be wrong, out of date or incomplete, and anything that matters is worth confirming with the business directly.
Results are labelled with how well they are supported: whether a business confirmed something during your search, whether it came from what they had already published, or whether they were asked and did not answer in time.
7.1 How results are ordered
Ordering is done by ordinary program logic, not by the model. The things that move a business up or down are:
- how well its published text matches what you asked, by wording and by meaning
- whether it matches specifics we extracted from your question, such as a service or a place
- how close it is, where your question is about a place
- whether it confirmed the details during your search, which counts for a great deal
- whether it stated a price and availability, and whether the price fits a budget you gave
Nobody can pay to rank higher. We take no payment for placement, there is no promoted position, and self-promotional language in a business's own text is filtered out rather than counted — otherwise ranking would measure how boldly a business describes itself.
7.2 Automated decisions about you
We do not make decisions about you by automated means that produce legal effects or similarly significant effects. We do not build a profile of you, we do not infer things about you to target anything, and search ranking is about businesses rather than about you.
Automated limits do exist on how many requests a single caller can make in a period. Their effect is that a request is refused and can be retried shortly after.
7.3 The model provider
We use OpenAI, and only OpenAI, to generate answers and to compute the numerical representations that make search work. What we send is the conversation and the business content needed to answer it.
- We call the API with response storage switched off, so OpenAI does not retain the responses it generates for us.
- Content sent through the API is not used to train OpenAI's models. That is OpenAI's standard position for API traffic and we have not opted out of it.
- We do not train models on your content either, and we do not build evaluation datasets from real conversations. The material we test against is written by hand.
8. Sensitive information
We never ask for special category data — health, religious or political views, trade union membership, sexual orientation, ethnic origin, biometric or genetic data — and the service has no feature that needs it. But conversations are free text, and a question about finding a clinic or a place of worship can reveal something sensitive without anyone intending it.
So, as a matter of design:
- we do not infer sensitive characteristics about anyone, for any purpose
- we do not use anything of the sort to rank, target, advertise or decide
- we do not build audiences or segments, and there are none to build
- what travels to a contacted business is the minimum described in When your question reaches a business, and it carries nothing that identifies you
- it is deleted with the conversation on the schedule below
On political and civic questions specifically: agents may give factual information, and must not be used for political persuasion aimed at a particular person, for campaigning, or for anything targeted on the basis of somebody's opinions. The Terms of Use prohibit it outright.
9. Cookies and what is stored on your device
This website sets no cookies and stores nothing on your device. There is no analytics, no advertising, no tracking pixel and no third-party script — not on this site and not in the signed-in apps. Our fonts are served from our own servers, so displaying a page contacts nobody but us.
That is why there is no cookie banner. There is nothing to ask you about.
When you sign in, two things are stored, and both are there to make the thing you asked for work:
| What | Where | Why | How long |
|---|---|---|---|
| Your session | Local storage in the dashboard; a cookie in MAP Open | Keeps you signed in. Without it you would sign in again on every page. | Until you sign out |
| Light or dark theme | Local storage | Remembers the setting you chose. | Until you clear it |
| Whether the side panel is open | Local storage in the dashboard | Remembers the layout you left it in. | Until you clear it |
All three are strictly necessary for a service you actively asked for, in the sense of § 25(2) TDDDG, so they do not require consent. None of them is used to recognise you anywhere else or to build any kind of profile.
If you use the dictation button, speech recognition is performed by your own browser. Depending on which browser you use, that may mean your browser's maker receives the audio — it does not reach us, and we receive only the text that appears in the box.
10. Who else receives data
We do not sell personal data and we do not share it for anyone else's marketing. These are the organisations that process it so the service can run.
| Who | What they do for us | What reaches them |
|---|---|---|
| OpenAI | Generates answers and computes search representations | Conversation text and the business content needed to answer it |
| Supabase | Database and sign-in, and the emails that sign-in sends | Everything we store, and your email address for sign-in messages |
| Amazon Web Services | Runs our API, in Frankfurt | Everything passing through the service |
| Vercel | Serves this website | Requests to these pages |
| Cloudflare | Provides custom domains for businesses that use one | Domain and certificate details; requests to those domains |
| Calendly, Google Calendar | Hold the calendar, where a business has connected one | Booking details, when you confirm a booking |
| Our email provider | Delivers messages sent through the contact form | Your name, email address and message |
| A business you reach through us | Answers your question | Only what is described in the forwarding section |
Beyond these, we disclose personal data only where the law requires it, or where we need to establish or defend a legal claim. If the business were ever sold or reorganised, data would pass to the buyer under the same protections, and we would say so here first.
11. Where data is processed
Our own servers run in Frankfurt, Germany. Some of the providers above are established outside the EU or process data outside it — OpenAI in particular.
Where personal data leaves the European Economic Area, it is transferred under an approved safeguard: an adequacy decision where one applies, and otherwise the European Commission's standard contractual clauses. You can ask us for details of the safeguard for a specific provider using the contact address above.
12. How long we keep things
Every period below is enforced by a job that runs every fifteen minutes and deletes what has passed its window. Where there is no period, the table says what actually determines it instead of borrowing a number — and where that is the case, it is because a period would be the wrong answer rather than because nothing enforces one.
| What | How long | What happens then |
|---|---|---|
| Your account and your business content | While the account exists | Deleted when the account is deleted |
| Conversations with a published business agent | For as long as the business has an account | Deleted when the business deletes the conversation, its agent, or its account. The business can delete any conversation at any time, and you can ask it or us to |
| Statistics about those conversations | Question text: 90 days. Counts: kept | The text is erased; the topic and counts remain, so past figures stay accurate |
| MAP Open conversations, signed in | 30 days after the last message | Deleted, along with everything from that search |
| Public search conversations, anonymous | 7 days after the last message | Deleted. Shorter because nobody can ask us to delete them — see below |
| The address hash on a public search | 1 day | Erased, while the conversation itself stays for its own period |
| Booking details awaiting confirmation | 7 days after the booking settles | The encrypted details are deleted. The booking itself lives at the calendar provider |
| Handles for a conversation opened with a business | 7 days after last use | Deleted |
| Records of what an agent did while answering | 14 days | Deleted |
| Sign-in state for connecting a calendar | 1 day | Deleted |
| Your conversations with the Builder while making your agent | Until you delete them or your account | There is no automatic period, because it is your own working material and deleting it on a timer would lose your work |
| Emails you send us | While the matter is live, and afterwards where we need it for a legal claim | Deleted when neither applies |
Two distinctions this table is careful about, because services routinely blur them. A conversation link expiring after 24 hours means you can no longer use it — the record is still there until its retention period ends and it is deleted. And deleting a record removes it from the live database; it can persist in encrypted backups for a further period until those rotate.
13. How it is protected
- Traffic is encrypted in transit, and the database is encrypted at rest.
- Calendar credentials, data-source secrets and booking details are separately encrypted by the application, so they are unreadable even to someone reading the database directly.
- Conversation links and booking tokens are stored only as one-way hashes. We cannot reconstruct the link from what we hold.
- Every table enforces row-level access rules that the application cannot bypass, so one account's data is not reachable from another's session.
- Credentials and tokens are kept out of logs.
- Request rates are limited, and unusual patterns are investigated.
These measures are designed to protect personal data, and we work on them continually. No service can promise to be perfectly secure, and we are not going to claim otherwise. If you find a security problem, please write to info@meddow.de and give us a chance to fix it.
14. Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything that is wrong
- delete it
- stop or limit what we do with it
- hand it over in a portable form, or send it to another provider
- stop processing based on legitimate interests, by objecting — including at any time, for any reason, where we rely on that basis
Write to info@meddow.de. We answer within one month, and will tell you if we need longer because a request is complex. It costs nothing.
We may need to check you are who you say you are — not to obstruct you, but because handing someone's data to the wrong person is the very thing these rights exist to prevent. If you are asking about a specific conversation, telling us which one is usually enough.
14.1 If you used the service anonymously
An anonymous search is not linked to you in any way we can search on. If you still hold the conversation link, send it to us and we can delete that conversation. If you do not, we genuinely cannot find it — there is nothing connecting it to you. That is why anonymous conversations are deleted after seven days rather than thirty.
14.2 Complaining to a regulator
You can complain to a data protection authority, in the country where you live or work or where you think something went wrong. We would appreciate the chance to put it right first, but that is your choice and not a condition.
The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–440213 DüsseldorfDeutschland15. Children
This is a service for businesses and for people looking for them. It is not designed for or directed at children, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
16. Changes to this policy
When something material changes we update this page, give it a new version number, and change the date at the top. Where a change affects you significantly we will tell you before it takes effect.
We will not treat your continued use of the service as agreement to a change that legally needs your consent. If we ever need consent for something, we will ask for it separately and you will be able to say no.
Version history
- 2026-08-23.1
- First published.