Matten is a governed access platform operated by IntellectSpace Corporation (“Matten,” “we,” “us”). Matten lets AI clients — Claude, ChatGPT, Codex, Claude Code, and others — interact with your business systems through a read-only, audited gateway. This policy explains what data Matten handles, how, and why.
What data we collect
Matten collects the minimum data required to operate the service:
- Login identity. When you sign in to Matten with Google, we receive your Google user identifier (
sub), your email address, and your Google Workspace domain (hd) if applicable. These are used to identify your Matten tenant and your user within it. - Provider grants. When you connect a business system — Salesforce, QuickBooks, or Google Analytics — we receive an OAuth refresh token from that provider on your behalf, along with a stable account identifier for the specific account you authorized (for example, the 18-character Salesforce Organization ID, the QuickBooks Company ID, or the Google user identifier of the Google Analytics account holder). We never see or store your provider password.
- Tool invocations. Every read request that Matten proxies to a connected provider is recorded in an audit log: who invoked it, which tool and which parameters, which provider responded, the size and row count of the response, whether it succeeded, and how long it took.
- Session state. Standard first-party cookies and server-side session rows so you can stay signed in.
- Public-site analytics. On Matten's public marketing site, Google Analytics, Google Tag Manager, Vercel Web Analytics may collect page paths, referrers, browser and device information, approximate location, and interactions such as calls-to-action clicked. These services do not load until the visitor allows analytics. We do not send prompts, business-system records, form contents, or email addresses in analytics events. Google advertising storage and advertising personalization remain disabled.
- Chat history. If you use the Matten portal chat feature, the messages you send and the assistant's replies are stored so you can resume recent conversations. We retain at most the last ten conversations per user; older conversations are pruned automatically.
For Google Analytics specifically, Matten can read the data your authorized Google account can see — property metadata, report results, and real-time reports — under the standard analytics.readonly scope. Matten does not see raw page traffic or individual visitor identifiers beyond what Google Analytics itself exposes.
How we use your data
Your data is used only to:
- Authenticate you and maintain your Matten session.
- Execute the tool calls you or an AI client acting on your behalf makes against your connected providers.
- Keep a tamper-evident audit trail so you and your tenant administrators can see what was accessed and when.
- Detect and respond to abuse of the service, including rate limiting and capability enforcement.
- Respond to your support requests.
- Understand use and performance of the public website, measure which messages and calls to action are useful, and improve the website.
Matten does not sell your data, does not use your business data to train machine-learning models, and does not share your data with third parties except the subprocessors listed below.
Subprocessors
Matten relies on the following third-party services to operate:
- Google — identity (sign-in), read-only access to Google Analytics data for users who connect it under the scopes they authorize, and Google Analytics and Tag Manager for public-site measurement when enabled by the visitor's analytics choice.
- Salesforce — for users who connect Salesforce, read-only access to the Salesforce objects your connected user can see.
- Intuit (QuickBooks Online) — for users who connect QuickBooks, read-only access to the QuickBooks company your connected user can see.
- Cloudflare — platform hosting (Workers, D1 database, KV storage) and TLS termination.
- Vercel — portal and marketing frontend hosting, and public-site web analytics when enabled by the visitor's analytics choice.
- Anthropic — for the Matten portal chat feature only. Anthropic's Claude models proxy tool calls back to Matten via the Model Context Protocol; business-system data passes through Anthropic only in response to a chat turn you initiate.
How we store and protect your data
Refresh tokens and other per-tenant secrets are encrypted with AES-GCM using a per-tenant Data Encryption Key. Each tenant DEK is wrapped by a master Key Encryption Key held in Cloudflare Workers secrets, so a compromise of the storage layer alone is not sufficient to recover plaintext. Every tool invocation is bound to a specific tenant and user and routed through a single execution path that re-validates capability and grant state on every call.
Data is stored in Cloudflare D1 (SQLite at the edge) and KV namespaces. Production data for IntellectSpace is pinned to Cloudflare's WNAM region. TLS 1.2+ is enforced for all traffic. Session cookies are set with the __Host- prefix and the Secure, HttpOnly, andSameSite attributes.
How long we keep your data
We retain:
- Session rows for up to thirty days after the session was last used.
- Provider grants for as long as your account is active. Revoking a grant marks it invalid at Matten immediately; the encrypted tokens are deleted during account cleanup.
- Audit events for as long as your account is active, for operational and security purposes. A deletion request will purge audit events tied to your user except those required to preserve the integrity of a tenant-level audit trail.
- Chat conversations up to the ten most recent per user; older conversations are pruned automatically.
- Public-site analytics according to the retention controls configured in Google Analytics and Vercel. You can change your analytics choice from “Analytics settings” in the marketing-site footer and can reset local identifiers by clearing site data in your browser.
When you delete your Matten account, we remove associated identity and grant records within thirty days, subject to legitimate operational, legal, or security-hold reasons to retain specific items longer.
Your rights
- Revoke a grant. Use the Revoke button on any grant row in the Matten portal. Subsequent tool calls against that grant fail closed.
- Delete your account. Email sandro@intellectspace.com from the email address associated with your Matten account and we will complete deletion within thirty days.
- Request a data export. Email the same address; we will return a machine-readable export of your identity, grant, and audit records within thirty days.
- Change analytics choice. Use “Analytics settings” in the public marketing-site footer to allow or deny public-site analytics for that browser.
- Regional rights. If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with comparable data-protection law, you have rights of access, rectification, erasure, restriction, portability, and objection. If you are a California resident, you have rights under the CCPA and CPRA including the right to know, delete, and opt out of sale or sharing (we do not sell or share personal information as those terms are defined). To exercise any regional right, email the same address with “privacy” in the subject line.
International data transfers
Matten is operated from the United States. If you access the service from outside the United States, your data may be transferred to, stored in, and processed in the United States and in Cloudflare's and Vercel's edge regions. Where a cross-border transfer falls under a data-protection regime that requires a lawful-transfer basis, Matten relies on the applicable mechanism (for example, Standard Contractual Clauses for EU-to-US transfers) as permitted by law.
Children
Matten is not directed to children. We do not knowingly collect data from anyone under the age of sixteen. If you believe we have collected data from a child under sixteen, please contact us and we will delete it.
Changes to this policy
We may update this policy as the service evolves or as required by law. When we make material changes, we will update the “Last updated” date at the top of this page and, where reasonably practicable, notify active users through the Matten portal or by email. Continued use of Matten after the change becomes effective constitutes acceptance of the updated policy.
Contact
Questions about this policy or our data practices: sandro@intellectspace.com. For data-protection-specific requests, please include “privacy” in the subject line.