From 6c632f627f17e6be1fe6a7e101aac77e2de9ac4d Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 15:25:38 -0700
Subject: [PATCH 01/58] Add App Store portal billing regression test
---
web/tests/billing-portal-route.test.ts | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/web/tests/billing-portal-route.test.ts b/web/tests/billing-portal-route.test.ts
index 6ffe94e4461c..39ca751954a4 100644
--- a/web/tests/billing-portal-route.test.ts
+++ b/web/tests/billing-portal-route.test.ts
@@ -127,6 +127,21 @@ describe("billing portal route", () => {
expect(getUser).toHaveBeenCalledWith({ or: "return-null" });
});
+ test("blocks direct portal requests from the iOS App Store distribution", async () => {
+ const response = await GET(
+ new NextRequest(
+ "https://cmux.test/api/billing/portal?cmux_distribution=appstore&cmux_scheme=cmux",
+ ),
+ );
+
+ expect(response.status).toBe(302);
+ expect(response.headers.get("location")).toBe(
+ "https://cmux.test/app-pricing?cmux_app=1&cmux_distribution=appstore&billing=unavailable&cmux_scheme=cmux",
+ );
+ expect(getUser).not.toHaveBeenCalled();
+ expect(createPortalSession).not.toHaveBeenCalled();
+ });
+
test("falls back to an existing anonymous purchaser and opens that portal", async () => {
returnNullUser = null;
anonymousIfExistsUser = anonymousUser;
From 0a8fa0f0947d06a697dbddd096ca9b3f5c22663b Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 15:25:45 -0700
Subject: [PATCH 02/58] Prepare iOS App Store review package
---
ios/AppStoreReview/README.md | 3 +
.../metadata-screenshots-checklist.md | 1 +
ios/AppStoreReview/review-notes.md | 8 +-
ios/AppStoreReview/reviewer-setup.md | 89 +++++++++++++++++++
.../[locale]/(legal)/privacy-policy/page.tsx | 62 +++++++++++--
web/app/api/billing/checkout/route.ts | 21 ++---
web/app/api/billing/portal/route.ts | 21 ++++-
web/app/lib/billing.ts | 14 +++
web/tests/billing-checkout-route.test.ts | 2 +-
web/tests/billing-portal-route.test.ts | 2 +-
10 files changed, 192 insertions(+), 31 deletions(-)
create mode 100644 ios/AppStoreReview/reviewer-setup.md
diff --git a/ios/AppStoreReview/README.md b/ios/AppStoreReview/README.md
index b4fad06ec77c..a5bca714a64c 100644
--- a/ios/AppStoreReview/README.md
+++ b/ios/AppStoreReview/README.md
@@ -5,6 +5,8 @@ readiness. Keep it separate from the TestFlight beta lane.
## Production Lane
+The official cmux iOS App Store Connect app is Apple ID `6783338052`.
+
Upload a production App Store Connect build:
```bash
@@ -82,6 +84,7 @@ ios/scripts/validate-app-store-release.sh \
## Files
- `review-notes.md` contains the notes to paste into App Store Connect Review Information.
+- `reviewer-setup.md` contains the prepared Mac and manual-pairing setup needed so App Review can test without owning a Mac.
- `metadata-screenshots-checklist.md` lists the metadata, screenshots, privacy, and payment gates that must be complete before submission.
Do not commit demo account passwords. Add them only in App Store Connect Review
diff --git a/ios/AppStoreReview/metadata-screenshots-checklist.md b/ios/AppStoreReview/metadata-screenshots-checklist.md
index bf06cc18b012..4b56c88e339b 100644
--- a/ios/AppStoreReview/metadata-screenshots-checklist.md
+++ b/ios/AppStoreReview/metadata-screenshots-checklist.md
@@ -43,6 +43,7 @@ complete in App Store Connect or in the submitted binary.
- [ ] The iOS App Store build exposes no Stripe, Stack checkout, external purchase, external upgrade, or billing-management link.
- [ ] `/app-pricing?cmux_app=1&cmux_distribution=appstore` renders without `/api/billing/checkout`, `/api/billing/portal`, or enterprise sales CTAs.
- [ ] `/api/billing/checkout?cmux_distribution=appstore` redirects before creating Stack or Stripe checkout state.
+- [ ] `/api/billing/portal?cmux_distribution=appstore` redirects before resolving Stack users or creating Stripe portal state.
- [ ] Existing paid entitlement state is read-only in iOS. If an iOS purchase flow is added later, it must use StoreKit and restore purchases.
## Permissions and Privacy
diff --git a/ios/AppStoreReview/review-notes.md b/ios/AppStoreReview/review-notes.md
index f33fb1eb26d4..cdbb9fe45ac5 100644
--- a/ios/AppStoreReview/review-notes.md
+++ b/ios/AppStoreReview/review-notes.md
@@ -4,6 +4,8 @@ cmux for iOS is a companion app for the cmux macOS terminal. It lets a signed-in
user pair with their Mac, view workspaces, receive terminal notifications, and
send input to an active terminal session from iPhone or iPad.
+Official App Store Connect app: Apple ID `6783338052`.
+
Reviewer access:
- Use the demo account entered in App Store Connect Review Information. Do not
@@ -11,6 +13,8 @@ Reviewer access:
- After sign-in, use the pairing flow shown in the app. Pairing can be tested
with a prepared review Mac, or with a manual pairing code supplied in the
Review Information notes for the submitted build.
+- Follow `reviewer-setup.md` before submission so the reviewer can test without
+ owning a Mac.
- The app may request Local Network permission during pairing so it can discover
and connect to the user's Mac.
- Camera permission is used only to scan cmux pairing QR codes.
@@ -26,12 +30,14 @@ Payments:
- The web billing surface is gated for App Store mode with
`cmux_distribution=appstore`; direct checkout requests with that distribution
are redirected before Stack or Stripe checkout creation.
+- Direct billing portal requests with `cmux_distribution=appstore` are also
+ redirected before Stack or Stripe portal session creation.
- Existing paid access from web or desktop accounts is read-only entitlement
state in the iOS app. There is no in-app upsell or purchase call to action.
Privacy and account handling:
-- Sign in supports Apple, Google, and email code through Stack Auth.
+- Sign in supports Apple, Google, GitHub, and email code through Stack Auth.
- Push notifications are opt-in. The device token is uploaded only after the user
enables phone notifications.
- `ITSAppUsesNonExemptEncryption` is `false`; the app uses standard platform
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
new file mode 100644
index 000000000000..5bb50e0cccf0
--- /dev/null
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -0,0 +1,89 @@
+# cmux iOS App Review Access Setup
+
+Use this source to prepare the App Store Connect Review Information for the
+official cmux iOS app, Apple ID `6783338052`. Do not commit passwords, one-time
+codes, or live pairing secrets.
+
+## Required Review Environment
+
+The reviewer must be able to test cmux for iOS without owning a Mac. Before
+submission, keep a prepared review Mac online and signed in to the same demo
+account entered in App Store Connect.
+
+The prepared Mac must:
+
+- Run the production cmux macOS app that matches the submitted iOS backend.
+- Stay awake, unlocked after reboot, and reachable from Apple review networks.
+- Use fictional account, workspace, terminal, file, and device names.
+- Expose a safe workspace named `App Review`.
+- Keep a terminal ready for harmless commands such as `echo app-review-ok`,
+ `pwd`, and `date`.
+- Have any required pairing route, relay, or tunnel live before submission.
+
+Do not rely on LAN-only discovery for review. If the pairing code resolves only
+to a private local-network address, the reviewer will not be able to verify the
+app from Apple.
+
+## App Store Connect Review Information
+
+Fill the App Store Connect fields for Apple ID `6783338052`:
+
+- Demo account email: enter only in App Store Connect.
+- Demo account password or stable access instructions: enter only in App Store
+ Connect.
+- Contact name, email, and phone: use a monitored owner.
+- Notes: paste `review-notes.md`, then replace the placeholders below with live
+ submission-specific details.
+
+Pasteable notes block:
+
+```text
+cmux for iOS is a companion app for the cmux macOS terminal. The reviewer does
+not need to own or install cmux on a Mac. We have prepared a review Mac that is
+already online and signed in to this demo account.
+
+Demo account:
+- Use the credentials in the App Review demo account fields.
+
+Pairing:
+1. Launch cmux.
+2. Sign in with the demo account.
+3. Tap Add Computer.
+4. Choose manual pairing.
+5. Enter this pairing code:
+
+Expected result:
+- A computer named "App Review Mac" appears.
+- Open the "App Review" workspace.
+- The terminal is ready for harmless commands.
+- Type: echo app-review-ok
+- The terminal should print: app-review-ok
+
+Optional permissions:
+- Local Network is used for Mac pairing and terminal sync.
+- Camera is used only to scan pairing QR codes.
+- Microphone and Speech Recognition are used only for voice transcription.
+- Photos are used only when attaching selected photos to a terminal-agent message.
+- Notifications are optional and can be enabled or disabled from the app.
+
+Payments:
+- This App Store build has no purchase, upgrade, checkout, or billing-management
+ links. Existing paid access from web or desktop accounts is read-only.
+
+Support during review:
+- Contact or if the prepared Mac
+ or pairing code is unreachable.
+```
+
+## Pre-Submission Check
+
+Before submitting:
+
+1. Sign in to the iOS App Store build with the review account.
+2. Pair using the exact code that will be pasted into App Store Connect.
+3. Open the `App Review` workspace.
+4. Send `echo app-review-ok`.
+5. Confirm the prepared Mac remains reachable from a network outside the office
+ LAN.
+6. Confirm the Privacy Policy URL in App Store Connect is
+ `https://cmux.com/privacy-policy`.
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 4e3f51d2a342..46c77f95a33c 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -11,7 +11,7 @@ export default function PrivacyPolicyPage() {
return (
<>
Privacy Policy
-
Last updated: June 23, 2026
+
Last updated: July 10, 2026
Manaflow (the “Company”) is committed to maintaining robust
@@ -21,13 +21,13 @@ export default function PrivacyPolicyPage() {
For purposes of this policy, “Site” refers to the
- Company’s website at{" "}
- cmux.com.
+ Company’s website at cmux.com.
“Application” refers to the cmux desktop application for
- macOS. “Service” refers to the Site and Application
- collectively. The terms “we,” “us,” and
- “our” refer to the Company. “You” refers to
- you, as a user of our Service.
+ macOS and the cmux mobile application for iPhone and iPad.
+ “Service” refers to the Site and Application collectively.
+ The terms “we,” “us,” and “our”
+ refer to the Company. “You” refers to you, as a user of our
+ Service.
By using our Service, you accept this Privacy Policy and our{" "}
@@ -42,7 +42,9 @@ export default function PrivacyPolicyPage() {
Information.” Non-Personal Information includes information that
cannot be used to personally identify you, such as anonymous usage data,
platform types, and crash diagnostics. Personal Information includes
- your email address if you choose to contact us.
+ your email address, account identifiers, and other information you
+ choose to provide when you sign in, contact us, pair a device, or use
+ the Application.
1. Information collected via Technology
@@ -53,6 +55,14 @@ export default function PrivacyPolicyPage() {
Crash reports and error diagnostics (via Sentry)
Operating system version and application version
Anonymous usage patterns
+
+ Device, account, and pairing metadata needed to connect your signed-in
+ devices
+
+
+ Apple Push Notification service device tokens, only after you enable
+ phone notifications
+
The Application checks for updates via Sparkle, which may transmit your
@@ -81,6 +91,23 @@ export default function PrivacyPolicyPage() {
notification of the signup (including that email address) to our internal
Slack workspace.
+
+ When you sign in to the Application, we receive the account information
+ required to authenticate you, such as your email address and provider
+ identifier from Apple, Google, GitHub, or email-code sign-in. When you
+ pair the mobile app with a Mac, we process the pairing information
+ required to connect those devices. When you use the mobile app to view a
+ workspace, send terminal input, attach selected photos, use speech
+ transcription, or receive terminal notifications, the related content or
+ transcript may be transmitted between your devices and our service as
+ needed to provide that feature.
+
+
+ Camera access is used only to scan cmux pairing QR codes. Microphone and
+ speech recognition access are used only when you choose voice
+ transcription in the message box. Photo library access is used only when
+ you choose photos to attach.
+
3. Children’s Privacy
@@ -95,6 +122,23 @@ export default function PrivacyPolicyPage() {
The Application integrates with the following third-party services:
+
+ Stack Auth — authentication and account
+ management for sign-in, session management, and account deletion.
+
+
+ Apple, Google, and GitHub — optional sign-in
+ providers. These providers send us the account information required to
+ authenticate you.
+
+
+ Apple Push Notification service — delivers
+ notifications to iPhone and iPad after you opt in.
+
+
+ Apple Speech Recognition — used when you choose
+ voice transcription in the mobile app.
+
Sentry — error tracking and crash reporting.
May collect error logs, stack traces, device information, and OS
@@ -190,7 +234,7 @@ export default function PrivacyPolicyPage() {
Crash reports and diagnostics are retained only as long as needed to
diagnose and fix issues. You may request deletion of any data associated
- with you by contacting us at{" "}
+ with you from the mobile app account settings or by contacting us at{" "}
founders@manaflow.com.
>
diff --git a/web/app/api/billing/checkout/route.ts b/web/app/api/billing/checkout/route.ts
index 908b662d7635..63e01ab7e6ab 100644
--- a/web/app/api/billing/checkout/route.ts
+++ b/web/app/api/billing/checkout/route.ts
@@ -3,7 +3,10 @@ import { NextRequest, NextResponse } from "next/server";
import { eq } from "drizzle-orm";
import { validatedNativeCallbackScheme } from "../../../lib/native-callback";
-import { isAppStoreDistributionMode } from "../../../lib/billing";
+import {
+ appStorePricingUnavailableURL,
+ isAppStoreDistributionMode,
+} from "../../../lib/billing";
import { cloudDb } from "../../../../db/client";
import { stripeCustomers } from "../../../../db/schema";
import {
@@ -48,7 +51,7 @@ async function resolveCheckout(request: NextRequest): Promise {
cmux_ios_app_store: request.nextUrl.searchParams.get("cmux_ios_app_store"),
})
) {
- return NextResponse.redirect(appStorePricingRedirect(request));
+ return NextResponse.redirect(appStorePricingUnavailableURL(request.nextUrl));
}
const stackServerApp = await checkoutStackServerApp();
@@ -310,20 +313,6 @@ async function checkoutStackServerApp(): Promise
return getStackServerApp();
}
-function appStorePricingRedirect(request: NextRequest): URL {
- const redirectURL = new URL("/app-pricing", request.url);
- redirectURL.searchParams.set("cmux_app", "1");
- redirectURL.searchParams.set("cmux_distribution", "appstore");
- redirectURL.searchParams.set("billing", "unavailable");
-
- for (const key of ["cmux_scheme", "appearance", "background"]) {
- const value = request.nextUrl.searchParams.get(key);
- if (value) redirectURL.searchParams.set(key, value);
- }
-
- return redirectURL;
-}
-
function isStackTeamUniqueConflict(error: unknown): boolean {
const cause = (error as { cause?: unknown } | null)?.cause;
const candidate = (cause ?? error) as { code?: string; constraint?: string } | null;
diff --git a/web/app/api/billing/portal/route.ts b/web/app/api/billing/portal/route.ts
index 1506aa8e76a3..b26d19b5fc81 100644
--- a/web/app/api/billing/portal/route.ts
+++ b/web/app/api/billing/portal/route.ts
@@ -1,9 +1,13 @@
import { eq } from "drizzle-orm";
import { NextRequest, NextResponse } from "next/server";
+import type * as StackLib from "../../../lib/stack";
import { cloudDb } from "../../../../db/client";
import { stripeCustomers } from "../../../../db/schema";
-import { getStackServerApp, isStackConfigured } from "../../../lib/stack";
+import {
+ appStorePricingUnavailableURL,
+ isAppStoreDistributionMode,
+} from "../../../lib/billing";
import { captureBillingError } from "../../../../services/errors";
import { resolveProPlanStatus } from "../../../../services/billing/pro";
import {
@@ -16,15 +20,26 @@ export const runtime = "nodejs";
export const dynamic = "force-dynamic";
const ANONYMOUS_IF_EXISTS = "anonymous-if-exists[deprecated]" as const;
+type GetStackServerApp = typeof StackLib.getStackServerApp;
export async function GET(request: NextRequest) {
+ if (
+ isAppStoreDistributionMode({
+ cmux_distribution: request.nextUrl.searchParams.get("cmux_distribution"),
+ cmux_ios_app_store: request.nextUrl.searchParams.get("cmux_ios_app_store"),
+ })
+ ) {
+ return NextResponse.redirect(appStorePricingUnavailableURL(request.nextUrl), 302);
+ }
+
+ const { getStackServerApp, isStackConfigured } = await import("../../../lib/stack");
if (!isStackConfigured() || !isStripeBillingConfigured()) {
return pricingRedirect(request, "unavailable");
}
let stackUserId: string | undefined;
try {
- const user = await currentStackUser();
+ const user = await currentStackUser(getStackServerApp);
if (!user) {
return NextResponse.redirect(new URL("/pricing", request.url), 302);
}
@@ -71,7 +86,7 @@ export async function GET(request: NextRequest) {
}
}
-async function currentStackUser() {
+async function currentStackUser(getStackServerApp: GetStackServerApp) {
const stackServerApp = getStackServerApp();
return (
(await stackServerApp.getUser({ or: "return-null" })) ??
diff --git a/web/app/lib/billing.ts b/web/app/lib/billing.ts
index 3c600b06c4e6..89f270a4dcfb 100644
--- a/web/app/lib/billing.ts
+++ b/web/app/lib/billing.ts
@@ -41,6 +41,20 @@ export function isAppStoreDistributionMode(params: {
return firstSearchParam(params.cmux_ios_app_store) === "1";
}
+export function appStorePricingUnavailableURL(requestUrl: URL): URL {
+ const redirectURL = new URL("/app-pricing", requestUrl);
+ redirectURL.searchParams.set("cmux_app", "1");
+ redirectURL.searchParams.set("cmux_distribution", "appstore");
+ redirectURL.searchParams.set("billing", "unavailable");
+
+ for (const key of ["appearance", "background"]) {
+ const value = requestUrl.searchParams.get(key);
+ if (value) redirectURL.searchParams.set(key, value);
+ }
+
+ return redirectURL;
+}
+
function withSearchParam(href: string, name: string, value: string): string {
const [withoutHash, hash] = href.split("#", 2);
const separator = withoutHash.includes("?") ? "&" : "?";
diff --git a/web/tests/billing-checkout-route.test.ts b/web/tests/billing-checkout-route.test.ts
index 540f38a73a96..b079116dfc38 100644
--- a/web/tests/billing-checkout-route.test.ts
+++ b/web/tests/billing-checkout-route.test.ts
@@ -179,7 +179,7 @@ describe("billing checkout route", () => {
expect(response.status).toBe(307);
expect(response.headers.get("location")).toBe(
- "https://cmux.test/app-pricing?cmux_app=1&cmux_distribution=appstore&billing=unavailable&cmux_scheme=cmux",
+ "https://cmux.test/app-pricing?cmux_app=1&cmux_distribution=appstore&billing=unavailable",
);
expect(getUser).not.toHaveBeenCalled();
expect(createStripeSession).not.toHaveBeenCalled();
diff --git a/web/tests/billing-portal-route.test.ts b/web/tests/billing-portal-route.test.ts
index 39ca751954a4..2d0794761625 100644
--- a/web/tests/billing-portal-route.test.ts
+++ b/web/tests/billing-portal-route.test.ts
@@ -136,7 +136,7 @@ describe("billing portal route", () => {
expect(response.status).toBe(302);
expect(response.headers.get("location")).toBe(
- "https://cmux.test/app-pricing?cmux_app=1&cmux_distribution=appstore&billing=unavailable&cmux_scheme=cmux",
+ "https://cmux.test/app-pricing?cmux_app=1&cmux_distribution=appstore&billing=unavailable",
);
expect(getUser).not.toHaveBeenCalled();
expect(createPortalSession).not.toHaveBeenCalled();
From 115e634e58e05a870de74b6ef7374d596521d61f Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 15:49:36 -0700
Subject: [PATCH 03/58] Address App Store review findings
---
ios/AppStoreReview/review-notes.md | 7 +--
ios/AppStoreReview/reviewer-setup.md | 39 ++++++++++++---
.../[locale]/(legal)/privacy-policy/page.tsx | 50 +++++++++++++------
web/app/api/billing/portal/route.ts | 3 ++
4 files changed, 74 insertions(+), 25 deletions(-)
diff --git a/ios/AppStoreReview/review-notes.md b/ios/AppStoreReview/review-notes.md
index cdbb9fe45ac5..2d343c063129 100644
--- a/ios/AppStoreReview/review-notes.md
+++ b/ios/AppStoreReview/review-notes.md
@@ -10,9 +10,10 @@ Reviewer access:
- Use the demo account entered in App Store Connect Review Information. Do not
put demo credentials in this repository.
-- After sign-in, use the pairing flow shown in the app. Pairing can be tested
- with a prepared review Mac, or with a manual pairing code supplied in the
- Review Information notes for the submitted build.
+- After sign-in, use the Add Computer flow shown in the app. Pairing can be
+ tested with a prepared review Mac by entering the exact Name, Host, and Port
+ values supplied in the Review Information notes, or by scanning a QR code whose
+ route is reachable from Apple review networks.
- Follow `reviewer-setup.md` before submission so the reviewer can test without
owning a Mac.
- The app may request Local Network permission during pairing so it can discover
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
index 5bb50e0cccf0..5acdcd333fee 100644
--- a/ios/AppStoreReview/reviewer-setup.md
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -18,11 +18,22 @@ The prepared Mac must:
- Expose a safe workspace named `App Review`.
- Keep a terminal ready for harmless commands such as `echo app-review-ok`,
`pwd`, and `date`.
-- Have any required pairing route, relay, or tunnel live before submission.
+- Have a reachable pairing route live before submission. Use either a tested
+ external host/port route, or provide Tailscale install/sign-in instructions
+ and credentials in App Store Connect so the reviewer can join the same
+ tailnet as the prepared Mac.
-Do not rely on LAN-only discovery for review. If the pairing code resolves only
-to a private local-network address, the reviewer will not be able to verify the
-app from Apple.
+Do not rely on LAN-only discovery or a generated route that resolves only to a
+private local-network address. The reviewer must receive exact field values for
+the iOS Add Computer form:
+
+- Name: `App Review Mac`
+- Host: an externally reachable hostname, or a Tailscale MagicDNS/100.x address
+ after the reviewer signs in to the supplied tailnet
+- Port: the prepared Mac's cmux mobile host port
+
+Before submission, verify those exact values from a clean network outside
+Manaflow's office and outside the prepared Mac's LAN.
## App Store Connect Review Information
@@ -49,8 +60,19 @@ Pairing:
1. Launch cmux.
2. Sign in with the demo account.
3. Tap Add Computer.
-4. Choose manual pairing.
-5. Enter this pairing code:
+4. If Tailscale is required, install Tailscale from the App Store and sign in
+ with the Tailscale credentials supplied here: .
+5. In the Add Computer form, enter:
+ - Name: App Review Mac
+ - Host:
+ - Port:
+6. Tap Pair.
+
+QR alternative:
+- If the prepared Mac shows a QR code whose route is reachable from Apple review
+ networks, tap Scan QR Code instead of typing Host and Port. Do not use a QR
+ route that only resolves on a private LAN unless Tailscale access above is
+ supplied and verified.
Expected result:
- A computer named "App Review Mac" appears.
@@ -80,10 +102,11 @@ Support during review:
Before submitting:
1. Sign in to the iOS App Store build with the review account.
-2. Pair using the exact code that will be pasted into App Store Connect.
+2. Pair using the exact host, port, and Tailscale instructions that will be
+ pasted into App Store Connect.
3. Open the `App Review` workspace.
4. Send `echo app-review-ok`.
5. Confirm the prepared Mac remains reachable from a network outside the office
- LAN.
+ LAN, and outside the Mac's tailnet unless Tailscale access is supplied.
6. Confirm the Privacy Policy URL in App Store Connect is
`https://cmux.com/privacy-policy`.
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 46c77f95a33c..c7edcdb6ad7d 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -54,7 +54,10 @@ export default function PrivacyPolicyPage() {
Crash reports and error diagnostics (via Sentry)
Operating system version and application version
-
Anonymous usage patterns
+
+ Product analytics and feature usage events for the Site and
+ Application
+
Device, account, and pairing metadata needed to connect your signed-in
devices
@@ -70,15 +73,33 @@ export default function PrivacyPolicyPage() {
The Site uses PostHog for analytics, including page views and navigation
- patterns. PostHog stores a cookie to distinguish unique visitors. This
- analytics is anonymous and collects no personally identifiable
- information, with one exception: if you join a platform waitlist, the
- email address you submit is recorded in PostHog so we can notify you when
- that platform is available. If you submit the Enterprise contact form,
- we record the company and contact details you provide in PostHog and
- send them to our internal Slack workspace and founders email inbox so we
- can respond. You can opt out of analytics by using a browser extension
- that blocks tracking scripts.
+ patterns. PostHog stores a cookie to distinguish unique visitors. If you
+ join a platform waitlist, the email address you submit is recorded in
+ PostHog so we can notify you when that platform is available. If you
+ submit the Enterprise contact form, we record the company and contact
+ details you provide in PostHog and send them to our internal Slack
+ workspace and founders email inbox so we can respond. You can opt out of
+ website analytics by using a browser extension that blocks tracking
+ scripts.
+
+
+ The iPhone and iPad Application sends product analytics events to our
+ server-side PostHog proxy. These events help us diagnose reliability,
+ understand feature usage, and improve the Application. They include app
+ launch and session events, sign-in status, pairing attempts and results,
+ connection recovery, workspace opens, terminal input byte and line
+ counts, and notification opt-in or notification-deep-link results. The
+ mobile analytics pipeline does not send terminal command text, terminal
+ output, selected photos, or speech transcripts to PostHog. Before sign
+ in, events use a random per-install client identifier. After sign in,
+ our server attaches your Stack Auth account identifier to events before
+ forwarding them to PostHog. We retain mobile analytics only as long as
+ needed for product analytics and debugging. Where the Application exposes
+ a Send anonymous telemetry preference, turning it off stops analytics
+ events from being buffered or sent. You may also contact us at{" "}
+ founders@manaflow.com to
+ request deletion of analytics associated with your account or to disable
+ account-linked analytics for your account.
2. Information you provide directly
@@ -153,10 +174,11 @@ export default function PrivacyPolicyPage() {
engine. Runs entirely locally on your device.
- PostHog — website analytics. Collects anonymous
- page view data, navigation patterns, and browser metadata via a
- first-party proxy. If you join a platform waitlist, the email address
- you submit is also recorded in PostHog so we can notify you.
+ PostHog — website and mobile product analytics.
+ Collects page view data, navigation patterns, browser metadata, mobile
+ app feature events, and account-linked mobile analytics after sign-in
+ via a first-party proxy. If you join a platform waitlist, the email
+ address you submit is also recorded in PostHog so we can notify you.
Resend — transactional email delivery. Used to
diff --git a/web/app/api/billing/portal/route.ts b/web/app/api/billing/portal/route.ts
index b26d19b5fc81..fe6d73501fc2 100644
--- a/web/app/api/billing/portal/route.ts
+++ b/web/app/api/billing/portal/route.ts
@@ -32,6 +32,9 @@ export async function GET(request: NextRequest) {
return NextResponse.redirect(appStorePricingUnavailableURL(request.nextUrl), 302);
}
+ // Keep Stack deferred until after the App Store distribution gate. lib/stack
+ // eagerly initializes stackServerApp, and this route must not do auth work for
+ // App Store billing-management requests.
const { getStackServerApp, isStackConfigured } = await import("../../../lib/stack");
if (!isStackConfigured() || !isStripeBillingConfigured()) {
return pricingRedirect(request, "unavailable");
From 1700d36c8ae6cbc468d5d9a1fd4b80bc80aa04e6 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 15:58:08 -0700
Subject: [PATCH 04/58] Harden App Review instructions and retention policy
---
ios/AppStoreReview/review-notes.md | 26 ++++++++++++++-----
ios/AppStoreReview/reviewer-setup.md | 12 ++++++++-
.../[locale]/(legal)/privacy-policy/page.tsx | 26 ++++++++++++++-----
3 files changed, 51 insertions(+), 13 deletions(-)
diff --git a/ios/AppStoreReview/review-notes.md b/ios/AppStoreReview/review-notes.md
index 2d343c063129..ce81d67fa5fe 100644
--- a/ios/AppStoreReview/review-notes.md
+++ b/ios/AppStoreReview/review-notes.md
@@ -14,8 +14,17 @@ Reviewer access:
tested with a prepared review Mac by entering the exact Name, Host, and Port
values supplied in the Review Information notes, or by scanning a QR code whose
route is reachable from Apple review networks.
-- Follow `reviewer-setup.md` before submission so the reviewer can test without
- owning a Mac.
+- The reviewer does not need to own or install cmux on a Mac. Before submission,
+ append the prepared review Mac details below directly into App Store Connect:
+ - Name: `App Review Mac`
+ - Host: ``
+ - Port: ``
+ - Tailscale access, only if required: ``
+ - Review contact: `` / ``
+- The prepared Mac must use a dedicated review-only macOS user, no personal or
+ developer credentials, a safe `App Review` workspace, and a network route
+ restricted to the cmux mobile host port. Revoke the credentials and reset the
+ review user after App Review finishes.
- The app may request Local Network permission during pairing so it can discover
and connect to the user's Mac.
- Camera permission is used only to scan cmux pairing QR codes.
@@ -47,8 +56,13 @@ Privacy and account handling:
Primary review path:
1. Sign in with the demo account supplied in App Store Connect.
-2. Pair with the prepared Mac or enter the supplied manual pairing code.
-3. Open the workspace list, then open a workspace detail.
-4. Send a short terminal input from the message box.
-5. Enable phone notifications and verify the opt-in prompt, then disable them
+2. Tap Add Computer.
+3. If Tailscale access is required, install Tailscale from the App Store and
+ sign in with the supplied review access first.
+4. Enter the supplied Name, Host, and Port values, then tap Pair. If the
+ supplied QR route is reachable from Apple review networks, Scan QR Code can
+ be used instead.
+5. Open the workspace list, then open the `App Review` workspace detail.
+6. Send `echo app-review-ok` from the message box.
+7. Enable phone notifications and verify the opt-in prompt, then disable them
again from the same surface.
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
index 5acdcd333fee..1f78146fa78e 100644
--- a/ios/AppStoreReview/reviewer-setup.md
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -15,6 +15,10 @@ The prepared Mac must:
- Run the production cmux macOS app that matches the submitted iOS backend.
- Stay awake, unlocked after reboot, and reachable from Apple review networks.
- Use fictional account, workspace, terminal, file, and device names.
+- Use a dedicated review-only macOS user account on a dedicated review Mac or
+ VM. Do not sign in with personal Apple IDs, GitHub accounts, production
+ developer credentials, password managers, SSH keys, cloud drives, Messages, or
+ other private services.
- Expose a safe workspace named `App Review`.
- Keep a terminal ready for harmless commands such as `echo app-review-ok`,
`pwd`, and `date`.
@@ -22,6 +26,9 @@ The prepared Mac must:
external host/port route, or provide Tailscale install/sign-in instructions
and credentials in App Store Connect so the reviewer can join the same
tailnet as the prepared Mac.
+- Restrict the network path to the prepared Mac only. Use a dedicated Tailscale
+ tailnet, ACL, firewall rule, or tunnel that exposes only the cmux mobile host
+ port needed for review, not the rest of Manaflow's network.
Do not rely on LAN-only discovery or a generated route that resolves only to a
private local-network address. The reviewer must receive exact field values for
@@ -35,6 +42,9 @@ the iOS Add Computer form:
Before submission, verify those exact values from a clean network outside
Manaflow's office and outside the prepared Mac's LAN.
+After review, revoke the review credentials, remove the Tailscale invite or
+tunnel, reset the review macOS user, and delete any files created during review.
+
## App Store Connect Review Information
Fill the App Store Connect fields for Apple ID `6783338052`:
@@ -94,7 +104,7 @@ Payments:
Support during review:
- Contact or if the prepared Mac
- or pairing code is unreachable.
+ or pairing route is unreachable.
```
## Pre-Submission Check
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index c7edcdb6ad7d..3f946237b800 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -68,8 +68,10 @@ export default function PrivacyPolicyPage() {
- The Application checks for updates via Sparkle, which may transmit your
- operating system version and application version to our update server.
+ The macOS Application checks for updates via Sparkle, which may transmit
+ your operating system version and application version to our update
+ server. The iPhone and iPad Application is updated through the App Store,
+ not Sparkle.
The Site uses PostHog for analytics, including page views and navigation
@@ -166,8 +168,8 @@ export default function PrivacyPolicyPage() {
version.
- Sparkle — auto-update framework. Transmits
- application and OS version to check for updates.
+ Sparkle — macOS auto-update framework.
+ Transmits application and OS version to check for macOS updates.
Crash reports and diagnostics are retained only as long as needed to
- diagnose and fix issues. You may request deletion of any data associated
- with you from the mobile app account settings or by contacting us at{" "}
+ diagnose and fix issues. Mobile account identifiers and authentication
+ records are retained while your account is active and are deleted or
+ anonymized when account deletion completes, except where retention is
+ required for security, legal, billing, or fraud-prevention reasons.
+ Device and pairing metadata is retained until you unpair the device,
+ sign out and delete local data, delete your account, or the pairing data
+ is pruned as stale. Apple Push Notification service tokens are retained
+ only while notifications are enabled for that device, and are removed
+ when you disable notifications, sign out, delete your account, or Apple
+ reports the token invalid. Mobile product analytics in PostHog is
+ retained for product analytics and debugging for up to 24 months unless
+ you request earlier deletion. You may request deletion of any data
+ associated with you from the mobile app account settings or by contacting
+ us at{" "}
founders@manaflow.com.
>
From 4a90b8d94ed57bfa4b753e446d2f9c793f107a92 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:09:22 -0700
Subject: [PATCH 05/58] Document App Store privacy blockers
---
.../metadata-screenshots-checklist.md | 2 ++
.../[locale]/(legal)/privacy-policy/page.tsx | 23 +++++++++++++++----
2 files changed, 20 insertions(+), 5 deletions(-)
diff --git a/ios/AppStoreReview/metadata-screenshots-checklist.md b/ios/AppStoreReview/metadata-screenshots-checklist.md
index 4b56c88e339b..c6bd2f3f994d 100644
--- a/ios/AppStoreReview/metadata-screenshots-checklist.md
+++ b/ios/AppStoreReview/metadata-screenshots-checklist.md
@@ -54,6 +54,8 @@ complete in App Store Connect or in the submitted binary.
- [ ] Photo library purpose string says attaching photos to terminal-agent messages.
- [ ] Permissions are requested only when the user starts the relevant feature.
- [ ] Push notifications are opt-in and can be disabled after enabling.
+- [ ] iPhone and iPad analytics collection is disabled until the user consents, and Settings exposes a control that withdraws consent for the same telemetry gate used by analytics and crash reporting. Do not submit while the absent `sendAnonymousTelemetry` default remains enabled without an iOS control.
+- [ ] In-app Delete Account deletes or anonymizes account-linked PostHog analytics, or the deletion flow gives the user a bounded follow-up process for that processor data. Do not submit while PostHog deletion is only a support-request path.
## ASC Validation Commands
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 3f946237b800..edb8cdd59297 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -96,9 +96,12 @@ export default function PrivacyPolicyPage() {
in, events use a random per-install client identifier. After sign in,
our server attaches your Stack Auth account identifier to events before
forwarding them to PostHog. We retain mobile analytics only as long as
- needed for product analytics and debugging. Where the Application exposes
- a Send anonymous telemetry preference, turning it off stops analytics
- events from being buffered or sent. You may also contact us at{" "}
+ needed for product analytics and debugging. The current iPhone and iPad
+ Application sends these analytics unless telemetry is disabled through an
+ app-provided preference or support disables account-linked analytics for
+ your account. Where the Application exposes a Send anonymous telemetry
+ preference, turning it off stops analytics events from being buffered or
+ sent. You may also contact us at{" "}
founders@manaflow.com to
request deletion of analytics associated with your account or to disable
account-linked analytics for your account.
@@ -196,7 +199,10 @@ export default function PrivacyPolicyPage() {
Each of these services has its own privacy policy governing the
- collection and use of your data.
+ collection and use of your data. When we use a third-party service to
+ process Personal Information on our behalf, we require that service to
+ protect the information with safeguards at least as protective as this
+ Privacy Policy and to use it only to provide services to cmux.
III. How We Use and Share Information
@@ -268,7 +274,14 @@ export default function PrivacyPolicyPage() {
when you disable notifications, sign out, delete your account, or Apple
reports the token invalid. Mobile product analytics in PostHog is
retained for product analytics and debugging for up to 24 months unless
- you request earlier deletion. You may request deletion of any data
+ you request earlier deletion. The mobile app account settings delete or
+ anonymize cmux-owned account, device, pairing, notification, billing, and
+ cloud data as part of account deletion. Account-linked PostHog analytics
+ deletion is not currently triggered by that in-app account deletion flow;
+ contact us to request deletion or anonymization of account-linked
+ PostHog analytics, and we will complete that request within 30 days
+ unless retention is required for security, legal, billing, or
+ fraud-prevention reasons. You may request deletion of cmux-owned data
associated with you from the mobile app account settings or by contacting
us at{" "}
founders@manaflow.com.
From eef235c156b947720d52bd0ef8b5989337ec7be9 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:18:47 -0700
Subject: [PATCH 06/58] Align review docs with trusted pairing
---
ios/AppStoreReview/review-notes.md | 21 +++++-----
ios/AppStoreReview/reviewer-setup.md | 40 ++++++++++---------
.../[locale]/(legal)/privacy-policy/page.tsx | 10 ++---
3 files changed, 37 insertions(+), 34 deletions(-)
diff --git a/ios/AppStoreReview/review-notes.md b/ios/AppStoreReview/review-notes.md
index ce81d67fa5fe..d89cb0b67446 100644
--- a/ios/AppStoreReview/review-notes.md
+++ b/ios/AppStoreReview/review-notes.md
@@ -11,15 +11,16 @@ Reviewer access:
- Use the demo account entered in App Store Connect Review Information. Do not
put demo credentials in this repository.
- After sign-in, use the Add Computer flow shown in the app. Pairing can be
- tested with a prepared review Mac by entering the exact Name, Host, and Port
- values supplied in the Review Information notes, or by scanning a QR code whose
- route is reachable from Apple review networks.
+ tested with a prepared review Mac after joining the supplied Tailscale network
+ and entering the exact Name, Tailscale Host, and Port values supplied in the
+ Review Information notes, or by scanning a generated QR/link whose ticketed
+ route is reachable from the same review network path.
- The reviewer does not need to own or install cmux on a Mac. Before submission,
append the prepared review Mac details below directly into App Store Connect:
- Name: `App Review Mac`
- - Host: ``
+ - Host: ``
- Port: ``
- - Tailscale access, only if required: ``
+ - Tailscale access: ``
- Review contact: `` / ``
- The prepared Mac must use a dedicated review-only macOS user, no personal or
developer credentials, a safe `App Review` workspace, and a network route
@@ -57,11 +58,11 @@ Primary review path:
1. Sign in with the demo account supplied in App Store Connect.
2. Tap Add Computer.
-3. If Tailscale access is required, install Tailscale from the App Store and
- sign in with the supplied review access first.
-4. Enter the supplied Name, Host, and Port values, then tap Pair. If the
- supplied QR route is reachable from Apple review networks, Scan QR Code can
- be used instead.
+3. Install Tailscale from the App Store and sign in with the supplied review
+ access first.
+4. Enter the supplied Name, Tailscale Host, and Port values, then tap Pair. If a
+ generated ticketed QR/link route is reachable after joining the supplied
+ Tailscale network, Scan QR Code can be used instead.
5. Open the workspace list, then open the `App Review` workspace detail.
6. Send `echo app-review-ok` from the message box.
7. Enable phone notifications and verify the opt-in prompt, then disable them
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
index 1f78146fa78e..5f76210b0c2e 100644
--- a/ios/AppStoreReview/reviewer-setup.md
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -22,25 +22,28 @@ The prepared Mac must:
- Expose a safe workspace named `App Review`.
- Keep a terminal ready for harmless commands such as `echo app-review-ok`,
`pwd`, and `date`.
-- Have a reachable pairing route live before submission. Use either a tested
- external host/port route, or provide Tailscale install/sign-in instructions
- and credentials in App Store Connect so the reviewer can join the same
- tailnet as the prepared Mac.
+ - Have a reachable pairing route live before submission. For the manual Add
+ Computer form, provide Tailscale install/sign-in instructions and
+ credentials in App Store Connect so the reviewer can join the same tailnet
+ as the prepared Mac.
- Restrict the network path to the prepared Mac only. Use a dedicated Tailscale
tailnet, ACL, firewall rule, or tunnel that exposes only the cmux mobile host
port needed for review, not the rest of Manaflow's network.
-Do not rely on LAN-only discovery or a generated route that resolves only to a
-private local-network address. The reviewer must receive exact field values for
-the iOS Add Computer form:
+Do not rely on LAN-only discovery, generic public hostnames, or a generated route
+that resolves only to a private local-network address. The reviewer must receive
+exact Tailscale field values for the iOS Add Computer form:
- Name: `App Review Mac`
-- Host: an externally reachable hostname, or a Tailscale MagicDNS/100.x address
+- Host: a Tailscale MagicDNS `*.ts.net` hostname or `100.64.0.0/10` address
after the reviewer signs in to the supplied tailnet
- Port: the prepared Mac's cmux mobile host port
Before submission, verify those exact values from a clean network outside
-Manaflow's office and outside the prepared Mac's LAN.
+Manaflow's office and outside the prepared Mac's LAN after signing in with the
+same Tailscale review access supplied to App Review. A QR/link alternative is
+acceptable only when it is generated by the prepared Mac, carries a valid attach
+ticket, and has been verified from the same clean review network path.
After review, revoke the review credentials, remove the Tailscale invite or
tunnel, reset the review macOS user, and delete any files created during review.
@@ -70,19 +73,19 @@ Pairing:
1. Launch cmux.
2. Sign in with the demo account.
3. Tap Add Computer.
-4. If Tailscale is required, install Tailscale from the App Store and sign in
- with the Tailscale credentials supplied here: .
+4. Install Tailscale from the App Store and sign in with the Tailscale
+ credentials supplied here: .
5. In the Add Computer form, enter:
- Name: App Review Mac
- - Host:
+ - Host:
- Port:
6. Tap Pair.
QR alternative:
-- If the prepared Mac shows a QR code whose route is reachable from Apple review
- networks, tap Scan QR Code instead of typing Host and Port. Do not use a QR
- route that only resolves on a private LAN unless Tailscale access above is
- supplied and verified.
+- If the prepared Mac shows a generated QR/link whose ticketed route is reachable
+ after the reviewer joins the supplied Tailscale network, tap Scan QR Code
+ instead of typing Host and Port. Do not use a generic public hostname or a QR
+ route that only resolves on a private LAN.
Expected result:
- A computer named "App Review Mac" appears.
@@ -112,11 +115,12 @@ Support during review:
Before submitting:
1. Sign in to the iOS App Store build with the review account.
-2. Pair using the exact host, port, and Tailscale instructions that will be
+2. Pair using the exact Tailscale host, port, and sign-in instructions that will be
pasted into App Store Connect.
3. Open the `App Review` workspace.
4. Send `echo app-review-ok`.
5. Confirm the prepared Mac remains reachable from a network outside the office
- LAN, and outside the Mac's tailnet unless Tailscale access is supplied.
+ LAN after signing in with the same Tailscale review access supplied to App
+ Review.
6. Confirm the Privacy Policy URL in App Store Connect is
`https://cmux.com/privacy-policy`.
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index edb8cdd59297..3e9c21e24290 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -98,13 +98,11 @@ export default function PrivacyPolicyPage() {
forwarding them to PostHog. We retain mobile analytics only as long as
needed for product analytics and debugging. The current iPhone and iPad
Application sends these analytics unless telemetry is disabled through an
- app-provided preference or support disables account-linked analytics for
- your account. Where the Application exposes a Send anonymous telemetry
- preference, turning it off stops analytics events from being buffered or
- sent. You may also contact us at{" "}
+ app-provided preference in the build you are using. Where the Application
+ exposes a Send anonymous telemetry preference, turning it off stops
+ analytics events from being buffered or sent. You may also contact us at{" "}
founders@manaflow.com to
- request deletion of analytics associated with your account or to disable
- account-linked analytics for your account.
+ request deletion of analytics associated with your account.
2. Information you provide directly
From 74e61c3225217a46e36e80207b882e2f67e756d1 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:21:45 -0700
Subject: [PATCH 07/58] Add iOS privacy manifest
---
ios/cmux-ios.xcodeproj/project.pbxproj | 4 ++++
ios/cmux/Resources/PrivacyInfo.xcprivacy | 29 ++++++++++++++++++++++++
2 files changed, 33 insertions(+)
create mode 100644 ios/cmux/Resources/PrivacyInfo.xcprivacy
diff --git a/ios/cmux-ios.xcodeproj/project.pbxproj b/ios/cmux-ios.xcodeproj/project.pbxproj
index 6124cc064f4c..4ec9b6b34d7a 100644
--- a/ios/cmux-ios.xcodeproj/project.pbxproj
+++ b/ios/cmux-ios.xcodeproj/project.pbxproj
@@ -13,6 +13,7 @@
8B8A10022DF5000000A66F90 /* Assets.xcassets in Resources */ = {isa = PBXBuildFile; fileRef = 8B8A10192DF5000000A66F90 /* Assets.xcassets */; };
8B8A10032DF5000000A66F90 /* InfoPlist.xcstrings in Resources */ = {isa = PBXBuildFile; fileRef = 8B8A101A2DF5000000A66F90 /* InfoPlist.xcstrings */; };
8B8A10042DF5000000A66F90 /* Localizable.xcstrings in Resources */ = {isa = PBXBuildFile; fileRef = 8B8A101B2DF5000000A66F90 /* Localizable.xcstrings */; };
+ 8B8A10062DF5000000A66F90 /* PrivacyInfo.xcprivacy in Resources */ = {isa = PBXBuildFile; fileRef = 8B8A101D2DF5000000A66F90 /* PrivacyInfo.xcprivacy */; };
8B8A10052DF5000000A66F90 /* cmuxUITests.swift in Sources */ = {isa = PBXBuildFile; fileRef = 8B8A101C2DF5000000A66F90 /* cmuxUITests.swift */; };
8B41F6832DEDD23B001A66F9 /* cmuxFeature in Frameworks */ = {isa = PBXBuildFile; productRef = 8B41F6822DEDD23B001A66F9 /* cmuxFeature */; };
8B41F6852DEDD25C001A66F9 /* cmuxFeature in Frameworks */ = {isa = PBXBuildFile; productRef = 8B41F6842DEDD25C001A66F9 /* cmuxFeature */; };
@@ -47,6 +48,7 @@
8B8A10192DF5000000A66F90 /* Assets.xcassets */ = {isa = PBXFileReference; lastKnownFileType = folder.assetcatalog; path = Assets.xcassets; sourceTree = ""; };
8B8A101A2DF5000000A66F90 /* InfoPlist.xcstrings */ = {isa = PBXFileReference; lastKnownFileType = text.json.xcstrings; path = InfoPlist.xcstrings; sourceTree = ""; };
8B8A101B2DF5000000A66F90 /* Localizable.xcstrings */ = {isa = PBXFileReference; lastKnownFileType = text.json.xcstrings; path = Localizable.xcstrings; sourceTree = ""; };
+ 8B8A101D2DF5000000A66F90 /* PrivacyInfo.xcprivacy */ = {isa = PBXFileReference; lastKnownFileType = text.plist.xml; path = PrivacyInfo.xcprivacy; sourceTree = ""; };
8B8A101C2DF5000000A66F90 /* cmuxUITests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = cmuxUITests.swift; sourceTree = ""; };
/* End PBXFileReference section */
@@ -126,6 +128,7 @@
children = (
8B8A101A2DF5000000A66F90 /* InfoPlist.xcstrings */,
8B8A101B2DF5000000A66F90 /* Localizable.xcstrings */,
+ 8B8A101D2DF5000000A66F90 /* PrivacyInfo.xcprivacy */,
);
path = Resources;
sourceTree = "";
@@ -237,6 +240,7 @@
8B8A10022DF5000000A66F90 /* Assets.xcassets in Resources */,
8B8A10032DF5000000A66F90 /* InfoPlist.xcstrings in Resources */,
8B8A10042DF5000000A66F90 /* Localizable.xcstrings in Resources */,
+ 8B8A10062DF5000000A66F90 /* PrivacyInfo.xcprivacy in Resources */,
);
runOnlyForDeploymentPostprocessing = 0;
};
diff --git a/ios/cmux/Resources/PrivacyInfo.xcprivacy b/ios/cmux/Resources/PrivacyInfo.xcprivacy
new file mode 100644
index 000000000000..085f7060281f
--- /dev/null
+++ b/ios/cmux/Resources/PrivacyInfo.xcprivacy
@@ -0,0 +1,29 @@
+
+
+
+
+ NSPrivacyAccessedAPITypes
+
+
+ NSPrivacyAccessedAPIType
+ NSPrivacyAccessedAPICategoryFileTimestamp
+ NSPrivacyAccessedAPITypeReasons
+
+ C617.1
+
+
+
+ NSPrivacyAccessedAPIType
+ NSPrivacyAccessedAPICategoryUserDefaults
+ NSPrivacyAccessedAPITypeReasons
+
+ CA92.1
+
+
+
+ NSPrivacyTracking
+
+ NSPrivacyTrackingDomains
+
+
+
From 8e60ebaacd1bfd5e5780eb1131ccffd3b283d16b Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:23:32 -0700
Subject: [PATCH 08/58] Tighten iOS reviewer setup checklist
---
ios/AppStoreReview/reviewer-setup.md | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
index 5f76210b0c2e..f680611d3d8b 100644
--- a/ios/AppStoreReview/reviewer-setup.md
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -22,10 +22,10 @@ The prepared Mac must:
- Expose a safe workspace named `App Review`.
- Keep a terminal ready for harmless commands such as `echo app-review-ok`,
`pwd`, and `date`.
- - Have a reachable pairing route live before submission. For the manual Add
- Computer form, provide Tailscale install/sign-in instructions and
- credentials in App Store Connect so the reviewer can join the same tailnet
- as the prepared Mac.
+- Have a reachable pairing route live before submission. For the manual Add
+ Computer form, provide Tailscale install/sign-in instructions and credentials
+ in App Store Connect so the reviewer can join the same tailnet as the
+ prepared Mac.
- Restrict the network path to the prepared Mac only. Use a dedicated Tailscale
tailnet, ACL, firewall rule, or tunnel that exposes only the cmux mobile host
port needed for review, not the rest of Manaflow's network.
From fdc9b58c7d4a993b057a453ba1d7fedfe30c353a Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:35:39 -0700
Subject: [PATCH 09/58] Harden iOS privacy review controls
---
.../AnalyticsConsentProviding.swift | 9 +-
.../AnalyticsEmitterTests.swift | 15 ++++
.../MobileSettingsView.swift | 24 +++++
.../metadata-screenshots-checklist.md | 5 +-
ios/cmux/Resources/Localizable.xcstrings | 51 +++++++++++
.../[locale]/(legal)/privacy-policy/page.tsx | 13 ++-
web/app/api/account/route.ts | 88 ++++++++++++++++++-
web/tests/account-route.test.ts | 82 +++++++++++++++++
8 files changed, 270 insertions(+), 17 deletions(-)
diff --git a/Packages/iOS/CmuxMobileAnalytics/Sources/CmuxMobileAnalytics/AnalyticsConsentProviding.swift b/Packages/iOS/CmuxMobileAnalytics/Sources/CmuxMobileAnalytics/AnalyticsConsentProviding.swift
index 7dfc54a10b45..d1fd1636568f 100644
--- a/Packages/iOS/CmuxMobileAnalytics/Sources/CmuxMobileAnalytics/AnalyticsConsentProviding.swift
+++ b/Packages/iOS/CmuxMobileAnalytics/Sources/CmuxMobileAnalytics/AnalyticsConsentProviding.swift
@@ -42,9 +42,9 @@ public struct AnalyticsConsentProvider: AnalyticsConsentProviding {
///
/// The iOS app cannot import the macOS-only `CmuxSettings` package, so this reads
/// the same backing key that `CmuxSettings.catalog.app.sendAnonymousTelemetry`
-/// writes (`"sendAnonymousTelemetry"`), with the same default of `true`. The
-/// value is read on every capture so toggling the Settings switch takes effect
-/// immediately without rewiring.
+/// writes (`"sendAnonymousTelemetry"`). iOS defaults to telemetry off until the
+/// user enables the Settings toggle. The value is read on every capture so
+/// toggling the switch takes effect immediately without rewiring.
public struct UserDefaultsAnalyticsConsentProvider: AnalyticsConsentProviding {
/// The `UserDefaults` key shared with the settings catalog's
/// `app.sendAnonymousTelemetry` entry.
@@ -61,7 +61,6 @@ public struct UserDefaultsAnalyticsConsentProvider: AnalyticsConsentProviding {
}
public var isTelemetryEnabled: Bool {
- // Absent key defaults to opted-in (true), matching the catalog default.
- defaults.object(forKey: Self.telemetryKey) as? Bool ?? true
+ defaults.object(forKey: Self.telemetryKey) as? Bool ?? false
}
}
diff --git a/Packages/iOS/CmuxMobileAnalytics/Tests/CmuxMobileAnalyticsTests/AnalyticsEmitterTests.swift b/Packages/iOS/CmuxMobileAnalytics/Tests/CmuxMobileAnalyticsTests/AnalyticsEmitterTests.swift
index 1ef424c4c16d..1a56a3b0d724 100644
--- a/Packages/iOS/CmuxMobileAnalytics/Tests/CmuxMobileAnalyticsTests/AnalyticsEmitterTests.swift
+++ b/Packages/iOS/CmuxMobileAnalytics/Tests/CmuxMobileAnalyticsTests/AnalyticsEmitterTests.swift
@@ -26,6 +26,21 @@ private final class MutableConsent: AnalyticsConsentProviding, @unchecked Sendab
}
@Suite struct AnalyticsEmitterTests {
+ @Test func userDefaultsConsentDefaultsOffUntilEnabled() {
+ let suiteName = "cmux.analytics-consent.\(UUID().uuidString)"
+ let defaults = UserDefaults(suiteName: suiteName)!
+ defer { defaults.removePersistentDomain(forName: suiteName) }
+
+ let consent = UserDefaultsAnalyticsConsentProvider(defaults: defaults)
+ #expect(!consent.isTelemetryEnabled)
+
+ defaults.set(true, forKey: UserDefaultsAnalyticsConsentProvider.telemetryKey)
+ #expect(consent.isTelemetryEnabled)
+
+ defaults.set(false, forKey: UserDefaultsAnalyticsConsentProvider.telemetryKey)
+ #expect(!consent.isTelemetryEnabled)
+ }
+
private func makeEmitter(
uploader: RecordingAnalyticsUploader,
consent: (any AnalyticsConsentProviding)? = nil,
diff --git a/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift b/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
index b52fcd30638c..e289e24e46e0 100644
--- a/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
+++ b/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
@@ -5,6 +5,12 @@ import CmuxMobileSupport
import CmuxMobileWorkspace
import SwiftUI
+private enum MobileTelemetryDefaults {
+ /// Shared with `UserDefaultsAnalyticsConsentProvider`; keep the string stable
+ /// so Settings controls the same gate used by analytics and crash reporting.
+ static let sendAnonymousTelemetryKey = "sendAnonymousTelemetry"
+}
+
/// The mobile app's settings page. Surfaces the signed-in account (so the user
/// can confirm which cmux account this device uses — the account must match the
/// Mac it pairs with), plus terminal shortcuts, agent notifications, and the
@@ -19,6 +25,7 @@ struct MobileSettingsView: View {
/// The shell store, used to drive the multi-Mac switcher. `nil` in previews,
/// where the "Switch Mac" entry is hidden.
var store: CMUXMobileShellStore?
+ @AppStorage(MobileTelemetryDefaults.sendAnonymousTelemetryKey) private var sendAnonymousTelemetry = false
@Environment(\.dismiss) private var dismiss
@State private var showingShortcuts = false
@@ -236,6 +243,23 @@ struct MobileSettingsView: View {
.accessibilityIdentifier("MobileSettingsNotifications")
}
+ Section {
+ Toggle(isOn: $sendAnonymousTelemetry) {
+ Text(L10n.string(
+ "mobile.settings.telemetry",
+ defaultValue: "Share Analytics and Crash Reports"
+ ))
+ }
+ .accessibilityIdentifier("MobileSettingsTelemetryToggle")
+ } header: {
+ Text(L10n.string("mobile.settings.privacy", defaultValue: "Privacy"))
+ } footer: {
+ Text(L10n.string(
+ "mobile.settings.telemetryFooter",
+ defaultValue: "When off, cmux does not send iPhone or iPad product analytics or crash reports."
+ ))
+ }
+
MobileSettingsLegalSupportSection()
Section(L10n.string("mobile.settings.about", defaultValue: "About")) {
diff --git a/ios/AppStoreReview/metadata-screenshots-checklist.md b/ios/AppStoreReview/metadata-screenshots-checklist.md
index c6bd2f3f994d..09a90febc472 100644
--- a/ios/AppStoreReview/metadata-screenshots-checklist.md
+++ b/ios/AppStoreReview/metadata-screenshots-checklist.md
@@ -54,8 +54,9 @@ complete in App Store Connect or in the submitted binary.
- [ ] Photo library purpose string says attaching photos to terminal-agent messages.
- [ ] Permissions are requested only when the user starts the relevant feature.
- [ ] Push notifications are opt-in and can be disabled after enabling.
-- [ ] iPhone and iPad analytics collection is disabled until the user consents, and Settings exposes a control that withdraws consent for the same telemetry gate used by analytics and crash reporting. Do not submit while the absent `sendAnonymousTelemetry` default remains enabled without an iOS control.
-- [ ] In-app Delete Account deletes or anonymizes account-linked PostHog analytics, or the deletion flow gives the user a bounded follow-up process for that processor data. Do not submit while PostHog deletion is only a support-request path.
+- [x] iPhone and iPad analytics collection is disabled until the user consents, and Settings exposes a control that withdraws consent for the same telemetry gate used by analytics and crash reporting.
+- [x] In-app Delete Account queues deletion of account-linked PostHog analytics before deleting the Stack user.
+- [ ] Production web env has `POSTHOG_PERSONAL_API_KEY` with `person:write` scope, and `POSTHOG_ENVIRONMENT_ID` if the default PostHog environment `244066` changes.
## ASC Validation Commands
diff --git a/ios/cmux/Resources/Localizable.xcstrings b/ios/cmux/Resources/Localizable.xcstrings
index 200ebe51c382..da3435be87b7 100644
--- a/ios/cmux/Resources/Localizable.xcstrings
+++ b/ios/cmux/Resources/Localizable.xcstrings
@@ -4404,6 +4404,23 @@
}
}
},
+ "mobile.settings.privacy": {
+ "extractionState": "manual",
+ "localizations": {
+ "en": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "Privacy"
+ }
+ },
+ "ja": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "プライバシー"
+ }
+ }
+ }
+ },
"mobile.settings.privacyPolicy": {
"extractionState": "manual",
"localizations": {
@@ -4642,6 +4659,40 @@
}
}
},
+ "mobile.settings.telemetry": {
+ "extractionState": "manual",
+ "localizations": {
+ "en": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "Share Analytics and Crash Reports"
+ }
+ },
+ "ja": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "分析とクラッシュレポートを共有"
+ }
+ }
+ }
+ },
+ "mobile.settings.telemetryFooter": {
+ "extractionState": "manual",
+ "localizations": {
+ "en": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "When off, cmux does not send iPhone or iPad product analytics or crash reports."
+ }
+ },
+ "ja": {
+ "stringUnit": {
+ "state": "translated",
+ "value": "オフの場合、cmux は iPhone または iPad の製品分析やクラッシュレポートを送信しません。"
+ }
+ }
+ }
+ },
"mobile.settings.termsOfService": {
"extractionState": "manual",
"localizations": {
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 3e9c21e24290..2c62e777aa8a 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -274,14 +274,11 @@ export default function PrivacyPolicyPage() {
retained for product analytics and debugging for up to 24 months unless
you request earlier deletion. The mobile app account settings delete or
anonymize cmux-owned account, device, pairing, notification, billing, and
- cloud data as part of account deletion. Account-linked PostHog analytics
- deletion is not currently triggered by that in-app account deletion flow;
- contact us to request deletion or anonymization of account-linked
- PostHog analytics, and we will complete that request within 30 days
- unless retention is required for security, legal, billing, or
- fraud-prevention reasons. You may request deletion of cmux-owned data
- associated with you from the mobile app account settings or by contacting
- us at{" "}
+ cloud data, and queue deletion of account-linked mobile PostHog
+ analytics, as part of account deletion. Some deletion work may be
+ processed asynchronously by our service providers. You may request
+ deletion of cmux-owned data associated with you from the mobile app
+ account settings or by contacting us at{" "}
founders@manaflow.com.
>
diff --git a/web/app/api/account/route.ts b/web/app/api/account/route.ts
index 50dc9cad36d2..724929acecc7 100644
--- a/web/app/api/account/route.ts
+++ b/web/app/api/account/route.ts
@@ -69,6 +69,9 @@ export const dynamic = "force-dynamic";
const VAULT_OBJECT_DELETE_BATCH_SIZE = 100;
const DELETED_ACCOUNT_ACTOR_ID = "deleted-account";
+const POSTHOG_DEFAULT_API_HOST = "https://us.posthog.com";
+// The shipped PostHog project key belongs to project/environment 244066.
+const POSTHOG_DEFAULT_ENVIRONMENT_ID = "244066";
type DeletableStackUser = {
readonly id: string;
@@ -194,6 +197,14 @@ export async function DELETE(request: Request): Promise {
},
}, accountScope.teamIds);
await refreshAccountDeletionTombstoneLease(userId);
+ await deletePostHogPersonForAccountDeletion(userId, {
+ beforeExternalRequest: () => {
+ destructiveCleanupStarted = true;
+ },
+ afterExternalMutation: async () => {
+ await refreshAccountDeletionTombstoneLease(userId);
+ },
+ });
// Delete cmux-owned data before the Stack user so a Stack-side failure does
// not strand retained app data behind an account the user can no longer use.
// These deletes are idempotent, so the same signed-in user can retry the
@@ -213,7 +224,9 @@ export async function DELETE(request: Request): Promise {
}, 500);
}
try {
- await finishPostStackAccountCleanup(userId, accountScope.teamIds);
+ await finishPostStackAccountCleanup(userId, accountScope.teamIds, {
+ deletePostHogPerson: false,
+ });
await markAccountDeletionTombstoneCompleted(userId);
} catch (error) {
logAccountDeleteError("account.delete.post_stack_cleanup_failed", error);
@@ -600,11 +613,82 @@ async function deleteVaultRowsAndObjectsForAccountLocked(
}
}
-async function finishPostStackAccountCleanup(userId: string, accountTeamIds: readonly string[]): Promise {
+async function finishPostStackAccountCleanup(
+ userId: string,
+ accountTeamIds: readonly string[],
+ options: { readonly deletePostHogPerson?: boolean } = {},
+): Promise {
await deleteVaultRowsAndObjectsForAccount(userId);
+ if (options.deletePostHogPerson !== false) {
+ await deletePostHogPersonForAccountDeletion(userId);
+ }
await deleteCmuxOwnedAccountRows(userId, accountTeamIds);
}
+async function deletePostHogPersonForAccountDeletion(
+ userId: string,
+ options: {
+ readonly beforeExternalRequest?: () => void;
+ readonly afterExternalMutation?: () => Promise;
+ } = {},
+): Promise {
+ const config = postHogPersonDeletionConfig();
+ if (!config) return;
+
+ options.beforeExternalRequest?.();
+ const response = await fetch(
+ `${config.apiHost}/api/environments/${encodeURIComponent(config.environmentId)}/persons/bulk_delete/`,
+ {
+ method: "POST",
+ headers: {
+ "Authorization": `Bearer ${config.personalApiKey}`,
+ "Content-Type": "application/json",
+ },
+ body: JSON.stringify({
+ distinct_ids: [userId],
+ delete_events: true,
+ delete_recordings: true,
+ keep_person: false,
+ }),
+ },
+ );
+ if (!response.ok) {
+ throw new Error(`PostHog account deletion failed with status ${response.status}`);
+ }
+ await options.afterExternalMutation?.();
+}
+
+function postHogPersonDeletionConfig(): {
+ readonly apiHost: string;
+ readonly environmentId: string;
+ readonly personalApiKey: string;
+} | null {
+ const personalApiKey = process.env.POSTHOG_PERSONAL_API_KEY?.trim();
+ if (!personalApiKey) {
+ if (
+ process.env.VERCEL_ENV === "production" ||
+ process.env.CMUX_REQUIRE_POSTHOG_PERSON_DELETE === "1"
+ ) {
+ throw new Error("POSTHOG_PERSONAL_API_KEY is required for account deletion");
+ }
+ return null;
+ }
+
+ const apiHost = (
+ process.env.POSTHOG_API_HOST ??
+ POSTHOG_DEFAULT_API_HOST
+ ).replace(/\/$/, "");
+ const environmentId = (
+ process.env.POSTHOG_ENVIRONMENT_ID ??
+ process.env.POSTHOG_PROJECT_ID ??
+ POSTHOG_DEFAULT_ENVIRONMENT_ID
+ ).trim();
+ if (!environmentId) {
+ throw new Error("POSTHOG_ENVIRONMENT_ID is required for account deletion");
+ }
+ return { apiHost, environmentId, personalApiKey };
+}
+
async function resolveUserBillingForAccountDeletion(
userId: string,
accountTeamIds: readonly string[],
diff --git a/web/tests/account-route.test.ts b/web/tests/account-route.test.ts
index fb5856ed5dbd..3f8533babf86 100644
--- a/web/tests/account-route.test.ts
+++ b/web/tests/account-route.test.ts
@@ -28,6 +28,9 @@ process.env.NEXT_PUBLIC_STACK_PROJECT_ID ??= "00000000-0000-4000-8000-0000000000
process.env.NEXT_PUBLIC_STACK_PUBLISHABLE_CLIENT_KEY ??= "test-stack-publishable";
const ACCOUNT_USER_ID = "account-user-1";
+const originalPostHogPersonalApiKey = process.env.POSTHOG_PERSONAL_API_KEY;
+const originalPostHogApiHost = process.env.POSTHOG_API_HOST;
+const originalPostHogEnvironmentId = process.env.POSTHOG_ENVIRONMENT_ID;
const stackModule = await import("../app/lib/stack");
const realGetStackServerApp = stackModule.getStackServerApp;
const realIsStackConfigured = stackModule.isStackConfigured;
@@ -259,6 +262,20 @@ const revokeTenant = mock(async (...args: unknown[]) => {
if (sequenceError) throw sequenceError;
if (subrouterRevokeError) throw subrouterRevokeError;
});
+const realFetch = globalThis.fetch;
+const postHogDeleteFetch = mock(async (...args: unknown[]) => {
+ const fetchArgs = args as Parameters;
+ routeEvents.push("posthog-delete");
+ postHogDeleteRequests.push(fetchArgs);
+ if (postHogDeleteError) throw postHogDeleteError;
+ return new Response(JSON.stringify({
+ persons_found: 1,
+ persons_deleted: 1,
+ events_queued_for_deletion: true,
+ recordings_queued_for_deletion: true,
+ deletion_errors: [],
+ }), { status: postHogDeleteStatus });
+});
let deletedTableCount = 0;
let deletedTables: unknown[] = [];
@@ -303,6 +320,9 @@ let stackUserTeams: StackList = [];
let useAccountRouteStubs = false;
let lastRevokeIdentityCall: { readonly userId: string; readonly afterBatch?: unknown } | null = null;
let vaultLockUsers: string[] = [];
+let postHogDeleteRequests: Parameters[] = [];
+let postHogDeleteError: unknown = null;
+let postHogDeleteStatus = 202;
const originalConsoleError = console.error;
const consoleError = mock(() => {});
@@ -378,6 +398,31 @@ function chainableSelectResult(rows: unknown[]): SelectResult {
return result;
}
+function restoreEnv(name: string, value: string | undefined): void {
+ if (value === undefined) {
+ delete process.env[name];
+ } else {
+ process.env[name] = value;
+ }
+}
+
+function expectPostHogAccountDeleteRequest(): void {
+ expect(postHogDeleteRequests).toHaveLength(1);
+ const [url, init] = postHogDeleteRequests[0]!;
+ expect(String(url)).toBe("https://posthog.test/api/environments/env-244066/persons/bulk_delete/");
+ expect(init?.method).toBe("POST");
+ expect(init?.headers).toEqual({
+ "Authorization": "Bearer test-posthog-personal-api-key",
+ "Content-Type": "application/json",
+ });
+ expect(JSON.parse(String(init?.body))).toEqual({
+ distinct_ids: [ACCOUNT_USER_ID],
+ delete_events: true,
+ delete_recordings: true,
+ keep_person: false,
+ });
+}
+
const mockDb = {
select: mock(() => {
let selectedTable: unknown = null;
@@ -519,6 +564,10 @@ afterAll(() => {
beforeEach(() => {
console.error = consoleError as typeof console.error;
+ globalThis.fetch = postHogDeleteFetch as typeof fetch;
+ process.env.POSTHOG_PERSONAL_API_KEY = "test-posthog-personal-api-key";
+ process.env.POSTHOG_API_HOST = "https://posthog.test";
+ process.env.POSTHOG_ENVIRONMENT_ID = "env-244066";
consoleError.mockClear();
deleteStackUser.mockClear();
updateStackUser.mockClear();
@@ -542,6 +591,7 @@ beforeEach(() => {
removeTester.mockClear();
captureAscError.mockClear();
revokeTenant.mockClear();
+ postHogDeleteFetch.mockClear();
deletedTableCount = 0;
deletedTables = [];
deletedWhere = [];
@@ -584,10 +634,17 @@ beforeEach(() => {
stackUserSelectedTeam = null;
stackUserTeams = [];
vaultLockUsers = [];
+ postHogDeleteRequests = [];
+ postHogDeleteError = null;
+ postHogDeleteStatus = 202;
});
afterEach(() => {
console.error = originalConsoleError;
+ globalThis.fetch = realFetch;
+ restoreEnv("POSTHOG_PERSONAL_API_KEY", originalPostHogPersonalApiKey);
+ restoreEnv("POSTHOG_API_HOST", originalPostHogApiHost);
+ restoreEnv("POSTHOG_ENVIRONMENT_ID", originalPostHogEnvironmentId);
});
describe("account deletion route", () => {
@@ -658,6 +715,7 @@ describe("account deletion route", () => {
]);
expect(cancelledStripeSubscriptions).toEqual(["sub_user_active"]);
expect(deletedStripeCustomers).toEqual(["cus_user"]);
+ expectPostHogAccountDeleteRequest();
expect(updateStackUser).toHaveBeenCalledWith({
clientReadOnlyMetadata: { cmuxAccountDeleting: true },
});
@@ -703,6 +761,7 @@ describe("account deletion route", () => {
"vault-delete",
"vault-delete",
"vault-delete",
+ "posthog-delete",
"transaction",
"transaction-lock",
"stack-delete",
@@ -711,6 +770,27 @@ describe("account deletion route", () => {
]);
});
+ test("blocks Stack deletion when PostHog account analytics deletion fails", async () => {
+ postHogDeleteStatus = 500;
+
+ const response = await DELETE(accountDeletionRequest());
+
+ expect(response.status).toBe(500);
+ expect(await response.json()).toEqual({
+ error: "account_delete_retryable",
+ retryable: true,
+ destroyedVms: 2,
+ });
+ expectPostHogAccountDeleteRequest();
+ expect(deleteStackUser).not.toHaveBeenCalled();
+ expect(routeEvents).toContain("posthog-delete");
+ expect(routeEvents).not.toContain("stack-delete");
+ expect(tombstoneUpdates.some((values) =>
+ (values as { readonly status?: unknown; readonly errorMessage?: unknown }).status === "failed" &&
+ (values as { readonly errorMessage?: unknown }).errorMessage === "Error: PostHog account deletion failed with status 500"
+ )).toBe(true);
+ });
+
test("destroys personal VMs with the same provider id on different providers", async () => {
listedPersonalVmIds = [
{ providerVmId: "shared-provider-id", provider: "freestyle" },
@@ -1779,6 +1859,7 @@ describe("account deletion route", () => {
clientReadOnlyMetadata: { cmuxAccountDeleting: true },
});
expect(updateStackUser).toHaveBeenCalledTimes(1);
+ expectPostHogAccountDeleteRequest();
expect(deleteStackUser).toHaveBeenCalledTimes(1);
expect(tombstoneUpdates.some((values) =>
(values as { readonly status?: unknown; readonly errorMessage?: unknown }).status === "failed" &&
@@ -1793,6 +1874,7 @@ describe("account deletion route", () => {
"list-vms",
"destroy-vm",
"destroy-vm",
+ "posthog-delete",
"transaction",
"transaction-lock",
"stack-delete",
From 8004ea80caf65040638fd8b0460341e823d9145d Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:39:47 -0700
Subject: [PATCH 10/58] Fix iOS settings convention lint
---
.../CmuxMobileShellUI/MobileSettingsView.swift | 12 +++++-------
1 file changed, 5 insertions(+), 7 deletions(-)
diff --git a/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift b/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
index e289e24e46e0..474bf259c179 100644
--- a/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
+++ b/Packages/iOS/CmuxMobileShellUI/Sources/CmuxMobileShellUI/MobileSettingsView.swift
@@ -5,17 +5,15 @@ import CmuxMobileSupport
import CmuxMobileWorkspace
import SwiftUI
-private enum MobileTelemetryDefaults {
- /// Shared with `UserDefaultsAnalyticsConsentProvider`; keep the string stable
- /// so Settings controls the same gate used by analytics and crash reporting.
- static let sendAnonymousTelemetryKey = "sendAnonymousTelemetry"
-}
-
/// The mobile app's settings page. Surfaces the signed-in account (so the user
/// can confirm which cmux account this device uses — the account must match the
/// Mac it pairs with), plus terminal shortcuts, agent notifications, and the
/// paired Mac. Presented as a sheet from the workspace list.
struct MobileSettingsView: View {
+ /// Shared with `UserDefaultsAnalyticsConsentProvider`; keep the string stable
+ /// so Settings controls the same gate used by analytics and crash reporting.
+ private static let sendAnonymousTelemetryKey = "sendAnonymousTelemetry"
+
@Environment(AuthCoordinator.self) private var authManager
@Environment(MobilePushCoordinator.self) private var pushCoordinator
@Environment(MobileDisplaySettings.self) private var displaySettings
@@ -25,7 +23,7 @@ struct MobileSettingsView: View {
/// The shell store, used to drive the multi-Mac switcher. `nil` in previews,
/// where the "Switch Mac" entry is hidden.
var store: CMUXMobileShellStore?
- @AppStorage(MobileTelemetryDefaults.sendAnonymousTelemetryKey) private var sendAnonymousTelemetry = false
+ @AppStorage(MobileSettingsView.sendAnonymousTelemetryKey) private var sendAnonymousTelemetry = false
@Environment(\.dismiss) private var dismiss
@State private var showingShortcuts = false
From 0e7800c849d4b7a33ef2546fb5382787873d2521 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 16:52:36 -0700
Subject: [PATCH 11/58] Align privacy policy with telemetry opt-in
---
web/app/[locale]/(legal)/privacy-policy/page.tsx | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 2c62e777aa8a..188080041946 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -96,11 +96,11 @@ export default function PrivacyPolicyPage() {
in, events use a random per-install client identifier. After sign in,
our server attaches your Stack Auth account identifier to events before
forwarding them to PostHog. We retain mobile analytics only as long as
- needed for product analytics and debugging. The current iPhone and iPad
- Application sends these analytics unless telemetry is disabled through an
- app-provided preference in the build you are using. Where the Application
- exposes a Send anonymous telemetry preference, turning it off stops
- analytics events from being buffered or sent. You may also contact us at{" "}
+ needed for product analytics and debugging. In the current iPhone and
+ iPad Application, analytics and crash reports start disabled and are sent
+ only after you enable the Share Analytics and Crash Reports control in
+ Settings. Turning that control off stops analytics events from being
+ buffered or sent. You may also contact us at{" "}
founders@manaflow.com to
request deletion of analytics associated with your account.
From bf7ffce2b10b11009c108ecb72ee7f55e468e3a3 Mon Sep 17 00:00:00 2001
From: Aziz Albahar
Date: Fri, 10 Jul 2026 21:07:47 -0700
Subject: [PATCH 12/58] Close iOS App Store readiness blockers
---
.../metadata-screenshots-checklist.md | 5 +-
ios/AppStoreReview/reviewer-setup.md | 8 +-
ios/cmux/Resources/PrivacyInfo.xcprivacy | 53 +++
.../(legal)/privacy-policy/content.ts | 72 ++++
.../(legal)/privacy-policy/content/ar.json | 128 ++++++
.../(legal)/privacy-policy/content/bs.json | 128 ++++++
.../(legal)/privacy-policy/content/da.json | 128 ++++++
.../(legal)/privacy-policy/content/de.json | 128 ++++++
.../(legal)/privacy-policy/content/en.json | 128 ++++++
.../(legal)/privacy-policy/content/es.json | 128 ++++++
.../(legal)/privacy-policy/content/fr.json | 128 ++++++
.../(legal)/privacy-policy/content/it.json | 128 ++++++
.../(legal)/privacy-policy/content/ja.json | 128 ++++++
.../(legal)/privacy-policy/content/km.json | 128 ++++++
.../(legal)/privacy-policy/content/ko.json | 128 ++++++
.../(legal)/privacy-policy/content/no.json | 128 ++++++
.../(legal)/privacy-policy/content/pl.json | 128 ++++++
.../(legal)/privacy-policy/content/pt-BR.json | 128 ++++++
.../(legal)/privacy-policy/content/ru.json | 128 ++++++
.../(legal)/privacy-policy/content/th.json | 128 ++++++
.../(legal)/privacy-policy/content/tr.json | 128 ++++++
.../(legal)/privacy-policy/content/uk.json | 128 ++++++
.../(legal)/privacy-policy/content/zh-CN.json | 128 ++++++
.../(legal)/privacy-policy/content/zh-TW.json | 128 ++++++
.../[locale]/(legal)/privacy-policy/page.tsx | 371 +++++-------------
web/app/[locale]/components/site-footer.tsx | 2 +-
web/app/api/account/route.ts | 14 +-
web/app/sitemap.ts | 4 +-
web/tests/account-route.test.ts | 24 ++
web/tests/privacy-policy-localization.test.ts | 68 ++++
30 files changed, 2896 insertions(+), 285 deletions(-)
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content.ts
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/ar.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/bs.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/da.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/de.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/en.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/es.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/fr.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/it.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/ja.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/km.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/ko.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/no.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/pl.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/pt-BR.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/ru.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/th.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/tr.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/uk.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/zh-CN.json
create mode 100644 web/app/[locale]/(legal)/privacy-policy/content/zh-TW.json
create mode 100644 web/tests/privacy-policy-localization.test.ts
diff --git a/ios/AppStoreReview/metadata-screenshots-checklist.md b/ios/AppStoreReview/metadata-screenshots-checklist.md
index 09a90febc472..5c91635bc284 100644
--- a/ios/AppStoreReview/metadata-screenshots-checklist.md
+++ b/ios/AppStoreReview/metadata-screenshots-checklist.md
@@ -55,8 +55,9 @@ complete in App Store Connect or in the submitted binary.
- [ ] Permissions are requested only when the user starts the relevant feature.
- [ ] Push notifications are opt-in and can be disabled after enabling.
- [x] iPhone and iPad analytics collection is disabled until the user consents, and Settings exposes a control that withdraws consent for the same telemetry gate used by analytics and crash reporting.
-- [x] In-app Delete Account queues deletion of account-linked PostHog analytics before deleting the Stack user.
-- [ ] Production web env has `POSTHOG_PERSONAL_API_KEY` with `person:write` scope, and `POSTHOG_ENVIRONMENT_ID` if the default PostHog environment `244066` changes.
+- [x] In-app Delete Account deletes the account-linked PostHog person and requests deletion of its events and recordings before deleting the Stack user.
+- [ ] Production web env has `POSTHOG_PERSONAL_API_KEY` with `person:write` scope and an explicit `POSTHOG_ENVIRONMENT_ID` (or `POSTHOG_PROJECT_ID`) for that key. Destructive deletion has no default project fallback.
+- [ ] Every `reviewer-setup.md` placeholder is replaced only in ASC with working demo credentials, concrete Tailscale access, concrete host, port, and monitored contact. These live values stay out of git.
## ASC Validation Commands
diff --git a/ios/AppStoreReview/reviewer-setup.md b/ios/AppStoreReview/reviewer-setup.md
index f680611d3d8b..dc46380fa2c8 100644
--- a/ios/AppStoreReview/reviewer-setup.md
+++ b/ios/AppStoreReview/reviewer-setup.md
@@ -35,8 +35,9 @@ that resolves only to a private local-network address. The reviewer must receive
exact Tailscale field values for the iOS Add Computer form:
- Name: `App Review Mac`
-- Host: a Tailscale MagicDNS `*.ts.net` hostname or `100.64.0.0/10` address
- after the reviewer signs in to the supplied tailnet
+- Host: the prepared Mac's concrete Tailscale MagicDNS `*.ts.net` hostname or
+ concrete `100.64.x.x` Tailscale address after the reviewer signs in to the
+ supplied tailnet
- Port: the prepared Mac's cmux mobile host port
Before submission, verify those exact values from a clean network outside
@@ -124,3 +125,6 @@ Before submitting:
Review.
6. Confirm the Privacy Policy URL in App Store Connect is
`https://cmux.com/privacy-policy`.
+7. Replace every angle-bracket placeholder in the notes with the exact live
+ review value. Exact demo credentials, Tailscale access, host, port, and
+ monitored contact are submission blockers and must never be committed here.
diff --git a/ios/cmux/Resources/PrivacyInfo.xcprivacy b/ios/cmux/Resources/PrivacyInfo.xcprivacy
index 085f7060281f..080b5dc890c1 100644
--- a/ios/cmux/Resources/PrivacyInfo.xcprivacy
+++ b/ios/cmux/Resources/PrivacyInfo.xcprivacy
@@ -21,6 +21,59 @@
+ NSPrivacyCollectedDataTypes
+
+
+ NSPrivacyCollectedDataType
+ NSPrivacyCollectedDataTypeUserID
+ NSPrivacyCollectedDataTypeLinked
+
+ NSPrivacyCollectedDataTypeTracking
+
+ NSPrivacyCollectedDataTypePurposes
+
+ NSPrivacyCollectedDataTypePurposeAnalytics
+
+
+
+ NSPrivacyCollectedDataType
+ NSPrivacyCollectedDataTypeProductInteraction
+ NSPrivacyCollectedDataTypeLinked
+
+ NSPrivacyCollectedDataTypeTracking
+
+ NSPrivacyCollectedDataTypePurposes
+
+ NSPrivacyCollectedDataTypePurposeAnalytics
+
+
+
+ NSPrivacyCollectedDataType
+ NSPrivacyCollectedDataTypeCrashData
+ NSPrivacyCollectedDataTypeLinked
+
+ NSPrivacyCollectedDataTypeTracking
+
+ NSPrivacyCollectedDataTypePurposes
+
+ NSPrivacyCollectedDataTypePurposeAppFunctionality
+ NSPrivacyCollectedDataTypePurposeAnalytics
+
+
+
+ NSPrivacyCollectedDataType
+ NSPrivacyCollectedDataTypeOtherDiagnosticData
+ NSPrivacyCollectedDataTypeLinked
+
+ NSPrivacyCollectedDataTypeTracking
+
+ NSPrivacyCollectedDataTypePurposes
+
+ NSPrivacyCollectedDataTypePurposeAppFunctionality
+ NSPrivacyCollectedDataTypePurposeAnalytics
+
+
+ NSPrivacyTrackingNSPrivacyTrackingDomains
diff --git a/web/app/[locale]/(legal)/privacy-policy/content.ts b/web/app/[locale]/(legal)/privacy-policy/content.ts
new file mode 100644
index 000000000000..f517410db897
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content.ts
@@ -0,0 +1,72 @@
+import type { Locale } from "../../../../i18n/routing";
+
+import ar from "./content/ar.json";
+import bs from "./content/bs.json";
+import da from "./content/da.json";
+import de from "./content/de.json";
+import en from "./content/en.json";
+import es from "./content/es.json";
+import fr from "./content/fr.json";
+import it from "./content/it.json";
+import ja from "./content/ja.json";
+import km from "./content/km.json";
+import ko from "./content/ko.json";
+import no from "./content/no.json";
+import pl from "./content/pl.json";
+import ptBR from "./content/pt-BR.json";
+import ru from "./content/ru.json";
+import th from "./content/th.json";
+import tr from "./content/tr.json";
+import uk from "./content/uk.json";
+import zhCN from "./content/zh-CN.json";
+import zhTW from "./content/zh-TW.json";
+
+export type PrivacyPolicySubsection = {
+ readonly heading: string;
+ readonly paragraphs?: readonly string[];
+ readonly bullets?: readonly string[];
+ readonly afterBullets?: readonly string[];
+};
+
+export type PrivacyPolicySection = {
+ readonly heading?: string;
+ readonly paragraphs?: readonly string[];
+ readonly bullets?: readonly string[];
+ readonly afterBullets?: readonly string[];
+ readonly subsections?: readonly PrivacyPolicySubsection[];
+};
+
+export type PrivacyPolicyContent = {
+ readonly metadataTitle: string;
+ readonly metadataDescription: string;
+ readonly title: string;
+ readonly lastUpdated: string;
+ readonly sections: readonly PrivacyPolicySection[];
+};
+
+export const privacyPolicyContent = {
+ en,
+ ja,
+ "zh-CN": zhCN,
+ "zh-TW": zhTW,
+ ko,
+ de,
+ es,
+ fr,
+ it,
+ da,
+ pl,
+ ru,
+ bs,
+ ar,
+ no,
+ "pt-BR": ptBR,
+ th,
+ tr,
+ km,
+ uk,
+} satisfies Record;
+
+export function privacyPolicyForLocale(locale: string): PrivacyPolicyContent {
+ return privacyPolicyContent[locale as Locale] ?? privacyPolicyContent.en;
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/ar.json b/web/app/[locale]/(legal)/privacy-policy/content/ar.json
new file mode 100644
index 000000000000..854643d63e33
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/ar.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "سياسة الخصوصية — cmux",
+ "metadataDescription": "سياسة الخصوصية لـ cmux",
+ "title": "سياسة الخصوصية",
+ "lastUpdated": "آخر تحديث: 10 يوليو 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "تلتزم Manaflow (\"الشركة\") بالحفاظ على حماية خصوصية قوية لمستخدميها. تشرح سياسة الخصوصية هذه كيف نقوم بجمع واستخدام وحماية المعلومات التي تقدمها لنا.",
+ "في هذه السياسة، يعني \"الموقع\" موقع الشركة على [cmux.com](https://cmux.com). \"التطبيق\" يعني تطبيق سطح المكتب cmux لـ macOS وتطبيق الهاتف المحمول cmux لـ iPhone وiPad. \"الخدمة\" تعني الموقع والتطبيق معًا. \"نحن\" و\"لنا\" و\"خاصتنا\" تعني الشركة. \"أنت\" تعني مستخدم خدمتنا.",
+ "باستخدام خدمتنا، فإنك تقبل سياسة الخصوصية هذه و[شروط الخدمة](https://cmux.com/terms-of-service)، وتوافق على التجميع والتخزين والاستخدام والكشف الموضح هنا."
+ ]
+ },
+ {
+ "heading": "I. المعلومات التي نجمعها",
+ "paragraphs": [
+ "نقوم بجمع المعلومات غير الشخصية والمعلومات الشخصية. لا يمكن للمعلومات غير الشخصية التعرف عليك وتتضمن بيانات الاستخدام المجهولة وأنواع الأنظمة الأساسية وتشخيصات الأعطال. تتضمن المعلومات الشخصية عنوان بريدك الإلكتروني ومعرفات الحساب والمعلومات التي تختار تقديمها عند تسجيل الدخول أو الاتصال بنا أو إقران جهاز أو استخدام التطبيق."
+ ],
+ "subsections": [
+ {
+ "heading": "1. المعلومات التي يتم جمعها من خلال التكنولوجيا",
+ "paragraphs": [
+ "قد يقوم التطبيق تلقائيًا بجمع المعلومات التالية:"
+ ],
+ "bullets": [
+ "تقارير الأعطال وتشخيص الأخطاء من خلال Sentry.",
+ "إصدار نظام التشغيل وإصدار التطبيق.",
+ "تحليلات المنتج وأحداث استخدام الميزات للموقع والتطبيق.",
+ "الجهاز والحساب والبيانات التعريفية المقترنة اللازمة لتوصيل أجهزتك التي تم تسجيل الدخول إليها.",
+ "الرموز المميزة لجهاز خدمة الإشعارات Apple، فقط بعد تمكين إشعارات الهاتف."
+ ],
+ "afterBullets": [
+ "يتحقق تطبيق macOS من التحديثات من خلال Sparkle، والذي قد يرسل نظام التشغيل وإصدارات التطبيق لديك إلى خادم التحديث الخاص بنا. يتم تحديث تطبيق iPhone وiPad من خلال App Store، وليس Sparkle.",
+ "يستخدم الموقع PostHog لعرض الصفحة وتحليلات التنقل. يقوم PostHog بتخزين ملف تعريف الارتباط لتمييز الزوار. إذا انضممت إلى قائمة انتظار النظام الأساسي، فسيتم تسجيل بريدك الإلكتروني المقدم في PostHog حتى نتمكن من إعلامك. إذا قمت بإرسال نموذج الاتصال بالمؤسسة، فإننا نسجل الشركة وتفاصيل الاتصال التي تقدمها في PostHog ونرسلها إلى مساحة عمل Slack الخاصة بنا وصندوق البريد الإلكتروني للمؤسسين حتى نتمكن من الرد. يمكنك حظر تحليلات موقع الويب باستخدام ملحق المتصفح الذي يحظر تتبع البرامج النصية.",
+ "يرسل تطبيق iPhone وiPad أحداث تحليلات المنتج إلى وكيل PostHog الخاص بنا من جانب الخادم. تساعد هذه الأحداث في تشخيص الموثوقية وفهم استخدام الميزات وتحسين التطبيق. وهي تتضمن أحداث تشغيل التطبيق وجلسته، وحالة تسجيل الدخول، ومحاولات الاقتران ونتائجها، واسترداد الاتصال، وفتح مساحة العمل، وعدد بايتات وأسطر الإدخال الطرفي، واشتراك الإشعارات أو نتائج الارتباط العميق للإشعارات. لا ترسل تحليلات الأجهزة المحمولة نص أمر المحطة الطرفية أو مخرجات المحطة الطرفية أو الصور المحددة أو نصوص الكلام إلى PostHog. قبل تسجيل الدخول، تستخدم الأحداث معرف عميل عشوائيًا لكل عملية تثبيت. بعد تسجيل الدخول، يقوم خادمنا بإرفاق معرف حساب Stack Auth الخاص بك قبل إعادة توجيه الأحداث إلى PostHog. يبدأ تعطيل التحليلات وتقارير الأعطال ولا يتم إرسالها إلا بعد تمكين مشاركة التحليلات وتقارير الأعطال في الإعدادات. يؤدي إيقاف تشغيل عنصر التحكم هذا إلى إيقاف تخزين التحليلات مؤقتًا أو إرسالها وإيقاف الإبلاغ عن الأعطال. اتصل بـ [founders@manaflow.com](mailto:founders@manaflow.com) لطلب حذف التحليلات المرتبطة بحسابك."
+ ]
+ },
+ {
+ "heading": "2. المعلومات التي تقدمها مباشرة",
+ "paragraphs": [
+ "إذا اتصلت بنا عبر البريد الإلكتروني، أو صفحة الاتصال الخاصة بنا، أو نموذج الاتصال بالمؤسسة، فإننا نجمع المعلومات التي تقدمها، بما في ذلك الاسم والبريد الإلكتروني والشركة والدور ورقم الهاتف والبلد واحتياجات النشر والتعليقات. إذا انضممت إلى قائمة انتظار النظام الأساسي، فإننا نجمع بريدك الإلكتروني المقدم لإعلامك عند إطلاق هذا النظام الأساسي ونرسل بريدًا إلكترونيًا للتسجيل ومنصات محددة إلى مساحة عمل Slack الخاصة بنا.",
+ "عندما تقوم بتسجيل الدخول، نتلقى معلومات المصادقة مثل عنوان بريدك الإلكتروني ومعرف الموفر من Apple، أو Google، أو GitHub، أو تسجيل الدخول برمز البريد الإلكتروني. عند إقران تطبيق الهاتف المحمول بجهاز Mac، نقوم بمعالجة معلومات الاقتران اللازمة لتوصيل الأجهزة. عندما تقوم بعرض مساحة عمل، أو إرسال مدخلات طرفية، أو إرفاق صور محددة، أو استخدام تحويل الكلام إلى نص، أو تلقي إشعارات طرفية، فقد يمر المحتوى أو النص ذي الصلة بين أجهزتك وخدمتنا حسب الحاجة لتوفير هذه الميزة.",
+ "يتم استخدام الوصول إلى الكاميرا فقط لمسح رموز cmux المقترنة بـ QR. يتم استخدام الوصول إلى الميكروفون والتعرف على الكلام فقط عندما تختار النسخ الصوتي في مربع الرسالة. يتم استخدام الوصول إلى مكتبة الصور فقط عندما تختار الصور المراد إرفاقها."
+ ]
+ },
+ {
+ "heading": "3. خصوصية الأطفال",
+ "paragraphs": [
+ "الخدمة ليست موجهة إلى أي شخص يقل عمره عن 13 عامًا، ونحن لا نجمع معلومات عن عمد من أي شخص يقل عمره عن 13 عامًا. إذا كنت تعتقد أننا جمعنا مثل هذه المعلومات، فاتصل بـ [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "ثانيا. خدمات الطرف الثالث",
+ "paragraphs": [
+ "يتكامل التطبيق مع خدمات الطرف الثالث هذه:"
+ ],
+ "bullets": [
+ "Stack Auth: المصادقة وإدارة الحساب لتسجيل الدخول والجلسات وحذف الحساب.",
+ "Apple، وGoogle، وGitHub: موفري تسجيل الدخول الاختياريون الذين يرسلون معلومات الحساب المطلوبة لمصادقتك.",
+ "خدمة الإشعارات الفورية Apple: إشعارات إلى iPhone وiPad بعد الاشتراك.",
+ "التعرف على الكلام Apple: النسخ الصوتي عند اختياره في تطبيق الهاتف المحمول.",
+ "Sentry: تتبع الأخطاء والإبلاغ عن الأعطال، والذي قد يجمع سجلات الأخطاء وتتبعات المكدس ومعلومات الجهاز وإصدار نظام التشغيل.",
+ "Sparkle: إطار عمل التحديث التلقائي macOS، الذي يرسل إصدارات التطبيق ونظام التشغيل للتحقق من تحديثات macOS.",
+ "Ghostty / libghostty: محرك العرض الطرفي، الذي يعمل محليًا على جهازك.",
+ "PostHog: تحليلات موقع الويب ومنتجات الهاتف المحمول، بما في ذلك مشاهدات الصفحة، وأنماط التنقل، وبيانات تعريف المتصفح، وأحداث ميزات الهاتف المحمول، وتحليلات الهاتف المحمول المرتبطة بالحساب بعد تسجيل الدخول من خلال وكيل الطرف الأول، وبريد إلكتروني مرسل لقائمة الانتظار حتى نتمكن من إعلامك.",
+ "Resend: تسليم البريد الإلكتروني للمعاملات. سيتم إرسال بريدك الإلكتروني إلى Resend فقط إذا قمت بإرسال تعليقات طوعًا.",
+ "Slack: إشعارات داخلية خاصة. إذا انضممت إلى قائمة انتظار النظام الأساسي، فسيتم إرسال البريد الإلكتروني والأنظمة الأساسية التي ترسلها إلى مساحة عمل Slack الخاصة بنا."
+ ],
+ "afterBullets": [
+ "كل خدمة لها سياسة الخصوصية الخاصة بها. عندما يقوم طرف ثالث بمعالجة المعلومات الشخصية لـ cmux، فإننا نطلب ضمانات وقائية على الأقل بقدر هذه السياسة ونقتصر استخدامها على تقديم الخدمات إلى cmux."
+ ]
+ },
+ {
+ "heading": "ثالثا. كيف نستخدم المعلومات ونشاركها",
+ "paragraphs": [
+ "نحن لا نبيع أو نتاجر أو نؤجر أو نشارك المعلومات الشخصية مع أطراف ثالثة للتسويق. نحن نستخدم تقارير الأعطال والتشخيصات فقط لتحسين التطبيق. يجوز لنا الكشف عن المعلومات عندما نعتقد بحسن نية أن الكشف ضروري للإجراءات القانونية أو الحماية من الأذى."
+ ]
+ },
+ {
+ "heading": "رابعا. كيف نحمي المعلومات",
+ "paragraphs": [
+ "نحن نستخدم تدابير مصممة لمنع الوصول غير المصرح به، بما في ذلك برنامج التشفير والخادم الآمن. لا توجد طريقة نقل أو تخزين آمنة تمامًا، وينطوي استخدام الخدمة على هذه المخاطر."
+ ]
+ },
+ {
+ "heading": "خامساً: حقوقك",
+ "paragraphs": [
+ "اعتمادًا على موقعك، قد تمنحك القوانين المعمول بها مثل GDPR أو CCPA هذه الحقوق:"
+ ],
+ "bullets": [
+ "الوصول إلى نسخة من البيانات التي نحتفظ بها عنك.",
+ "تصحيح البيانات غير الدقيقة.",
+ "اطلب حذف بياناتك.",
+ "تلقي البيانات المحمولة.",
+ "تقييد أو الاعتراض على المعالجة."
+ ],
+ "afterBullets": [
+ "لممارسة هذه الحقوق، اتصل بـ [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "سادسا. روابط لمواقع أخرى",
+ "paragraphs": [
+ "قد ترتبط الخدمة بمواقع الطرف الثالث. نحن لسنا مسؤولين عن ممارسات الخصوصية الخاصة بهم. تنطبق هذه السياسة فقط على المعلومات التي نجمعها."
+ ]
+ },
+ {
+ "heading": "سابعا. التغييرات على هذه السياسة",
+ "paragraphs": [
+ "قد نقوم بتغيير هذه السياسة. تدخل التغييرات المهمة حيز التنفيذ بعد 30 يومًا من الإخطار. قم بمراجعة الموقع بشكل دوري للحصول على التحديثات."
+ ]
+ },
+ {
+ "heading": "ثامنا. اتصل بنا",
+ "paragraphs": [
+ "يمكن إرسال الأسئلة حول هذه السياسة إلى [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "تاسعا. الاحتفاظ بالبيانات",
+ "paragraphs": [
+ "يتم الاحتفاظ بتقارير الأعطال والتشخيصات فقط طالما كان ذلك ضروريًا لتشخيص المشكلات وإصلاحها. يتم الاحتفاظ بمعرفات حساب الهاتف المحمول وسجلات المصادقة أثناء نشاط حسابك، ثم يتم حذفها أو إخفاء هويتها عند انتهاء حذف الحساب، إلا عندما تتطلب الواجبات الأمنية أو القانونية أو الفوترة أو منع الاحتيال الاحتفاظ بها. يتم الاحتفاظ بالبيانات التعريفية للجهاز والإقران حتى تقوم بإلغاء الإقران أو تسجيل الخروج وحذف البيانات المحلية أو حذف حسابك أو تقليم بيانات الاقتران القديمة. يتم الاحتفاظ بالرموز المميزة لخدمة الإشعارات Apple فقط أثناء تمكين الإشعارات وتتم إزالتها عند تعطيل الإشعارات، أو تسجيل الخروج، أو حذف حسابك، أو الإبلاغ عن Apple أن الرمز المميز غير صالح. يتم الاحتفاظ بتحليلات منتجات الأجهزة المحمولة في PostHog لمدة تصل إلى 24 شهرًا ما لم تطلب الحذف مسبقًا. تقوم إعدادات حساب الهاتف المحمول بحذف أو إخفاء هوية الحساب والجهاز والإقران والإشعارات والفوترة والبيانات السحابية المملوكة لـ cmux، وحذف شخص PostHog المرتبط بالحساب، وطلب حذف أحداث وتسجيلات تحليلات الهاتف المحمول الخاصة به. قد تكتمل بعض أعمال حذف الموفر بشكل غير متزامن. اطلب الحذف في إعدادات حساب الهاتف المحمول أو عن طريق الاتصال بـ [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/bs.json b/web/app/[locale]/(legal)/privacy-policy/content/bs.json
new file mode 100644
index 000000000000..7bace64693ba
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/bs.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Politika privatnosti — cmux",
+ "metadataDescription": "Politika privatnosti za cmux",
+ "title": "Politika privatnosti",
+ "lastUpdated": "Posljednje ažuriranje: 10. jula 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow („Kompanija“) je posvećena održavanju robusne zaštite privatnosti za svoje korisnike. Ova Politika privatnosti objašnjava kako prikupljamo, koristimo i štitimo informacije koje nam dostavite.",
+ "U ovoj politici, \"Site\" označava web stranicu Kompanije na adresi [cmux.com](https://cmux.com). \"Aplikacija\" znači cmux desktop aplikaciju za macOS i cmux mobilnu aplikaciju za iPhone i iPad. \"Usluga\" označava stranicu i aplikaciju zajedno. \"Mi\", \"nas\" i \"naš\" znači Kompanija. \"Vi\" znači korisnik naše usluge.",
+ "Korištenjem naše usluge, prihvatate ovu Politiku privatnosti i naše [Uslove korištenja](https://cmux.com/terms-of-service), te pristajete na prikupljanje, skladištenje, korištenje i otkrivanje ovdje opisanih."
+ ]
+ },
+ {
+ "heading": "I. Informacije koje prikupljamo",
+ "paragraphs": [
+ "Prikupljamo nelične podatke i lične podatke. Nelični podaci vas ne mogu identificirati i uključuju anonimne podatke o korištenju, tipove platforme i dijagnostiku pada. Lični podaci uključuju vašu adresu e-pošte, identifikatore naloga i informacije koje odaberete da pružite kada se prijavite, kontaktirate nas, uparite uređaj ili koristite Aplikaciju."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informacije prikupljene tehnologijom",
+ "paragraphs": [
+ "Aplikacija može automatski prikupljati sljedeće informacije:"
+ ],
+ "bullets": [
+ "Izvještaji o padu i dijagnostika grešaka putem Sentry.",
+ "Verzija operativnog sistema i verzija aplikacije.",
+ "Analitika proizvoda i događaji korištenja funkcija za web mjesto i aplikaciju.",
+ "Metapodaci uređaja, računa i uparivanja potrebni su za povezivanje vaših prijavljenih uređaja.",
+ "Apple Tokeni uređaja usluge Push Notification, samo nakon što omogućite telefonska obavještenja."
+ ],
+ "afterBullets": [
+ "Aplikacija macOS proverava da li postoje ažuriranja preko Sparkle, koji može poslati verzije vašeg operativnog sistema i aplikacije na naš server za ažuriranje. Aplikacija iPhone i iPad se ažurira preko App Store, a ne Sparkle.",
+ "Stranica koristi PostHog za analizu prikaza stranica i navigacije. PostHog pohranjuje kolačić da razlikuje posjetitelje. Ako se pridružite listi čekanja platforme, vaša poslana e-pošta se snima u PostHog tako da vas možemo obavijestiti. Ako pošaljete obrazac za kontakt za preduzeće, mi bilježimo kompaniju i kontakt podatke koje navedete u PostHog i šaljemo ih u naš privatni Slack radni prostor i e-poštu osnivača kako bismo mogli odgovoriti. Analitiku web stranice možete blokirati ekstenzijom preglednika koja blokira skripte za praćenje.",
+ "iPhone i iPad aplikacija šalje analitičke događaje proizvoda našem PostHog proxy serveru. Ovi događaji pomažu u dijagnosticiranju pouzdanosti, razumijevanju upotrebe funkcija i poboljšanju aplikacije. Oni uključuju događaje pokretanja aplikacije i sesije, status prijave, pokušaje uparivanja i rezultate, oporavak veze, otvaranje radnog prostora, broj bajtova i redova za unos terminala i rezultate za prijavu obavijesti ili dubinske veze obavijesti. Mobilna analitika ne šalje na PostHog tekst naredbe terminala, izlaz terminala, odabrane fotografije ili transkripte govora. Prije prijave, događaji koriste nasumični identifikator klijenta po instalaciji. Nakon prijave, naš server prilaže identifikator vašeg Stack Auth naloga prije prosljeđivanja događaja na PostHog. Analitika i izvještaji o rušenju počinju onemogućeni i šalju se tek nakon što omogućite Dijeli analitiku i izvještaje o rušenju u postavkama. Isključivanjem te kontrole zaustavlja se baferovanje ili slanje analitike i zaustavlja se izvještavanje o padu. Kontaktirajte [founders@manaflow.com](mailto:founders@manaflow.com) da zatražite brisanje analitike povezane s vašim računom."
+ ]
+ },
+ {
+ "heading": "2. Informacije koje dajete direktno",
+ "paragraphs": [
+ "Ako nas kontaktirate putem e-pošte, naše kontakt stranice ili obrasca za kontakt preduzeća, prikupljamo informacije koje nam dajete, uključujući ime, e-poštu, kompaniju, ulogu, broj telefona, zemlju, potrebe za implementacijom i komentare. Ako se pridružite listi čekanja na platformi, prikupljamo vašu poslanu e-poštu kako bismo vas obavijestili kada se platforma pokrene i šaljemo e-poštu za prijavu i odabrane platforme u naš privatni Slack radni prostor.",
+ "Kada se prijavite, primamo informacije o autentifikaciji kao što su vaša adresa e-pošte i identifikator provajdera od Apple, Google, GitHub ili kod prijave putem e-pošte. Kada uparite mobilnu aplikaciju sa Mac-om, obrađujemo informacije o uparivanju potrebne za povezivanje uređaja. Kada pregledate radni prostor, pošaljete unos terminala, priložite odabrane fotografije, koristite transkripciju govora ili primate obavještenja terminala, povezani sadržaj ili transkript mogu proći između vaših uređaja i naše usluge prema potrebi za pružanje te funkcije.",
+ "Pristup kameri se koristi samo za skeniranje cmux kodova uparivanja QR. Pristup mikrofonu i prepoznavanju govora se koristi samo kada odaberete transkripciju glasa u okviru za poruke. Pristup fototeci se koristi samo kada odaberete fotografije za prilaganje."
+ ]
+ },
+ {
+ "heading": "3. Privatnost djece",
+ "paragraphs": [
+ "Usluga nije usmjerena na bilo koga mlađeg od 13 godina i ne prikupljamo svjesno informacije od bilo koga mlađeg od 13 godina. Ako vjerujete da smo prikupili takve informacije, kontaktirajte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Usluge trećih strana",
+ "paragraphs": [
+ "Aplikacija se integrira sa ovim uslugama trećih strana:"
+ ],
+ "bullets": [
+ "Stack Auth: autentikacija i upravljanje nalogom za prijavu, sesije i brisanje naloga.",
+ "Apple, Google i GitHub: opcioni provajderi za prijavu koji šalju informacije o nalogu potrebne za vašu autentifikaciju.",
+ "Apple Push Notification usluga: obavještenja za iPhone i iPad nakon što se uključite.",
+ "Apple Prepoznavanje govora: transkripcija glasa kada je odaberete u mobilnoj aplikaciji.",
+ "Sentry: praćenje grešaka i izvještavanje o padu, koje može prikupljati evidencije grešaka, tragove steka, informacije o uređaju i verziju operativnog sistema.",
+ "Sparkle: okvir za automatsko ažuriranje macOS, koji šalje verzije aplikacija i operativnog sistema da provjeri ima li macOS ažuriranja.",
+ "Ghostty / libghostty: mehanizam za prikazivanje terminala, koji radi lokalno na vašem uređaju.",
+ "PostHog: analiza web stranica i mobilnih proizvoda, uključujući prikaze stranica, obrasce navigacije, metapodatke preglednika, događaje mobilnih funkcija, mobilnu analitiku povezanu s računom nakon prijave putem proxyja prve strane i poslanu e-poštu na listi čekanja kako bismo vas mogli obavijestiti.",
+ "Resend: transakcijska isporuka e-pošte. Vaša e-pošta se šalje na Resend samo ako dobrovoljno pošaljete povratne informacije.",
+ "Slack: privatne interne obavijesti. Ako se pridružite listi čekanja platforme, e-pošta i platforme koje pošaljete šalju se u naš privatni radni prostor Slack."
+ ],
+ "afterBullets": [
+ "Svaki servis ima svoju politiku privatnosti. Kada treća strana obrađuje lične podatke za cmux, zahtijevamo zaštitne mjere barem jednako zaštitne kao ova politika i ograničavamo upotrebu na pružanje usluga za cmux."
+ ]
+ },
+ {
+ "heading": "III. Kako koristimo i dijelimo informacije",
+ "paragraphs": [
+ "Ne prodajemo, ne trgujemo, iznajmljujemo niti dijelimo lične podatke sa trećim stranama radi marketinga. Koristimo izvještaje o padu i dijagnostiku samo za poboljšanje aplikacije. Možemo otkriti informacije kada u dobroj vjeri vjerujemo da je otkrivanje neophodno za pravni proces ili zaštitu od štete."
+ ]
+ },
+ {
+ "heading": "IV. Kako štitimo informacije",
+ "paragraphs": [
+ "Koristimo mjere osmišljene za sprječavanje neovlaštenog pristupa, uključujući šifriranje i siguran serverski softver. Nijedan način prijenosa ili skladištenja nije potpuno siguran, a korištenje Usluge uključuje ovaj rizik."
+ ]
+ },
+ {
+ "heading": "V. Vaša prava",
+ "paragraphs": [
+ "Ovisno o vašoj lokaciji, primjenjivi zakoni kao što su GDPR ili CCPA mogu vam dati ova prava:"
+ ],
+ "bullets": [
+ "Pristupite kopiji podataka koje imamo o vama.",
+ "Ispravite netačne podatke.",
+ "Zatražite brisanje vaših podataka.",
+ "Primite prenosive podatke.",
+ "Ograničite ili prigovorite na obradu."
+ ],
+ "afterBullets": [
+ "Za korištenje ovih prava, kontaktirajte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Linkovi na druge web stranice",
+ "paragraphs": [
+ "Usluga može povezivati na web stranice trećih strana. Nismo odgovorni za njihovu praksu privatnosti. Ova politika se odnosi samo na informacije koje prikupljamo."
+ ]
+ },
+ {
+ "heading": "VII. Promjene ove politike",
+ "paragraphs": [
+ "Možemo promijeniti ovu politiku. Značajne promjene stupaju na snagu 30 dana nakon obavještenja. Povremeno provjeravajte stranicu za ažuriranja."
+ ]
+ },
+ {
+ "heading": "VIII. Kontaktirajte nas",
+ "paragraphs": [
+ "Pitanja o ovoj politici mogu se poslati na [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Zadržavanje podataka",
+ "paragraphs": [
+ "Izvještaji o padu i dijagnostika čuvaju se samo onoliko dugo koliko je potrebno za dijagnosticiranje i rješavanje problema. Identifikatori mobilnog računa i zapisi o autentifikaciji čuvaju se dok je vaš račun aktivan, a zatim se brišu ili anonimiziraju kada se završi brisanje računa, osim kada je potrebno čuvanje sigurnosnih, pravnih, naplatnih ili prevara. Metapodaci uređaja i uparivanja se čuvaju sve dok ne prekinete uparivanje, odjavite se i izbrišete lokalne podatke, izbrišete svoj račun ili ne skinete zastarjeli podaci o uparivanju. Tokeni usluge Apple Push Notification čuvaju se samo dok su obavještenja omogućena i uklanjaju se kada onemogućite obavještenja, odjavite se, izbrišete svoj račun ili Apple prijavi token nevažećim. Analitika mobilnih proizvoda u PostHog čuva se do 24 mjeseca osim ako ne zatražite ranije brisanje. Postavke mobilnog računa brišu ili anonimiziraju račun u vlasništvu cmux, uređaj, uparivanje, obavještenja, naplatu i podatke u oblaku, brišu osobu PostHog povezanu s računom i zahtijevaju brisanje njegovih događaja i snimaka mobilne analitike. Neki posao brisanja provajdera može se završiti asinhrono. Zatražite brisanje u postavkama mobilnog naloga ili kontaktiranjem [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/da.json b/web/app/[locale]/(legal)/privacy-policy/content/da.json
new file mode 100644
index 000000000000..9439f7dcbe29
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/da.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Privatlivspolitik — cmux",
+ "metadataDescription": "Privatlivspolitik for cmux",
+ "title": "Privatlivspolitik",
+ "lastUpdated": "Sidst opdateret: 10. juli 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (\"Virksomheden\") er forpligtet til at opretholde robust privatlivsbeskyttelse for sine brugere. Denne privatlivspolitik forklarer, hvordan vi indsamler, bruger og beskytter oplysninger, du giver os.",
+ "I denne politik betyder \"Site\" virksomhedens websted på [cmux.com](https://cmux.com). \"Applikation\" betyder cmux desktop-applikationen til macOS og cmux-mobilapplikationen til iPhone og iPad. \"Service\" betyder webstedet og applikationen sammen. \"Vi\", \"os\" og \"vores\" betyder virksomheden. \"Du\" betyder en bruger af vores Tjeneste.",
+ "Ved at bruge vores tjeneste accepterer du denne privatlivspolitik og vores [servicevilkår](https://cmux.com/terms-of-service) og giver dit samtykke til indsamling, opbevaring, brug og offentliggørelse beskrevet her."
+ ]
+ },
+ {
+ "heading": "I. Oplysninger, vi indsamler",
+ "paragraphs": [
+ "Vi indsamler ikke-personlige oplysninger og personlige oplysninger. Ikke-personlige oplysninger kan ikke identificere dig og inkluderer anonyme brugsdata, platformstyper og nedbrudsdiagnostik. Personlige oplysninger inkluderer din e-mailadresse, konto-id'er og oplysninger, du vælger at angive, når du logger ind, kontakter os, parrer en enhed eller bruger applikationen."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Information indsamlet gennem teknologi",
+ "paragraphs": [
+ "Applikationen kan automatisk indsamle følgende oplysninger:"
+ ],
+ "bullets": [
+ "Nedbrudsrapporter og fejldiagnostik gennem Sentry.",
+ "Operativsystemversion og applikationsversion.",
+ "Produktanalyse og hændelser vedrørende brug af funktioner for webstedet og applikationen.",
+ "Enheds-, konto- og parringsmetadata, der er nødvendige for at forbinde dine loggede enheder.",
+ "Apple Push Notification service enhedstokens, kun efter du har aktiveret telefonmeddelelser."
+ ],
+ "afterBullets": [
+ "macOS-applikationen søger efter opdateringer gennem Sparkle, som kan sende dit operativsystem og applikationsversioner til vores opdateringsserver. iPhone- og iPad-applikationen opdateres gennem App Store, ikke Sparkle.",
+ "Siden bruger PostHog til sidevisning og navigationsanalyse. PostHog gemmer en cookie for at skelne besøgende. Hvis du tilmelder dig en platforms venteliste, bliver din indsendte e-mail registreret i PostHog, så vi kan give dig besked. Hvis du indsender Enterprise-kontaktformularen, registrerer vi virksomheden og kontaktoplysningerne, du angiver, i PostHog og sender dem til vores private Slack-arbejdsområde og grundlæggernes e-mail-indbakke, så vi kan svare. Du kan blokere webstedsanalyse med en browserudvidelse, der blokerer sporingsscripts.",
+ "iPhone- og iPad-applikationen sender produktanalysehændelser til vores serverside PostHog-proxy. Disse hændelser hjælper med at diagnosticere pålidelighed, forstå funktionsbrug og forbedre applikationen. De omfatter applancering og -sessionsbegivenheder, log-in-status, parringsforsøg og resultater, gendannelse af forbindelse, åbninger af arbejdsområde, terminalinput-byte og linjeantal og meddelelsestilvalg eller meddelelses-deep-link-resultater. Mobile analytics sender ikke terminalkommandotekst, terminaloutput, udvalgte fotos eller taletransskriptioner til PostHog. Før du logger på, bruger hændelser et tilfældigt klient-id pr. installation. Efter login vedhæfter vores server din Stack Auth-konto-id, før den videresender begivenheder til PostHog. Analytics og nedbrudsrapporter starter deaktiveret og sendes først, når du har aktiveret Del Analytics og nedbrudsrapporter i Indstillinger. Deaktivering af denne kontrol stopper analyser i at blive bufferet eller sendt og stopper nedbrudsrapportering. Kontakt [founders@manaflow.com](mailto:founders@manaflow.com) for at anmode om sletning af analyser knyttet til din konto."
+ ]
+ },
+ {
+ "heading": "2. Oplysninger, du giver direkte",
+ "paragraphs": [
+ "Hvis du kontakter os via e-mail, vores kontaktside eller Enterprise-kontaktformularen, indsamler vi oplysninger, du giver, herunder navn, e-mail, virksomhed, rolle, telefonnummer, land, implementeringsbehov og kommentarer. Hvis du tilmelder dig en platforms venteliste, indsamler vi din indsendte e-mail for at give dig besked, når den pågældende platform lanceres, og sender tilmeldings-e-mailen og udvalgte platforme til vores private Slack-arbejdsområde.",
+ "Når du logger ind, modtager vi godkendelsesoplysninger såsom din e-mailadresse og udbyder-id fra Apple, Google, GitHub eller login med e-mail-kode. Når du parrer mobilappen med en Mac, behandler vi de parringsoplysninger, der er nødvendige for at forbinde enhederne. Når du ser et arbejdsområde, sender terminalinput, vedhæfter udvalgte billeder, bruger taletransskription eller modtager terminalmeddelelser, kan det relaterede indhold eller transskription passere mellem dine enheder og vores service efter behov for at levere denne funktion.",
+ "Kameraadgang bruges kun til at scanne cmux-parring af QR-koder. Mikrofon- og talegenkendelsesadgang bruges kun, når du vælger stemmetransskription i beskedboksen. Fotobiblioteksadgang bruges kun, når du vælger billeder at vedhæfte."
+ ]
+ },
+ {
+ "heading": "3. Børns privatliv",
+ "paragraphs": [
+ "Tjenesten er ikke rettet til nogen under 13, og vi indsamler ikke bevidst oplysninger fra nogen under 13. Hvis du mener, at vi har indsamlet sådanne oplysninger, skal du kontakte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Tredjepartstjenester",
+ "paragraphs": [
+ "Applikationen integreres med disse tredjepartstjenester:"
+ ],
+ "bullets": [
+ "Stack Auth: godkendelse og kontostyring til login, sessioner og kontosletning.",
+ "Apple, Google og GitHub: valgfri login-udbydere, der sender kontooplysninger, der kræves for at godkende dig.",
+ "Apple Push Notification-tjeneste: meddelelser til iPhone og iPad, efter du har tilmeldt dig.",
+ "Apple talegenkendelse: stemmetransskription, når du vælger det i mobilappen.",
+ "Sentry: fejlsporing og nedbrudsrapportering, som kan indsamle fejllogfiler, stakspor, enhedsoplysninger og operativsystemversion.",
+ "Sparkle: macOS automatisk opdateringsramme, som sender applikations- og operativsystemversioner for at søge efter macOS-opdateringer.",
+ "Ghostty / libghostty: terminalgengivelsesmotoren, som kører lokalt på din enhed.",
+ "PostHog: websteds- og mobilproduktanalyse, herunder sidevisninger, navigationsmønstre, browsermetadata, mobilfunktionshændelser, kontotilknyttede mobilanalyse efter login via en førstepartsproxy og en indsendt venteliste-e-mail, så vi kan give dig besked.",
+ "Resend: transaktionel e-mail-levering. Din e-mail sendes kun til Resend, hvis du frivilligt sender feedback.",
+ "Slack: private interne meddelelser. Hvis du tilmelder dig en platforms venteliste, sendes den e-mail og de platforme, du indsender, til vores private Slack-arbejdsområde."
+ ],
+ "afterBullets": [
+ "Hver tjeneste har sin egen privatlivspolitik. Når en tredjepart behandler personlige oplysninger til cmux, kræver vi sikkerhedsforanstaltninger, der er mindst lige så beskyttende som denne politik og begrænser brugen til at levere tjenester til cmux."
+ ]
+ },
+ {
+ "heading": "III. Hvordan vi bruger og deler oplysninger",
+ "paragraphs": [
+ "Vi sælger, bytter, udlejer eller deler ikke personlige oplysninger med tredjeparter til markedsføring. Vi bruger kun nedbrudsrapporter og diagnostik til at forbedre applikationen. Vi kan videregive oplysninger, når vi i god tro mener, at videregivelse er nødvendig for juridisk proces eller beskyttelse mod skade."
+ ]
+ },
+ {
+ "heading": "IV. Hvordan vi beskytter oplysninger",
+ "paragraphs": [
+ "Vi bruger foranstaltninger designet til at forhindre uautoriseret adgang, herunder kryptering og sikker serversoftware. Ingen transmissions- eller lagringsmetode er fuldstændig sikker, og brugen af Tjenesten indebærer denne risiko."
+ ]
+ },
+ {
+ "heading": "V. Dine rettigheder",
+ "paragraphs": [
+ "Afhængigt af din placering kan gældende love såsom GDPR eller CCPA give dig disse rettigheder:"
+ ],
+ "bullets": [
+ "Få adgang til en kopi af data, vi har om dig.",
+ "Ret unøjagtige data.",
+ "Anmod om sletning af dine data.",
+ "Modtag bærbare data.",
+ "Begræns eller gør indsigelse mod behandling."
+ ],
+ "afterBullets": [
+ "For at udøve disse rettigheder skal du kontakte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Links til andre websteder",
+ "paragraphs": [
+ "Tjenesten kan linke til tredjepartswebsteder. Vi er ikke ansvarlige for deres privatlivspraksis. Denne politik gælder kun for oplysninger, vi indsamler."
+ ]
+ },
+ {
+ "heading": "VII. Ændringer af denne politik",
+ "paragraphs": [
+ "Vi kan ændre denne politik. Væsentlige ændringer træder i kraft 30 dage efter meddelelsen. Tjek siden jævnligt for opdateringer."
+ ]
+ },
+ {
+ "heading": "VIII. Kontakt os",
+ "paragraphs": [
+ "Spørgsmål om denne politik kan sendes til [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Dataopbevaring",
+ "paragraphs": [
+ "Nedbrudsrapporter og diagnostik gemmes kun så længe det er nødvendigt for at diagnosticere og løse problemer. Mobilkonto-id'er og godkendelsesregistreringer opbevares, mens din konto er aktiv, og slettes eller anonymiseres derefter, når kontosletningen afsluttes, undtagen når sikkerheds-, juridiske, fakturerings- eller svindelforebyggende pligter kræver opbevaring. Enheds- og parringsmetadata opbevares, indtil du ophæver parringen, logger ud og sletter lokale data, sletter din konto, eller forældede parringsdata beskæres. Apple Push Notification-tjenestetokens opbevares kun, mens notifikationer er aktiveret og fjernes, når du deaktiverer notifikationer, logger ud, sletter din konto, eller Apple rapporterer tokenet ugyldigt. Mobil produktanalyse i PostHog opbevares i op til 24 måneder, medmindre du anmoder om tidligere sletning. Mobilkontoindstillinger sletter eller anonymiserer cmux-ejet konto, enhed, parring, meddelelse, fakturering og skydata, sletter den kontotilknyttede PostHog-person og anmoder om sletning af dens mobilanalysebegivenheder og optagelser. Noget udbydersletningsarbejde kan udføres asynkront. Anmod om sletning i mobilkontoindstillinger eller ved at kontakte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/de.json b/web/app/[locale]/(legal)/privacy-policy/content/de.json
new file mode 100644
index 000000000000..b2fbb542b26f
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/de.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Datenschutzrichtlinie – cmux",
+ "metadataDescription": "Datenschutzrichtlinie für cmux",
+ "title": "Datenschutzrichtlinie",
+ "lastUpdated": "Letzte Aktualisierung: 10. Juli 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (das „Unternehmen“) verpflichtet sich, einen strengen Datenschutz für seine Benutzer aufrechtzuerhalten. In dieser Datenschutzrichtlinie wird erläutert, wie wir die von Ihnen bereitgestellten Informationen erfassen, verwenden und schützen.",
+ "In dieser Richtlinie bezeichnet „Site“ die Website des Unternehmens unter [cmux.com](https://cmux.com). „Anwendung“ bezeichnet die cmux-Desktopanwendung für macOS und die cmux-Mobilanwendung für iPhone und iPad. „Dienst“ bezeichnet die Website und die Anwendung zusammen. Mit „wir“, „uns“ und „unser“ ist das Unternehmen gemeint. „Sie“ bezeichnet einen Benutzer unseres Dienstes.",
+ "Durch die Nutzung unseres Dienstes akzeptieren Sie diese Datenschutzrichtlinie und unsere [Nutzungsbedingungen](https://cmux.com/terms-of-service) und stimmen der hier beschriebenen Erfassung, Speicherung, Nutzung und Offenlegung zu."
+ ]
+ },
+ {
+ "heading": "I. Informationen, die wir sammeln",
+ "paragraphs": [
+ "Wir erfassen nicht-personenbezogene Daten und personenbezogene Daten. Nicht-personenbezogene Daten können Sie nicht identifizieren und umfassen anonyme Nutzungsdaten, Plattformtypen und Absturzdiagnosen. Zu den personenbezogenen Daten gehören Ihre E-Mail-Adresse, Kontokennungen und Informationen, die Sie angeben, wenn Sie sich anmelden, mit uns Kontakt aufnehmen, ein Gerät koppeln oder die Anwendung verwenden."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Durch Technologie gesammelte Informationen",
+ "paragraphs": [
+ "Die Anwendung kann automatisch die folgenden Informationen erfassen:"
+ ],
+ "bullets": [
+ "Absturzberichte und Fehlerdiagnose über Sentry.",
+ "Betriebssystemversion und Anwendungsversion.",
+ "Produktanalysen und Funktionsnutzungsereignisse für die Website und Anwendung.",
+ "Geräte-, Konto- und Kopplungsmetadaten, die zum Verbinden Ihrer angemeldeten Geräte erforderlich sind.",
+ "Apple Push-Benachrichtigungsdienst-Gerätetokens, erst nachdem Sie Telefonbenachrichtigungen aktiviert haben."
+ ],
+ "afterBullets": [
+ "Die macOS-Anwendung sucht über Sparkle nach Updates, das möglicherweise Ihre Betriebssystem- und Anwendungsversionen an unseren Update-Server sendet. Die iPhone- und iPad-Anwendung wird über App Store und nicht über Sparkle aktualisiert.",
+ "Die Website verwendet PostHog für Seitenaufruf- und Navigationsanalysen. PostHog speichert ein Cookie, um Besucher zu unterscheiden. Wenn Sie sich einer Plattform-Warteliste anschließen, wird Ihre übermittelte E-Mail in PostHog aufgezeichnet, damit wir Sie benachrichtigen können. Wenn Sie das Enterprise-Kontaktformular absenden, erfassen wir die von Ihnen angegebenen Unternehmens- und Kontaktdaten in PostHog und senden sie an unseren privaten Slack-Arbeitsbereich und den E-Mail-Posteingang für Gründer, damit wir antworten können. Sie können Website-Analysen mit einer Browsererweiterung blockieren, die Tracking-Skripte blockiert.",
+ "Die iPhone- und iPad-Anwendung sendet Produktanalyseereignisse an unseren serverseitigen PostHog-Proxy. Diese Ereignisse helfen bei der Diagnose der Zuverlässigkeit, dem Verständnis der Funktionsnutzung und der Verbesserung der Anwendung. Dazu gehören App-Start- und Sitzungsereignisse, Anmeldestatus, Pairing-Versuche und -Ergebnisse, Verbindungswiederherstellung, Arbeitsbereichsöffnungen, Terminal-Eingabebyte- und Zeilenanzahl sowie Benachrichtigungs-Opt-in- oder Benachrichtigungs-Deep-Link-Ergebnisse. Mobile Analytics sendet keinen Terminalbefehlstext, keine Terminalausgabe, keine ausgewählten Fotos oder Sprachtranskripte an PostHog. Vor der Anmeldung verwenden Ereignisse eine zufällige Client-ID pro Installation. Nach der Anmeldung hängt unser Server Ihre Stack Auth-Kontokennung an, bevor er Ereignisse an PostHog weiterleitet. Analysen und Absturzberichte sind zunächst deaktiviert und werden erst gesendet, nachdem Sie „Analysen und Absturzberichte teilen“ in den Einstellungen aktiviert haben. Wenn Sie diese Kontrolle deaktivieren, wird verhindert, dass Analysen zwischengespeichert oder gesendet werden, und die Absturzberichte werden gestoppt. Wenden Sie sich an [founders@manaflow.com](mailto:founders@manaflow.com), um die Löschung der mit Ihrem Konto verknüpften Analysen anzufordern."
+ ]
+ },
+ {
+ "heading": "2. Informationen, die Sie direkt bereitstellen",
+ "paragraphs": [
+ "Wenn Sie uns per E-Mail, über unsere Kontaktseite oder über das Enterprise-Kontaktformular kontaktieren, erfassen wir die von Ihnen bereitgestellten Informationen, einschließlich Name, E-Mail-Adresse, Unternehmen, Rolle, Telefonnummer, Land, Bereitstellungsanforderungen und Kommentare. Wenn Sie sich einer Warteliste für eine Plattform anschließen, erfassen wir Ihre übermittelte E-Mail, um Sie zu benachrichtigen, wenn diese Plattform startet, und senden die Anmelde-E-Mail und ausgewählte Plattformen an unseren privaten Slack-Arbeitsbereich.",
+ "Wenn Sie sich anmelden, erhalten wir Authentifizierungsinformationen wie Ihre E-Mail-Adresse und Anbieterkennung von Apple, Google, GitHub oder die E-Mail-Code-Anmeldung. Wenn Sie die mobile App mit einem Mac koppeln, verarbeiten wir die zum Verbinden der Geräte erforderlichen Kopplungsinformationen. Wenn Sie einen Arbeitsbereich ansehen, Terminaleingaben senden, ausgewählte Fotos anhängen, Sprachtranskription verwenden oder Terminalbenachrichtigungen erhalten, können die zugehörigen Inhalte oder Transkripte je nach Bedarf zwischen Ihren Geräten und unserem Dienst übertragen werden, um diese Funktion bereitzustellen.",
+ "Der Kamerazugriff wird nur zum Scannen von cmux-Pairing-QR-Codes verwendet. Der Zugriff auf Mikrofon und Spracherkennung wird nur verwendet, wenn Sie im Nachrichtenfeld die Sprachtranskription auswählen. Der Zugriff auf die Fotobibliothek wird nur verwendet, wenn Sie Fotos zum Anhängen auswählen."
+ ]
+ },
+ {
+ "heading": "3. Privatsphäre von Kindern",
+ "paragraphs": [
+ "Der Dienst richtet sich nicht an Personen unter 13 Jahren und wir sammeln wissentlich keine Informationen von Personen unter 13 Jahren. Wenn Sie glauben, dass wir solche Informationen gesammelt haben, wenden Sie sich an [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Dienste Dritter",
+ "paragraphs": [
+ "Die Anwendung lässt sich in die folgenden Dienste von Drittanbietern integrieren:"
+ ],
+ "bullets": [
+ "Stack Auth: Authentifizierung und Kontoverwaltung für Anmeldung, Sitzungen und Kontolöschung.",
+ "Apple, Google und GitHub: optionale Anmeldeanbieter, die Kontoinformationen senden, die für Ihre Authentifizierung erforderlich sind.",
+ "Apple-Push-Benachrichtigungsdienst: Benachrichtigungen an iPhone und iPad, nachdem Sie sich angemeldet haben.",
+ "Apple Spracherkennung: Sprachtranskription, wenn Sie sie in der mobilen App auswählen.",
+ "Sentry: Fehlerverfolgung und Absturzberichte, die Fehlerprotokolle, Stack-Traces, Geräteinformationen und die Betriebssystemversion sammeln können.",
+ "Sparkle: das macOS-Auto-Update-Framework, das Anwendungs- und Betriebssystemversionen sendet, um nach macOS-Updates zu suchen.",
+ "Ghostty / libghostty: die Terminal-Rendering-Engine, die lokal auf Ihrem Gerät ausgeführt wird.",
+ "PostHog: Website- und mobile Produktanalysen, einschließlich Seitenaufrufe, Navigationsmuster, Browser-Metadaten, mobile Funktionsereignisse, kontoverknüpfte mobile Analysen nach der Anmeldung über einen Erstanbieter-Proxy und eine übermittelte Wartelisten-E-Mail, damit wir Sie benachrichtigen können.",
+ "Resend: Transaktionale E-Mail-Zustellung. Ihre E-Mail wird nur dann an Resend gesendet, wenn Sie freiwillig Feedback abgeben.",
+ "Slack: private interne Benachrichtigungen. Wenn Sie sich einer Plattform-Warteliste anschließen, werden die von Ihnen übermittelten E-Mails und Plattformen an unseren privaten Slack-Arbeitsbereich gesendet."
+ ],
+ "afterBullets": [
+ "Jeder Dienst hat seine eigene Datenschutzrichtlinie. Wenn ein Dritter personenbezogene Daten für cmux verarbeitet, benötigen wir Schutzmaßnahmen, die mindestens so schützend sind wie diese Richtlinie, und beschränken die Nutzung auf die Bereitstellung von Diensten für cmux."
+ ]
+ },
+ {
+ "heading": "III. Wie wir Informationen nutzen und weitergeben",
+ "paragraphs": [
+ "Wir verkaufen, tauschen, vermieten oder geben personenbezogene Daten nicht zu Marketingzwecken an Dritte weiter. Wir verwenden Absturzberichte und Diagnosen ausschließlich zur Verbesserung der Anwendung. Wir können Informationen offenlegen, wenn wir in gutem Glauben davon ausgehen, dass die Offenlegung für ein Gerichtsverfahren oder zum Schutz vor Schaden erforderlich ist."
+ ]
+ },
+ {
+ "heading": "IV. Wie wir Informationen schützen",
+ "paragraphs": [
+ "Wir verwenden Maßnahmen zur Verhinderung unbefugten Zugriffs, einschließlich Verschlüsselung und sicherer Serversoftware. Keine Übertragungs- oder Speichermethode ist absolut sicher und die Nutzung des Dienstes birgt dieses Risiko."
+ ]
+ },
+ {
+ "heading": "V. Ihre Rechte",
+ "paragraphs": [
+ "Abhängig von Ihrem Standort können Ihnen geltende Gesetze wie GDPR oder CCPA diese Rechte einräumen:"
+ ],
+ "bullets": [
+ "Greifen Sie auf eine Kopie der Daten zu, die wir über Sie gespeichert haben.",
+ "Korrigieren Sie ungenaue Daten.",
+ "Fordern Sie die Löschung Ihrer Daten an.",
+ "Empfangen Sie tragbare Daten.",
+ "Einschränkung oder Widerspruch gegen die Verarbeitung."
+ ],
+ "afterBullets": [
+ "Um diese Rechte auszuüben, wenden Sie sich an [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Links zu anderen Websites",
+ "paragraphs": [
+ "Der Dienst kann Links zu Websites Dritter enthalten. Wir sind nicht für deren Datenschutzpraktiken verantwortlich. Diese Richtlinie gilt nur für die von uns erfassten Informationen."
+ ]
+ },
+ {
+ "heading": "VII. Änderungen an dieser Richtlinie",
+ "paragraphs": [
+ "Wir können diese Richtlinie ändern. Wesentliche Änderungen treten 30 Tage nach Bekanntgabe in Kraft. Überprüfen Sie die Website regelmäßig auf Aktualisierungen."
+ ]
+ },
+ {
+ "heading": "VIII. Kontaktieren Sie uns",
+ "paragraphs": [
+ "Fragen zu dieser Richtlinie können an [founders@manaflow.com](mailto:founders@manaflow.com) gesendet werden."
+ ]
+ },
+ {
+ "heading": "IX. Datenaufbewahrung",
+ "paragraphs": [
+ "Absturzberichte und Diagnosen werden nur so lange aufbewahrt, wie es zur Diagnose und Behebung von Problemen erforderlich ist. Identifikatoren und Authentifizierungsdaten für mobile Konten werden aufbewahrt, solange Ihr Konto aktiv ist, und nach Abschluss der Kontolöschung gelöscht oder anonymisiert, es sei denn, die Aufbewahrung ist aus Sicherheits-, Rechts-, Abrechnungs- oder Betrugspräventionsgründen erforderlich. Geräte- und Kopplungsmetadaten bleiben erhalten, bis Sie die Kopplung aufheben, sich abmelden und lokale Daten löschen, Ihr Konto löschen oder veraltete Kopplungsdaten bereinigt werden. Apple-Push-Benachrichtigungsdienst-Tokens werden nur aufbewahrt, solange Benachrichtigungen aktiviert sind, und werden entfernt, wenn Sie Benachrichtigungen deaktivieren, sich abmelden, Ihr Konto löschen oder Apple das Token als ungültig meldet. Mobile Produktanalysen in PostHog werden bis zu 24 Monate lang aufbewahrt, es sei denn, Sie beantragen eine frühere Löschung. Mobile Kontoeinstellungen löschen oder anonymisieren cmux-eigene Konto-, Geräte-, Kopplungs-, Benachrichtigungs-, Abrechnungs- und Cloud-Daten, löschen die mit dem Konto verknüpfte PostHog-Person und fordern die Löschung ihrer mobilen Analyseereignisse und Aufzeichnungen an. Einige Löscharbeiten für Anbieter werden möglicherweise asynchron abgeschlossen. Fordern Sie die Löschung in den Einstellungen des mobilen Kontos an oder wenden Sie sich an [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/en.json b/web/app/[locale]/(legal)/privacy-policy/content/en.json
new file mode 100644
index 000000000000..a7ea39f5c867
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/en.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Privacy Policy — cmux",
+ "metadataDescription": "Privacy policy for cmux",
+ "title": "Privacy Policy",
+ "lastUpdated": "Last updated: July 10, 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (the \"Company\") is committed to maintaining robust privacy protections for its users. This Privacy Policy explains how we collect, use, and safeguard information you provide to us.",
+ "In this policy, \"Site\" means the Company website at [cmux.com](https://cmux.com). \"Application\" means the cmux desktop application for macOS and the cmux mobile application for iPhone and iPad. \"Service\" means the Site and Application together. \"We,\" \"us,\" and \"our\" mean the Company. \"You\" means a user of our Service.",
+ "By using our Service, you accept this Privacy Policy and our [Terms of Service](https://cmux.com/terms-of-service), and consent to the collection, storage, use, and disclosure described here."
+ ]
+ },
+ {
+ "heading": "I. Information We Collect",
+ "paragraphs": [
+ "We collect Non-Personal Information and Personal Information. Non-Personal Information cannot identify you and includes anonymous usage data, platform types, and crash diagnostics. Personal Information includes your email address, account identifiers, and information you choose to provide when you sign in, contact us, pair a device, or use the Application."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Information collected through technology",
+ "paragraphs": [
+ "The Application may automatically collect the following information:"
+ ],
+ "bullets": [
+ "Crash reports and error diagnostics through Sentry.",
+ "Operating-system version and application version.",
+ "Product analytics and feature-usage events for the Site and Application.",
+ "Device, account, and pairing metadata needed to connect your signed-in devices.",
+ "Apple Push Notification service device tokens, only after you enable phone notifications."
+ ],
+ "afterBullets": [
+ "The macOS Application checks for updates through Sparkle, which may send your operating-system and application versions to our update server. The iPhone and iPad Application is updated through the App Store, not Sparkle.",
+ "The Site uses PostHog for page-view and navigation analytics. PostHog stores a cookie to distinguish visitors. If you join a platform waitlist, your submitted email is recorded in PostHog so we can notify you. If you submit the Enterprise contact form, we record the company and contact details you provide in PostHog and send them to our private Slack workspace and founders email inbox so we can respond. You can block website analytics with a browser extension that blocks tracking scripts.",
+ "The iPhone and iPad Application sends product analytics events to our server-side PostHog proxy. These events help diagnose reliability, understand feature use, and improve the Application. They include app launch and session events, sign-in status, pairing attempts and results, connection recovery, workspace opens, terminal-input byte and line counts, and notification opt-in or notification-deep-link results. Mobile analytics does not send terminal command text, terminal output, selected photos, or speech transcripts to PostHog. Before sign-in, events use a random per-install client identifier. After sign-in, our server attaches your Stack Auth account identifier before forwarding events to PostHog. Analytics and crash reports start disabled and are sent only after you enable Share Analytics and Crash Reports in Settings. Turning that control off stops analytics from being buffered or sent and stops crash reporting. Contact [founders@manaflow.com](mailto:founders@manaflow.com) to request deletion of analytics associated with your account."
+ ]
+ },
+ {
+ "heading": "2. Information you provide directly",
+ "paragraphs": [
+ "If you contact us by email, our contact page, or the Enterprise contact form, we collect information you provide, including name, email, company, role, phone number, country, deployment needs, and comments. If you join a platform waitlist, we collect your submitted email to notify you when that platform launches and send the signup email and selected platforms to our private Slack workspace.",
+ "When you sign in, we receive authentication information such as your email address and provider identifier from Apple, Google, GitHub, or email-code sign-in. When you pair the mobile app with a Mac, we process pairing information needed to connect the devices. When you view a workspace, send terminal input, attach selected photos, use speech transcription, or receive terminal notifications, the related content or transcript may pass between your devices and our service as needed to provide that feature.",
+ "Camera access is used only to scan cmux pairing QR codes. Microphone and speech-recognition access are used only when you choose voice transcription in the message box. Photo-library access is used only when you choose photos to attach."
+ ]
+ },
+ {
+ "heading": "3. Children’s Privacy",
+ "paragraphs": [
+ "The Service is not directed to anyone under 13, and we do not knowingly collect information from anyone under 13. If you believe we collected such information, contact [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Third-Party Services",
+ "paragraphs": [
+ "The Application integrates with these third-party services:"
+ ],
+ "bullets": [
+ "Stack Auth: authentication and account management for sign-in, sessions, and account deletion.",
+ "Apple, Google, and GitHub: optional sign-in providers that send account information required to authenticate you.",
+ "Apple Push Notification service: notifications to iPhone and iPad after you opt in.",
+ "Apple Speech Recognition: voice transcription when you choose it in the mobile app.",
+ "Sentry: error tracking and crash reporting, which may collect error logs, stack traces, device information, and operating-system version.",
+ "Sparkle: the macOS auto-update framework, which sends application and operating-system versions to check for macOS updates.",
+ "Ghostty / libghostty: the terminal-rendering engine, which runs locally on your device.",
+ "PostHog: website and mobile product analytics, including page views, navigation patterns, browser metadata, mobile feature events, account-linked mobile analytics after sign-in through a first-party proxy, and a submitted waitlist email so we can notify you.",
+ "Resend: transactional email delivery. Your email is sent to Resend only if you voluntarily submit feedback.",
+ "Slack: private internal notifications. If you join a platform waitlist, the email and platforms you submit are sent to our private Slack workspace."
+ ],
+ "afterBullets": [
+ "Each service has its own privacy policy. When a third party processes Personal Information for cmux, we require safeguards at least as protective as this policy and limit use to providing services to cmux."
+ ]
+ },
+ {
+ "heading": "III. How We Use and Share Information",
+ "paragraphs": [
+ "We do not sell, trade, rent, or share Personal Information with third parties for marketing. We use crash reports and diagnostics only to improve the Application. We may disclose information when we believe in good faith that disclosure is necessary for legal process or protection from harm."
+ ]
+ },
+ {
+ "heading": "IV. How We Protect Information",
+ "paragraphs": [
+ "We use measures designed to prevent unauthorized access, including encryption and secure server software. No transmission or storage method is completely secure, and use of the Service involves this risk."
+ ]
+ },
+ {
+ "heading": "V. Your Rights",
+ "paragraphs": [
+ "Depending on your location, applicable laws such as GDPR or CCPA may give you these rights:"
+ ],
+ "bullets": [
+ "Access a copy of data we hold about you.",
+ "Correct inaccurate data.",
+ "Request deletion of your data.",
+ "Receive portable data.",
+ "Restrict or object to processing."
+ ],
+ "afterBullets": [
+ "To exercise these rights, contact [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Links to Other Websites",
+ "paragraphs": [
+ "The Service may link to third-party websites. We are not responsible for their privacy practices. This policy applies only to information we collect."
+ ]
+ },
+ {
+ "heading": "VII. Changes to This Policy",
+ "paragraphs": [
+ "We may change this policy. Significant changes take effect 30 days after notification. Check the Site periodically for updates."
+ ]
+ },
+ {
+ "heading": "VIII. Contact Us",
+ "paragraphs": [
+ "Questions about this policy can be sent to [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Data Retention",
+ "paragraphs": [
+ "Crash reports and diagnostics are kept only as long as needed to diagnose and fix issues. Mobile account identifiers and authentication records are kept while your account is active, then deleted or anonymized when account deletion finishes, except when security, legal, billing, or fraud-prevention duties require retention. Device and pairing metadata is kept until you unpair, sign out and delete local data, delete your account, or stale pairing data is pruned. Apple Push Notification service tokens are kept only while notifications are enabled and are removed when you disable notifications, sign out, delete your account, or Apple reports the token invalid. Mobile product analytics in PostHog is kept for up to 24 months unless you request earlier deletion. Mobile account settings delete or anonymize cmux-owned account, device, pairing, notification, billing, and cloud data, delete the account-linked PostHog person, and request deletion of its mobile analytics events and recordings. Some provider deletion work may complete asynchronously. Request deletion in mobile account settings or by contacting [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/es.json b/web/app/[locale]/(legal)/privacy-policy/content/es.json
new file mode 100644
index 000000000000..a80a767363a7
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/es.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Política de privacidad - cmux",
+ "metadataDescription": "Política de privacidad para cmux",
+ "title": "Política de privacidad",
+ "lastUpdated": "Última actualización: 10 de julio de 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (la \"Compañía\") se compromete a mantener sólidas protecciones de privacidad para sus usuarios. Esta Política de Privacidad explica cómo recopilamos, utilizamos y salvaguardamos la información que usted nos proporciona.",
+ "En esta política, \"Sitio\" significa el sitio web de la Compañía en [cmux.com](https://cmux.com). \"Aplicación\" significa la aplicación de escritorio cmux para macOS y la aplicación móvil cmux para iPhone y iPad. \"Servicio\" significa el Sitio y la Aplicación juntos. \"Nosotros\", \"nos\" y \"nuestro\" se refieren a la Compañía. \"Usted\" significa un usuario de nuestro Servicio.",
+ "Al utilizar nuestro Servicio, acepta esta Política de privacidad y nuestros [Términos de servicio](https://cmux.com/terms-of-service), y acepta la recopilación, el almacenamiento, el uso y la divulgación que se describen aquí."
+ ]
+ },
+ {
+ "heading": "I. Información que recopilamos",
+ "paragraphs": [
+ "Recopilamos información no personal e información personal. La información no personal no puede identificarlo e incluye datos de uso anónimos, tipos de plataformas y diagnósticos de fallas. La información personal incluye su dirección de correo electrónico, identificadores de cuenta e información que usted elige proporcionar cuando inicia sesión, se comunica con nosotros, vincula un dispositivo o utiliza la Aplicación."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Información recopilada a través de la tecnología",
+ "paragraphs": [
+ "La Aplicación puede recopilar automáticamente la siguiente información:"
+ ],
+ "bullets": [
+ "Informes de fallos y diagnóstico de errores a través de Sentry.",
+ "Versión del sistema operativo y versión de la aplicación.",
+ "Análisis de productos y eventos de uso de funciones para el Sitio y la Aplicación.",
+ "Metadatos de dispositivo, cuenta y emparejamiento necesarios para conectar los dispositivos en los que hayas iniciado sesión.",
+ "Apple Tokens de dispositivo del servicio de notificaciones push, solo después de habilitar las notificaciones telefónicas."
+ ],
+ "afterBullets": [
+ "La aplicación macOS busca actualizaciones a través de Sparkle, que puede enviar las versiones de su sistema operativo y de la aplicación a nuestro servidor de actualizaciones. La aplicación iPhone y iPad se actualiza a través de App Store, no de Sparkle.",
+ "El Sitio utiliza PostHog para análisis de navegación y visualización de páginas. PostHog almacena una cookie para distinguir a los visitantes. Si se une a una lista de espera de la plataforma, el correo electrónico enviado se registra en PostHog para que podamos notificarle. Si envía el formulario de contacto empresarial, registramos la empresa y los datos de contacto que proporciona en PostHog y los enviamos a nuestro espacio de trabajo privado Slack y a la bandeja de entrada de correo electrónico de los fundadores para que podamos responder. Puede bloquear los análisis de sitios web con una extensión del navegador que bloquee los scripts de seguimiento.",
+ "Las aplicaciones iPhone y iPad envían eventos de análisis de productos a nuestro proxy PostHog del lado del servidor. Estos eventos ayudan a diagnosticar la confiabilidad, comprender el uso de funciones y mejorar la Aplicación. Incluyen eventos de inicio de sesión y de aplicación, estado de inicio de sesión, intentos y resultados de emparejamiento, recuperación de conexión, apertura de espacio de trabajo, recuento de líneas y bytes de entrada de terminal, y resultados de notificación de suscripción voluntaria o enlace profundo de notificación. El análisis móvil no envía texto de comando de terminal, salida de terminal, fotografías seleccionadas ni transcripciones de voz a PostHog. Antes de iniciar sesión, los eventos utilizan un identificador de cliente aleatorio por instalación. Después de iniciar sesión, nuestro servidor adjunta su identificador de cuenta Stack Auth antes de reenviar eventos a PostHog. Los informes de análisis y fallos comienzan deshabilitados y se envían solo después de habilitar Compartir análisis e informes de fallos en Configuración. Desactivar ese control impide que los análisis se almacenen en el búfer o se envíen y detiene los informes de fallos. Comuníquese con [founders@manaflow.com](mailto:founders@manaflow.com) para solicitar la eliminación de los análisis asociados con su cuenta."
+ ]
+ },
+ {
+ "heading": "2. Información que usted proporciona directamente",
+ "paragraphs": [
+ "Si se comunica con nosotros por correo electrónico, nuestra página de contacto o el formulario de contacto empresarial, recopilamos la información que usted proporciona, incluido el nombre, el correo electrónico, la empresa, la función, el número de teléfono, el país, las necesidades de implementación y los comentarios. Si se une a una lista de espera de una plataforma, recopilamos el correo electrónico enviado para notificarle cuando se lance esa plataforma y enviar el correo electrónico de registro y las plataformas seleccionadas a nuestro espacio de trabajo privado Slack.",
+ "Cuando inicia sesión, recibimos información de autenticación, como su dirección de correo electrónico y su identificador de proveedor de Apple, Google, GitHub o inicio de sesión con código de correo electrónico. Cuando vincula la aplicación móvil con una Mac, procesamos la información de emparejamiento necesaria para conectar los dispositivos. Cuando ve un espacio de trabajo, envía entradas de terminal, adjunta fotos seleccionadas, utiliza transcripción de voz o recibe notificaciones de terminal, el contenido relacionado o la transcripción pueden pasar entre sus dispositivos y nuestro servicio según sea necesario para proporcionar esa función.",
+ "El acceso a la cámara se utiliza únicamente para escanear códigos cmux de emparejamiento QR. El acceso al micrófono y al reconocimiento de voz se utiliza solo cuando elige la transcripción de voz en el cuadro de mensaje. El acceso a la biblioteca de fotografías se utiliza solo cuando elige las fotografías que desea adjuntar."
+ ]
+ },
+ {
+ "heading": "3. Privacidad de los niños",
+ "paragraphs": [
+ "El Servicio no está dirigido a menores de 13 años y no recopilamos información de ninguna persona menor de 13 años de manera consciente. Si cree que recopilamos dicha información, comuníquese con [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Servicios de terceros",
+ "paragraphs": [
+ "La Aplicación se integra con estos servicios de terceros:"
+ ],
+ "bullets": [
+ "Stack Auth: autenticación y gestión de cuentas para inicio de sesión, sesiones y eliminación de cuentas.",
+ "Apple, Google y GitHub: proveedores de inicio de sesión opcionales que envían la información de cuenta necesaria para autenticarlo.",
+ "Servicio de notificaciones push Apple: notificaciones a iPhone y iPad después de suscribirse.",
+ "Apple Reconocimiento de voz: transcripción de voz cuando lo eliges en la aplicación móvil.",
+ "Sentry: seguimiento de errores e informes de fallos, que pueden recopilar registros de errores, seguimientos de pila, información del dispositivo y versión del sistema operativo.",
+ "Sparkle: el marco de actualización automática de macOS, que envía versiones de aplicaciones y sistemas operativos para buscar actualizaciones de macOS.",
+ "Ghostty / libghostty: el motor de renderizado de terminal, que se ejecuta localmente en su dispositivo.",
+ "PostHog: análisis de sitios web y productos móviles, incluidas visitas a páginas, patrones de navegación, metadatos del navegador, eventos de funciones móviles, análisis móviles vinculados a la cuenta después de iniciar sesión a través de un proxy propio y un correo electrónico de lista de espera enviado para que podamos notificarle.",
+ "Resend: entrega de correo electrónico transaccional. Su correo electrónico se envía a Resend solo si envía comentarios voluntariamente.",
+ "Slack: notificaciones internas privadas. Si se une a una lista de espera de una plataforma, el correo electrónico y las plataformas que envíe se envían a nuestro espacio de trabajo privado Slack."
+ ],
+ "afterBullets": [
+ "Cada servicio tiene su propia política de privacidad. Cuando un tercero procesa información personal para cmux, requerimos medidas de seguridad al menos tan protectoras como esta política y limitamos el uso a la prestación de servicios a cmux."
+ ]
+ },
+ {
+ "heading": "III. Cómo utilizamos y compartimos la información",
+ "paragraphs": [
+ "No vendemos, comercializamos, alquilamos ni compartimos información personal con terceros con fines de marketing. Utilizamos informes de fallos y diagnósticos solo para mejorar la Aplicación. Podemos divulgar información cuando creamos de buena fe que la divulgación es necesaria para un proceso legal o para protegernos contra daños."
+ ]
+ },
+ {
+ "heading": "IV. Cómo protegemos la información",
+ "paragraphs": [
+ "Utilizamos medidas diseñadas para evitar el acceso no autorizado, incluido el cifrado y el software de servidor seguro. Ningún método de transmisión o almacenamiento es completamente seguro y el uso del Servicio implica este riesgo."
+ ]
+ },
+ {
+ "heading": "V. Tus derechos",
+ "paragraphs": [
+ "Dependiendo de su ubicación, las leyes aplicables como GDPR o CCPA pueden otorgarle estos derechos:"
+ ],
+ "bullets": [
+ "Acceda a una copia de los datos que tenemos sobre usted.",
+ "Corregir datos inexactos.",
+ "Solicitar la eliminación de tus datos.",
+ "Reciba datos portátiles.",
+ "Restringir u oponerse al tratamiento."
+ ],
+ "afterBullets": [
+ "Para ejercer estos derechos, comuníquese con [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Enlaces a otros sitios web",
+ "paragraphs": [
+ "El Servicio puede vincularse a sitios web de terceros. No somos responsables de sus prácticas de privacidad. Esta política se aplica únicamente a la información que recopilamos."
+ ]
+ },
+ {
+ "heading": "VII. Cambios a esta política",
+ "paragraphs": [
+ "Podemos cambiar esta política. Los cambios importantes entran en vigor 30 días después de la notificación. Consulte el Sitio periódicamente para obtener actualizaciones."
+ ]
+ },
+ {
+ "heading": "VIII. Contáctenos",
+ "paragraphs": [
+ "Las preguntas sobre esta política se pueden enviar a [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Retención de datos",
+ "paragraphs": [
+ "Los informes y diagnósticos de fallos se conservan solo el tiempo necesario para diagnosticar y solucionar problemas. Los identificadores de cuentas móviles y los registros de autenticación se conservan mientras su cuenta está activa y luego se eliminan o se anonimizan cuando finaliza la eliminación de la cuenta, excepto cuando las tareas de seguridad, legales, de facturación o de prevención de fraude requieran su conservación. Los metadatos del dispositivo y de emparejamiento se conservan hasta que lo desvincules, cierres sesión y elimines los datos locales, elimines tu cuenta o se eliminen los datos de emparejamiento obsoletos. Los tokens del servicio de notificaciones push Apple se conservan solo mientras las notificaciones están habilitadas y se eliminan cuando las desactiva, cierra sesión, elimina su cuenta o Apple informa que el token no es válido. Los análisis de productos móviles en PostHog se conservan hasta por 24 meses, a menos que solicite una eliminación anticipada. La configuración de la cuenta móvil elimina o anonimiza la cuenta, el dispositivo, el emparejamiento, la notificación, la facturación y los datos de la nube propiedad de cmux, elimina la persona PostHog vinculada a la cuenta y solicita la eliminación de sus eventos y grabaciones de análisis móvil. Es posible que algunos trabajos de eliminación de proveedores se completen de forma asincrónica. Solicite la eliminación en la configuración de la cuenta móvil o comunicándose con [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/fr.json b/web/app/[locale]/(legal)/privacy-policy/content/fr.json
new file mode 100644
index 000000000000..308e79ea1133
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/fr.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Politique de confidentialité — cmux",
+ "metadataDescription": "Politique de confidentialité pour cmux",
+ "title": "Politique de confidentialité",
+ "lastUpdated": "Dernière mise à jour : 10 juillet 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (la « Société ») s'engage à maintenir de solides protections de la vie privée pour ses utilisateurs. Cette politique de confidentialité explique comment nous collectons, utilisons et protégeons les informations que vous nous fournissez.",
+ "Dans cette politique, « Site » désigne le site Web de la société à l'adresse [cmux.com](https://cmux.com). « Application » désigne l'application de bureau cmux pour macOS et l'application mobile cmux pour iPhone et iPad. « Service » désigne le Site et l'Application ensemble. « Nous », « notre » et « notre » désignent la Société. « Vous » désigne un utilisateur de notre Service.",
+ "En utilisant notre service, vous acceptez cette politique de confidentialité et nos [Conditions d'utilisation](https://cmux.com/terms-of-service), et consentez à la collecte, au stockage, à l'utilisation et à la divulgation décrites ici."
+ ]
+ },
+ {
+ "heading": "I. Informations que nous collectons",
+ "paragraphs": [
+ "Nous collectons des informations non personnelles et des informations personnelles. Les informations non personnelles ne peuvent pas vous identifier et incluent des données d'utilisation anonymes, des types de plates-formes et des diagnostics de crash. Les informations personnelles incluent votre adresse e-mail, vos identifiants de compte et les informations que vous choisissez de fournir lorsque vous vous connectez, nous contactez, associez un appareil ou utilisez l'application."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informations collectées grâce à la technologie",
+ "paragraphs": [
+ "L’Application peut collecter automatiquement les informations suivantes :"
+ ],
+ "bullets": [
+ "Rapports de crash et diagnostics d'erreurs via Sentry.",
+ "Version du système d'exploitation et version de l'application.",
+ "Analyses de produits et événements d'utilisation des fonctionnalités pour le site et l'application.",
+ "Métadonnées de l'appareil, du compte et du couplage nécessaires pour connecter vos appareils connectés.",
+ "Apple Jetons de périphérique du service de notification push, uniquement après avoir activé les notifications téléphoniques."
+ ],
+ "afterBullets": [
+ "L'application macOS recherche les mises à jour via Sparkle, qui peut envoyer les versions de votre système d'exploitation et de vos applications à notre serveur de mise à jour. Les applications iPhone et iPad sont mises à jour via App Store, et non Sparkle.",
+ "Le site utilise PostHog pour l'analyse des pages consultées et de la navigation. PostHog stocke un cookie pour distinguer les visiteurs. Si vous rejoignez une liste d'attente d'une plateforme, votre e-mail soumis est enregistré dans PostHog afin que nous puissions vous en informer. Si vous soumettez le formulaire de contact Entreprise, nous enregistrons l'entreprise et les coordonnées que vous fournissez dans PostHog et les envoyons à notre espace de travail privé Slack et à la boîte de réception des fondateurs afin que nous puissions répondre. Vous pouvez bloquer les analyses de sites Web avec une extension de navigateur qui bloque les scripts de suivi.",
+ "L'application iPhone et iPad envoie des événements d'analyse de produits à notre proxy PostHog côté serveur. Ces événements aident à diagnostiquer la fiabilité, à comprendre l'utilisation des fonctionnalités et à améliorer l'application. Ils incluent les événements de lancement et de session d'application, l'état de connexion, les tentatives et les résultats de couplage, la récupération de connexion, les ouvertures d'espace de travail, le nombre d'octets et de lignes d'entrée du terminal, ainsi que les résultats d'adhésion aux notifications ou de liens profonds de notification. L'analyse mobile n'envoie pas le texte de commande du terminal, la sortie du terminal, les photos sélectionnées ou les transcriptions vocales à PostHog. Avant la connexion, les événements utilisent un identifiant client aléatoire par installation. Après la connexion, notre serveur attache votre identifiant de compte Stack Auth avant de transmettre les événements à PostHog. Les analyses et les rapports d'erreur sont initialement désactivés et ne sont envoyés qu'après avoir activé le partage d'analyses et de rapports d'erreur dans les paramètres. La désactivation de ce contrôle empêche la mise en mémoire tampon ou l'envoi des analyses et arrête les rapports d'erreur. Contactez [founders@manaflow.com](mailto:founders@manaflow.com) pour demander la suppression des analyses associées à votre compte."
+ ]
+ },
+ {
+ "heading": "2. Informations que vous fournissez directement",
+ "paragraphs": [
+ "Si vous nous contactez par e-mail, via notre page de contact ou via le formulaire de contact Entreprise, nous collectons les informations que vous fournissez, notamment votre nom, votre adresse e-mail, votre entreprise, votre rôle, votre numéro de téléphone, votre pays, vos besoins de déploiement et vos commentaires. Si vous rejoignez une liste d'attente d'une plateforme, nous collectons votre e-mail soumis pour vous informer du lancement de cette plateforme et envoyons l'e-mail d'inscription et les plateformes sélectionnées à notre espace de travail privé Slack.",
+ "Lorsque vous vous connectez, nous recevons des informations d'authentification telles que votre adresse e-mail et l'identifiant du fournisseur de Apple, Google, GitHub ou de connexion par code e-mail. Lorsque vous associez l'application mobile à un Mac, nous traitons les informations de couplage nécessaires pour connecter les appareils. Lorsque vous affichez un espace de travail, envoyez une entrée au terminal, joignez des photos sélectionnées, utilisez une transcription vocale ou recevez des notifications de terminal, le contenu ou la transcription associé peut être transmis entre vos appareils et notre service si nécessaire pour fournir cette fonctionnalité.",
+ "L'accès à la caméra est utilisé uniquement pour scanner les codes cmux d'appariement QR. L'accès au microphone et à la reconnaissance vocale est utilisé uniquement lorsque vous choisissez la transcription vocale dans la boîte de message. L'accès à la photothèque n'est utilisé que lorsque vous choisissez des photos à joindre."
+ ]
+ },
+ {
+ "heading": "3. Confidentialité des enfants",
+ "paragraphs": [
+ "Le Service ne s'adresse pas aux personnes de moins de 13 ans et nous ne collectons pas sciemment d'informations auprès de personnes de moins de 13 ans. Si vous pensez que nous avons collecté de telles informations, contactez [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Services tiers",
+ "paragraphs": [
+ "L'Application s'intègre à ces services tiers :"
+ ],
+ "bullets": [
+ "Stack Auth : authentification et gestion de compte pour la connexion, les sessions et la suppression de compte.",
+ "Apple, Google et GitHub : fournisseurs de connexion facultatifs qui envoient les informations de compte requises pour vous authentifier.",
+ "Service de notification push Apple : notifications à iPhone et iPad après votre inscription.",
+ "Reconnaissance vocale Apple : transcription vocale lorsque vous la choisissez dans l'application mobile.",
+ "Sentry : suivi des erreurs et rapport d'erreurs, qui peuvent collecter des journaux d'erreurs, des traces de pile, des informations sur le périphérique et la version du système d'exploitation.",
+ "Sparkle : le cadre de mise à jour automatique macOS, qui envoie les versions des applications et du système d'exploitation pour vérifier les mises à jour macOS.",
+ "Ghostty / libghostty : le moteur de rendu de terminal, qui s'exécute localement sur votre appareil.",
+ "PostHog : analyses de sites Web et de produits mobiles, y compris les pages vues, les modèles de navigation, les métadonnées du navigateur, les événements de fonctionnalités mobiles, les analyses mobiles liées au compte après la connexion via un proxy propriétaire et un e-mail de liste d'attente soumis afin que nous puissions vous informer.",
+ "Resend : envoi d'e-mails transactionnels. Votre e-mail est envoyé à Resend uniquement si vous soumettez volontairement vos commentaires.",
+ "Slack : notifications internes privées. Si vous rejoignez une liste d'attente de plateforme, l'e-mail et les plateformes que vous soumettez sont envoyés à notre espace de travail privé Slack."
+ ],
+ "afterBullets": [
+ "Chaque service a sa propre politique de confidentialité. Lorsqu'un tiers traite des informations personnelles pour cmux, nous exigeons des garanties au moins aussi protectrices que cette politique et limitons leur utilisation à la fourniture de services à cmux."
+ ]
+ },
+ {
+ "heading": "III. Comment nous utilisons et partageons les informations",
+ "paragraphs": [
+ "Nous ne vendons, n’échangeons, ne louons ni ne partageons d’informations personnelles avec des tiers à des fins de marketing. Nous utilisons des rapports d'erreur et des diagnostics uniquement pour améliorer l'application. Nous pouvons divulguer des informations lorsque nous pensons de bonne foi que la divulgation est nécessaire à une procédure judiciaire ou à une protection contre tout préjudice."
+ ]
+ },
+ {
+ "heading": "IV. Comment nous protégeons les informations",
+ "paragraphs": [
+ "Nous utilisons des mesures conçues pour empêcher tout accès non autorisé, notamment le cryptage et un logiciel serveur sécurisé. Aucune méthode de transmission ou de stockage n'est totalement sécurisée et l'utilisation du Service implique ce risque."
+ ]
+ },
+ {
+ "heading": "V. Vos droits",
+ "paragraphs": [
+ "En fonction de votre emplacement, les lois applicables telles que GDPR ou CCPA peuvent vous accorder ces droits :"
+ ],
+ "bullets": [
+ "Accédez à une copie des données que nous détenons à votre sujet.",
+ "Corrigez les données inexactes.",
+ "Demander la suppression de vos données.",
+ "Recevez des données portables.",
+ "Restreindre ou s'opposer au traitement."
+ ],
+ "afterBullets": [
+ "Pour exercer ces droits, contactez [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Liens vers d'autres sites Web",
+ "paragraphs": [
+ "Le Service peut créer des liens vers des sites Web tiers. Nous ne sommes pas responsables de leurs pratiques de confidentialité. Cette politique s'applique uniquement aux informations que nous collectons."
+ ]
+ },
+ {
+ "heading": "VII. Modifications de cette politique",
+ "paragraphs": [
+ "Nous pouvons modifier cette politique. Les modifications importantes entrent en vigueur 30 jours après notification. Consultez périodiquement le site pour les mises à jour."
+ ]
+ },
+ {
+ "heading": "VIII. Contactez-nous",
+ "paragraphs": [
+ "Les questions concernant cette politique peuvent être envoyées à [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Conservation des données",
+ "paragraphs": [
+ "Les rapports d'erreur et les diagnostics ne sont conservés que le temps nécessaire au diagnostic et à la résolution des problèmes. Les identifiants de compte mobile et les enregistrements d'authentification sont conservés pendant que votre compte est actif, puis supprimés ou anonymisés une fois la suppression du compte terminée, sauf lorsque des obligations de sécurité, juridiques, de facturation ou de prévention de la fraude nécessitent leur conservation. Les métadonnées de l'appareil et du couplage sont conservées jusqu'à ce que vous dissociez, déconnectez-vous et supprimez les données locales, supprimez votre compte ou que les données de couplage obsolètes soient supprimées. Les jetons du service de notification push Apple sont conservés uniquement lorsque les notifications sont activées et sont supprimés lorsque vous désactivez les notifications, vous déconnectez, supprimez votre compte ou Apple signale le jeton invalide. Les analyses de produits mobiles dans PostHog sont conservées jusqu'à 24 mois, sauf si vous demandez une suppression anticipée. Les paramètres du compte mobile suppriment ou anonymisent le compte, l'appareil, le couplage, la notification, la facturation et les données cloud appartenant à cmux, suppriment la personne PostHog liée au compte et demandent la suppression de ses événements et enregistrements d'analyse mobile. Certains travaux de suppression de fournisseur peuvent s'effectuer de manière asynchrone. Demandez la suppression dans les paramètres du compte mobile ou en contactant [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/it.json b/web/app/[locale]/(legal)/privacy-policy/content/it.json
new file mode 100644
index 000000000000..aa33c259b3ba
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/it.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Informativa sulla privacy — cmux",
+ "metadataDescription": "Informativa sulla privacy per cmux",
+ "title": "Informativa sulla privacy",
+ "lastUpdated": "Ultimo aggiornamento: 10 luglio 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (la \"Società\") si impegna a mantenere una solida protezione della privacy per i propri utenti. La presente Informativa sulla privacy spiega come raccogliamo, utilizziamo e salvaguardamo le informazioni che ci fornisci.",
+ "Nella presente politica, per \"Sito\" si intende il sito Web della Società all'indirizzo [cmux.com](https://cmux.com). Per \"Applicazione\" si intende l'applicazione desktop cmux per macOS e l'applicazione mobile cmux per iPhone e iPad. \"Servizio\" indica congiuntamente il Sito e l'Applicazione. \"Noi\", \"ci\" e \"nostro\" indicano la Società. \"Tu\" indica un utente del nostro Servizio.",
+ "Utilizzando il nostro Servizio, accetti la presente Informativa sulla privacy e i nostri [Termini di servizio](https://cmux.com/terms-of-service) e acconsenti alla raccolta, archiviazione, utilizzo e divulgazione qui descritti."
+ ]
+ },
+ {
+ "heading": "I. Informazioni che raccogliamo",
+ "paragraphs": [
+ "Raccogliamo informazioni non personali e informazioni personali. Le informazioni non personali non possono identificarti e includono dati di utilizzo anonimi, tipi di piattaforma e diagnostica degli arresti anomali. Le informazioni personali includono il tuo indirizzo e-mail, gli identificatori dell'account e le informazioni che scegli di fornire quando accedi, ci contatti, accoppi un dispositivo o utilizzi l'Applicazione."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informazioni raccolte attraverso la tecnologia",
+ "paragraphs": [
+ "L'Applicazione può raccogliere automaticamente le seguenti informazioni:"
+ ],
+ "bullets": [
+ "Rapporti sugli arresti anomali e diagnostica degli errori tramite Sentry.",
+ "Versione del sistema operativo e versione dell'applicazione.",
+ "Analisi del prodotto ed eventi di utilizzo delle funzionalità per il Sito e l'Applicazione.",
+ "Dispositivo, account e metadati di associazione necessari per connettere i dispositivi su cui hai eseguito l'accesso.",
+ "Apple Token del dispositivo del servizio di notifica push, solo dopo aver abilitato le notifiche del telefono."
+ ],
+ "afterBullets": [
+ "L'applicazione macOS verifica la disponibilità di aggiornamenti tramite Sparkle, che potrebbe inviare le versioni del sistema operativo e dell'applicazione al nostro server di aggiornamento. L'applicazione iPhone e iPad viene aggiornata tramite App Store e non Sparkle.",
+ "Il sito utilizza PostHog per l'analisi della visualizzazione della pagina e della navigazione. PostHog memorizza un cookie per distinguere i visitatori. Se ti iscrivi a una lista d'attesa della piattaforma, l'e-mail inviata viene registrata in PostHog in modo che possiamo avvisarti. Se invii il modulo di contatto aziendale, registriamo l'azienda e i dettagli di contatto forniti in PostHog e li inviamo al nostro spazio di lavoro privato Slack e alla casella di posta elettronica dei fondatori in modo da poter rispondere. Puoi bloccare l'analisi dei siti web con un'estensione del browser che blocca gli script di tracciamento.",
+ "L'applicazione iPhone e iPad invia eventi di analisi del prodotto al nostro proxy PostHog lato server. Questi eventi aiutano a diagnosticare l'affidabilità, comprendere l'utilizzo delle funzionalità e migliorare l'Applicazione. Includono l'avvio dell'app e gli eventi della sessione, lo stato di accesso, i tentativi e i risultati di associazione, il ripristino della connessione, le aperture dell'area di lavoro, il conteggio dei byte e delle righe di input del terminale e l'attivazione delle notifiche o i risultati del collegamento diretto alle notifiche. L'analisi mobile non invia il testo dei comandi del terminale, l'output del terminale, le foto selezionate o le trascrizioni vocali a PostHog. Prima dell'accesso, gli eventi utilizzano un identificatore client casuale per installazione. Dopo l'accesso, il nostro server collega l'identificatore del tuo account Stack Auth prima di inoltrare gli eventi a PostHog. Le analisi e i rapporti sugli arresti anomali iniziano disabilitati e vengono inviati solo dopo aver abilitato Condividi analisi e rapporti sugli arresti anomali nelle Impostazioni. La disattivazione di tale controllo interrompe il buffering o l'invio delle analisi e interrompe la segnalazione degli arresti anomali. Contatta [founders@manaflow.com](mailto:founders@manaflow.com) per richiedere l'eliminazione dei dati analitici associati al tuo account."
+ ]
+ },
+ {
+ "heading": "2. Informazioni fornite direttamente",
+ "paragraphs": [
+ "Se ci contatti tramite e-mail, tramite la nostra pagina dei contatti o tramite il modulo di contatto Enterprise, raccogliamo le informazioni fornite, tra cui nome, e-mail, azienda, ruolo, numero di telefono, paese, esigenze di distribuzione e commenti. Se ti iscrivi a una lista d'attesa di una piattaforma, raccogliamo l'e-mail inviata per avvisarti quando la piattaforma verrà lanciata e invieremo l'e-mail di registrazione e le piattaforme selezionate al nostro spazio di lavoro privato Slack.",
+ "Quando accedi, riceviamo informazioni di autenticazione come il tuo indirizzo email e l'identificatore del provider da Apple, Google, GitHub o l'accesso tramite codice email. Quando accoppi l'app mobile con un Mac, elaboriamo le informazioni di associazione necessarie per connettere i dispositivi. Quando visualizzi un'area di lavoro, invii input dal terminale, alleghi foto selezionate, utilizzi la trascrizione vocale o ricevi notifiche dal terminale, il contenuto o la trascrizione correlati potrebbero passare tra i tuoi dispositivi e il nostro servizio secondo necessità per fornire tale funzionalità.",
+ "L'accesso alla telecamera viene utilizzato solo per scansionare i codici cmux associati a QR. L'accesso al microfono e al riconoscimento vocale viene utilizzato solo quando si sceglie la trascrizione vocale nella finestra del messaggio. L'accesso alla libreria fotografica viene utilizzato solo quando si scelgono le foto da allegare."
+ ]
+ },
+ {
+ "heading": "3. Privacy dei bambini",
+ "paragraphs": [
+ "Il Servizio non è rivolto a minori di 13 anni e non raccogliamo consapevolmente informazioni da minori di 13 anni. Se ritieni che abbiamo raccolto tali informazioni, contatta [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Servizi di terze parti",
+ "paragraphs": [
+ "L'Applicazione si integra con questi servizi di terze parti:"
+ ],
+ "bullets": [
+ "Stack Auth: autenticazione e gestione dell'account per accesso, sessioni ed eliminazione dell'account.",
+ "Apple, Google e GitHub: provider di accesso facoltativi che inviano le informazioni sull'account necessarie per autenticarti.",
+ "Servizio di notifica push Apple: notifiche a iPhone e iPad dopo l'attivazione.",
+ "Apple Riconoscimento vocale: trascrizione vocale quando lo scegli nell'app mobile.",
+ "Sentry: tracciamento degli errori e segnalazione degli arresti anomali, che può raccogliere log degli errori, tracce dello stack, informazioni sul dispositivo e versione del sistema operativo.",
+ "Sparkle: il framework di aggiornamento automatico macOS, che invia le versioni dell'applicazione e del sistema operativo per verificare la presenza di aggiornamenti macOS.",
+ "Ghostty / libghostty: il motore di rendering del terminale, che viene eseguito localmente sul tuo dispositivo.",
+ "PostHog: analisi di siti Web e prodotti mobili, incluse visualizzazioni di pagina, modelli di navigazione, metadati del browser, eventi di funzionalità mobili, analisi mobili collegate all'account dopo l'accesso tramite un proxy proprietario e un'e-mail di lista d'attesa inviata per consentirci di avvisarti.",
+ "Resend: recapito di posta elettronica transazionale. La tua email viene inviata a Resend solo se invii volontariamente il feedback.",
+ "Slack: notifiche interne private. Se ti iscrivi a una lista d'attesa di una piattaforma, l'e-mail e le piattaforme che invii verranno inviate al nostro spazio di lavoro privato Slack."
+ ],
+ "afterBullets": [
+ "Ogni servizio ha la propria politica sulla privacy. Quando una terza parte elabora le informazioni personali per cmux, richiediamo misure di protezione almeno altrettanto protettive quanto questa politica e limitiamo l'uso alla fornitura di servizi a cmux."
+ ]
+ },
+ {
+ "heading": "III. Come utilizziamo e condividiamo le informazioni",
+ "paragraphs": [
+ "Non vendiamo, scambiamo, affittiamo o condividiamo informazioni personali con terze parti a scopo di marketing. Utilizziamo rapporti sugli arresti anomali e diagnostica solo per migliorare l'applicazione. Potremmo divulgare informazioni quando riteniamo in buona fede che la divulgazione sia necessaria per procedimenti legali o protezione da danni."
+ ]
+ },
+ {
+ "heading": "IV. Come proteggiamo le informazioni",
+ "paragraphs": [
+ "Utilizziamo misure progettate per impedire l'accesso non autorizzato, inclusa la crittografia e il software del server sicuro. Nessun metodo di trasmissione o archiviazione è completamente sicuro e l'utilizzo del Servizio comporta questo rischio."
+ ]
+ },
+ {
+ "heading": "V. I tuoi diritti",
+ "paragraphs": [
+ "A seconda della tua posizione, le leggi applicabili come GDPR o CCPA potrebbero concederti questi diritti:"
+ ],
+ "bullets": [
+ "Accedi a una copia dei dati che conserviamo su di te.",
+ "Correggere i dati imprecisi.",
+ "Richiedi la cancellazione dei tuoi dati.",
+ "Ricevi dati portatili.",
+ "Limitare o opporsi al trattamento."
+ ],
+ "afterBullets": [
+ "Per esercitare questi diritti, contattare [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Collegamenti ad altri siti web",
+ "paragraphs": [
+ "Il Servizio può collegarsi a siti Web di terzi. Non siamo responsabili delle loro pratiche sulla privacy. Questa politica si applica solo alle informazioni che raccogliamo."
+ ]
+ },
+ {
+ "heading": "VII. Modifiche a questa politica",
+ "paragraphs": [
+ "Potremmo cambiare questa politica. Le modifiche significative entrano in vigore 30 giorni dopo la notifica. Controllare periodicamente il Sito per eventuali aggiornamenti."
+ ]
+ },
+ {
+ "heading": "VIII. Contattaci",
+ "paragraphs": [
+ "Le domande su questa politica possono essere inviate a [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Conservazione dei dati",
+ "paragraphs": [
+ "I rapporti sugli arresti anomali e la diagnostica vengono conservati solo per il tempo necessario per diagnosticare e risolvere i problemi. Gli identificatori dell'account mobile e i record di autenticazione vengono conservati mentre il tuo account è attivo, quindi eliminati o resi anonimi al termine dell'eliminazione dell'account, tranne quando obblighi di sicurezza, legali, di fatturazione o di prevenzione delle frodi richiedono la conservazione. I metadati del dispositivo e dell'associazione vengono conservati finché non annulli l'associazione, ti disconnetti ed elimini i dati locali, elimini il tuo account o finché i dati di associazione obsoleti non vengono eliminati. I token del servizio di notifica push Apple vengono conservati solo mentre le notifiche sono abilitate e vengono rimossi quando si disabilitano le notifiche, ci si disconnette, si elimina l'account o Apple segnala che il token non è valido. L'analisi dei prodotti mobili in PostHog viene conservata per un massimo di 24 mesi, a meno che tu non richieda l'eliminazione anticipata. Le impostazioni dell'account mobile eliminano o rendono anonimi l'account, il dispositivo, l'associazione, la notifica, la fatturazione e i dati cloud di proprietà di cmux, eliminano la persona PostHog collegata all'account e richiedono l'eliminazione dei suoi eventi e registrazioni di analisi mobile. Alcune operazioni di eliminazione del provider potrebbero essere completate in modo asincrono. Richiedi l'eliminazione nelle impostazioni dell'account mobile o contattando [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/ja.json b/web/app/[locale]/(legal)/privacy-policy/content/ja.json
new file mode 100644
index 000000000000..68f0153d72b2
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/ja.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "プライバシーポリシー — cmux",
+ "metadataDescription": "cmux のプライバシー ポリシー",
+ "title": "プライバシーポリシー",
+ "lastUpdated": "最終更新日: 2026 年 7 月 10 日",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (以下「当社」) は、ユーザーのために堅牢なプライバシー保護を維持することに取り組んでいます。このプライバシー ポリシーでは、お客様から提供された情報を当社が収集、使用、保護する方法について説明します。",
+ "このポリシーにおいて、「サイト」とは、[cmux.com](https://cmux.com) にある当社 Web サイトを意味します。 「アプリケーション」とは、macOS の場合は cmux デスクトップ アプリケーション、iPhone および iPad の場合は cmux モバイル アプリケーションを意味します。 「サービス」とは、サイトとアプリケーションを合わせて意味します。 「当社」、「弊社」、「弊社」とは当社を意味します。 「あなた」とは、当社サービスのユーザーを意味します。",
+ "当社のサービスを使用することにより、お客様はこのプライバシー ポリシーと当社の [利用規約](https://cmux.com/terms-of-service) に同意し、ここに記載されている収集、保管、使用、および開示に同意したものとみなされます。"
+ ]
+ },
+ {
+ "heading": "I. 当社が収集する情報",
+ "paragraphs": [
+ "当社は非個人情報および個人情報を収集します。非個人情報には個人を特定することはできず、匿名の使用状況データ、プラットフォームの種類、クラッシュ診断が含まれます。個人情報には、電子メール アドレス、アカウント ID、およびサインイン時、当社への連絡時、デバイスのペアリング時、またはアプリケーションの使用時に提供することを選択した情報が含まれます。"
+ ],
+ "subsections": [
+ {
+ "heading": "1. テクノロジーを通じて収集される情報",
+ "paragraphs": [
+ "アプリケーションは次の情報を自動的に収集する場合があります。"
+ ],
+ "bullets": [
+ "Sentry を介したクラッシュ レポートとエラー診断。",
+ "オペレーティング システムのバージョンとアプリケーションのバージョン。",
+ "サイトとアプリケーションの製品分析と機能使用イベント。",
+ "サインインしているデバイスを接続するために必要なデバイス、アカウント、およびペアリングのメタデータ。",
+ "Apple プッシュ通知サービス デバイス トークン (電話通知を有効にした後にのみ)。"
+ ],
+ "afterBullets": [
+ "macOS アプリケーションは、Sparkle を通じてアップデートをチェックし、オペレーティング システムとアプリケーションのバージョンを当社のアップデート サーバーに送信する場合があります。 iPhone および iPad アプリケーションは、Sparkle ではなく App Store を通じて更新されます。",
+ "このサイトでは、ページビューとナビゲーション分析に PostHog を使用します。 PostHog は、訪問者を区別するために Cookie を保存します。プラットフォームの待機リストに参加すると、送信された電子メールが PostHog に記録されるため、通知を受け取ることができます。エンタープライズ連絡フォームを送信すると、PostHog に入力した会社名と連絡先の詳細が記録され、プライベート Slack ワークスペースと創設者の電子メール受信箱に送信され、返信できるようになります。追跡スクリプトをブロックするブラウザ拡張機能を使用して、Web サイト分析をブロックできます。",
+ "iPhone および iPad アプリケーションは、製品分析イベントをサーバー側の PostHog プロキシに送信します。これらのイベントは、信頼性の診断、機能の使用状況の理解、アプリケーションの改善に役立ちます。これらには、アプリの起動およびセッション イベント、サインイン ステータス、ペアリングの試行と結果、接続の回復、ワークスペースのオープン、端末入力のバイト数と行数、通知オプトインまたは通知ディープリンクの結果が含まれます。モバイル分析は、端末コマンド テキスト、端末出力、選択された写真、または音声トランスクリプトを PostHog に送信しません。サインインする前に、イベントはインストールごとにランダムなクライアント ID を使用します。サインイン後、サーバーはイベントを PostHog に転送する前に、Stack Auth アカウント ID を添付します。分析とクラッシュ レポートは無効になり、設定で分析とクラッシュ レポートの共有を有効にした後にのみ送信されます。このコントロールをオフにすると、分析のバッファリングや送信が停止され、クラッシュ レポートも停止されます。 [founders@manaflow.com](mailto:founders@manaflow.com) に連絡して、アカウントに関連付けられた分析の削除をリクエストしてください。"
+ ]
+ },
+ {
+ "heading": "2. あなたが直接提供する情報",
+ "paragraphs": [
+ "電子メール、お問い合わせページ、またはエンタープライズお問い合わせフォームで当社にお問い合わせいただく場合、当社は、名前、電子メール、会社、役割、電話番号、国、展開のニーズ、コメントなど、お客様が提供する情報を収集します。プラットフォームの待機リストに参加すると、プラットフォームの開始時に通知するために送信された電子メールが収集され、サインアップ電子メールと選択されたプラットフォームがプライベート Slack ワークスペースに送信されます。",
+ "サインインすると、Apple、Google、GitHub、または電子メール コード サインインから電子メール アドレスやプロバイダー ID などの認証情報を受け取ります。モバイル アプリを Mac とペアリングすると、デバイスの接続に必要なペアリング情報が処理されます。ワークスペースを表示したり、端末入力を送信したり、選択した写真を添付したり、音声文字起こしを使用したり、端末通知を受信したりすると、その機能を提供するために必要に応じて、関連するコンテンツや文字起こしがデバイスと当社のサービスの間で受け渡される場合があります。",
+ "カメラ アクセスは、cmux ペアリング QR コードをスキャンするためにのみ使用されます。マイクと音声認識アクセスは、メッセージ ボックスで音声転写を選択した場合にのみ使用されます。フォト ライブラリへのアクセスは、添付する写真を選択した場合にのみ使用されます。"
+ ]
+ },
+ {
+ "heading": "3. 子供のプライバシー",
+ "paragraphs": [
+ "このサービスは 13 歳未満のユーザーを対象としたものではなく、当社が 13 歳未満のユーザーから故意に情報を収集することはありません。当社がそのような情報を収集したと思われる場合は、[founders@manaflow.com](mailto:founders@manaflow.com) にお問い合わせください。"
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II.サードパーティのサービス",
+ "paragraphs": [
+ "アプリケーションは次のサードパーティ サービスと統合します。"
+ ],
+ "bullets": [
+ "Stack Auth: サインイン、セッション、アカウント削除のための認証とアカウント管理。",
+ "Apple、Google、および GitHub: 認証に必要なアカウント情報を送信するオプションのサインイン プロバイダー。",
+ "Apple プッシュ通知サービス: オプトイン後の iPhone および iPad への通知。",
+ "Apple 音声認識: モバイル アプリで選択した場合の音声文字起こし。",
+ "Sentry: エラー追跡とクラッシュレポート。エラーログ、スタックトレース、デバイス情報、オペレーティングシステムのバージョンを収集します。",
+ "Sparkle: macOS 自動更新フレームワーク。アプリケーションとオペレーティング システムのバージョンを送信して、macOS の更新を確認します。",
+ "Ghostty / libghostty: デバイス上でローカルに実行されるターミナル レンダリング エンジン。",
+ "PostHog: ページ ビュー、ナビゲーション パターン、ブラウザーのメタデータ、モバイル機能イベント、ファーストパーティ プロキシ経由でサインインした後のアカウントにリンクされたモバイル分析、およびお客様に通知できるように送信された待機リストの電子メールを含む、Web サイトおよびモバイル製品の分析。",
+ "Resend: トランザクション電子メール配信。自発的にフィードバックを送信した場合にのみ、電子メールが Resend に送信されます。",
+ "Slack: プライベートな内部通知。プラットフォームの待機リストに参加すると、送信した電子メールとプラットフォームがプライベート Slack ワークスペースに送信されます。"
+ ],
+ "afterBullets": [
+ "各サービスには独自のプライバシー ポリシーがあります。第三者が cmux の個人情報を処理する場合、当社は少なくともこのポリシーと同等の保護措置を要求し、使用を cmux へのサービスの提供に限定します。"
+ ]
+ },
+ {
+ "heading": "Ⅲ.情報の使用および共有方法",
+ "paragraphs": [
+ "当社は、マーケティング目的で個人情報を第三者に販売、取引、貸与、または共有することはありません。当社は、アプリケーションを改善する目的でのみクラッシュ レポートと診断を使用します。当社は、法的手続きまたは危害からの保護のために開示が必要であると誠意を持って判断した場合、情報を開示することがあります。"
+ ]
+ },
+ {
+ "heading": "IV.情報を保護する方法",
+ "paragraphs": [
+ "当社では、暗号化や安全なサーバー ソフトウェアなど、不正アクセスを防止するための対策を講じています。完全に安全な送信方法や保存方法はなく、サービスの使用にはこのリスクが伴います。"
+ ]
+ },
+ {
+ "heading": "V. お客様の権利",
+ "paragraphs": [
+ "お住まいの地域に応じて、GDPR または CCPA などの適用法により、次の権利が付与される場合があります。"
+ ],
+ "bullets": [
+ "当社があなたに関して保持しているデータのコピーにアクセスします。",
+ "不正確なデータを修正します。",
+ "データの削除をリクエストしてください。",
+ "ポータブルデータを受信します。",
+ "処理を制限または反対します。"
+ ],
+ "afterBullets": [
+ "これらの権利を行使するには、[founders@manaflow.com](mailto:founders@manaflow.com) にお問い合わせください。"
+ ]
+ },
+ {
+ "heading": "VI.他のウェブサイトへのリンク",
+ "paragraphs": [
+ "本サービスはサードパーティの Web サイトにリンクする場合があります。当社は、彼らのプライバシー慣行については責任を負いません。このポリシーは、当社が収集する情報にのみ適用されます。"
+ ]
+ },
+ {
+ "heading": "VII.このポリシーの変更",
+ "paragraphs": [
+ "このポリシーは変更される場合があります。重大な変更は通知から 30 日後に有効になります。定期的にサイトをチェックして更新情報を確認してください。"
+ ]
+ },
+ {
+ "heading": "Ⅷ.お問い合わせ",
+ "paragraphs": [
+ "このポリシーに関する質問は、[founders@manaflow.com](mailto:founders@manaflow.com) に送信できます。"
+ ]
+ },
+ {
+ "heading": "IX.データの保持",
+ "paragraphs": [
+ "クラッシュ レポートと診断は、問題の診断と修正に必要な期間のみ保存されます。モバイル アカウントの識別子と認証記録は、アカウントがアクティブである間は保持され、セキュリティ、法律、請求、または詐欺防止の義務により保持が必要な場合を除き、アカウントの削除が完了すると削除または匿名化されます。デバイスとペアリングのメタデータは、ペアリングを解除するか、サインアウトしてローカル データを削除するか、アカウントを削除するか、古いペアリング データが削除されるまで保持されます。 Apple プッシュ通知サービス トークンは、通知が有効になっている間のみ保持され、通知を無効にするか、サインアウトするか、アカウントを削除するか、Apple がトークンが無効であると報告すると削除されます。 PostHog のモバイル製品分析は、早期に削除をリクエストしない限り、最大 24 か月間保存されます。モバイル アカウント設定では、cmux が所有するアカウント、デバイス、ペアリング、通知、請求、およびクラウド データを削除または匿名化し、アカウントにリンクされた PostHog ユーザーを削除し、そのモバイル分析イベントと記録の削除を要求します。一部のプロバイダーの削除作業は非同期で完了する場合があります。モバイル アカウント設定で削除をリクエストするか、[founders@manaflow.com](mailto:founders@manaflow.com) に連絡してください。"
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/km.json b/web/app/[locale]/(legal)/privacy-policy/content/km.json
new file mode 100644
index 000000000000..0de1e30a3129
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/km.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "គោលការណ៍ឯកជនភាព — cmux",
+ "metadataDescription": "គោលការណ៍ឯកជនភាពសម្រាប់ cmux",
+ "title": "គោលការណ៍ឯកជនភាព",
+ "lastUpdated": "អាប់ដេតចុងក្រោយ៖ ថ្ងៃទី 10 ខែកក្កដា ឆ្នាំ 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (\"ក្រុមហ៊ុន\") ប្តេជ្ញារក្សាការការពារឯកជនភាពដ៏រឹងមាំសម្រាប់អ្នកប្រើប្រាស់របស់ខ្លួន។ គោលការណ៍ឯកជនភាពនេះពន្យល់ពីរបៀបដែលយើងប្រមូល ប្រើប្រាស់ និងការពារព័ត៌មានដែលអ្នកផ្តល់ឱ្យយើង។",
+ "នៅក្នុងគោលការណ៍នេះ \"គេហទំព័រ\" មានន័យថាគេហទំព័ររបស់ក្រុមហ៊ុននៅ [cmux.com](https://cmux.com)។ \"កម្មវិធី\" មានន័យថាកម្មវិធីកុំព្យូទ័រលើតុ cmux សម្រាប់ macOS និងកម្មវិធីទូរស័ព្ទ cmux សម្រាប់ iPhone និង iPad ។ \"សេវាកម្ម\" មានន័យថាគេហទំព័រ និងកម្មវិធីរួមគ្នា។ \"យើង\" \"យើង\" និង \"របស់យើង\" មានន័យថាក្រុមហ៊ុន។ \"អ្នក\" មានន័យថាអ្នកប្រើប្រាស់សេវាកម្មរបស់យើង។",
+ "តាមរយៈការប្រើប្រាស់សេវាកម្មរបស់យើង អ្នកទទួលយកគោលការណ៍ឯកជនភាពនេះ និង [លក្ខខណ្ឌនៃសេវាកម្ម](https://cmux.com/terms-of-service) របស់យើង ហើយយល់ព្រមចំពោះការប្រមូល ការផ្ទុក ការប្រើប្រាស់ និងការបង្ហាញដែលបានពិពណ៌នានៅទីនេះ។"
+ ]
+ },
+ {
+ "heading": "I. ព័ត៌មានដែលយើងប្រមូល",
+ "paragraphs": [
+ "យើងប្រមូលព័ត៌មានមិនផ្ទាល់ខ្លួន និងព័ត៌មានផ្ទាល់ខ្លួន។ ព័ត៌មានដែលមិនមែនជាបុគ្គលមិនអាចកំណត់អត្តសញ្ញាណអ្នក និងរួមបញ្ចូលទិន្នន័យប្រើប្រាស់អនាមិក ប្រភេទវេទិកា និងការវិនិច្ឆ័យគាំង។ ព័ត៌មានផ្ទាល់ខ្លួនរួមមានអាសយដ្ឋានអ៊ីមែលរបស់អ្នក ការកំណត់អត្តសញ្ញាណគណនី និងព័ត៌មានដែលអ្នកជ្រើសរើសផ្តល់នៅពេលអ្នកចូល ទាក់ទងមកយើង ផ្គូផ្គងឧបករណ៍ ឬប្រើកម្មវិធី។"
+ ],
+ "subsections": [
+ {
+ "heading": "1. ព័ត៌មានដែលប្រមូលបានតាមរយៈបច្ចេកវិទ្យា",
+ "paragraphs": [
+ "កម្មវិធីអាចប្រមូលព័ត៌មានខាងក្រោមដោយស្វ័យប្រវត្តិ៖"
+ ],
+ "bullets": [
+ "របាយការណ៍គាំង និងការវិនិច្ឆ័យកំហុសតាមរយៈ Sentry ។",
+ "កំណែប្រព័ន្ធប្រតិបត្តិការ និងកំណែកម្មវិធី។",
+ "ការវិភាគផលិតផល និងព្រឹត្តិការណ៍ប្រើប្រាស់លក្ខណៈពិសេសសម្រាប់គេហទំព័រ និងកម្មវិធី។",
+ "ឧបករណ៍ គណនី និងការផ្គូផ្គងទិន្នន័យមេតាដែលត្រូវការដើម្បីភ្ជាប់ឧបករណ៍ដែលបានចូលរបស់អ្នក។",
+ "Apple Push Notification សញ្ញាសម្ងាត់ឧបករណ៍ មានតែបន្ទាប់ពីអ្នកបើកការជូនដំណឹងតាមទូរសព្ទប៉ុណ្ណោះ។"
+ ],
+ "afterBullets": [
+ "កម្មវិធី macOS ពិនិត្យមើលការអាប់ដេតតាមរយៈ Sparkle ដែលអាចផ្ញើកំណែប្រព័ន្ធប្រតិបត្តិការ និងកម្មវិធីរបស់អ្នកទៅកាន់ម៉ាស៊ីនមេអាប់ដេតរបស់យើង។ កម្មវិធី iPhone និង iPad ត្រូវបានធ្វើបច្ចុប្បន្នភាពតាមរយៈ App Store មិនមែន Sparkle ទេ។",
+ "គេហទំព័រប្រើប្រាស់ PostHog សម្រាប់មើលទំព័រ និងការវិភាគការរុករក។ PostHog រក្សាទុកខូគីដើម្បីសម្គាល់អ្នកទស្សនា។ ប្រសិនបើអ្នកចូលរួមក្នុងបញ្ជីរង់ចាំវេទិកា អ៊ីមែលរបស់អ្នកដែលបានដាក់ស្នើត្រូវបានកត់ត្រានៅក្នុង PostHog ដូច្នេះយើងអាចជូនដំណឹងដល់អ្នកបាន។ ប្រសិនបើអ្នកដាក់ស្នើទម្រង់ទំនាក់ទំនងសហគ្រាស យើងកត់ត្រាក្រុមហ៊ុន និងព័ត៌មានលម្អិតទំនាក់ទំនងដែលអ្នកផ្តល់នៅក្នុង PostHog ហើយផ្ញើពួកគេទៅកាន់កន្លែងធ្វើការ Slack ឯកជនរបស់យើង ហើយអ្នកបង្កើតអ៊ីម៉ែល inbox ដូច្នេះយើងអាចឆ្លើយតបបាន។ អ្នកអាចទប់ស្កាត់ការវិភាគគេហទំព័រដោយប្រើផ្នែកបន្ថែមកម្មវិធីរុករកដែលរារាំងស្គ្រីបតាមដាន។",
+ "កម្មវិធី iPhone និង iPad ផ្ញើព្រឹត្តិការណ៍វិភាគផលិតផលទៅកាន់ប្រូកស៊ី PostHog ខាងម៉ាស៊ីនមេរបស់យើង។ ព្រឹត្តិការណ៍ទាំងនេះជួយធ្វើរោគវិនិច្ឆ័យភាពជឿជាក់ ស្វែងយល់ពីការប្រើប្រាស់មុខងារ និងកែលម្អកម្មវិធី។ ពួកវារួមមានការបើកដំណើរការកម្មវិធី និងព្រឹត្តិការណ៍វគ្គ ស្ថានភាពចូល ការព្យាយាមផ្គូផ្គង និងលទ្ធផល ការស្ដារការតភ្ជាប់ ការបើកកន្លែងធ្វើការ ការបញ្ចូលបៃរបស់ស្ថានីយ និងចំនួនបន្ទាត់ និងការជូនដំណឹងអំពីការចូលប្រើ ឬលទ្ធផលការជូនដំណឹង-តំណជ្រៅ។ ការវិភាគតាមទូរស័ព្ទមិនផ្ញើអត្ថបទពាក្យបញ្ជាស្ថានីយ លទ្ធផលស្ថានីយ រូបថតដែលបានជ្រើសរើស ឬប្រតិចារឹកការនិយាយទៅកាន់ PostHog ទេ។ មុនពេលចូល ព្រឹត្តិការណ៍ប្រើប្រាស់ឧបករណ៍កំណត់អត្តសញ្ញាណអតិថិជនដែលដំឡើងដោយចៃដន្យ។ បន្ទាប់ពីចូល នោះម៉ាស៊ីនមេរបស់យើងភ្ជាប់អត្តសញ្ញាណគណនី Stack Auth របស់អ្នក មុនពេលបញ្ជូនព្រឹត្តិការណ៍ទៅ PostHog ។ ការវិភាគ និងរបាយការណ៍គាំងចាប់ផ្តើមបិទ ហើយត្រូវបានផ្ញើតែបន្ទាប់ពីអ្នកបើកការចែករំលែកការវិភាគ និងរបាយការណ៍គាំងនៅក្នុងការកំណត់។ ការបិទការគ្រប់គ្រងនោះ បញ្ឈប់ការវិភាគពីការរំខាន ឬផ្ញើ និងបញ្ឈប់ការរាយការណ៍គាំង។ ទាក់ទង [founders@manaflow.com](mailto:founders@manaflow.com) ដើម្បីស្នើសុំការលុបការវិភាគដែលទាក់ទងនឹងគណនីរបស់អ្នក។"
+ ]
+ },
+ {
+ "heading": "2. ព័ត៌មានដែលអ្នកផ្តល់ដោយផ្ទាល់",
+ "paragraphs": [
+ "ប្រសិនបើអ្នកទាក់ទងមកយើងតាមអ៊ីម៉ែល ទំព័រទំនាក់ទំនងរបស់យើង ឬទម្រង់ទំនាក់ទំនងសហគ្រាស យើងប្រមូលព័ត៌មានដែលអ្នកផ្តល់ឱ្យ រួមទាំងឈ្មោះ អ៊ីមែល ក្រុមហ៊ុន តួនាទី លេខទូរស័ព្ទ ប្រទេស តម្រូវការដាក់ឱ្យប្រើប្រាស់ និងមតិយោបល់។ ប្រសិនបើអ្នកចូលរួមក្នុងបញ្ជីរង់ចាំវេទិកា យើងប្រមូលអ៊ីមែលរបស់អ្នកដែលបានដាក់ជូន ដើម្បីជូនដំណឹងដល់អ្នកនៅពេលដែលវេទិកានោះបើកដំណើរការ ហើយផ្ញើអ៊ីមែលចុះឈ្មោះ និងវេទិកាដែលបានជ្រើសរើសទៅកាន់កន្លែងធ្វើការ Slack ឯកជនរបស់យើង។",
+ "នៅពេលអ្នកចូល យើងទទួលបានព័ត៌មានផ្ទៀងផ្ទាត់ដូចជាអាសយដ្ឋានអ៊ីមែលរបស់អ្នក និងអត្តសញ្ញាណអ្នកផ្តល់សេវាពី Apple, Google, GitHub ឬការចូលកូដតាមអ៊ីមែល។ នៅពេលអ្នកផ្គូផ្គងកម្មវិធីទូរស័ព្ទជាមួយ Mac យើងដំណើរការព័ត៌មានផ្គូផ្គងដែលត្រូវការដើម្បីភ្ជាប់ឧបករណ៍។ នៅពេលអ្នកមើលកន្លែងធ្វើការ ផ្ញើការបញ្ចូលស្ថានីយ ភ្ជាប់រូបថតដែលបានជ្រើសរើស ប្រើការចម្លងការនិយាយ ឬទទួលការជូនដំណឹងពីស្ថានីយ ខ្លឹមសារ ឬប្រតិចារឹកដែលពាក់ព័ន្ធអាចនឹងឆ្លងកាត់រវាងឧបករណ៍របស់អ្នក និងសេវាកម្មរបស់យើងតាមតម្រូវការ ដើម្បីផ្តល់មុខងារនោះ។",
+ "ការចូលប្រើកាមេរ៉ាត្រូវបានប្រើដើម្បីស្កេនលេខកូដ cmux ដែលផ្គូផ្គង QR ប៉ុណ្ណោះ។ ការចូលប្រើមីក្រូហ្វូន និងការទទួលស្គាល់ការនិយាយត្រូវបានប្រើតែនៅពេលដែលអ្នកជ្រើសរើសការចម្លងសំឡេងនៅក្នុងប្រអប់សារប៉ុណ្ណោះ។ ការចូលប្រើបណ្ណាល័យរូបថតត្រូវបានប្រើតែនៅពេលដែលអ្នកជ្រើសរើសរូបថតដើម្បីភ្ជាប់។"
+ ]
+ },
+ {
+ "heading": "3. ឯកជនភាពរបស់កុមារ",
+ "paragraphs": [
+ "សេវាកម្មនេះមិនត្រូវបានដឹកនាំទៅនរណាម្នាក់ដែលមានអាយុក្រោម 13 ឆ្នាំទេ ហើយយើងមិនបានប្រមូលព័ត៌មានពីនរណាម្នាក់ដែលមានអាយុក្រោម 13 ឆ្នាំដោយចេតនាទេ។ ប្រសិនបើអ្នកជឿថាយើងប្រមូលព័ត៌មានបែបនេះ សូមទាក់ទង [founders@manaflow.com](mailto:founders@manaflow.com)។"
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. សេវាកម្មភាគីទីបី",
+ "paragraphs": [
+ "កម្មវិធីរួមបញ្ចូលជាមួយសេវាកម្មភាគីទីបីទាំងនេះ៖"
+ ],
+ "bullets": [
+ "Stack Auth៖ ការផ្ទៀងផ្ទាត់ភាពត្រឹមត្រូវ និងការគ្រប់គ្រងគណនីសម្រាប់ការចូល វគ្គ និងការលុបគណនី។",
+ "Apple, Google, និង GitHub៖ អ្នកផ្តល់ការចូលជាជម្រើសដែលផ្ញើព័ត៌មានគណនីដែលទាមទារដើម្បីផ្ទៀងផ្ទាត់អ្នក។",
+ "សេវាកម្មជូនដំណឹងជំរុញ Apple៖ ការជូនដំណឹងទៅកាន់ iPhone និង iPad បន្ទាប់ពីអ្នកជ្រើសរើសចូល។",
+ "Apple ការទទួលស្គាល់ការនិយាយ៖ ការចម្លងសំឡេងនៅពេលអ្នកជ្រើសរើសវានៅក្នុងកម្មវិធីទូរស័ព្ទ។",
+ "Sentry៖ ការតាមដានកំហុស និងការរាយការណ៍ការគាំង ដែលអាចប្រមូលកំណត់ហេតុកំហុស ដានជង់ ព័ត៌មានឧបករណ៍ និងកំណែប្រព័ន្ធប្រតិបត្តិការ។",
+ "Sparkle៖ ក្របខ័ណ្ឌធ្វើបច្ចុប្បន្នភាពដោយស្វ័យប្រវត្តិ macOS ដែលផ្ញើកំណែកម្មវិធី និងប្រព័ន្ធប្រតិបត្តិការ ដើម្បីពិនិត្យមើលការអាប់ដេត macOS ។",
+ "Ghostty / libghostty៖ ម៉ាស៊ីនបង្ហាញស្ថានីយ ដែលដំណើរការក្នុងមូលដ្ឋានលើឧបករណ៍របស់អ្នក។",
+ "PostHog៖ គេហទំព័រ និងការវិភាគផលិតផលទូរសព្ទចល័ត រួមទាំងការមើលទំព័រ គំរូរុករក ទិន្នន័យមេតានៃកម្មវិធីរុករកតាមអ៊ីនធឺណិត ព្រឹត្តិការណ៍មុខងារទូរសព្ទចល័ត ការវិភាគទូរសព្ទដែលភ្ជាប់គណនីបន្ទាប់ពីចូលតាមរយៈប្រូកស៊ីភាគីទីមួយ និងអ៊ីមែលបញ្ជីរង់ចាំដែលបានដាក់ជូន ដូច្នេះយើងអាចជូនដំណឹងដល់អ្នកបាន។",
+ "Resend៖ ការដឹកជញ្ជូនតាមអ៊ីមែលប្រតិបត្តិការ។ អ៊ីមែលរបស់អ្នកត្រូវបានផ្ញើទៅ Resend លុះត្រាតែអ្នកបញ្ជូនមតិកែលម្អដោយស្ម័គ្រចិត្ត។",
+ "Slack៖ ការជូនដំណឹងផ្ទៃក្នុងឯកជន។ ប្រសិនបើអ្នកចូលរួមក្នុងបញ្ជីរង់ចាំវេទិកា អ៊ីមែល និងវេទិកាដែលអ្នកដាក់ស្នើត្រូវបានផ្ញើទៅកាន់កន្លែងធ្វើការ Slack ឯកជនរបស់យើង។"
+ ],
+ "afterBullets": [
+ "សេវាកម្មនីមួយៗមានគោលការណ៍ឯកជនភាពរបស់ខ្លួន។ នៅពេលដែលភាគីទីបីដំណើរការព័ត៌មានផ្ទាល់ខ្លួនសម្រាប់ cmux យើងទាមទារការការពារយ៉ាងហោចជាការការពារដូចគោលការណ៍នេះ និងកំណត់ការប្រើប្រាស់ក្នុងការផ្តល់សេវាកម្មដល់ cmux ។"
+ ]
+ },
+ {
+ "heading": "III. របៀបដែលយើងប្រើប្រាស់ និងចែករំលែកព័ត៌មាន",
+ "paragraphs": [
+ "យើងមិនលក់ ជួញដូរ ជួល ឬចែករំលែកព័ត៌មានផ្ទាល់ខ្លួនជាមួយភាគីទីបីសម្រាប់ទីផ្សារទេ។ យើងប្រើរបាយការណ៍គាំង និងការវិនិច្ឆ័យដើម្បីកែលម្អកម្មវិធីប៉ុណ្ណោះ។ យើងអាចបញ្ចេញព័ត៌មាននៅពេលដែលយើងជឿជាក់ដោយស្មោះត្រង់ថាការបង្ហាញគឺចាំបាច់សម្រាប់ដំណើរការផ្លូវច្បាប់ ឬការការពារពីគ្រោះថ្នាក់។"
+ ]
+ },
+ {
+ "heading": "IV. របៀបដែលយើងការពារព័ត៌មាន",
+ "paragraphs": [
+ "យើងប្រើវិធានការដែលបានរចនាឡើងដើម្បីការពារការចូលប្រើដោយគ្មានការអនុញ្ញាត រួមទាំងការអ៊ិនគ្រីប និងកម្មវិធីម៉ាស៊ីនមេដែលមានសុវត្ថិភាព។ គ្មានមធ្យោបាយបញ្ជូន ឬការផ្ទុកមានសុវត្ថិភាពទាំងស្រុងនោះទេ ហើយការប្រើប្រាស់សេវាកម្មពាក់ព័ន្ធនឹងហានិភ័យនេះ។"
+ ]
+ },
+ {
+ "heading": "V. សិទ្ធិរបស់អ្នក។",
+ "paragraphs": [
+ "អាស្រ័យលើទីតាំងរបស់អ្នក ច្បាប់ដែលអាចអនុវត្តបានដូចជា GDPR ឬ CCPA អាចផ្តល់ឱ្យអ្នកនូវសិទ្ធិទាំងនេះ៖"
+ ],
+ "bullets": [
+ "ចូលប្រើច្បាប់ចម្លងនៃទិន្នន័យដែលយើងកាន់អំពីអ្នក។",
+ "កែតម្រូវទិន្នន័យមិនត្រឹមត្រូវ។",
+ "ស្នើសុំលុបទិន្នន័យរបស់អ្នក។",
+ "ទទួលទិន្នន័យចល័ត។",
+ "ដាក់កម្រិត ឬជំទាស់នឹងដំណើរការ។"
+ ],
+ "afterBullets": [
+ "ដើម្បីអនុវត្តសិទ្ធិទាំងនេះ សូមទាក់ទង [founders@manaflow.com](mailto:founders@manaflow.com)។"
+ ]
+ },
+ {
+ "heading": "VI. តំណភ្ជាប់ទៅកាន់គេហទំព័រផ្សេងទៀត។",
+ "paragraphs": [
+ "សេវាកម្មនេះអាចភ្ជាប់ទៅគេហទំព័រភាគីទីបី។ យើងមិនទទួលខុសត្រូវចំពោះការអនុវត្តឯកជនភាពរបស់ពួកគេទេ។ គោលការណ៍នេះអនុវត្តចំពោះតែព័ត៌មានដែលយើងប្រមូលបាន។"
+ ]
+ },
+ {
+ "heading": "VII. ការផ្លាស់ប្តូរចំពោះគោលការណ៍នេះ។",
+ "paragraphs": [
+ "យើងអាចផ្លាស់ប្តូរគោលការណ៍នេះ។ ការផ្លាស់ប្តូរសំខាន់ៗមានសុពលភាព 30 ថ្ងៃបន្ទាប់ពីការជូនដំណឹង។ ពិនិត្យគេហទំព័រជាទៀងទាត់សម្រាប់ការធ្វើបច្ចុប្បន្នភាព។"
+ ]
+ },
+ {
+ "heading": "VIII. ទាក់ទងមកយើងខ្ញុំ",
+ "paragraphs": [
+ "សំណួរអំពីគោលការណ៍នេះអាចផ្ញើទៅកាន់ [founders@manaflow.com](mailto:founders@manaflow.com)។"
+ ]
+ },
+ {
+ "heading": "IX ការរក្សាទិន្នន័យ",
+ "paragraphs": [
+ "របាយការណ៍គាំង និងការវិនិច្ឆ័យត្រូវបានរក្សាទុកតែដរាបណាចាំបាច់ដើម្បីធ្វើរោគវិនិច្ឆ័យ និងដោះស្រាយបញ្ហា។ ការកំណត់អត្តសញ្ញាណគណនីទូរសព្ទចល័ត និងកំណត់ត្រាការផ្ទៀងផ្ទាត់ភាពត្រឹមត្រូវត្រូវបានរក្សាទុក ខណៈពេលដែលគណនីរបស់អ្នកសកម្ម បន្ទាប់មកត្រូវបានលុប ឬអនាមិកនៅពេលដែលការលុបគណនីបានបញ្ចប់ លើកលែងតែនៅពេលដែលកាតព្វកិច្ចសុវត្ថិភាព ច្បាប់ វិក្កយបត្រ ឬការការពារការក្លែងបន្លំទាមទារការរក្សាទុក។ ឧបករណ៍ និងការផ្គូផ្គងទិន្នន័យមេតាត្រូវបានរក្សាទុករហូតដល់អ្នកមិនផ្គូផ្គង ចេញ និងលុបទិន្នន័យមូលដ្ឋាន លុបគណនីរបស់អ្នក ឬទិន្នន័យការផ្គូផ្គងជាប់គាំងត្រូវបានកាត់ចេញ។ Apple Push Notification tokens ត្រូវបានរក្សាទុកតែខណៈពេលដែលការជូនដំណឹងត្រូវបានបើក និងត្រូវបានដកចេញនៅពេលដែលអ្នកបិទការជូនដំណឹង ចាកចេញ លុបគណនីរបស់អ្នក ឬ Apple រាយការណ៍ថាសញ្ញាសម្ងាត់មិនត្រឹមត្រូវ។ ការវិភាគផលិតផលចល័តនៅក្នុង PostHog ត្រូវបានរក្សាទុករហូតដល់ 24 ខែ លុះត្រាតែអ្នកស្នើសុំការលុបមុន។ ការកំណត់គណនីទូរសព្ទចល័តលុប ឬអនាមិកគណនីដែលជាកម្មសិទ្ធិរបស់ cmux ឧបករណ៍ ការផ្គូផ្គង ការជូនដំណឹង ការចេញវិក្កយបត្រ និងទិន្នន័យពពក លុបមនុស្ស PostHog ដែលភ្ជាប់គណនី ហើយស្នើសុំការលុបព្រឹត្តិការណ៍ និងការថតវិភាគលើទូរសព្ទរបស់ខ្លួន។ ការងារលុបអ្នកផ្តល់សេវាមួយចំនួនអាចបញ្ចប់ដោយអសមកាល។ ស្នើសុំការលុបនៅក្នុងការកំណត់គណនីចល័ត ឬដោយការទាក់ទង [founders@manaflow.com](mailto:founders@manaflow.com)។"
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/ko.json b/web/app/[locale]/(legal)/privacy-policy/content/ko.json
new file mode 100644
index 000000000000..edd118b5f0ef
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/ko.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "개인정보 보호정책 — cmux",
+ "metadataDescription": "cmux에 대한 개인 정보 보호 정책",
+ "title": "개인 정보 보호 정책",
+ "lastUpdated": "최종 업데이트 날짜: 2026년 7월 10일",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow(\"회사\")는 사용자를 위한 강력한 개인정보 보호를 유지하기 위해 최선을 다하고 있습니다. 본 개인정보 보호정책은 귀하가 당사에 제공한 정보를 당사가 수집, 사용 및 보호하는 방법을 설명합니다.",
+ "본 정책에서 \"사이트\"는 [cmux.com](https://cmux.com)에 있는 회사 웹사이트를 의미합니다. \"애플리케이션\"은 macOS용 cmux 데스크톱 애플리케이션과 iPhone 및 iPad용 cmux 모바일 애플리케이션을 의미합니다. \"서비스\"는 사이트와 애플리케이션을 함께 의미합니다. \"당사\", \"당사\" 및 \"당사\"는 회사를 의미합니다. \"귀하\"는 당사 서비스의 사용자를 의미합니다.",
+ "당사 서비스를 이용함으로써 귀하는 본 개인정보 보호정책과 당사의 [서비스 약관](https://cmux.com/terms-of-service)을 수락하고 여기에 설명된 수집, 저장, 사용 및 공개에 동의하는 것입니다."
+ ]
+ },
+ {
+ "heading": "I. 당사가 수집하는 정보",
+ "paragraphs": [
+ "당사는 비개인정보 및 개인정보를 수집합니다. 비개인 정보는 귀하를 식별할 수 없으며 익명의 사용 데이터, 플랫폼 유형 및 충돌 진단을 포함합니다. 개인 정보에는 귀하의 이메일 주소, 계정 식별자, 귀하가 로그인할 때, 당사에 연락할 때, 장치를 페어링할 때 또는 애플리케이션을 사용할 때 제공하기로 선택한 정보가 포함됩니다."
+ ],
+ "subsections": [
+ {
+ "heading": "1. 기술을 통해 수집된 정보",
+ "paragraphs": [
+ "애플리케이션은 다음 정보를 자동으로 수집할 수 있습니다."
+ ],
+ "bullets": [
+ "Sentry를 통한 충돌 보고 및 오류 진단.",
+ "운영 체제 버전 및 애플리케이션 버전.",
+ "사이트 및 애플리케이션에 대한 제품 분석 및 기능 사용 이벤트.",
+ "로그인한 장치를 연결하는 데 필요한 장치, 계정 및 페어링 메타데이터입니다.",
+ "Apple 푸시 알림 서비스 장치 토큰은 전화 알림을 활성화한 후에만 가능합니다."
+ ],
+ "afterBullets": [
+ "macOS 애플리케이션은 Sparkle를 통해 업데이트를 확인하며, 이를 통해 운영 체제 및 애플리케이션 버전을 업데이트 서버로 보낼 수 있습니다. iPhone 및 iPad 애플리케이션은 Sparkle가 아닌 App Store를 통해 업데이트됩니다.",
+ "사이트는 페이지 보기 및 탐색 분석을 위해 PostHog를 사용합니다. PostHog는 방문자를 구별하기 위해 쿠키를 저장합니다. 플랫폼 대기자 명단에 등록하면 제출된 이메일이 PostHog에 기록되어 알려드릴 수 있습니다. 기업 연락처 양식을 제출하면 당사는 귀하가 PostHog에 제공한 회사 및 연락처 세부 정보를 기록하고 당사가 응답할 수 있도록 개인 Slack 작업 공간 및 창립자 이메일 받은 편지함으로 보냅니다. 추적 스크립트를 차단하는 브라우저 확장 프로그램을 사용하면 웹사이트 분석을 차단할 수 있습니다.",
+ "iPhone 및 iPad 애플리케이션은 제품 분석 이벤트를 서버 측 PostHog 프록시로 보냅니다. 이러한 이벤트는 안정성을 진단하고, 기능 사용을 이해하고, 애플리케이션을 개선하는 데 도움이 됩니다. 여기에는 앱 실행 및 세션 이벤트, 로그인 상태, 페어링 시도 및 결과, 연결 복구, 작업 영역 열기, 터미널 입력 바이트 및 줄 수, 알림 옵트인 또는 알림 딥 링크 결과가 포함됩니다. 모바일 분석은 터미널 명령 텍스트, 터미널 출력, 선택한 사진 또는 음성 기록을 PostHog로 보내지 않습니다. 로그인하기 전에 이벤트는 임의의 설치별 클라이언트 식별자를 사용합니다. 로그인 후 당사 서버는 이벤트를 PostHog에 전달하기 전에 귀하의 Stack Auth 계정 식별자를 연결합니다. 분석 및 충돌 보고서는 비활성화되기 시작하며 설정에서 분석 공유 및 충돌 보고서를 활성화한 후에만 전송됩니다. 해당 제어를 끄면 분석의 버퍼링이나 전송이 중지되고 충돌 보고가 중지됩니다. 계정과 관련된 분석 삭제를 요청하려면 [founders@manaflow.com](mailto:founders@manaflow.com)에 문의하세요."
+ ]
+ },
+ {
+ "heading": "2. 귀하가 직접 제공하는 정보",
+ "paragraphs": [
+ "귀하가 이메일, 연락처 페이지 또는 기업 문의 양식을 통해 당사에 연락하는 경우 당사는 이름, 이메일, 회사, 역할, 전화번호, 국가, 배포 요구 사항 및 의견을 포함하여 귀하가 제공하는 정보를 수집합니다. 플랫폼 대기자 명단에 등록하면 제출된 이메일을 수집하여 해당 플랫폼이 출시될 때 이를 알리고 등록 이메일과 선택한 플랫폼을 비공개 Slack 작업 공간으로 보냅니다.",
+ "귀하가 로그인하면 당사는 Apple, Google, GitHub 또는 이메일 코드 로그인을 통해 귀하의 이메일 주소 및 공급자 식별자와 같은 인증 정보를 수신합니다. 모바일 앱을 Mac과 페어링하면 장치를 연결하는 데 필요한 페어링 정보가 처리됩니다. 귀하가 작업 공간을 보거나, 터미널 입력을 보내거나, 선택한 사진을 첨부하거나, 음성 기록을 사용하거나, 터미널 알림을 받을 때 관련 콘텐츠 또는 기록은 해당 기능을 제공하기 위해 필요에 따라 귀하의 장치와 당사 서비스 간에 전달될 수 있습니다.",
+ "카메라 액세스는 cmux 페어링 QR 코드를 스캔하는 데에만 사용됩니다. 마이크 및 음성 인식 액세스는 메시지 상자에서 음성 전사를 선택한 경우에만 사용됩니다. 사진 라이브러리 액세스는 첨부할 사진을 선택한 경우에만 사용됩니다."
+ ]
+ },
+ {
+ "heading": "3. 아동의 개인정보 보호",
+ "paragraphs": [
+ "본 서비스는 13세 미만의 사용자를 대상으로 하지 않으며 당사는 13세 미만의 사용자로부터 고의로 정보를 수집하지 않습니다. 당사가 그러한 정보를 수집했다고 생각하는 경우 [founders@manaflow.com](mailto:founders@manaflow.com)에 문의하세요."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. 제3자 서비스",
+ "paragraphs": [
+ "애플리케이션은 다음과 같은 제3자 서비스와 통합됩니다."
+ ],
+ "bullets": [
+ "Stack Auth: 로그인, 세션, 계정 삭제를 위한 인증 및 계정 관리.",
+ "Apple, Google 및 GitHub: 사용자를 인증하는 데 필요한 계정 정보를 보내는 선택적 로그인 공급자입니다.",
+ "Apple 푸시 알림 서비스: 선택한 후 iPhone 및 iPad에 알림을 보냅니다.",
+ "Apple 음성 인식: 모바일 앱에서 선택하면 음성 전사가 가능합니다.",
+ "Sentry: 오류 로그, 스택 추적, 장치 정보 및 운영 체제 버전을 수집할 수 있는 오류 추적 및 충돌 보고.",
+ "Sparkle: macOS 업데이트를 확인하기 위해 애플리케이션 및 운영 체제 버전을 보내는 macOS 자동 업데이트 프레임워크입니다.",
+ "Ghostty / libghostty: 장치에서 로컬로 실행되는 터미널 렌더링 엔진입니다.",
+ "PostHog: 페이지 보기, 탐색 패턴, 브라우저 메타데이터, 모바일 기능 이벤트, 자사 프록시를 통한 로그인 후 계정 연결 모바일 분석, 제출된 대기자 명단 이메일을 포함한 웹사이트 및 모바일 제품 분석으로 귀하에게 알림을 제공합니다.",
+ "Resend: 거래 이메일 전달. 귀하가 자발적으로 피드백을 제출하는 경우에만 귀하의 이메일이 Resend로 전송됩니다.",
+ "Slack: 비공개 내부 알림. 플랫폼 대기자 명단에 등록하면 제출한 이메일과 플랫폼이 비공개 Slack 작업 공간으로 전송됩니다."
+ ],
+ "afterBullets": [
+ "각 서비스에는 자체 개인 정보 보호 정책이 있습니다. 제3자가 cmux에 대한 개인 정보를 처리하는 경우 당사는 최소한 이 정책만큼 보호적인 보호 장치를 요구하고 cmux에 대한 서비스 제공으로 사용을 제한합니다."
+ ]
+ },
+ {
+ "heading": "III. 정보 사용 및 공유 방법",
+ "paragraphs": [
+ "당사는 마케팅을 위해 개인정보를 제3자에게 판매, 거래, 임대 또는 공유하지 않습니다. 우리는 애플리케이션을 개선하기 위해서만 충돌 보고서와 진단을 사용합니다. 당사는 법적 절차나 피해로부터의 보호를 위해 공개가 필요하다고 선의로 믿는 경우 정보를 공개할 수 있습니다."
+ ]
+ },
+ {
+ "heading": "IV. 정보를 보호하는 방법",
+ "paragraphs": [
+ "우리는 암호화 및 보안 서버 소프트웨어를 포함하여 무단 액세스를 방지하기 위해 고안된 조치를 사용합니다. 전송 또는 저장 방법은 완전히 안전하지 않으며 서비스 사용에는 이러한 위험이 따릅니다."
+ ]
+ },
+ {
+ "heading": "V. 귀하의 권리",
+ "paragraphs": [
+ "귀하의 위치에 따라 GDPR 또는 CCPA와 같은 관련 법률이 귀하에게 다음과 같은 권리를 부여할 수 있습니다."
+ ],
+ "bullets": [
+ "당사가 귀하에 대해 보유하고 있는 데이터 사본에 접근하세요.",
+ "부정확한 데이터를 수정하세요.",
+ "데이터 삭제를 요청하세요.",
+ "휴대용 데이터를 수신합니다.",
+ "처리를 제한하거나 반대합니다."
+ ],
+ "afterBullets": [
+ "이러한 권리를 행사하려면 [founders@manaflow.com](mailto:founders@manaflow.com)에 문의하세요."
+ ]
+ },
+ {
+ "heading": "6. 다른 웹사이트에 대한 링크",
+ "paragraphs": [
+ "서비스는 제3자 웹사이트로 연결될 수 있습니다. 우리는 그들의 개인 정보 보호 관행에 대해 책임을 지지 않습니다. 이 정책은 당사가 수집하는 정보에만 적용됩니다."
+ ]
+ },
+ {
+ "heading": "Ⅶ. 본 정책의 변경 사항",
+ "paragraphs": [
+ "당사는 이 정책을 변경할 수 있습니다. 중요한 변경 사항은 통지 후 30일 후에 적용됩니다. 업데이트가 있는지 주기적으로 사이트를 확인하세요."
+ ]
+ },
+ {
+ "heading": "Ⅷ. 문의하기",
+ "paragraphs": [
+ "이 정책에 대한 질문은 [founders@manaflow.com](mailto:founders@manaflow.com)로 보낼 수 있습니다."
+ ]
+ },
+ {
+ "heading": "Ⅸ. 데이터 보존",
+ "paragraphs": [
+ "충돌 보고서 및 진단은 문제를 진단하고 수정하는 데 필요한 기간 동안만 보관됩니다. 모바일 계정 식별자 및 인증 기록은 귀하의 계정이 활성화된 동안 보관되었다가 보안, 법률, 청구 또는 사기 방지 의무를 위해 보관이 필요한 경우를 제외하고는 계정 삭제가 완료되면 삭제되거나 익명화됩니다. 장치 및 페어링 메타데이터는 페어링을 해제하거나, 로그아웃하고, 로컬 데이터를 삭제하거나, 계정을 삭제하거나, 오래된 페어링 데이터가 정리될 때까지 보관됩니다. Apple 푸시 알림 서비스 토큰은 알림이 활성화된 동안에만 유지되며 알림을 비활성화하거나 로그아웃하거나 계정을 삭제하거나 Apple가 토큰이 유효하지 않다고 보고하면 제거됩니다. PostHog의 모바일 제품 분석은 조기 삭제를 요청하지 않는 한 최대 24개월 동안 보관됩니다. 모바일 계정 설정은 cmux 소유 계정, 장치, 페어링, 알림, 청구 및 클라우드 데이터를 삭제하거나 익명화하고, 계정에 연결된 PostHog 개인을 삭제하고, 모바일 분석 이벤트 및 녹음 삭제를 요청합니다. 일부 공급자 삭제 작업은 비동기적으로 완료될 수 있습니다. 모바일 계정 설정에서 삭제를 요청하거나 [founders@manaflow.com](mailto:founders@manaflow.com)에 문의하세요."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/no.json b/web/app/[locale]/(legal)/privacy-policy/content/no.json
new file mode 100644
index 000000000000..9e2c1f0923b2
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/no.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Retningslinjer for personvern — cmux",
+ "metadataDescription": "Personvernerklæring for cmux",
+ "title": "Personvernerklæring",
+ "lastUpdated": "Sist oppdatert: 10. juli 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (\"Selskapet\") er forpliktet til å opprettholde robust personvern for sine brukere. Denne personvernerklæringen forklarer hvordan vi samler inn, bruker og beskytter informasjon du gir oss.",
+ "I disse retningslinjene betyr \"nettstedet\" selskapets nettsted på [cmux.com](https://cmux.com). \"Applikasjon\" betyr cmux skrivebordsapplikasjon for macOS og cmux mobilapplikasjon for iPhone og iPad. \"Tjenesten\" betyr nettstedet og applikasjonen sammen. \"Vi\", \"oss\" og \"vår\" betyr selskapet. \"Du\" betyr en bruker av tjenesten vår.",
+ "Ved å bruke tjenesten vår godtar du denne personvernerklæringen og våre [vilkår for bruk](https://cmux.com/terms-of-service), og samtykker til innsamlingen, lagringen, bruken og avsløringen beskrevet her."
+ ]
+ },
+ {
+ "heading": "I. Informasjon vi samler inn",
+ "paragraphs": [
+ "Vi samler inn ikke-personlig informasjon og personlig informasjon. Ikke-personlig informasjon kan ikke identifisere deg og inkluderer anonyme bruksdata, plattformtyper og krasjdiagnostikk. Personlig informasjon inkluderer e-postadressen din, kontoidentifikatorer og informasjon du velger å oppgi når du logger på, kontakter oss, parer en enhet eller bruker applikasjonen."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informasjon samlet inn gjennom teknologi",
+ "paragraphs": [
+ "Applikasjonen kan automatisk samle inn følgende informasjon:"
+ ],
+ "bullets": [
+ "Krasjrapporter og feildiagnostikk gjennom Sentry.",
+ "Operativsystemversjon og applikasjonsversjon.",
+ "Produktanalyse og funksjonsbruk hendelser for nettstedet og applikasjonen.",
+ "Enhets-, konto- og sammenkoblingsmetadata som trengs for å koble til påloggede enheter.",
+ "Apple Push Notification-tjenesteenhetstokener, bare etter at du har aktivert telefonvarsler."
+ ],
+ "afterBullets": [
+ "macOS-applikasjonen ser etter oppdateringer gjennom Sparkle, som kan sende operativsystem- og applikasjonsversjonene til vår oppdateringsserver. iPhone- og iPad-applikasjonen oppdateres gjennom App Store, ikke Sparkle.",
+ "Nettstedet bruker PostHog for sidevisning og navigasjonsanalyse. PostHog lagrer en informasjonskapsel for å skille besøkende. Hvis du blir med på en plattformventeliste, registreres den innsendte e-posten din i PostHog slik at vi kan varsle deg. Hvis du sender inn Enterprise-kontaktskjemaet, registrerer vi selskapet og kontaktinformasjonen du oppgir i PostHog og sender dem til vårt private Slack-arbeidsområde og grunnleggernes e-postinnboks slik at vi kan svare. Du kan blokkere nettstedsanalyse med en nettleserutvidelse som blokkerer sporingsskript.",
+ "iPhone- og iPad-applikasjonen sender produktanalysehendelser til vår PostHog-proxy på serversiden. Disse hendelsene hjelper til med å diagnostisere pålitelighet, forstå funksjonsbruk og forbedre applikasjonen. De inkluderer appstart- og økthendelser, påloggingsstatus, sammenkoblingsforsøk og resultater, tilkoblingsgjenoppretting, arbeidsområdeåpninger, terminalinndatabyte og linjetelling, og varslingsvalgte-på- eller varslingsdypkoblingsresultater. Mobilanalyse sender ikke terminalkommandotekst, terminalutdata, utvalgte bilder eller taleavskrifter til PostHog. Før pålogging bruker hendelser en tilfeldig klientidentifikator per installasjon. Etter pålogging legger serveren vår ved din Stack Auth-kontoidentifikator før den videresender hendelser til PostHog. Analytics og krasjrapporter starter deaktivert og sendes først etter at du har aktivert Del Analytics og krasjrapporter i Innstillinger. Hvis du slår av denne kontrollen, stopper du at analyser bufres eller sendes og stopper krasjrapportering. Kontakt [founders@manaflow.com](mailto:founders@manaflow.com) for å be om sletting av analyser knyttet til kontoen din."
+ ]
+ },
+ {
+ "heading": "2. Informasjon du oppgir direkte",
+ "paragraphs": [
+ "Hvis du kontakter oss via e-post, kontaktsiden vår eller Enterprise-kontaktskjemaet, samler vi inn informasjon du oppgir, inkludert navn, e-post, firma, rolle, telefonnummer, land, distribusjonsbehov og kommentarer. Hvis du melder deg på en venteliste for plattformer, samler vi inn den innsendte e-posten din for å varsle deg når den plattformen lanseres og sender registrerings-e-posten og utvalgte plattformer til vårt private Slack-arbeidsområde.",
+ "Når du logger på, mottar vi autentiseringsinformasjon som din e-postadresse og leverandøridentifikator fra Apple, Google, GitHub eller pålogging med e-postkode. Når du parer mobilappen med en Mac, behandler vi sammenkoblingsinformasjonen som er nødvendig for å koble til enhetene. Når du ser på et arbeidsområde, sender terminalinndata, legger ved valgte bilder, bruker taletranskripsjon eller mottar terminalvarsler, kan det relaterte innholdet eller transkripsjonen overføres mellom enhetene dine og tjenesten vår etter behov for å tilby denne funksjonen.",
+ "Kameratilgang brukes kun til å skanne cmux-paring av QR-koder. Mikrofon- og talegjenkjenningstilgang brukes bare når du velger taletranskripsjon i meldingsboksen. Tilgang til bildebibliotek brukes bare når du velger bilder å legge ved."
+ ]
+ },
+ {
+ "heading": "3. Barns personvern",
+ "paragraphs": [
+ "Tjenesten er ikke rettet til noen under 13 år, og vi samler ikke bevisst inn informasjon fra noen under 13. Hvis du tror vi har samlet inn slik informasjon, kontakt [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Tredjepartstjenester",
+ "paragraphs": [
+ "Applikasjonen integreres med disse tredjepartstjenestene:"
+ ],
+ "bullets": [
+ "Stack Auth: autentisering og kontoadministrasjon for pålogging, økter og kontosletting.",
+ "Apple, Google og GitHub: valgfrie påloggingsleverandører som sender kontoinformasjon som kreves for å autentisere deg.",
+ "Apple Push Notification-tjeneste: varsler til iPhone og iPad etter at du melder deg på.",
+ "Apple talegjenkjenning: stemmetranskripsjon når du velger det i mobilappen.",
+ "Sentry: feilsporing og krasjrapportering, som kan samle feillogger, stabelsporing, enhetsinformasjon og operativsystemversjon.",
+ "Sparkle: macOS-rammeverket for automatisk oppdatering, som sender applikasjons- og operativsystemversjoner for å se etter macOS-oppdateringer.",
+ "Ghostty / libghostty: terminalgjengivelsesmotoren som kjører lokalt på enheten din.",
+ "PostHog: nettsteds- og mobilproduktanalyse, inkludert sidevisninger, navigasjonsmønstre, nettlesermetadata, mobilfunksjonshendelser, kontotilknyttet mobilanalyse etter pålogging via en førsteparts proxy, og en innsendt venteliste-e-post slik at vi kan varsle deg.",
+ "Resend: transaksjonell e-postlevering. E-posten din sendes til Resend bare hvis du frivillig sender inn tilbakemelding.",
+ "Slack: private interne varsler. Hvis du blir med på en plattformventeliste, sendes e-posten og plattformene du sender til vårt private Slack-arbeidsområde."
+ ],
+ "afterBullets": [
+ "Hver tjeneste har sine egne retningslinjer for personvern. Når en tredjepart behandler personopplysninger for cmux, krever vi sikkerhetstiltak som er minst like beskyttende som denne policyen og begrenser bruken til å levere tjenester til cmux."
+ ]
+ },
+ {
+ "heading": "III. Hvordan vi bruker og deler informasjon",
+ "paragraphs": [
+ "Vi selger, bytter, leier eller deler ikke personlig informasjon med tredjeparter for markedsføring. Vi bruker krasjrapporter og diagnostikk kun for å forbedre applikasjonen. Vi kan avsløre informasjon når vi i god tro mener at avsløring er nødvendig for juridisk prosess eller beskyttelse mot skade."
+ ]
+ },
+ {
+ "heading": "IV. Hvordan vi beskytter informasjon",
+ "paragraphs": [
+ "Vi bruker tiltak utformet for å forhindre uautorisert tilgang, inkludert kryptering og sikker serverprogramvare. Ingen overførings- eller lagringsmetode er helt sikker, og bruk av tjenesten innebærer denne risikoen."
+ ]
+ },
+ {
+ "heading": "V. Dine rettigheter",
+ "paragraphs": [
+ "Avhengig av hvor du befinner deg, kan gjeldende lover som GDPR eller CCPA gi deg disse rettighetene:"
+ ],
+ "bullets": [
+ "Få tilgang til en kopi av data vi har om deg.",
+ "Korriger unøyaktige data.",
+ "Be om sletting av dataene dine.",
+ "Motta bærbare data.",
+ "Begrense eller protestere mot behandling."
+ ],
+ "afterBullets": [
+ "For å utøve disse rettighetene, kontakt [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Lenker til andre nettsteder",
+ "paragraphs": [
+ "Tjenesten kan lenke til tredjeparts nettsteder. Vi er ikke ansvarlige for deres personvernpraksis. Denne policyen gjelder kun for informasjon vi samler inn."
+ ]
+ },
+ {
+ "heading": "VII. Endringer i denne policyen",
+ "paragraphs": [
+ "Vi kan endre denne policyen. Vesentlige endringer trer i kraft 30 dager etter varsel. Sjekk nettstedet med jevne mellomrom for oppdateringer."
+ ]
+ },
+ {
+ "heading": "VIII. Kontakt oss",
+ "paragraphs": [
+ "Spørsmål om disse retningslinjene kan sendes til [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Oppbevaring av data",
+ "paragraphs": [
+ "Krasjrapporter og diagnostikk lagres bare så lenge det er nødvendig for å diagnostisere og fikse problemer. Mobilkontoidentifikatorer og autentiseringsposter oppbevares mens kontoen din er aktiv, og slettes eller anonymiseres deretter når slettingen av kontoen er fullført, bortsett fra når sikkerhets-, juridiske, fakturerings- eller svindelforebyggende plikter krever oppbevaring. Enhets- og sammenkoblingsmetadata beholdes til du opphever paringen, logger av og sletter lokale data, sletter kontoen din eller foreldede sammenkoblingsdata beskjæres. Apple Push Notification-tjenestetokener beholdes bare mens varsler er aktivert og fjernes når du deaktiverer varsler, logger av, sletter kontoen din eller Apple rapporterer tokenet ugyldig. Mobil produktanalyse i PostHog lagres i opptil 24 måneder med mindre du ber om tidligere sletting. Mobilkontoinnstillinger sletter eller anonymiserer cmux-eid konto, enhet, sammenkobling, varsling, fakturering og skydata, sletter den kontotilknyttede PostHog-personen og ber om sletting av mobilanalysehendelser og -opptak. Noe slettingsarbeid fra leverandøren kan fullføres asynkront. Be om sletting i mobilkontoinnstillinger eller ved å kontakte [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/pl.json b/web/app/[locale]/(legal)/privacy-policy/content/pl.json
new file mode 100644
index 000000000000..033b4d3a27db
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/pl.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Polityka prywatności — cmux",
+ "metadataDescription": "Polityka prywatności dla cmux",
+ "title": "Polityka prywatności",
+ "lastUpdated": "Ostatnia aktualizacja: 10 lipca 2026 r",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow („Firma”) zobowiązuje się do utrzymywania solidnej ochrony prywatności swoich użytkowników. Niniejsza Polityka prywatności wyjaśnia, w jaki sposób gromadzimy, wykorzystujemy i zabezpieczamy informacje, które nam przekazujesz.",
+ "W tej polityce „Witryna” oznacza witrynę internetową Spółki pod adresem [cmux.com](https://cmux.com). „Aplikacja” oznacza aplikację komputerową cmux dla macOS oraz aplikację mobilną cmux dla iPhone i iPad. „Usługa” oznacza łącznie Witrynę i Aplikację. „My”, „nas” i „nasz” oznaczają Firmę. „Ty” oznacza użytkownika naszej Usługi.",
+ "Korzystając z naszej Usługi, akceptujesz niniejszą Politykę prywatności i nasze [Warunki korzystania z usługi](https://cmux.com/terms-of-service) oraz wyrażasz zgodę na gromadzenie, przechowywanie, wykorzystywanie i ujawnianie opisane tutaj."
+ ]
+ },
+ {
+ "heading": "I. Informacje, które zbieramy",
+ "paragraphs": [
+ "Gromadzimy dane nieosobowe i dane osobowe. Dane nieosobowe nie umożliwiają identyfikacji użytkownika i obejmują anonimowe dane dotyczące użytkowania, typów platform i diagnostyki awarii. Dane osobowe obejmują Twój adres e-mail, identyfikatory konta i informacje, które zdecydujesz się podać podczas logowania, kontaktowania się z nami, parowania urządzenia lub korzystania z Aplikacji."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informacje gromadzone za pomocą technologii",
+ "paragraphs": [
+ "Aplikacja może automatycznie zbierać następujące informacje:"
+ ],
+ "bullets": [
+ "Raporty o awariach i diagnostyka błędów poprzez Sentry.",
+ "Wersja systemu operacyjnego i wersja aplikacji.",
+ "Analityka produktów i zdarzenia dotyczące wykorzystania funkcji w Witrynie i Aplikacji.",
+ "Metadane urządzenia, konta i parowania potrzebne do połączenia zalogowanych urządzeń.",
+ "Apple Tokeny urządzenia usługi powiadomień push, tylko po włączeniu powiadomień telefonicznych."
+ ],
+ "afterBullets": [
+ "Aplikacja macOS sprawdza dostępność aktualizacji za pośrednictwem Sparkle, który może wysyłać wersje systemu operacyjnego i aplikacji do naszego serwera aktualizacji. Aplikacja iPhone i iPad jest aktualizowana za pomocą App Store, a nie Sparkle.",
+ "Witryna wykorzystuje PostHog do analiz przeglądania stron i nawigacji. PostHog przechowuje plik cookie w celu rozróżnienia odwiedzających. Jeśli dołączysz do listy oczekujących platformy, przesłany przez Ciebie adres e-mail zostanie zapisany w PostHog, abyśmy mogli Cię powiadomić. Jeśli prześlesz formularz kontaktowy dla przedsiębiorstwa, zarejestrujemy firmę i dane kontaktowe, które podałeś w PostHog i wyślemy je do naszego prywatnego obszaru roboczego Slack i skrzynki e-mail założycieli, abyśmy mogli odpowiedzieć. Możesz zablokować analitykę witryny internetowej za pomocą rozszerzenia przeglądarki, które blokuje skrypty śledzące.",
+ "Aplikacja iPhone i iPad wysyła zdarzenia związane z analizą produktu do naszego serwera proxy PostHog po stronie serwera. Zdarzenia te pomagają zdiagnozować niezawodność, zrozumieć wykorzystanie funkcji i ulepszyć Aplikację. Obejmują one uruchomienie aplikacji i zdarzenia sesji, status logowania, próby i wyniki parowania, przywrócenie połączenia, otwarcia obszaru roboczego, liczbę bajtów i linii wejściowych terminala oraz wyniki zgody na powiadomienie lub głębokiego łącza do powiadomień. Usługa Mobile Analytics nie wysyła tekstu poleceń terminala, wyników terminala, wybranych zdjęć ani transkrypcji mowy do PostHog. Przed zalogowaniem zdarzenia używają losowego identyfikatora klienta dla każdej instalacji. Po zalogowaniu nasz serwer dołącza identyfikator Twojego konta Stack Auth przed przekazaniem zdarzeń do PostHog. Analityka i raporty o awariach uruchamiają się wyłączone i są wysyłane dopiero po włączeniu opcji Udostępnij analizę i raporty o awariach w Ustawieniach. Wyłączenie tej opcji powoduje zatrzymanie buforowania i wysyłania analiz oraz raportowanie awarii. Skontaktuj się z [founders@manaflow.com](mailto:founders@manaflow.com), aby poprosić o usunięcie statystyk powiązanych z Twoim kontem."
+ ]
+ },
+ {
+ "heading": "2. Informacje podawane bezpośrednio",
+ "paragraphs": [
+ "Jeśli skontaktujesz się z nami za pośrednictwem poczty elektronicznej, naszej strony kontaktowej lub formularza kontaktowego Enterprise, zbieramy podane przez Ciebie informacje, w tym imię i nazwisko, adres e-mail, firma, rola, numer telefonu, kraj, potrzeby wdrożeniowe i komentarze. Jeśli dołączysz do listy oczekujących platformy, zbierzemy przesłaną przez Ciebie wiadomość e-mail, aby powiadomić Cię o uruchomieniu platformy i wysłać wiadomość e-mail rejestracyjną oraz wybrane platformy do naszego prywatnego obszaru roboczego Slack.",
+ "Kiedy się logujesz, otrzymujemy informacje uwierzytelniające, takie jak adres e-mail i identyfikator dostawcy, od Apple, Google, GitHub lub kod e-mail do logowania. Kiedy łączysz aplikację mobilną z komputerem Mac, przetwarzamy informacje dotyczące parowania potrzebne do połączenia urządzeń. Gdy przeglądasz obszar roboczy, wysyłasz dane wejściowe z terminala, dołączasz wybrane zdjęcia, korzystasz z transkrypcji mowy lub odbierasz powiadomienia z terminala, powiązana treść lub transkrypcja może być przekazywana między Twoimi urządzeniami a naszą usługą, jeśli jest to konieczne do zapewnienia tej funkcji.",
+ "Dostęp do kamery służy wyłącznie do skanowania kodów parowania cmux QR. Dostęp do mikrofonu i rozpoznawania mowy jest używany tylko wtedy, gdy w oknie wiadomości wybierzesz transkrypcję głosu. Dostęp do biblioteki zdjęć jest używany tylko wtedy, gdy wybierzesz zdjęcia do załączenia."
+ ]
+ },
+ {
+ "heading": "3. Prywatność dzieci",
+ "paragraphs": [
+ "Usługa nie jest skierowana do osób poniżej 13 roku życia i nie zbieramy świadomie informacji od osób poniżej 13 roku życia. Jeśli uważasz, że zebraliśmy takie informacje, skontaktuj się z [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Usługi stron trzecich",
+ "paragraphs": [
+ "Aplikacja integruje się z usługami stron trzecich:"
+ ],
+ "bullets": [
+ "Stack Auth: uwierzytelnianie i zarządzanie kontem w zakresie logowania, sesji i usuwania konta.",
+ "Apple, Google i GitHub: opcjonalni dostawcy logowania, którzy wysyłają informacje o koncie wymagane do uwierzytelnienia.",
+ "Usługa powiadomień push Apple: powiadomienia wysyłane do iPhone i iPad po wyrażeniu zgody.",
+ "Apple Rozpoznawanie mowy: transkrypcja głosu po wybraniu tej opcji w aplikacji mobilnej.",
+ "Sentry: śledzenie błędów i raportowanie awarii, które może zbierać dzienniki błędów, ślady stosu, informacje o urządzeniu i wersji systemu operacyjnego.",
+ "Sparkle: platforma automatycznej aktualizacji macOS, która wysyła wersje aplikacji i systemów operacyjnych w celu sprawdzenia dostępności aktualizacji macOS.",
+ "Ghostty / libghostty: silnik renderujący terminal, który działa lokalnie na Twoim urządzeniu.",
+ "PostHog: analityka witryn internetowych i produktów mobilnych, w tym odsłony stron, wzorce nawigacji, metadane przeglądarki, zdarzenia związane z funkcjami mobilnymi, analityka mobilna powiązana z kontem po zalogowaniu się za pośrednictwem własnego serwera proxy oraz przesłana wiadomość e-mail z listą oczekujących, abyśmy mogli Cię powiadomić.",
+ "Resend: dostarczanie e-maili transakcyjnych. Twój e-mail zostanie wysłany do Resend tylko wtedy, gdy dobrowolnie prześlesz opinię.",
+ "Slack: prywatne powiadomienia wewnętrzne. Jeśli dołączysz do listy oczekujących platformy, przesłane wiadomości e-mail i platformy zostaną przesłane do naszego prywatnego obszaru roboczego Slack."
+ ],
+ "afterBullets": [
+ "Każdy serwis posiada własną politykę prywatności. Kiedy strona trzecia przetwarza dane osobowe na rzecz cmux, wymagamy zabezpieczeń co najmniej tak samo ochronnych jak niniejsza polityka i ograniczamy ich wykorzystanie do świadczenia usług na rzecz cmux."
+ ]
+ },
+ {
+ "heading": "III. Jak wykorzystujemy i udostępniamy informacje",
+ "paragraphs": [
+ "Nie sprzedajemy, nie handlujemy, nie wynajmujemy ani nie udostępniamy danych osobowych stronom trzecim w celach marketingowych. Wykorzystujemy raporty o awariach i diagnostykę wyłącznie w celu ulepszenia Aplikacji. Możemy ujawnić informacje, jeśli w dobrej wierze uważamy, że ich ujawnienie jest konieczne ze względu na proces prawny lub ochronę przed krzywdą."
+ ]
+ },
+ {
+ "heading": "IV. Jak chronimy informacje",
+ "paragraphs": [
+ "Stosujemy środki mające na celu uniemożliwienie nieuprawnionego dostępu, w tym szyfrowanie i bezpieczne oprogramowanie serwerowe. Żaden sposób przesyłania ani przechowywania nie jest w pełni bezpieczny, a korzystanie z Usługi wiąże się z takim ryzykiem."
+ ]
+ },
+ {
+ "heading": "V. Twoje prawa",
+ "paragraphs": [
+ "W zależności od Twojej lokalizacji obowiązujące przepisy, takie jak GDPR lub CCPA, mogą przyznawać Ci następujące prawa:"
+ ],
+ "bullets": [
+ "Uzyskaj dostęp do kopii danych, które o Tobie posiadamy.",
+ "Popraw niedokładne dane.",
+ "Poproś o usunięcie swoich danych.",
+ "Otrzymuj przenośne dane.",
+ "Ograniczyć lub sprzeciwić się przetwarzaniu."
+ ],
+ "afterBullets": [
+ "Aby skorzystać z tych praw, skontaktuj się z [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Linki do innych stron internetowych",
+ "paragraphs": [
+ "Usługa może zawierać łącza do stron internetowych osób trzecich. Nie ponosimy odpowiedzialności za ich praktyki dotyczące prywatności. Niniejsza polityka dotyczy wyłącznie informacji, które zbieramy."
+ ]
+ },
+ {
+ "heading": "VII. Zmiany w niniejszej Polityce",
+ "paragraphs": [
+ "Możemy zmienić tę politykę. Istotne zmiany wchodzą w życie po 30 dniach od powiadomienia. Sprawdzaj okresowo Stronę pod kątem aktualizacji."
+ ]
+ },
+ {
+ "heading": "VIII. Skontaktuj się z nami",
+ "paragraphs": [
+ "Pytania dotyczące tej polityki można przesyłać na adres [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Przechowywanie danych",
+ "paragraphs": [
+ "Raporty o awariach i dane diagnostyczne są przechowywane tylko tak długo, jak jest to konieczne do zdiagnozowania i rozwiązania problemów. Identyfikatory kont mobilnych i zapisy uwierzytelniania są przechowywane, gdy konto jest aktywne, a następnie usuwane lub anonimizowane po zakończeniu usuwania konta, z wyjątkiem sytuacji, gdy wymagane jest zachowanie obowiązków związanych z bezpieczeństwem, przepisami prawnymi, rozliczeniami lub zapobieganiem oszustwom. Metadane urządzenia i parowania pozostają zachowane do czasu rozparowania, wylogowania się i usunięcia danych lokalnych, usunięcia konta lub usunięcia nieaktualnych danych parowania. Tokeny usługi powiadomień push Apple są przechowywane tylko wtedy, gdy powiadomienia są włączone i usuwane, gdy wyłączysz powiadomienia, wylogujesz się, usuniesz konto lub Apple zgłosi nieprawidłowy token. Analityka produktów mobilnych w PostHog jest przechowywana do 24 miesięcy, chyba że poprosisz o wcześniejsze usunięcie. Ustawienia konta mobilnego usuwają lub anonimizują konto, urządzenie, parowanie, powiadomienia, rozliczenia i dane w chmurze należące do cmux, usuwają osobę powiązaną z kontem PostHog i żądają usunięcia jej zdarzeń i nagrań związanych z analityką mobilną. Niektóre prace związane z usuwaniem dostawców mogą zakończyć się asynchronicznie. Poproś o usunięcie w ustawieniach konta mobilnego lub kontaktując się z [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/pt-BR.json b/web/app/[locale]/(legal)/privacy-policy/content/pt-BR.json
new file mode 100644
index 000000000000..8755895e130a
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/pt-BR.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Política de Privacidade — cmux",
+ "metadataDescription": "Política de privacidade para cmux",
+ "title": "Política de Privacidade",
+ "lastUpdated": "Última atualização: 10 de julho de 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (a \"Empresa\") está comprometida em manter proteções robustas de privacidade para seus usuários. Esta Política de Privacidade explica como coletamos, usamos e protegemos as informações que você nos fornece.",
+ "Nesta política, \"Site\" significa o site da Empresa em [cmux.com](https://cmux.com). \"Aplicativo\" significa o aplicativo de desktop cmux para macOS e o aplicativo móvel cmux para iPhone e iPad. \"Serviço\" significa o Site e o Aplicativo juntos. \"Nós\", \"nos\" e \"nosso\" significam a Empresa. \"Você\" significa um usuário do nosso Serviço.",
+ "Ao utilizar nosso Serviço, você aceita esta Política de Privacidade e nossos [Termos de Serviço](https://cmux.com/terms-of-service) e concorda com a coleta, armazenamento, uso e divulgação descritos aqui."
+ ]
+ },
+ {
+ "heading": "I. Informações que coletamos",
+ "paragraphs": [
+ "Coletamos Informações Não Pessoais e Informações Pessoais. As informações não pessoais não podem identificá-lo e incluem dados de uso anônimos, tipos de plataforma e diagnósticos de falhas. As Informações Pessoais incluem seu endereço de e-mail, identificadores de conta e informações que você escolhe fornecer ao fazer login, entrar em contato conosco, emparelhar um dispositivo ou usar o Aplicativo."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Informações coletadas por meio da tecnologia",
+ "paragraphs": [
+ "O Aplicativo poderá coletar automaticamente as seguintes informações:"
+ ],
+ "bullets": [
+ "Relatórios de falhas e diagnósticos de erros através do Sentry.",
+ "Versão do sistema operacional e versão do aplicativo.",
+ "Análise de produto e eventos de uso de recursos para o Site e Aplicativo.",
+ "Metadados de dispositivo, conta e pareamento necessários para conectar seus dispositivos conectados.",
+ "Apple Tokens de dispositivo de serviço de notificação por push, somente depois de ativar as notificações por telefone."
+ ],
+ "afterBullets": [
+ "O aplicativo macOS verifica atualizações por meio do Sparkle, que pode enviar o sistema operacional e as versões do aplicativo para nosso servidor de atualização. Os aplicativos iPhone e iPad são atualizados por meio do App Store, não do Sparkle.",
+ "O Site usa PostHog para visualização de página e análise de navegação. PostHog armazena um cookie para distinguir os visitantes. Se você entrar em uma lista de espera da plataforma, o e-mail enviado será registrado em PostHog para que possamos notificá-lo. Se você enviar o formulário de contato empresarial, registraremos a empresa e os detalhes de contato que você fornece no PostHog e os enviaremos para nosso espaço de trabalho privado Slack e caixa de entrada de e-mail dos fundadores para que possamos responder. Você pode bloquear análises de sites com uma extensão de navegador que bloqueia scripts de rastreamento.",
+ "Os aplicativos iPhone e iPad enviam eventos de análise de produto para nosso proxy PostHog do lado do servidor. Esses eventos ajudam a diagnosticar a confiabilidade, compreender o uso dos recursos e melhorar o Aplicativo. Eles incluem eventos de inicialização e sessão de aplicativos, status de login, tentativas e resultados de emparelhamento, recuperação de conexão, aberturas de espaço de trabalho, bytes de entrada de terminal e contagens de linhas e resultados de ativação de notificação ou link direto de notificação. A análise móvel não envia texto de comando de terminal, saída de terminal, fotos selecionadas ou transcrições de fala para PostHog. Antes de entrar, os eventos usam um identificador de cliente aleatório por instalação. Após o login, nosso servidor anexa o identificador da sua conta Stack Auth antes de encaminhar eventos para PostHog. Os relatórios analíticos e de falhas começam desativados e são enviados somente depois que você ativa Compartilhar análises e relatórios de falhas nas configurações. Desativar esse controle impede que as análises sejam armazenadas em buffer ou enviadas e interrompe os relatórios de falhas. Entre em contato com [founders@manaflow.com](mailto:founders@manaflow.com) para solicitar a exclusão das análises associadas à sua conta."
+ ]
+ },
+ {
+ "heading": "2. Informações que você fornece diretamente",
+ "paragraphs": [
+ "Se você entrar em contato conosco por e-mail, pela nossa página de contato ou pelo formulário de contato empresarial, coletaremos as informações que você fornecer, incluindo nome, e-mail, empresa, função, número de telefone, país, necessidades de implantação e comentários. Se você ingressar em uma lista de espera de plataforma, coletaremos o e-mail enviado para notificá-lo quando a plataforma for lançada e enviaremos o e-mail de inscrição e as plataformas selecionadas para nosso espaço de trabalho privado Slack.",
+ "Quando você faz login, recebemos informações de autenticação, como seu endereço de e-mail e identificador de provedor de Apple, Google, GitHub ou login com código de e-mail. Quando você emparelha o aplicativo móvel com um Mac, processamos as informações de emparelhamento necessárias para conectar os dispositivos. Quando você visualiza um espaço de trabalho, envia entradas de terminal, anexa fotos selecionadas, usa transcrição de fala ou recebe notificações de terminal, o conteúdo ou transcrição relacionado pode passar entre seus dispositivos e nosso serviço conforme necessário para fornecer esse recurso.",
+ "O acesso à câmera é usado apenas para digitalizar códigos cmux de emparelhamento QR. O acesso ao microfone e ao reconhecimento de fala são usados somente quando você escolhe a transcrição de voz na caixa de mensagem. O acesso à biblioteca de fotos é usado somente quando você escolhe fotos para anexar."
+ ]
+ },
+ {
+ "heading": "3. Privacidade das Crianças",
+ "paragraphs": [
+ "O Serviço não é direcionado a menores de 13 anos e não coletamos intencionalmente informações de menores de 13 anos. Se você acredita que coletamos tais informações, entre em contato com [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Serviços de terceiros",
+ "paragraphs": [
+ "O Aplicativo se integra a estes serviços de terceiros:"
+ ],
+ "bullets": [
+ "Stack Auth: autenticação e gerenciamento de contas para login, sessões e exclusão de contas.",
+ "Apple, Google e GitHub: provedores de login opcionais que enviam informações de conta necessárias para autenticá-lo.",
+ "Serviço de notificação push Apple: notificações para iPhone e iPad após você aceitar.",
+ "Apple Reconhecimento de fala: transcrição de voz quando você escolhe no aplicativo móvel.",
+ "Sentry: rastreamento de erros e relatórios de falhas, que podem coletar logs de erros, rastreamentos de pilha, informações do dispositivo e versão do sistema operacional.",
+ "Sparkle: a estrutura de atualização automática macOS, que envia versões de aplicativos e sistemas operacionais para verificar atualizações do macOS.",
+ "Ghostty / libghostty: o mecanismo de renderização de terminal, que é executado localmente no seu dispositivo.",
+ "PostHog: análises de sites e produtos móveis, incluindo visualizações de páginas, padrões de navegação, metadados do navegador, eventos de recursos móveis, análises móveis vinculadas à conta após login por meio de um proxy primário e um e-mail de lista de espera enviado para que possamos notificá-lo.",
+ "Resend: entrega de e-mail transacional. Seu e-mail será enviado para Resend somente se você enviar feedback voluntariamente.",
+ "Slack: notificações internas privadas. Se você ingressar em uma lista de espera de plataforma, o e-mail e as plataformas enviadas serão enviados para nosso espaço de trabalho privado Slack."
+ ],
+ "afterBullets": [
+ "Cada serviço tem sua própria política de privacidade. Quando um terceiro processa Informações Pessoais para cmux, exigimos salvaguardas pelo menos tão protetoras quanto esta política e limitamos o uso ao fornecimento de serviços para cmux."
+ ]
+ },
+ {
+ "heading": "III. Como usamos e compartilhamos informações",
+ "paragraphs": [
+ "Não vendemos, comercializamos, alugamos ou compartilhamos Informações Pessoais com terceiros para fins de marketing. Usamos relatórios de falhas e diagnósticos apenas para melhorar o Aplicativo. Poderemos divulgar informações quando acreditarmos de boa fé que a divulgação é necessária para processos legais ou proteção contra danos."
+ ]
+ },
+ {
+ "heading": "4. Como protegemos as informações",
+ "paragraphs": [
+ "Utilizamos medidas destinadas a impedir o acesso não autorizado, incluindo criptografia e software de servidor seguro. Nenhum método de transmissão ou armazenamento é completamente seguro e a utilização do Serviço envolve este risco."
+ ]
+ },
+ {
+ "heading": "V. Seus direitos",
+ "paragraphs": [
+ "Dependendo da sua localização, as leis aplicáveis, como GDPR ou CCPA, podem conceder-lhe estes direitos:"
+ ],
+ "bullets": [
+ "Acesse uma cópia dos dados que mantemos sobre você.",
+ "Corrija dados imprecisos.",
+ "Solicite a exclusão dos seus dados.",
+ "Receba dados portáteis.",
+ "Restringir ou opor-se ao processamento."
+ ],
+ "afterBullets": [
+ "Para exercer esses direitos, entre em contato com [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Links para outros sites",
+ "paragraphs": [
+ "O Serviço pode conter links para sites de terceiros. Não somos responsáveis por suas práticas de privacidade. Esta política se aplica apenas às informações que coletamos."
+ ]
+ },
+ {
+ "heading": "VII. Mudanças nesta política",
+ "paragraphs": [
+ "Podemos alterar esta política. Alterações significativas entram em vigor 30 dias após a notificação. Verifique o Site periodicamente para atualizações."
+ ]
+ },
+ {
+ "heading": "VIII. Contate-nos",
+ "paragraphs": [
+ "Perguntas sobre esta política podem ser enviadas para [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Retenção de dados",
+ "paragraphs": [
+ "Os relatórios e diagnósticos de falhas são mantidos apenas pelo tempo necessário para diagnosticar e corrigir problemas. Os identificadores de contas móveis e os registros de autenticação são mantidos enquanto sua conta está ativa e, em seguida, excluídos ou anonimizados quando a exclusão da conta é concluída, exceto quando tarefas de segurança, jurídicas, de cobrança ou de prevenção de fraudes exigem retenção. Os metadados do dispositivo e do emparelhamento são mantidos até você desemparelhar, sair e excluir dados locais, excluir sua conta ou até que os dados de emparelhamento obsoletos sejam removidos. Os tokens de serviço de notificação por push Apple são mantidos apenas enquanto as notificações estão habilitadas e são removidos quando você desativa notificações, sai, exclui sua conta ou Apple relata que o token é inválido. A análise de produtos móveis no PostHog é mantida por até 24 meses, a menos que você solicite a exclusão antecipada. As configurações da conta móvel excluem ou anonimizam dados de conta, dispositivo, emparelhamento, notificação, cobrança e nuvem de propriedade do cmux, excluem a pessoa PostHog vinculada à conta e solicitam a exclusão de seus eventos e gravações de análise móvel. Alguns trabalhos de exclusão de provedor podem ser concluídos de forma assíncrona. Solicite a exclusão nas configurações da conta móvel ou entrando em contato com [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/ru.json b/web/app/[locale]/(legal)/privacy-policy/content/ru.json
new file mode 100644
index 000000000000..e1b946933921
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/ru.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Политика конфиденциальности — cmux",
+ "metadataDescription": "Политика конфиденциальности для cmux",
+ "title": "Политика конфиденциальности",
+ "lastUpdated": "Последнее обновление: 10 июля 2026 г.",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow («Компания») стремится обеспечить надежную защиту конфиденциальности своих пользователей. В настоящей Политике конфиденциальности объясняется, как мы собираем, используем и защищаем информацию, которую вы нам предоставляете.",
+ "В настоящей политике «Сайт» означает веб-сайт Компании по адресу [cmux.com](https://cmux.com). «Приложение» означает настольное приложение cmux для macOS и мобильное приложение cmux для iPhone и iPad. «Сервис» означает Сайт и Приложение вместе. «Мы», «нас» и «наш» означают Компанию. «Вы» означает пользователя нашего Сервиса.",
+ "Используя наш Сервис, вы принимаете настоящую Политику конфиденциальности и наши [Условия обслуживания](https://cmux.com/terms-of-service) и соглашаетесь на сбор, хранение, использование и раскрытие, описанные здесь."
+ ]
+ },
+ {
+ "heading": "I. Информация, которую мы собираем",
+ "paragraphs": [
+ "Мы собираем информацию неличного характера и личную информацию. Информация неличного характера не может идентифицировать вас и включает анонимные данные об использовании, типы платформ и диагностику сбоев. Личная информация включает ваш адрес электронной почты, идентификаторы учетной записи и информацию, которую вы решаете предоставить при входе в систему, обращении к нам, подключении устройства или использовании Приложения."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Информация, собранная с помощью технологий",
+ "paragraphs": [
+ "Приложение может автоматически собирать следующую информацию:"
+ ],
+ "bullets": [
+ "Отчеты о сбоях и диагностика ошибок через Sentry.",
+ "Версия операционной системы и версия приложения.",
+ "Аналитика продуктов и события использования функций Сайта и Приложения.",
+ "Метаданные устройства, учетной записи и сопряжения, необходимые для подключения устройств, на которых выполнен вход.",
+ "Apple Токены устройства службы push-уведомлений, только после включения уведомлений по телефону."
+ ],
+ "afterBullets": [
+ "Приложение macOS проверяет наличие обновлений через Sparkle, который может отправлять версии вашей операционной системы и приложений на наш сервер обновлений. Приложение iPhone и iPad обновляется через App Store, а не Sparkle.",
+ "Сайт использует PostHog для просмотра страниц и анализа навигации. PostHog сохраняет файл cookie, чтобы различать посетителей. Если вы присоединяетесь к списку ожидания платформы, отправленный вами адрес электронной почты записывается в PostHog, чтобы мы могли уведомить вас. Если вы отправляете контактную форму Enterprise, мы записываем информацию о компании и контактные данные, которые вы предоставляете, в PostHog и отправляем их в наше личное рабочее пространство Slack и в почтовый ящик основателей, чтобы мы могли ответить. Вы можете заблокировать аналитику веб-сайта с помощью расширения браузера, которое блокирует сценарии отслеживания.",
+ "Приложение iPhone и iPad отправляет события аналитики продукта на наш серверный прокси-сервер PostHog. Эти события помогают диагностировать надежность, понимать использование функций и улучшать Приложение. К ним относятся события запуска приложения и сеанса, состояние входа, попытки и результаты сопряжения, восстановление соединения, открытие рабочей области, количество байтов и строк ввода терминала, а также результаты согласия на получение уведомлений или результатов глубоких ссылок на уведомления. Мобильная аналитика не отправляет текст команды терминала, выходные данные терминала, выбранные фотографии или расшифровки речи в PostHog. Перед входом в систему события используют случайный идентификатор клиента для каждой установки. После входа в систему наш сервер присоединяет идентификатор вашей учетной записи Stack Auth перед пересылкой событий в PostHog. Аналитика и отчеты о сбоях сначала отключаются и отправляются только после того, как вы включите «Поделиться аналитикой» и «Отчеты о сбоях» в настройках. Отключение этого элемента управления останавливает буферизацию или отправку аналитики, а также останавливает отчеты о сбоях. Свяжитесь с [founders@manaflow.com](mailto:founders@manaflow.com), чтобы запросить удаление аналитики, связанной с вашей учетной записью."
+ ]
+ },
+ {
+ "heading": "2. Информация, которую вы предоставляете напрямую",
+ "paragraphs": [
+ "Если вы связываетесь с нами по электронной почте, на нашей контактной странице или через контактную форму Enterprise, мы собираем предоставленную вами информацию, включая имя, адрес электронной почты, компанию, роль, номер телефона, страну, потребности в развертывании и комментарии. Если вы присоединяетесь к списку ожидания платформы, мы собираем отправленное вами электронное письмо, чтобы уведомить вас о запуске этой платформы, и отправляем электронное письмо о регистрации и выбранные платформы в наше личное рабочее пространство Slack.",
+ "Когда вы входите в систему, мы получаем информацию для аутентификации, такую как ваш адрес электронной почты и идентификатор провайдера, от Apple, Google, GitHub или для входа в систему с помощью кода электронной почты. Когда вы связываете мобильное приложение с Mac, мы обрабатываем информацию о сопряжении, необходимую для подключения устройств. Когда вы просматриваете рабочую область, отправляете входные данные терминала, прикрепляете выбранные фотографии, используете транскрипцию речи или получаете уведомления терминала, соответствующий контент или расшифровка могут передаваться между вашими устройствами и нашей службой, если это необходимо для предоставления этой функции.",
+ "Доступ к камере используется только для сканирования парных кодов cmux QR. Доступ к микрофону и распознаванию речи используются только тогда, когда вы выбираете транскрипцию голоса в окне сообщения. Доступ к фотобиблиотеке используется только тогда, когда вы выбираете фотографии для прикрепления."
+ ]
+ },
+ {
+ "heading": "3. Конфиденциальность детей",
+ "paragraphs": [
+ "Сервис не предназначен для лиц младше 13 лет, и мы сознательно не собираем информацию от лиц младше 13 лет. Если вы считаете, что мы собрали такую информацию, свяжитесь с [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Сторонние услуги",
+ "paragraphs": [
+ "Приложение интегрируется со следующими сторонними сервисами:"
+ ],
+ "bullets": [
+ "Stack Auth: аутентификация и управление учетными записями для входа, сеансов и удаления учетной записи.",
+ "Apple, Google и GitHub: дополнительные поставщики входа в систему, которые отправляют данные учетной записи, необходимые для вашей аутентификации.",
+ "Служба push-уведомлений Apple: уведомления для iPhone и iPad после вашего согласия.",
+ "Apple Распознавание речи: транскрипция голоса, когда вы выбираете ее в мобильном приложении.",
+ "Sentry: отслеживание ошибок и отчеты о сбоях, которые могут собирать журналы ошибок, трассировки стека, информацию об устройстве и версию операционной системы.",
+ "Sparkle: платформа автоматического обновления macOS, которая отправляет версии приложений и операционной системы для проверки обновлений macOS.",
+ "Ghostty / libghostty: механизм рендеринга терминала, который работает локально на вашем устройстве.",
+ "PostHog: аналитика веб-сайтов и мобильных продуктов, включая просмотры страниц, шаблоны навигации, метаданные браузера, события мобильных функций, мобильную аналитику, связанную с учетной записью, после входа в систему через собственный прокси-сервер и отправленное электронное письмо из списка ожидания, чтобы мы могли уведомить вас.",
+ "Resend: транзакционная доставка электронной почты. Ваше электронное письмо будет отправлено на Resend только в том случае, если вы добровольно отправите отзыв.",
+ "Slack: частные внутренние уведомления. Если вы присоединитесь к списку ожидания платформы, отправленное вами электронное письмо и платформы будут отправлены в наше личное рабочее пространство Slack."
+ ],
+ "afterBullets": [
+ "Каждый сервис имеет свою политику конфиденциальности. Когда третья сторона обрабатывает Персональную информацию для cmux, мы требуем гарантий, по крайней мере, таких же защитных, как и эта политика, и ограничиваем использование предоставлением услуг cmux."
+ ]
+ },
+ {
+ "heading": "III. Как мы используем и передаем информацию",
+ "paragraphs": [
+ "Мы не продаем, не обмениваем, не сдаем в аренду и не передаем Персональную информацию третьим лицам в целях маркетинга. Мы используем отчеты о сбоях и диагностику только для улучшения Приложения. Мы можем раскрывать информацию, если добросовестно полагаем, что раскрытие информации необходимо для судебного процесса или защиты от вреда."
+ ]
+ },
+ {
+ "heading": "IV. Как мы защищаем информацию",
+ "paragraphs": [
+ "Мы используем меры, предназначенные для предотвращения несанкционированного доступа, включая шифрование и безопасное серверное программное обеспечение. Ни один метод передачи или хранения не является полностью безопасным, и использование Сервиса сопряжено с этим риском."
+ ]
+ },
+ {
+ "heading": "V. Ваши права",
+ "paragraphs": [
+ "В зависимости от вашего местоположения применимые законы, такие как GDPR или CCPA, могут предоставить вам следующие права:"
+ ],
+ "bullets": [
+ "Получите доступ к копии данных о вас, которые мы храним.",
+ "Исправьте неточные данные.",
+ "Запросить удаление ваших данных.",
+ "Получайте портативные данные.",
+ "Ограничить обработку или запретить ее обработку."
+ ],
+ "afterBullets": [
+ "Чтобы воспользоваться этими правами, свяжитесь с [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Ссылки на другие сайты",
+ "paragraphs": [
+ "Сервис может ссылаться на сторонние веб-сайты. Мы не несем ответственности за их политику конфиденциальности. Эта политика применяется только к информации, которую мы собираем."
+ ]
+ },
+ {
+ "heading": "VII. Изменения в этой политике",
+ "paragraphs": [
+ "Мы можем изменить эту политику. Существенные изменения вступают в силу через 30 дней после уведомления. Периодически проверяйте Сайт на наличие обновлений."
+ ]
+ },
+ {
+ "heading": "VIII. Свяжитесь с нами",
+ "paragraphs": [
+ "Вопросы об этой политике можно отправлять по адресу [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Хранение данных",
+ "paragraphs": [
+ "Отчеты о сбоях и диагностические данные хранятся только до тех пор, пока это необходимо для диагностики и устранения проблем. Идентификаторы мобильных учетных записей и записи аутентификации сохраняются, пока ваша учетная запись активна, а затем удаляются или анонимизируются по завершении удаления учетной записи, за исключением случаев, когда сохранение требуется в целях обеспечения безопасности, юридических вопросов, выставления счетов или предотвращения мошенничества. Метаданные устройства и сопряжения сохраняются до тех пор, пока вы не отсоедините его, не выйдете из системы и не удалите локальные данные, не удалите свою учетную запись или пока не будут удалены устаревшие данные о сопряжении. Токены службы push-уведомлений Apple сохраняются только тогда, когда уведомления включены, и удаляются, когда вы отключаете уведомления, выходите из системы, удаляете свою учетную запись или Apple сообщает, что токен недействителен. Аналитика мобильных продуктов в PostHog хранится до 24 месяцев, если вы не запросите более раннее удаление. Настройки мобильной учетной записи удаляют или анонимизируют принадлежащую cmux учетную запись, устройство, сопряжение, уведомления, выставление счетов и облачные данные, удаляют человека PostHog, связанного с учетной записью, и запрашивают удаление его событий и записей мобильной аналитики. Удаление некоторых поставщиков может выполняться асинхронно. Запросите удаление в настройках мобильного аккаунта или связавшись с [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/th.json b/web/app/[locale]/(legal)/privacy-policy/content/th.json
new file mode 100644
index 000000000000..5789f7b0f903
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/th.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "นโยบายความเป็นส่วนตัว — cmux",
+ "metadataDescription": "นโยบายความเป็นส่วนตัวสำหรับ cmux",
+ "title": "นโยบายความเป็นส่วนตัว",
+ "lastUpdated": "อัปเดตล่าสุด: 10 กรกฎาคม 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (\"บริษัท\") มุ่งมั่นที่จะรักษาการปกป้องความเป็นส่วนตัวที่แข็งแกร่งสำหรับผู้ใช้ นโยบายความเป็นส่วนตัวนี้อธิบายถึงวิธีที่เรารวบรวม ใช้ และปกป้องข้อมูลที่คุณให้ไว้กับเรา",
+ "ในนโยบายนี้ \"ไซต์\" หมายถึงเว็บไซต์ของบริษัทที่ [cmux.com](https://cmux.com) \"แอปพลิเคชัน\" หมายถึงแอปพลิเคชันเดสก์ท็อป cmux สำหรับ macOS และแอปพลิเคชันมือถือ cmux สำหรับ iPhone และ iPad \"บริการ\" หมายถึงเว็บไซต์และแอปพลิเคชันร่วมกัน \"เรา\" \"พวกเรา\" และ \"ของเรา\" หมายถึงบริษัท \"คุณ\" หมายถึงผู้ใช้บริการของเรา",
+ "ด้วยการใช้บริการของเรา คุณยอมรับนโยบายความเป็นส่วนตัวนี้และ [ข้อกำหนดในการให้บริการ](https://cmux.com/terms-of-service) ของเรา และยินยอมให้มีการรวบรวม การจัดเก็บ ใช้ และการเปิดเผยตามที่อธิบายไว้ที่นี่"
+ ]
+ },
+ {
+ "heading": "I. ข้อมูลที่เรารวบรวม",
+ "paragraphs": [
+ "เรารวบรวมข้อมูลที่ไม่ใช่ข้อมูลส่วนบุคคลและข้อมูลส่วนบุคคล ข้อมูลที่ไม่ใช่ข้อมูลส่วนบุคคลไม่สามารถระบุตัวคุณได้ และรวมถึงข้อมูลการใช้งานที่ไม่ระบุชื่อ ประเภทแพลตฟอร์ม และการวินิจฉัยข้อขัดข้อง ข้อมูลส่วนบุคคลรวมถึงที่อยู่อีเมลของคุณ ตัวระบุบัญชี และข้อมูลที่คุณเลือกที่จะให้เมื่อคุณลงชื่อเข้าใช้ ติดต่อเรา จับคู่อุปกรณ์ หรือใช้แอปพลิเคชัน"
+ ],
+ "subsections": [
+ {
+ "heading": "1. ข้อมูลที่รวบรวมผ่านเทคโนโลยี",
+ "paragraphs": [
+ "แอปพลิเคชันอาจรวบรวมข้อมูลต่อไปนี้โดยอัตโนมัติ:"
+ ],
+ "bullets": [
+ "รายงานข้อขัดข้องและการวินิจฉัยข้อผิดพลาดผ่าน Sentry",
+ "เวอร์ชันระบบปฏิบัติการและเวอร์ชันแอปพลิเคชัน",
+ "การวิเคราะห์ผลิตภัณฑ์และเหตุการณ์การใช้งานฟีเจอร์สำหรับไซต์และแอปพลิเคชัน",
+ "อุปกรณ์ บัญชี และข้อมูลเมตาการจับคู่ที่จำเป็นสำหรับการเชื่อมต่ออุปกรณ์ที่คุณลงชื่อเข้าใช้",
+ "โทเค็นอุปกรณ์บริการการแจ้งเตือนแบบพุช Apple หลังจากที่คุณเปิดใช้งานการแจ้งเตือนทางโทรศัพท์เท่านั้น"
+ ],
+ "afterBullets": [
+ "แอปพลิเคชัน macOS ตรวจสอบการอัปเดตผ่าน Sparkle ซึ่งอาจส่งระบบปฏิบัติการและเวอร์ชันแอปพลิเคชันของคุณไปยังเซิร์ฟเวอร์อัปเดตของเรา แอปพลิเคชัน iPhone และ iPad ได้รับการอัปเดตผ่าน App Store ไม่ใช่ Sparkle",
+ "เว็บไซต์ใช้ PostHog สำหรับการวิเคราะห์การดูหน้าเว็บและการนำทาง PostHog จัดเก็บคุกกี้เพื่อแยกแยะผู้เข้าชม หากคุณเข้าร่วมรายการรอแพลตฟอร์ม อีเมลที่คุณส่งมาจะถูกบันทึกไว้ใน PostHog เพื่อให้เราสามารถแจ้งให้คุณทราบได้ หากคุณส่งแบบฟอร์มติดต่อ Enterprise เราจะบันทึกบริษัทและรายละเอียดการติดต่อที่คุณให้ไว้ใน PostHog และส่งไปยังพื้นที่ทำงานส่วนตัว Slack และกล่องจดหมายอีเมลของผู้ก่อตั้ง เพื่อให้เราตอบกลับได้ คุณสามารถบล็อกการวิเคราะห์เว็บไซต์ด้วยส่วนขยายเบราว์เซอร์ที่บล็อกสคริปต์การติดตาม",
+ "แอปพลิเคชัน iPhone และ iPad ส่งเหตุการณ์การวิเคราะห์ผลิตภัณฑ์ไปยังพร็อกซี PostHog ฝั่งเซิร์ฟเวอร์ของเรา เหตุการณ์เหล่านี้ช่วยวินิจฉัยความน่าเชื่อถือ ทำความเข้าใจการใช้คุณลักษณะ และปรับปรุงแอปพลิเคชัน ซึ่งรวมถึงการเปิดตัวแอปและเหตุการณ์เซสชัน สถานะการลงชื่อเข้าใช้ ความพยายามในการจับคู่และผลลัพธ์ การกู้คืนการเชื่อมต่อ การเปิดพื้นที่ทำงาน ไบต์อินพุตเทอร์มินัลและจำนวนบรรทัด และการเลือกใช้การแจ้งเตือนหรือผลลัพธ์ลิงก์ในการแจ้งเตือน การวิเคราะห์อุปกรณ์เคลื่อนที่จะไม่ส่งข้อความคำสั่งเทอร์มินัล เอาต์พุตเทอร์มินัล รูปภาพที่เลือก หรือการถอดเสียงคำพูดไปยัง PostHog ก่อนลงชื่อเข้าใช้ กิจกรรมจะใช้ตัวระบุไคลเอ็นต์แบบสุ่มต่อการติดตั้ง หลังจากลงชื่อเข้าใช้ เซิร์ฟเวอร์ของเราจะแนบตัวระบุบัญชี Stack Auth ของคุณก่อนที่จะส่งต่อกิจกรรมไปยัง PostHog การวิเคราะห์และรายงานข้อขัดข้องเริ่มปิดใช้งานและจะถูกส่งหลังจากที่คุณเปิดใช้งานแชร์การวิเคราะห์และรายงานข้อขัดข้องในการตั้งค่าเท่านั้น การปิดการควบคุมนั้นจะหยุดการวิเคราะห์ไม่ให้ถูกบัฟเฟอร์หรือส่ง และหยุดการรายงานข้อขัดข้อง ติดต่อ [founders@manaflow.com](mailto:founders@manaflow.com) เพื่อขอลบการวิเคราะห์ที่เกี่ยวข้องกับบัญชีของคุณ"
+ ]
+ },
+ {
+ "heading": "2. ข้อมูลที่คุณให้โดยตรง",
+ "paragraphs": [
+ "หากคุณติดต่อเราทางอีเมล หน้าติดต่อของเรา หรือแบบฟอร์มติดต่อ Enterprise เราจะรวบรวมข้อมูลที่คุณให้ไว้ รวมถึงชื่อ อีเมล บริษัท บทบาท หมายเลขโทรศัพท์ ประเทศ ความต้องการในการใช้งาน และความคิดเห็น หากคุณเข้าร่วมรายชื่อรอแพลตฟอร์ม เราจะรวบรวมอีเมลที่คุณส่งมาเพื่อแจ้งให้คุณทราบเมื่อแพลตฟอร์มนั้นเปิดตัว และส่งอีเมลลงทะเบียนและแพลตฟอร์มที่เลือกไปยังพื้นที่ทำงานส่วนตัว Slack ของเรา",
+ "เมื่อคุณลงชื่อเข้าใช้ เราจะได้รับข้อมูลการตรวจสอบสิทธิ์ เช่น ที่อยู่อีเมลของคุณและตัวระบุผู้ให้บริการจาก Apple, Google, GitHub หรือการลงชื่อเข้าใช้ด้วยรหัสอีเมล เมื่อคุณจับคู่แอพมือถือกับ Mac เราจะประมวลผลข้อมูลการจับคู่ที่จำเป็นในการเชื่อมต่ออุปกรณ์ เมื่อคุณดูพื้นที่ทำงาน ส่งข้อมูลอินพุตเทอร์มินัล แนบรูปภาพที่เลือก ใช้การถอดเสียงพูด หรือรับการแจ้งเตือนเทอร์มินัล เนื้อหาหรือการถอดเสียงที่เกี่ยวข้องอาจส่งผ่านระหว่างอุปกรณ์ของคุณและบริการของเราตามความจำเป็นเพื่อมอบคุณสมบัตินั้น",
+ "การเข้าถึงกล้องใช้เพื่อสแกนรหัสการจับคู่ cmux เท่านั้น การเข้าถึงไมโครโฟนและการรู้จำเสียงจะใช้เฉพาะเมื่อคุณเลือกการถอดเสียงในกล่องข้อความเท่านั้น การเข้าถึงคลังรูปภาพจะใช้เฉพาะเมื่อคุณเลือกรูปภาพที่จะแนบเท่านั้น"
+ ]
+ },
+ {
+ "heading": "3. ความเป็นส่วนตัวของเด็ก",
+ "paragraphs": [
+ "บริการนี้ไม่ได้มุ่งเป้าไปที่ผู้ที่มีอายุต่ำกว่า 13 ปี และเราไม่ได้รวบรวมข้อมูลจากผู้ที่มีอายุต่ำกว่า 13 ปีโดยเจตนา หากคุณเชื่อว่าเรารวบรวมข้อมูลดังกล่าว โปรดติดต่อ [founders@manaflow.com](mailto:founders@manaflow.com)"
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "ครั้งที่สอง บริการของบุคคลที่สาม",
+ "paragraphs": [
+ "แอปพลิเคชันทำงานร่วมกับบริการของบุคคลที่สามเหล่านี้:"
+ ],
+ "bullets": [
+ "Stack Auth: การรับรองความถูกต้องและการจัดการบัญชีสำหรับการลงชื่อเข้าใช้ เซสชัน และการลบบัญชี",
+ "Apple, Google และ GitHub: ผู้ให้บริการลงชื่อเข้าใช้เพิ่มเติมที่ส่งข้อมูลบัญชีที่จำเป็นสำหรับการตรวจสอบสิทธิ์ของคุณ",
+ "บริการแจ้งเตือนแบบพุช Apple: การแจ้งเตือนไปยัง iPhone และ iPad หลังจากที่คุณเลือกใช้",
+ "Apple Speech Recognition: การถอดเสียงเมื่อคุณเลือกในแอปมือถือ",
+ "Sentry: การติดตามข้อผิดพลาดและการรายงานข้อขัดข้อง ซึ่งอาจรวบรวมบันทึกข้อผิดพลาด การติดตามสแต็ก ข้อมูลอุปกรณ์ และเวอร์ชันของระบบปฏิบัติการ",
+ "Sparkle: เฟรมเวิร์กการอัปเดตอัตโนมัติของ macOS ซึ่งจะส่งเวอร์ชันของแอปพลิเคชันและระบบปฏิบัติการเพื่อตรวจสอบการอัปเดตของ macOS",
+ "Ghostty / libghostty: เอ็นจิ้นการเรนเดอร์เทอร์มินัลซึ่งทำงานภายในอุปกรณ์ของคุณ",
+ "PostHog: การวิเคราะห์ผลิตภัณฑ์เว็บไซต์และมือถือ รวมถึงการดูเพจ รูปแบบการนำทาง ข้อมูลเมตาของเบราว์เซอร์ กิจกรรมฟีเจอร์มือถือ การวิเคราะห์มือถือที่เชื่อมโยงกับบัญชีหลังจากลงชื่อเข้าใช้ผ่านพร็อกซีบุคคลที่หนึ่ง และอีเมลรายการรอที่ส่งเพื่อให้เราสามารถแจ้งคุณได้",
+ "Resend: การส่งอีเมลธุรกรรม อีเมลของคุณจะถูกส่งไปยัง Resend เฉพาะในกรณีที่คุณสมัครใจส่งข้อเสนอแนะ",
+ "Slack: การแจ้งเตือนภายในส่วนตัว หากคุณเข้าร่วมรายการรอแพลตฟอร์ม อีเมลและแพลตฟอร์มที่คุณส่งจะถูกส่งไปยังพื้นที่ทำงาน Slack ส่วนตัวของเรา"
+ ],
+ "afterBullets": [
+ "แต่ละบริการมีนโยบายความเป็นส่วนตัวของตัวเอง เมื่อบุคคลที่สามประมวลผลข้อมูลส่วนบุคคลสำหรับ cmux เราจำเป็นต้องมีการป้องกันอย่างน้อยพอๆ กับนโยบายนี้ และจำกัดการใช้งานเพื่อให้บริการแก่ cmux"
+ ]
+ },
+ {
+ "heading": "ที่สาม วิธีที่เราใช้และแบ่งปันข้อมูล",
+ "paragraphs": [
+ "เราไม่ขาย แลกเปลี่ยน ให้เช่า หรือแบ่งปันข้อมูลส่วนบุคคลกับบุคคลที่สามเพื่อทำการตลาด เราใช้รายงานข้อขัดข้องและการวินิจฉัยเพื่อปรับปรุงแอปพลิเคชันเท่านั้น เราอาจเปิดเผยข้อมูลเมื่อเราเชื่อโดยสุจริตว่าการเปิดเผยข้อมูลเป็นสิ่งจำเป็นสำหรับกระบวนการทางกฎหมายหรือการป้องกันจากอันตราย"
+ ]
+ },
+ {
+ "heading": "IV. เราปกป้องข้อมูลอย่างไร",
+ "paragraphs": [
+ "เราใช้มาตรการที่ออกแบบมาเพื่อป้องกันการเข้าถึงโดยไม่ได้รับอนุญาต รวมถึงการเข้ารหัสและซอฟต์แวร์เซิร์ฟเวอร์ที่ปลอดภัย ไม่มีวิธีการส่งหรือจัดเก็บข้อมูลใดที่ปลอดภัยอย่างสมบูรณ์ และการใช้บริการเกี่ยวข้องกับความเสี่ยงนี้"
+ ]
+ },
+ {
+ "heading": "V. สิทธิของคุณ",
+ "paragraphs": [
+ "กฎหมายที่บังคับใช้ เช่น GDPR หรือ CCPA อาจให้สิทธิ์เหล่านี้แก่คุณ ทั้งนี้ขึ้นอยู่กับสถานที่ตั้งของคุณ:"
+ ],
+ "bullets": [
+ "เข้าถึงสำเนาข้อมูลเกี่ยวกับคุณที่เราเก็บไว้",
+ "แก้ไขข้อมูลที่ไม่ถูกต้อง",
+ "ขอให้ลบข้อมูลของคุณ",
+ "รับข้อมูลแบบพกพา",
+ "จำกัดหรือคัดค้านการประมวลผล"
+ ],
+ "afterBullets": [
+ "หากต้องการใช้สิทธิ์เหล่านี้ โปรดติดต่อ [founders@manaflow.com](mailto:founders@manaflow.com)"
+ ]
+ },
+ {
+ "heading": "วี. ลิงค์ไปยังเว็บไซต์อื่น",
+ "paragraphs": [
+ "บริการอาจเชื่อมโยงไปยังเว็บไซต์บุคคลที่สาม เราไม่รับผิดชอบต่อหลักปฏิบัติด้านความเป็นส่วนตัวของพวกเขา นโยบายนี้ใช้กับข้อมูลที่เรารวบรวมเท่านั้น"
+ ]
+ },
+ {
+ "heading": "ปกเกล้าเจ้าอยู่หัว การเปลี่ยนแปลงนโยบายนี้",
+ "paragraphs": [
+ "เราอาจเปลี่ยนแปลงนโยบายนี้ การเปลี่ยนแปลงที่สำคัญจะมีผล 30 วันหลังจากการแจ้งเตือน ตรวจสอบเว็บไซต์เป็นระยะเพื่อดูการอัปเดต"
+ ]
+ },
+ {
+ "heading": "8. ติดต่อเรา",
+ "paragraphs": [
+ "คำถามเกี่ยวกับนโยบายนี้สามารถส่งไปที่ [founders@manaflow.com](mailto:founders@manaflow.com)"
+ ]
+ },
+ {
+ "heading": "ทรงเครื่อง การเก็บรักษาข้อมูล",
+ "paragraphs": [
+ "รายงานข้อขัดข้องและการวินิจฉัยจะถูกเก็บไว้ตราบเท่าที่จำเป็นเพื่อวินิจฉัยและแก้ไขปัญหาเท่านั้น ตัวระบุบัญชีมือถือและบันทึกการรับรองความถูกต้องจะถูกเก็บไว้ในขณะที่บัญชีของคุณใช้งานอยู่ จากนั้นจะถูกลบหรือไม่เปิดเผยตัวตนเมื่อการลบบัญชีเสร็จสิ้น ยกเว้นเมื่อหน้าที่ด้านความปลอดภัย กฎหมาย การเรียกเก็บเงิน หรือการป้องกันการฉ้อโกงต้องมีการเก็บรักษาไว้ ข้อมูลเมตาของอุปกรณ์และการจับคู่จะถูกเก็บไว้จนกว่าคุณจะยกเลิกการจับคู่ ออกจากระบบและลบข้อมูลในเครื่อง ลบบัญชีของคุณ หรือข้อมูลการจับคู่ที่เก่าจะถูกตัดออก โทเค็นบริการการแจ้งเตือนแบบพุช Apple จะถูกเก็บไว้เฉพาะในขณะที่เปิดใช้งานการแจ้งเตือน และจะถูกลบออกเมื่อคุณปิดใช้งานการแจ้งเตือน ออกจากระบบ ลบบัญชีของคุณ หรือ Apple รายงานว่าโทเค็นไม่ถูกต้อง การวิเคราะห์ผลิตภัณฑ์มือถือใน PostHog จะถูกเก็บไว้นานถึง 24 เดือน เว้นแต่คุณจะขอลบก่อนหน้านี้ การตั้งค่าบัญชีมือถือลบหรือไม่ระบุชื่อบัญชี อุปกรณ์ การจับคู่ การแจ้งเตือน การเรียกเก็บเงิน และข้อมูลคลาวด์ที่ cmux เป็นเจ้าของ ลบบุคคล PostHog ที่เชื่อมโยงกับบัญชี และขอให้ลบเหตุการณ์และการบันทึกการวิเคราะห์มือถือ งานการลบผู้ให้บริการบางรายอาจเสร็จสิ้นแบบอะซิงโครนัส ขอลบในการตั้งค่าบัญชีมือถือหรือติดต่อ [founders@manaflow.com](mailto:founders@manaflow.com)"
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/tr.json b/web/app/[locale]/(legal)/privacy-policy/content/tr.json
new file mode 100644
index 000000000000..14201e6ddae3
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/tr.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Gizlilik Politikası — cmux",
+ "metadataDescription": "cmux için gizlilik politikası",
+ "title": "Gizlilik Politikası",
+ "lastUpdated": "Son güncelleme: 10 Temmuz 2026",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow (\"Şirket\"), kullanıcıları için güçlü gizlilik korumaları sağlamaya kararlıdır. Bu Gizlilik Politikası, bize sağladığınız bilgileri nasıl topladığımızı, kullandığımızı ve koruduğumuzu açıklamaktadır.",
+ "Bu politikada \"Site\", [cmux.com](https://cmux.com) adresindeki Şirketin web sitesi anlamına gelir. \"Uygulama\", macOS için cmux masaüstü uygulaması ve iPhone ve iPad için cmux mobil uygulaması anlamına gelir. \"Hizmet\" Site ve Uygulamayı birlikte ifade eder. \"Biz\", \"bize\" ve \"bizim\" Şirket anlamına gelir. \"Siz\" Hizmetimizin kullanıcısı anlamına gelir.",
+ "Hizmetimizi kullanarak, bu Gizlilik Politikasını ve [Hizmet Şartlarımızı](https://cmux.com/terms-of-service) kabul etmiş ve burada açıklanan toplama, saklama, kullanma ve ifşa etme işlemlerini kabul etmiş olursunuz."
+ ]
+ },
+ {
+ "heading": "I. Topladığımız Bilgiler",
+ "paragraphs": [
+ "Kişisel Olmayan Bilgileri ve Kişisel Bilgileri topluyoruz. Kişisel Olmayan Bilgiler sizi tanımlayamaz ve anonim kullanım verilerini, platform türlerini ve kilitlenme teşhislerini içerir. Kişisel Bilgiler, e-posta adresinizi, hesap tanımlayıcılarınızı ve oturum açtığınızda, bizimle iletişime geçtiğinizde, bir cihazı eşleştirdiğinizde veya Uygulamayı kullandığınızda vermeyi seçtiğiniz bilgileri içerir."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Teknoloji aracılığıyla toplanan bilgiler",
+ "paragraphs": [
+ "Uygulama aşağıdaki bilgileri otomatik olarak toplayabilir:"
+ ],
+ "bullets": [
+ "Sentry aracılığıyla kilitlenme raporları ve hata teşhisi.",
+ "İşletim sistemi sürümü ve uygulama sürümü.",
+ "Site ve Uygulamaya ilişkin ürün analizleri ve özellik kullanımı etkinlikleri.",
+ "Oturum açtığınız cihazlarınızı bağlamak için gereken cihaz, hesap ve eşleştirme meta verileri.",
+ "Apple Anında Bildirim hizmeti cihazı belirteçleri, yalnızca telefon bildirimlerini etkinleştirdikten sonra."
+ ],
+ "afterBullets": [
+ "macOS Uygulaması, işletim sisteminizi ve uygulama sürümlerinizi güncelleme sunucumuza gönderebilecek Sparkle aracılığıyla güncellemeleri kontrol eder. iPhone ve iPad Uygulaması Sparkle değil App Store aracılığıyla güncellenir.",
+ "Site, sayfa görüntüleme ve gezinme analitiği için PostHog'i kullanır. PostHog, ziyaretçileri ayırt etmek için bir çerez saklar. Bir platform bekleme listesine katılırsanız gönderdiğiniz e-postanız PostHog'e kaydedilir, böylece sizi bilgilendirebiliriz. Kurumsal iletişim formunu gönderirseniz, sağladığınız şirketi ve iletişim bilgilerini PostHog'e kaydedip yanıt verebilmemiz için bunları özel Slack çalışma alanımıza ve kurucuların e-posta gelen kutunuza göndeririz. İzleme komut dosyalarını engelleyen bir tarayıcı uzantısıyla web sitesi analizlerini engelleyebilirsiniz.",
+ "iPhone ve iPad Uygulaması, ürün analitiği olaylarını sunucu tarafı PostHog proxy'mize gönderir. Bu olaylar güvenilirliğin teşhis edilmesine, özellik kullanımının anlaşılmasına ve Uygulamanın iyileştirilmesine yardımcı olur. Bunlar, uygulama başlatma ve oturum olaylarını, oturum açma durumunu, eşleştirme denemelerini ve sonuçlarını, bağlantı kurtarmayı, çalışma alanı açılışlarını, terminal giriş baytı ve satır sayımlarını ve bildirime katılım veya bildirim derin bağlantı sonuçlarını içerir. Mobil analiz, PostHog'e terminal komut metnini, terminal çıkışını, seçilen fotoğrafları veya konuşma transkriptlerini göndermez. Oturum açmadan önce etkinlikler, yükleme başına rastgele bir istemci tanımlayıcısı kullanır. Oturum açtıktan sonra sunucumuz, olayları PostHog'e iletmeden önce Stack Auth hesap tanımlayıcınızı ekler. Analizler ve kilitlenme raporları devre dışı bırakılır ve yalnızca Ayarlar'da Analizleri Paylaş ve Kilitlenme Raporlarını etkinleştirdikten sonra gönderilir. Bu kontrolün kapatılması, analizlerin arabelleğe alınmasını veya gönderilmesini durdurur ve kilitlenme raporlamasını durdurur. Hesabınızla ilişkili analizlerin silinmesini talep etmek için [founders@manaflow.com](mailto:founders@manaflow.com) ile iletişime geçin."
+ ]
+ },
+ {
+ "heading": "2. Doğrudan sağladığınız bilgiler",
+ "paragraphs": [
+ "Bizimle e-posta, iletişim sayfamız veya Kurumsal iletişim formu aracılığıyla iletişime geçerseniz ad, e-posta, şirket, görev, telefon numarası, ülke, dağıtım ihtiyaçları ve yorumlar dahil olmak üzere sağladığınız bilgileri toplarız. Bir platform bekleme listesine katılırsanız, platform başlatıldığında sizi bilgilendirmek için gönderdiğiniz e-postanızı toplarız ve kayıt e-postasını ve seçilen platformları özel Slack çalışma alanımıza göndeririz.",
+ "Oturum açtığınızda, e-posta adresiniz ve Apple, Google, GitHub'ten sağlayıcı tanımlayıcınız veya e-posta koduyla oturum açma gibi kimlik doğrulama bilgilerini alırız. Mobil uygulamayı bir Mac ile eşleştirdiğinizde, cihazları bağlamak için gereken eşleştirme bilgilerini işleriz. Bir çalışma alanını görüntülediğinizde, terminal girişi gönderdiğinizde, seçilen fotoğrafları eklediğinizde, konuşma transkripsiyonunu kullandığınızda veya terminal bildirimleri aldığınızda, ilgili içerik veya transkript, bu özelliğin sağlanması için gerektiği şekilde cihazlarınız ve hizmetimiz arasında aktarılabilir.",
+ "Kamera erişimi yalnızca cmux eşleştirme QR kodlarını taramak için kullanılır. Mikrofon ve konuşma tanıma erişimi yalnızca mesaj kutusunda ses transkripsiyonunu seçtiğinizde kullanılır. Fotoğraf kitaplığı erişimi yalnızca eklenecek fotoğrafları seçtiğinizde kullanılır."
+ ]
+ },
+ {
+ "heading": "3. Çocukların Gizliliği",
+ "paragraphs": [
+ "Hizmet 13 yaşın altındaki kişilere yönelik değildir ve 13 yaşın altındaki hiç kimseden bilerek bilgi toplamıyoruz. Bu tür bilgileri topladığımızı düşünüyorsanız [founders@manaflow.com](mailto:founders@manaflow.com) ile iletişime geçin."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Üçüncü Taraf Hizmetleri",
+ "paragraphs": [
+ "Uygulama şu üçüncü taraf hizmetleriyle entegre olur:"
+ ],
+ "bullets": [
+ "Stack Auth: oturum açma, oturumlar ve hesap silme için kimlik doğrulama ve hesap yönetimi.",
+ "Apple, Google ve GitHub: kimliğinizi doğrulamak için gereken hesap bilgilerini gönderen isteğe bağlı oturum açma sağlayıcıları.",
+ "Apple Anında Bildirim hizmeti: kaydolduktan sonra iPhone ve iPad'e bildirimler.",
+ "Apple Konuşma Tanıma: mobil uygulamada seçtiğinizde ses transkripsiyonu.",
+ "Sentry: hata günlüklerini, yığın izlerini, cihaz bilgilerini ve işletim sistemi sürümünü toplayabilen hata izleme ve kilitlenme raporlama.",
+ "Sparkle: macOS güncellemelerini kontrol etmek için uygulama ve işletim sistemi sürümlerini gönderen macOS otomatik güncelleme çerçevesi.",
+ "Ghostty / libghostty: cihazınızda yerel olarak çalışan terminal oluşturma motoru.",
+ "PostHog: sayfa görünümleri, gezinme modelleri, tarayıcı meta verileri, mobil özellik etkinlikleri, birinci taraf bir proxy aracılığıyla oturum açtıktan sonra hesaba bağlı mobil analizler ve sizi bilgilendirebilmemiz için gönderilen bir bekleme listesi e-postası dahil olmak üzere web sitesi ve mobil ürün analizleri.",
+ "Resend: işlemsel e-posta teslimi. E-postanız Resend'e yalnızca gönüllü olarak geri bildirim göndermeniz durumunda gönderilir.",
+ "Slack: özel dahili bildirimler. Bir platform bekleme listesine katılırsanız gönderdiğiniz e-posta ve platformlar özel Slack çalışma alanımıza gönderilir."
+ ],
+ "afterBullets": [
+ "Her hizmetin kendi gizlilik politikası vardır. Üçüncü bir taraf cmux için Kişisel Bilgileri işlediğinde, en az bu politika kadar koruyucu önlemlere ihtiyaç duyarız ve kullanımı cmux'e hizmet sağlamayla sınırlandırırız."
+ ]
+ },
+ {
+ "heading": "III. Bilgileri Nasıl Kullanıyoruz ve Paylaşıyoruz",
+ "paragraphs": [
+ "Kişisel Bilgileri pazarlama amacıyla üçüncü taraflara satmıyoruz, takas etmiyoruz, kiralamıyoruz veya paylaşmıyoruz. Kilitlenme raporlarını ve teşhislerini yalnızca Uygulamayı geliştirmek için kullanırız. Yasal süreç veya zarardan korunma için açıklamanın gerekli olduğuna iyi niyetle inandığımızda bilgileri açıklayabiliriz."
+ ]
+ },
+ {
+ "heading": "IV. Bilgileri Nasıl Koruyoruz",
+ "paragraphs": [
+ "Şifreleme ve güvenli sunucu yazılımı da dahil olmak üzere, yetkisiz erişimi önlemek için tasarlanmış önlemler kullanıyoruz. Hiçbir iletim veya depolama yöntemi tamamen güvenli değildir ve Hizmetin kullanımı bu riski içerir."
+ ]
+ },
+ {
+ "heading": "V. Haklarınız",
+ "paragraphs": [
+ "Bulunduğunuz yere bağlı olarak GDPR veya CCPA gibi geçerli yasalar size şu hakları verebilir:"
+ ],
+ "bullets": [
+ "Hakkınızda tuttuğumuz verilerin bir kopyasına erişin.",
+ "Yanlış verileri düzeltin.",
+ "Verilerinizin silinmesini isteyin.",
+ "Taşınabilir verileri alın.",
+ "İşlemeyi kısıtlayın veya işleme itiraz edin."
+ ],
+ "afterBullets": [
+ "Bu hakları kullanmak için [founders@manaflow.com](mailto:founders@manaflow.com) ile iletişime geçin."
+ ]
+ },
+ {
+ "heading": "VI. Diğer Web Sitelerine Bağlantılar",
+ "paragraphs": [
+ "Hizmet üçüncü taraf web sitelerine bağlantı verebilir. Onların gizlilik uygulamalarından biz sorumlu değiliz. Bu politika yalnızca topladığımız bilgiler için geçerlidir."
+ ]
+ },
+ {
+ "heading": "VII. Bu Politikadaki Değişiklikler",
+ "paragraphs": [
+ "Bu politikayı değiştirebiliriz. Önemli değişiklikler bildirimden 30 gün sonra yürürlüğe girer. Güncellemeler için Siteyi periyodik olarak kontrol edin."
+ ]
+ },
+ {
+ "heading": "VIII. Bize Ulaşın",
+ "paragraphs": [
+ "Bu politikayla ilgili sorular [founders@manaflow.com](mailto:founders@manaflow.com) adresine gönderilebilir."
+ ]
+ },
+ {
+ "heading": "IX. Veri Saklama",
+ "paragraphs": [
+ "Kilitlenme raporları ve tanılamalar yalnızca sorunları tanılamak ve düzeltmek için gerekli olduğu sürece saklanır. Mobil hesap tanımlayıcıları ve kimlik doğrulama kayıtları, hesabınız etkinken tutulur, güvenlik, yasal, faturalandırma veya dolandırıcılığı önleme görevlerinin saklamayı gerektirdiği durumlar hariç, hesap silme işlemi tamamlandığında silinir veya anonimleştirilir. Cihaz ve eşleştirme meta verileri, siz eşleştirmeyi kaldırıncaya, oturumunuzu kapatıp yerel verileri silinceye, hesabınızı silinceye veya eski eşleştirme verileri budanıncaya kadar tutulur. Apple Anında Bildirim hizmeti belirteçleri yalnızca bildirimler etkinleştirildiğinde tutulur ve bildirimleri devre dışı bıraktığınızda, oturumu kapattığınızda, hesabınızı sildiğinizde veya Apple belirtecin geçersiz olduğunu bildirdiğinizde kaldırılır. PostHog'teki mobil ürün analitiği, daha önce silinmesini talep etmediğiniz sürece 24 aya kadar saklanır. Mobil hesap ayarları, cmux'e ait hesabı, cihazı, eşleştirmeyi, bildirimi, faturalandırmayı ve bulut verilerini siler veya anonimleştirir, hesaba bağlı PostHog kişisini siler ve mobil analiz etkinliklerinin ve kayıtlarının silinmesini talep eder. Bazı sağlayıcı silme çalışmaları eşzamansız olarak tamamlanabilir. Mobil hesap ayarlarından veya [founders@manaflow.com](mailto:founders@manaflow.com) ile iletişime geçerek silme işlemini talep edin."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/uk.json b/web/app/[locale]/(legal)/privacy-policy/content/uk.json
new file mode 100644
index 000000000000..1dd14b34d04d
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/uk.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "Політика конфіденційності — cmux",
+ "metadataDescription": "Політика конфіденційності для cmux",
+ "title": "Політика конфіденційності",
+ "lastUpdated": "Востаннє оновлено: 10 липня 2026 р",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow («Компанія») прагне підтримувати надійний захист конфіденційності своїх користувачів. Ця Політика конфіденційності пояснює, як ми збираємо, використовуємо та захищаємо інформацію, яку ви нам надаєте.",
+ "У цій політиці «Сайт» означає веб-сайт Компанії за адресою [cmux.com](https://cmux.com). «Програма» означає настільну програму cmux для macOS і мобільну програму cmux для iPhone і iPad. «Сервіс» означає Сайт і Додаток разом. «Ми», «нас» і «наш» означають Компанію. «Ви» означає користувача нашого Сервісу.",
+ "Користуючись нашою Сервісом, ви приймаєте цю Політику конфіденційності та наші [Умови використання](https://cmux.com/terms-of-service), а також погоджуєтеся на збір, зберігання, використання та розкриття, описані тут."
+ ]
+ },
+ {
+ "heading": "I. Інформація, яку ми збираємо",
+ "paragraphs": [
+ "Ми збираємо інформацію неособистого характеру та особисту інформацію. Неособиста інформація не може ідентифікувати вас і включає анонімні дані про використання, типи платформ і діагностику збоїв. Особиста інформація включає вашу адресу електронної пошти, ідентифікатори облікового запису та інформацію, яку ви надаєте під час входу, зв’язку з нами, створення пари з пристроєм або використання Програми."
+ ],
+ "subsections": [
+ {
+ "heading": "1. Інформація, зібрана за допомогою технологій",
+ "paragraphs": [
+ "Програма може автоматично збирати таку інформацію:"
+ ],
+ "bullets": [
+ "Звіти про збої та діагностика помилок через Sentry.",
+ "Версія операційної системи та версія програми.",
+ "Аналітика продукту та події використання функцій для Сайту та Програми.",
+ "Пристрій, обліковий запис і метадані сполучення, необхідні для підключення пристроїв, на яких ви ввійшли.",
+ "Apple Маркери пристрою служби Push Notification, лише після ввімкнення телефонних сповіщень."
+ ],
+ "afterBullets": [
+ "Програма macOS перевіряє наявність оновлень через Sparkle, який може надсилати версію вашої операційної системи та програми на наш сервер оновлень. Програма iPhone і iPad оновлюється через App Store, а не через Sparkle.",
+ "Сайт використовує PostHog для аналізу перегляду сторінок і навігації. PostHog зберігає файл cookie, щоб розрізняти відвідувачів. Якщо ви приєднаєтеся до списку очікування на платформі, ваш надісланий електронний лист буде зареєстровано в PostHog, щоб ми могли повідомити вас. Якщо ви надсилаєте контактну форму Enterprise, ми реєструємо компанію та контактні дані, які ви надаєте, у PostHog і надсилаємо їх у нашу приватну робочу область Slack та електронну пошту засновників, щоб ми могли відповісти. Ви можете заблокувати аналітику веб-сайту за допомогою розширення для браузера, яке блокує сценарії відстеження.",
+ "Додаток iPhone і iPad надсилає події аналітики продукту на наш серверний проксі PostHog. Ці події допомагають діагностувати надійність, зрозуміти використання функцій і покращити програму. Вони включають події запуску програми та сеансу, статус входу, спроби з’єднання та результати, відновлення з’єднання, відкриття робочої області, кількість байтів і рядків, введених терміналом, а також результати підключення до сповіщень або сповіщень. Мобільна аналітика не надсилає текст команди терміналу, вихідні дані терміналу, вибрані фотографії чи стенограми мовлення до PostHog. Перед входом події використовують випадковий ідентифікатор клієнта для встановлення. Після входу наш сервер додає ідентифікатор вашого облікового запису Stack Auth перед тим, як пересилати події на PostHog. Аналітика та звіти про збої починають вимкнено та надсилаються лише після того, як ви ввімкнете спільний доступ до аналітики та звітів про збої в налаштуваннях. Якщо вимкнути цей елемент керування, аналітика не буде буферизуватися або надсилатися, а звіти про збої припиниться. Зверніться до [founders@manaflow.com](mailto:founders@manaflow.com), щоб подати запит на видалення аналітики, пов’язаної з вашим обліковим записом."
+ ]
+ },
+ {
+ "heading": "2. Інформація, яку ви надаєте безпосередньо",
+ "paragraphs": [
+ "Якщо ви зв’яжетеся з нами електронною поштою, через нашу сторінку контактів або контактну форму Enterprise, ми збираємо надану вами інформацію, зокрема ім’я, електронну адресу, компанію, роль, номер телефону, країну, потреби розгортання та коментарі. Якщо ви приєднаєтеся до списку очікування на платформі, ми збираємо надіслані вами електронні листи, щоб повідомити вас про запуск цієї платформи, і надішлемо електронний лист для реєстрації та вибрані платформи в наш приватний робочий простір Slack.",
+ "Коли ви входите в обліковий запис, ми отримуємо інформацію для автентифікації, таку як ваша адреса електронної пошти та ідентифікатор постачальника, від Apple, Google, GitHub або входу за допомогою коду електронної пошти. Коли ви сполучаєте мобільну програму з Mac, ми обробляємо інформацію про сполучення, необхідну для підключення пристроїв. Коли ви переглядаєте робочу область, надсилаєте вхідні дані терміналу, вкладаєте вибрані фотографії, використовуєте транскрипцію мовлення або отримуєте сповіщення терміналу, пов’язаний вміст або стенограма може передаватися між вашими пристроями та нашою службою, якщо це необхідно для надання цієї функції.",
+ "Доступ до камери використовується лише для сканування кодів сполучення cmux QR. Доступ до мікрофона та розпізнавання мовлення використовується лише тоді, коли ви вибираєте транскрипцію голосу у вікні повідомлення. Доступ до бібліотеки фотографій використовується лише тоді, коли ви вибираєте фотографії для прикріплення."
+ ]
+ },
+ {
+ "heading": "3. Конфіденційність дітей",
+ "paragraphs": [
+ "Служба не призначена для осіб віком до 13 років, і ми свідомо не збираємо інформацію від осіб віком до 13 років. Якщо ви вважаєте, що ми зібрали таку інформацію, зв’яжіться з [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "II. Послуги третіх осіб",
+ "paragraphs": [
+ "Програма інтегрується з такими сторонніми службами:"
+ ],
+ "bullets": [
+ "Stack Auth: автентифікація та керування обліковим записом для входу, сеансів і видалення облікового запису.",
+ "Apple, Google і GitHub: додаткові постачальники послуг входу, які надсилають інформацію облікового запису, необхідну для вашої автентифікації.",
+ "Служба Push-сповіщень Apple: сповіщення для iPhone і iPad після того, як ви погодитеся.",
+ "Apple Розпізнавання мовлення: транскрипція голосу, коли ви вибираєте її в мобільному додатку.",
+ "Sentry: відстеження помилок і звітування про збої, які можуть збирати журнали помилок, трасування стека, інформацію про пристрій і версію операційної системи.",
+ "Sparkle: платформа автоматичного оновлення macOS, яка надсилає версії програми та операційної системи для перевірки оновлень macOS.",
+ "Ghostty / libghostty: механізм відтворення терміналів, який працює локально на вашому пристрої.",
+ "PostHog: аналітика веб-сайтів і мобільних продуктів, включаючи перегляди сторінок, шаблони навігації, метадані веб-переглядача, події мобільних функцій, пов’язану з обліковим записом мобільну аналітику після входу через основний проксі та надісланий лист очікування, щоб ми могли сповістити вас.",
+ "Resend: транзакційна доставка електронної пошти. Ваш електронний лист надсилається на адресу Resend, лише якщо ви добровільно надсилаєте відгук.",
+ "Slack: приватні внутрішні сповіщення. Якщо ви приєднаєтеся до списку очікування на платформі, надіслані вами електронні листи та платформи надсилатимуться в наш приватний робочий простір Slack."
+ ],
+ "afterBullets": [
+ "Кожен сервіс має власну політику конфіденційності. Коли третя сторона обробляє Персональну інформацію для cmux, ми вимагаємо заходів захисту, принаймні таких же, як ця політика, і обмежуємо використання наданням послуг для cmux."
+ ]
+ },
+ {
+ "heading": "III. Як ми використовуємо та обмінюємося інформацією",
+ "paragraphs": [
+ "Ми не продаємо, не обмінюємо, не здаємо в оренду та не надаємо особисту інформацію третім особам для маркетингу. Ми використовуємо звіти про збої та діагностику лише для покращення Програми. Ми можемо розкривати інформацію, якщо добросовісно вважаємо, що розкриття необхідно для судового процесу або захисту від шкоди."
+ ]
+ },
+ {
+ "heading": "IV. Як ми захищаємо інформацію",
+ "paragraphs": [
+ "Ми використовуємо заходи, призначені для запобігання несанкціонованому доступу, включаючи шифрування та безпечне серверне програмне забезпечення. Жоден метод передачі чи зберігання не є повністю безпечним, і використання Сервісу пов’язане з цим ризиком."
+ ]
+ },
+ {
+ "heading": "V. Ваші права",
+ "paragraphs": [
+ "Залежно від вашого місцезнаходження відповідні закони, такі як GDPR або CCPA, можуть надавати вам такі права:"
+ ],
+ "bullets": [
+ "Доступ до копії даних, які ми зберігаємо про вас.",
+ "Виправте неточні дані.",
+ "Вимагайте видалення своїх даних.",
+ "Отримувати портативні дані.",
+ "Обмежити або заперечити обробку."
+ ],
+ "afterBullets": [
+ "Щоб скористатися цими правами, зверніться до [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "VI. Посилання на інші веб-сайти",
+ "paragraphs": [
+ "Сервіс може посилатися на веб-сайти третіх осіб. Ми не несемо відповідальності за їхню практику конфіденційності. Ця політика стосується лише інформації, яку ми збираємо."
+ ]
+ },
+ {
+ "heading": "VII. Зміни до цієї Політики",
+ "paragraphs": [
+ "Ми можемо змінити цю політику. Значні зміни набувають чинності через 30 днів після повідомлення. Періодично перевіряйте Сайт на наявність оновлень."
+ ]
+ },
+ {
+ "heading": "VIII. Зв'яжіться з нами",
+ "paragraphs": [
+ "Запитання щодо цієї політики можна надсилати на адресу [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ },
+ {
+ "heading": "IX. Зберігання даних",
+ "paragraphs": [
+ "Звіти про збої та діагностику зберігаються лише стільки, скільки потрібно для діагностики та вирішення проблем. Ідентифікатори мобільного облікового запису та записи автентифікації зберігаються, поки ваш обліковий запис активний, а потім видаляються або знеособлюються, коли видалення облікового запису завершується, за винятком випадків, коли збереження вимагається з питань безпеки, юридичних питань, виставлення рахунків або запобігання шахрайству. Метадані про пристрій і з’єднання зберігаються, доки ви не роз’єднаєтеся, не вийдете з системи та не видалите локальні дані, не видалите свій обліковий запис або не видалите застарілі дані з’єднання. Маркери служби push-сповіщень Apple зберігаються, лише коли сповіщення ввімкнено, і видаляються, коли ви вимикаєте сповіщення, виходите з системи, видаляєте обліковий запис або Apple повідомляє про недійсний маркер. Аналітика мобільних продуктів у PostHog зберігається до 24 місяців, якщо ви не подасте запит на видалення раніше. Налаштування мобільного облікового запису видаляють або анонімізують обліковий запис, пристрій, сполучення, сповіщення, платежі та хмарні дані, що належать cmux, а також видаляють пов’язану з обліковим записом особу PostHog і надсилають запит на видалення подій і записів мобільної аналітики. Деякі роботи з видалення постачальника можуть завершуватися асинхронно. Надішліть запит на видалення в налаштуваннях мобільного облікового запису або зв’яжіться з [founders@manaflow.com](mailto:founders@manaflow.com)."
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/zh-CN.json b/web/app/[locale]/(legal)/privacy-policy/content/zh-CN.json
new file mode 100644
index 000000000000..2bf2bbbb8a5f
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/zh-CN.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "隐私政策 — cmux",
+ "metadataDescription": "cmux 的隐私政策",
+ "title": "隐私政策",
+ "lastUpdated": "最后更新时间:2026 年 7 月 10 日",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow(“公司”)致力于为其用户维护强大的隐私保护。本隐私政策解释了我们如何收集、使用和保护您向我们提供的信息。",
+ "在本政策中,“网站”是指公司网站 [cmux.com](https://cmux.com)。 “应用程序”是指 macOS 的 cmux 桌面应用程序以及 iPhone 和 iPad 的 cmux 移动应用程序。 “服务”指网站和应用程序。 “我们”和“我们的”均指公司。 “您”是指我们服务的用户。",
+ "使用我们的服务,即表示您接受本隐私政策和我们的[服务条款](https://cmux.com/terms-of-service),并同意此处所述的收集、存储、使用和披露。"
+ ]
+ },
+ {
+ "heading": "一、我们收集的信息",
+ "paragraphs": [
+ "我们收集非个人信息和个人信息。非个人信息无法识别您的身份,包括匿名使用数据、平台类型和崩溃诊断。个人信息包括您的电子邮件地址、帐户标识符以及您在登录、联系我们、配对设备或使用应用程序时选择提供的信息。"
+ ],
+ "subsections": [
+ {
+ "heading": "1.通过技术收集的信息",
+ "paragraphs": [
+ "该应用程序可能会自动收集以下信息:"
+ ],
+ "bullets": [
+ "通过 CMUXOKEN0X 进行崩溃报告和错误诊断。",
+ "操作系统版本和应用程序版本。",
+ "网站和应用程序的产品分析和功能使用事件。",
+ "连接登录设备所需的设备、帐户和配对元数据。",
+ "CMUXOKEN0X 推送通知服务设备令牌,仅在您启用电话通知后。"
+ ],
+ "afterBullets": [
+ "macOS 应用程序通过 Sparkle 检查更新,这可能会将您的操作系统和应用程序版本发送到我们的更新服务器。 iPhone 和 iPad 应用程序通过 App Store 进行更新,而不是通过 Sparkle 进行更新。",
+ "该网站使用 PostHog 进行页面浏览和导航分析。 CMUXOKEN0X 存储一个 cookie 来区分访问者。如果您加入平台候补名单,您提交的电子邮件将记录在 PostHog 中,以便我们通知您。如果您提交企业联系表,我们会记录您在 PostHog 中提供的公司和联系方式,并将其发送到我们的私人 Slack 工作区和创始人电子邮件收件箱,以便我们做出回复。您可以使用阻止跟踪脚本的浏览器扩展来阻止网站分析。",
+ "iPhone 和 iPad 应用程序将产品分析事件发送到我们的服务器端 PostHog 代理。这些事件有助于诊断可靠性、了解功能使用情况并改进应用程序。它们包括应用程序启动和会话事件、登录状态、配对尝试和结果、连接恢复、工作区打开、终端输入字节和行计数以及通知选择加入或通知深层链接结果。移动分析不会将终端命令文本、终端输出、选定的照片或语音转录发送到 PostHog。登录之前,事件使用随机的每次安装客户端标识符。登录后,我们的服务器会在将事件转发到 PostHog 之前附加您的 Stack Auth 帐户标识符。分析和崩溃报告开始时处于禁用状态,并且仅在您在“设置”中启用“共享分析和崩溃报告”后才会发送。关闭该控制会阻止分析数据被缓冲或发送,并停止崩溃报告。请联系 [founders@manaflow.com](mailto:founders@manaflow.com) 请求删除与您的帐户关联的分析。"
+ ]
+ },
+ {
+ "heading": "2.您直接提供的信息",
+ "paragraphs": [
+ "如果您通过电子邮件、我们的联系页面或企业联系表单联系我们,我们会收集您提供的信息,包括姓名、电子邮件、公司、角色、电话号码、国家/地区、部署需求和评论。如果您加入平台候补名单,我们会收集您提交的电子邮件,以便在该平台启动时通知您,并将注册电子邮件和选定的平台发送到我们的私人 Slack 工作区。",
+ "当您登录时,我们会从 Apple、CMUXOKEN0X、CMUXOKEN1X 或电子邮件代码登录接收身份验证信息,例如您的电子邮件地址和提供商标识符。当您将移动应用程序与 Mac 配对时,我们会处理连接设备所需的配对信息。当您查看工作区、发送终端输入、附加选定的照片、使用语音转录或接收终端通知时,相关内容或转录可能会根据需要在您的设备和我们的服务之间传递以提供该功能。",
+ "相机访问仅用于扫描 cmux 配对 QR 代码。仅当您在消息框中选择语音转录时,才会使用麦克风和语音识别访问。仅当您选择要附加的照片时才使用照片库访问权限。"
+ ]
+ },
+ {
+ "heading": "3. 儿童隐私",
+ "paragraphs": [
+ "本服务不针对 13 岁以下的任何人,我们也不会故意收集 13 岁以下的任何人的信息。如果您认为我们收集了此类信息,请联系 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "二.第三方服务",
+ "paragraphs": [
+ "该应用程序与以下第三方服务集成:"
+ ],
+ "bullets": [
+ "CMUXOKEN0X:登录、会话和帐户删除的身份验证和帐户管理。",
+ "Apple、CMUXOKEN0X 和 GitHub:可选的登录提供程序,用于发送对您进行身份验证所需的帐户信息。",
+ "Apple 推送通知服务:在您选择加入后向 iPhone 和 iPad 发送通知。",
+ "Apple 语音识别:当您在移动应用程序中选择它时进行语音转录。",
+ "Sentry:错误跟踪和崩溃报告,可能收集错误日志、堆栈跟踪、设备信息和操作系统版本。",
+ "Sparkle:CMUXOKEN1X 自动更新框架,它发送应用程序和操作系统版本以检查 macOS 更新。",
+ "Ghostty / libghostty:终端渲染引擎,在您的设备上本地运行。",
+ "PostHog:网站和移动产品分析,包括页面浏览量、导航模式、浏览器元数据、移动功能事件、通过第一方代理登录后的帐户链接移动分析,以及提交的候补名单电子邮件,以便我们通知您。",
+ "Resend:交易电子邮件传送。仅当您自愿提交反馈时,您的电子邮件才会发送至 Resend。",
+ "CMUXOKEN0X:私有内部通知。如果您加入平台候补名单,您提交的电子邮件和平台将发送到我们的私人 Slack 工作区。"
+ ],
+ "afterBullets": [
+ "每项服务都有自己的隐私政策。当第三方处理 cmux 的个人信息时,我们要求采取至少与本政策一样的保护措施,并限制其用于向 cmux 提供服务。"
+ ]
+ },
+ {
+ "heading": "三.我们如何使用和共享信息",
+ "paragraphs": [
+ "我们不会出于营销目的向第三方出售、交易、出租或共享个人信息。我们仅使用崩溃报告和诊断来改进应用程序。当我们真诚地相信披露对于法律程序或保护免受伤害是必要的时,我们可能会披露信息。"
+ ]
+ },
+ {
+ "heading": "四.我们如何保护信息",
+ "paragraphs": [
+ "我们使用旨在防止未经授权的访问的措施,包括加密和安全服务器软件。没有一种传输或存储方法是完全安全的,使用服务会涉及这种风险。"
+ ]
+ },
+ {
+ "heading": "五、您的权利",
+ "paragraphs": [
+ "根据您所在的位置,适用的法律(例如 GDPR 或 CCPA)可能会赋予您以下权利:"
+ ],
+ "bullets": [
+ "访问我们持有的有关您的数据的副本。",
+ "纠正不准确的数据。",
+ "请求删除您的数据。",
+ "接收便携式数据。",
+ "限制或反对处理。"
+ ],
+ "afterBullets": [
+ "要行使这些权利,请联系 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ },
+ {
+ "heading": "六.其他网站的链接",
+ "paragraphs": [
+ "该服务可能会链接到第三方网站。我们不对他们的隐私做法负责。本政策仅适用于我们收集的信息。"
+ ]
+ },
+ {
+ "heading": "七.本政策的变更",
+ "paragraphs": [
+ "我们可能会更改此政策。重大变更将在通知后 30 天生效。定期检查网站是否有更新。"
+ ]
+ },
+ {
+ "heading": "八.联系我们",
+ "paragraphs": [
+ "有关此政策的问题可以发送至 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ },
+ {
+ "heading": "九.数据保留",
+ "paragraphs": [
+ "崩溃报告和诊断仅在诊断和修复问题所需时保留。移动帐户标识符和身份验证记录会在您的帐户处于活动状态时保留,然后在帐户删除完成后删除或匿名化,除非安全、法律、计费或防欺诈职责需要保留。设备和配对元数据将一直保留,直到您取消配对、注销和删除本地数据、删除您的帐户或删除过时的配对数据。 Apple 推送通知服务令牌仅在启用通知时保留,并在您禁用通知、注销、删除帐户或 Apple 报告令牌无效时删除。 PostHog 中的移动产品分析最多可保留 24 个月,除非您请求提前删除。移动帐户设置删除或匿名 cmux 拥有的帐户、设备、配对、通知、计费和云数据,删除帐户链接的 PostHog 人员,并请求删除其移动分析事件和记录。某些提供程序删除工作可能会异步完成。在移动帐户设置中或联系 [founders@manaflow.com](mailto:founders@manaflow.com) 请求删除。"
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/content/zh-TW.json b/web/app/[locale]/(legal)/privacy-policy/content/zh-TW.json
new file mode 100644
index 000000000000..96924ec4c01e
--- /dev/null
+++ b/web/app/[locale]/(legal)/privacy-policy/content/zh-TW.json
@@ -0,0 +1,128 @@
+{
+ "metadataTitle": "隱私權政策 — cmux",
+ "metadataDescription": "cmux 的隱私權政策",
+ "title": "隱私權政策",
+ "lastUpdated": "最後更新時間:2026 年 7 月 10 日",
+ "sections": [
+ {
+ "paragraphs": [
+ "Manaflow(「本公司」)致力於為其使用者維護強大的隱私保護。本隱私權政策解釋了我們如何收集、使用和保護您提供給我們的資訊。",
+ "在本政策中,「網站」是指公司網站 [cmux.com](https://cmux.com)。 「應用程式」指 macOS 的 cmux 桌面應用程式以及 iPhone 和 iPad 的 cmux 行動應用程式。 「服務」指網站和應用程式。 「我們」和「我們的」均指本公司。 「您」是指我們服務的用戶。",
+ "使用我們的服務,即表示您接受本隱私權政策和我們的[服務條款](https://cmux.com/terms-of-service),並同意此處所述的收集、儲存、使用和揭露。"
+ ]
+ },
+ {
+ "heading": "一、我們收集的資訊",
+ "paragraphs": [
+ "我們收集非個人資訊和個人資訊。非個人資訊無法識別您的身份,包括匿名使用資料、平台類型和崩潰診斷。個人資訊包括您的電子郵件地址、帳戶識別碼以及您在登入、聯絡我們、配對裝置或使用應用程式時選擇提供的資訊。"
+ ],
+ "subsections": [
+ {
+ "heading": "1.透過科技收集的信息",
+ "paragraphs": [
+ "該應用程式可能會自動收集以下資訊:"
+ ],
+ "bullets": [
+ "透過 CMUXOKEN0X 進行崩潰報告和錯誤診斷。",
+ "作業系統版本和應用程式版本。",
+ "網站和應用程式的產品分析和功能使用事件。",
+ "連接登入裝置所需的裝置、帳號和配對元資料。",
+ "CMUXOKEN0X 推播通知服務設備令牌,僅在您啟用電話通知後。"
+ ],
+ "afterBullets": [
+ "macOS 應用程式透過 Sparkle 檢查更新,這可能會將您的作業系統和應用程式版本傳送到我們的更新伺服器。 iPhone 和 iPad 應用程式透過 App Store 進行更新,而不是透過 Sparkle 進行更新。",
+ "該網站使用 PostHog 進行頁面瀏覽和導航分析。 CMUXOKEN0X 儲存一個 cookie 來區分訪客。如果您加入平台候補名單,您提交的電子郵件將記錄在 PostHog 中,以便我們通知您。如果您提交企業聯絡表,我們會記錄您在 PostHog 中提供的公司和聯絡方式,並將其發送到我們的私人 Slack 工作區和創辦人電子郵件收件匣,以便我們做出回應。您可以使用阻止追蹤腳本的瀏覽器擴充功能來阻止網站分析。",
+ "iPhone 和 iPad 应用程序将产品分析事件发送到我们的服务器端 PostHog 代理。这些事件有助于诊断可靠性、了解功能使用情况并改进应用程序。它们包括应用程序启动和会话事件、登录状态、配对尝试和结果、连接恢复、工作区打开、终端输入字节和行计数以及通知选择加入或通知深层链接结果。移动分析不会将终端命令文本、终端输出、选定的照片或语音转录发送到 PostHog。登录之前,事件使用随机的每次安装客户端标识符。登录后,我们的服务器会在将事件转发到 PostHog 之前附加您的 Stack Auth 帐户标识符。分析和崩溃报告开始时处于禁用状态,并且仅在您在“设置”中启用“共享分析和崩溃报告”后才会发送。关闭该控制会阻止分析数据被缓冲或发送,并停止崩溃报告。請聯絡 [founders@manaflow.com](mailto:founders@manaflow.com) 要求刪除與您的帳戶關聯的分析。"
+ ]
+ },
+ {
+ "heading": "2.您直接提供的信息",
+ "paragraphs": [
+ "如果您通过电子邮件、我们的联系页面或企业联系表单联系我们,我们会收集您提供的信息,包括姓名、电子邮件、公司、角色、电话号码、国家/地区、部署需求和评论。如果您加入平台候补名单,我们会收集您提交的电子邮件,以便在该平台启动时通知您,并将注册电子邮件和选定的平台发送到我们的私人 Slack 工作区。",
+ "当您登录时,我们会从 Apple、CMUXOKEN0X、CMUXOKEN1X 或电子邮件代码登录接收身份验证信息,例如您的电子邮件地址和提供商标识符。當您將行動應用程式與 Mac 配對時,我們會處理連接裝置所需的配對資訊。当您查看工作区、发送终端输入、附加选定的照片、使用语音转录或接收终端通知时,相关内容或转录可能会根据需要在您的设备和我们的服务之间传递以提供该功能。",
+ "相机访问仅用于扫描 cmux 配对 QR 代码。只有當您在訊息方塊中選擇語音轉錄時,才會使用麥克風和語音辨識存取。仅当您选择要附加的照片时才使用照片库访问权限。"
+ ]
+ },
+ {
+ "heading": "3. 兒童隱私",
+ "paragraphs": [
+ "本服务不针对 13 岁以下的任何人,我们也不会故意收集 13 岁以下的任何人的信息。如果您認為我們收集了此類信息,請聯繫 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ }
+ ]
+ },
+ {
+ "heading": "二.第三方服務",
+ "paragraphs": [
+ "該應用程式與以下第三方服務整合:"
+ ],
+ "bullets": [
+ "CMUXOKEN0X:登入、會話和帳戶刪除的身份驗證和帳戶管理。",
+ "Apple、CMUXOKEN0X 和 GitHub:可選的登入提供程序,用於傳送對您進行身份驗證所需的帳戶資訊。",
+ "Apple 推播通知服務:在您選擇加入後向 iPhone 和 iPad 發送通知。",
+ "Apple 語音辨識:當您在行動應用程式中選擇它時進行語音轉錄。",
+ "Sentry:错误跟踪和崩溃报告,可能收集错误日志、堆栈跟踪、设备信息和操作系统版本。",
+ "Sparkle:CMUXOKEN1X 自動更新框架,它會傳送應用程式和作業系統版本以檢查 macOS 更新。",
+ "Ghostty / libghostty:終端渲染引擎,在您的裝置上本地運行。",
+ "PostHog:網站和行動產品分析,包括頁面瀏覽量、導覽模式、瀏覽器元資料、行動功能事件、透過第一方代理登入後的帳戶連結行動分析,以及提交的候補名單電子郵件,以便我們通知您。",
+ "Resend:交易電子郵件傳送。只有當您自願提交回饋時,您的電子郵件才會發送至 Resend。",
+ "CMUXOKEN0X:私有內部通知。如果您加入平台候補名單,您提交的電子郵件和平台將發送到我們的私人 Slack 工作區。"
+ ],
+ "afterBullets": [
+ "每項服務都有自己的隱私權政策。當第三方處理 cmux 的個人資訊時,我們要求採取至少與本政策相同的保護措施,並限制其用於向 cmux 提供服務。"
+ ]
+ },
+ {
+ "heading": "三.我們如何使用和共享資訊",
+ "paragraphs": [
+ "我們不會出於行銷目的向第三方出售、交易、出租或分享個人資訊。我們僅使用崩潰報告和診斷來改進應用程式。當我們真誠地相信披露對於法律程序或保護免受傷害是必要的時,我們可能會披露資訊。"
+ ]
+ },
+ {
+ "heading": "四.我們如何保護資訊",
+ "paragraphs": [
+ "我們使用旨在防止未經授權的存取的措施,包括加密和安全伺服器軟體。沒有一種傳輸或儲存方法是完全安全的,使用服務會涉及這種風險。"
+ ]
+ },
+ {
+ "heading": "五、您的權利",
+ "paragraphs": [
+ "根據您所在的位置,適用的法律(例如 GDPR 或 CCPA)可能會賦予您以下權利:"
+ ],
+ "bullets": [
+ "存取我們持有的有關您的資料的副本。",
+ "修正不準確的數據。",
+ "請求刪除您的資料。",
+ "接收便攜式資料。",
+ "限製或反對處理。"
+ ],
+ "afterBullets": [
+ "若要行使這些權利,請聯絡 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ },
+ {
+ "heading": "六.其他網站的連結",
+ "paragraphs": [
+ "該服務可能會連結到第三方網站。我們不對他們的隱私做法負責。本政策僅適用於我們收集的資訊。"
+ ]
+ },
+ {
+ "heading": "七.本政策的變更",
+ "paragraphs": [
+ "我們可能會更改此政策。重大變更將在通知後 30 天生效。定期檢查網站是否有更新。"
+ ]
+ },
+ {
+ "heading": "八.聯絡我們",
+ "paragraphs": [
+ "有關此政策的問題可以發送至 [founders@manaflow.com](mailto:founders@manaflow.com)。"
+ ]
+ },
+ {
+ "heading": "九.資料保留",
+ "paragraphs": [
+ "崩潰報告和診斷僅在診斷和修復問題所需時保留。行動帳戶識別碼和驗證記錄會在您的帳戶處於活動狀態時保留,然後在帳戶刪除完成後刪除或匿名化,除非安全、法律、計費或防詐欺職責需要保留。裝置和配對元資料將保留,直到您取消配對、登出和刪除本機資料、刪除您的帳戶或刪除過時的配對資料。 Apple 推播通知服務令牌僅在啟用通知時保留,並在您停用通知、登出、刪除帳戶或 Apple 報告令牌無效時刪除。 PostHog 中的行動產品分析最多可保留 24 個月,除非您要求提前刪除。行動帳戶設定刪除或匿名 cmux 擁有的帳戶、裝置、配對、通知、計費和雲端數據,刪除帳戶連結的 PostHog 人員,並請求刪除其行動分析事件和記錄。某些提供者刪除工作可能會非同步完成。在行動帳戶設定中或聯絡 [founders@manaflow.com](mailto:founders@manaflow.com) 請求刪除。"
+ ]
+ }
+ ]
+}
diff --git a/web/app/[locale]/(legal)/privacy-policy/page.tsx b/web/app/[locale]/(legal)/privacy-policy/page.tsx
index 188080041946..a563e2942688 100644
--- a/web/app/[locale]/(legal)/privacy-policy/page.tsx
+++ b/web/app/[locale]/(legal)/privacy-policy/page.tsx
@@ -1,286 +1,109 @@
import type { Metadata } from "next";
-import { Link } from "../../../../i18n/navigation";
+import type { ReactNode } from "react";
-export const metadata: Metadata = {
- title: "Privacy Policy — cmux",
- description: "Privacy policy for cmux",
- alternates: { canonical: "https://cmux.com/privacy-policy" },
-};
-
-export default function PrivacyPolicyPage() {
- return (
- <>
-
Privacy Policy
-
Last updated: July 10, 2026
-
-
- Manaflow (the “Company”) is committed to maintaining robust
- privacy protections for its users. This Privacy Policy is designed to
- help you understand how we collect, use and safeguard the information you
- provide to us.
-
-
- For purposes of this policy, “Site” refers to the
- Company’s website at cmux.com.
- “Application” refers to the cmux desktop application for
- macOS and the cmux mobile application for iPhone and iPad.
- “Service” refers to the Site and Application collectively.
- The terms “we,” “us,” and “our”
- refer to the Company. “You” refers to you, as a user of our
- Service.
-
-
- By using our Service, you accept this Privacy Policy and our{" "}
- Terms of Service, and you consent to
- our collection, storage, use and disclosure of your information as
- described here.
-
-
-
I. Information We Collect
-
- We collect “Non-Personal Information” and “Personal
- Information.” Non-Personal Information includes information that
- cannot be used to personally identify you, such as anonymous usage data,
- platform types, and crash diagnostics. Personal Information includes
- your email address, account identifiers, and other information you
- choose to provide when you sign in, contact us, pair a device, or use
- the Application.
-
-
-
1. Information collected via Technology
-
- The Application may collect the following information automatically:
-
-
-
Crash reports and error diagnostics (via Sentry)
-
Operating system version and application version
-
- Product analytics and feature usage events for the Site and
- Application
-
-
- Device, account, and pairing metadata needed to connect your signed-in
- devices
-
-
- Apple Push Notification service device tokens, only after you enable
- phone notifications
-
-
-
- The macOS Application checks for updates via Sparkle, which may transmit
- your operating system version and application version to our update
- server. The iPhone and iPad Application is updated through the App Store,
- not Sparkle.
-
-
- The Site uses PostHog for analytics, including page views and navigation
- patterns. PostHog stores a cookie to distinguish unique visitors. If you
- join a platform waitlist, the email address you submit is recorded in
- PostHog so we can notify you when that platform is available. If you
- submit the Enterprise contact form, we record the company and contact
- details you provide in PostHog and send them to our internal Slack
- workspace and founders email inbox so we can respond. You can opt out of
- website analytics by using a browser extension that blocks tracking
- scripts.
-
-
- The iPhone and iPad Application sends product analytics events to our
- server-side PostHog proxy. These events help us diagnose reliability,
- understand feature usage, and improve the Application. They include app
- launch and session events, sign-in status, pairing attempts and results,
- connection recovery, workspace opens, terminal input byte and line
- counts, and notification opt-in or notification-deep-link results. The
- mobile analytics pipeline does not send terminal command text, terminal
- output, selected photos, or speech transcripts to PostHog. Before sign
- in, events use a random per-install client identifier. After sign in,
- our server attaches your Stack Auth account identifier to events before
- forwarding them to PostHog. We retain mobile analytics only as long as
- needed for product analytics and debugging. In the current iPhone and
- iPad Application, analytics and crash reports start disabled and are sent
- only after you enable the Share Analytics and Crash Reports control in
- Settings. Turning that control off stops analytics events from being
- buffered or sent. You may also contact us at{" "}
- founders@manaflow.com to
- request deletion of analytics associated with your account.
-
-
-
2. Information you provide directly
-
- If you contact us via email, our contact page, or the Enterprise contact
- form, we collect the information you provide such as your name, email
- address, company, role, phone number, country, deployment needs, and
- comments. If you join a platform waitlist, we collect the email address
- you submit so we can email you when that platform launches, and we send a
- notification of the signup (including that email address) to our internal
- Slack workspace.
-
-
- When you sign in to the Application, we receive the account information
- required to authenticate you, such as your email address and provider
- identifier from Apple, Google, GitHub, or email-code sign-in. When you
- pair the mobile app with a Mac, we process the pairing information
- required to connect those devices. When you use the mobile app to view a
- workspace, send terminal input, attach selected photos, use speech
- transcription, or receive terminal notifications, the related content or
- transcript may be transmitted between your devices and our service as
- needed to provide that feature.
-
-
- Camera access is used only to scan cmux pairing QR codes. Microphone and
- speech recognition access are used only when you choose voice
- transcription in the message box. Photo library access is used only when
- you choose photos to attach.
-
+import { buildAlternates } from "../../../../i18n/seo";
+import {
+ type PrivacyPolicySection,
+ type PrivacyPolicySubsection,
+ privacyPolicyForLocale,
+} from "./content";
-
3. Children’s Privacy
-
- The Service is not directed to anyone under the age of 13. We do not
- knowingly collect information from anyone under 13. If you believe we
- have collected such information, please contact us at{" "}
- founders@manaflow.com.
-
-
-
II. Third-Party Services
-
- The Application integrates with the following third-party services:
-
-
-
- Stack Auth — authentication and account
- management for sign-in, session management, and account deletion.
-
-
- Apple, Google, and GitHub — optional sign-in
- providers. These providers send us the account information required to
- authenticate you.
-
-
- Apple Push Notification service — delivers
- notifications to iPhone and iPad after you opt in.
-
-
- Apple Speech Recognition — used when you choose
- voice transcription in the mobile app.
-
-
- Sentry — error tracking and crash reporting.
- May collect error logs, stack traces, device information, and OS
- version.
-
-
- Sparkle — macOS auto-update framework.
- Transmits application and OS version to check for macOS updates.
-
-
- Ghostty / libghostty — terminal rendering
- engine. Runs entirely locally on your device.
-
-
- PostHog — website and mobile product analytics.
- Collects page view data, navigation patterns, browser metadata, mobile
- app feature events, and account-linked mobile analytics after sign-in
- via a first-party proxy. If you join a platform waitlist, the email
- address you submit is also recorded in PostHog so we can notify you.
-
-
- Resend — transactional email delivery. Used to
- deliver feedback submissions from the Application. Your email address
- is transmitted to Resend only if you voluntarily submit feedback.
-
-
- Slack — internal team notifications. If you join
- a platform waitlist, the email address and platforms you submit are
- sent to our private Slack workspace so the team is notified of the
- signup.
-
-
-
- Each of these services has its own privacy policy governing the
- collection and use of your data. When we use a third-party service to
- process Personal Information on our behalf, we require that service to
- protect the information with safeguards at least as protective as this
- Privacy Policy and to use it only to provide services to cmux.
-
-
-
III. How We Use and Share Information
-
- We do not sell, trade, rent or otherwise share your Personal Information
- with third parties for marketing purposes. We use crash reports and
- diagnostics solely to improve the Application. We may share information
- if we have a good-faith belief that disclosure is necessary to meet
- legal process or protect against harm.
-
- We implement security measures designed to protect your information from
- unauthorized access, including encryption and secure server software.
- However, no method of transmission or storage is 100% secure. By using
- our Service, you acknowledge and agree to assume these risks.
-
- The Service may provide links to third-party websites. We are not
- responsible for the privacy practices of those websites. This Privacy
- Policy applies solely to information collected by us.
-
- We reserve the right to change this policy at any time. Significant
- changes will go into effect 30 days following notification. You should
- periodically check the Site for updates.
-
- Crash reports and diagnostics are retained only as long as needed to
- diagnose and fix issues. Mobile account identifiers and authentication
- records are retained while your account is active and are deleted or
- anonymized when account deletion completes, except where retention is
- required for security, legal, billing, or fraud-prevention reasons.
- Device and pairing metadata is retained until you unpair the device,
- sign out and delete local data, delete your account, or the pairing data
- is pruned as stale. Apple Push Notification service tokens are retained
- only while notifications are enabled for that device, and are removed
- when you disable notifications, sign out, delete your account, or Apple
- reports the token invalid. Mobile product analytics in PostHog is
- retained for product analytics and debugging for up to 24 months unless
- you request earlier deletion. The mobile app account settings delete or
- anonymize cmux-owned account, device, pairing, notification, billing, and
- cloud data, and queue deletion of account-linked mobile PostHog
- analytics, as part of account deletion. Some deletion work may be
- processed asynchronously by our service providers. You may request
- deletion of cmux-owned data associated with you from the mobile app
- account settings or by contacting us at{" "}
- founders@manaflow.com.
-