Privacy Policy

Last updated: December 24, 2025

Thank you for visiting Mango App Studio's MD Editor website and application. Your privacy is important to us, and we are committed to protecting your personal information. This Privacy Policy describes our practices regarding the collection, use, and disclosure of your personal information across both our marketing website (mdedit.ai) and our application (app.mdedit.ai).

Information We Collect

Information You Provide

We collect personal information that you voluntarily provide to us when you use our services:

  • Account information (name, email address)
  • Authentication data (password, OAuth tokens from GitHub)
  • Payment information (processed securely through Stripe)
  • Content you create (articles, notes, images)
  • Support communications and feedback

Information We Collect Automatically

We automatically collect certain information about your visit and use of our services:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, time spent)
  • Performance metrics (page load times, error rates)
  • Cookies and similar tracking technologies

Google Analytics and Tracking

We use Google Analytics 4 (GA4) to understand how users interact with our services and to improve your experience. This section explains what data we collect through analytics and how it's used.

Analytics Data Collection

Google Analytics automatically collects:

  • Page views and navigation: Pages you visit, time on page, navigation paths
  • Device and browser information: Browser type, screen resolution, operating system
  • Geographic location: Country and city (based on IP address, which is anonymized)
  • Traffic sources: How you found our site (search engines, social media, direct visits)
  • Engagement metrics: Scroll depth, outbound link clicks, file downloads

User Properties We Track

For logged-in users of our application, we collect additional analytics to provide personalized experiences and improve our product. We track the following user properties (none contain personally identifiable information):

  • Subscription tier: Free, Standard, or Premium plan
  • Subscription status: Active, trial, cancelled, or expired
  • Account metrics: Number of articles created, account age, onboarding completion
  • Feature usage: AI provider selection, editor theme preference, collaboration settings
  • Workspace data: Number of workspaces, team size (counts only, no member identities)

Events We Track

We track specific user actions to understand feature usage and improve functionality:

  • Authentication: Login attempts, signup completions, OAuth connections
  • Content creation: Article creation, editing, publishing, deletion
  • AI features: AI text improvements, code generation, image creation
  • E-commerce: Subscription checkouts, purchases, cancellations
  • Engagement: Feature discovery, onboarding progress, settings changes

What We Don't Track

We respect your privacy and do NOT track or collect:

  • Article content or text you write
  • API keys or credentials you provide
  • Email addresses or names in analytics (only anonymized user IDs)
  • Keystroke logging or detailed writing patterns
  • Personal conversations or sensitive data

Cross-Domain Tracking

We use cross-domain tracking between our marketing website (mdedit.ai) and our application (app.mdedit.ai) to understand the complete user journey from discovery to signup. This allows us to measure marketing effectiveness and optimize the conversion funnel. Your session is linked across these domains using Google Analytics linker parameters, but your identity remains anonymized through GA4's automatic IP anonymization.

Data Retention

Google Analytics data is retained for 14 months, in compliance with GDPR requirements. After this period, aggregated data is retained for reporting purposes, but individual user identifiers are automatically deleted.

Cookies and Similar Technologies

We use cookies and similar tracking technologies for authentication, preferences, and analytics:

Essential Cookies

  • Authentication cookies: Keep you logged in to your account
  • Session cookies: Maintain your session state and preferences
  • Security cookies: Protect against fraud and abuse

Analytics Cookies

  • _ga: Google Analytics cookie for user identification (2 years)
  • _ga_*: Google Analytics session cookie (2 years)
  • _gid: Google Analytics short-term identifier (24 hours)

Advertising Cookies

We use Google Ads conversion tracking to measure the effectiveness of our advertising campaigns. These cookies track conversions but do not collect personally identifiable information.

How We Use Your Information

We use the collected information to:

  • Provide and maintain our services
  • Process your transactions and manage subscriptions
  • Send you service updates and marketing communications (with your consent)
  • Improve our product based on usage analytics
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Provide customer support

Information Sharing and Disclosure

We may share your information with:

  • Service providers: Stripe (payments), Google Analytics (analytics), AWS/Vercel (hosting)
  • AI providers: If you configure your own API keys (OpenAI, Anthropic, etc.), your content is sent directly to them according to your configuration
  • Legal requirements: When required by law or to protect our rights
  • Business transfers: In connection with a merger, acquisition, or sale of assets

We do NOT sell your personal information to third parties.

Your Rights and Choices

Access and Control

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your content (articles, notes)
  • Opt-out of marketing communications

Analytics Opt-Out

You can opt-out of Google Analytics tracking by:

Data Deletion

To request deletion of your data, contact us at contact@mdedit.ai. We will delete your account and personal information within 30 days, except where retention is required by law.

Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest for sensitive data
  • Secure authentication with hashed passwords
  • Regular security audits and updates
  • Access controls and monitoring

International Data Transfers

Your information may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.

Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

Links to Other Websites

Our website may contain links to third-party websites (e.g., Medium, Dev.to, Hashnode when publishing articles). We are not responsible for the privacy practices of these websites. We recommend reviewing their privacy policies before providing any personal information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: contact@mdedit.ai
Data Protection Officer: contact@mdedit.ai

Additional Information for EU/EEA Residents

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to access: Obtain a copy of your personal data
  • Right to rectification: Correct inaccurate personal data
  • Right to erasure: Request deletion of your personal data
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured format
  • Right to object: Object to processing of your personal data
  • Right to withdraw consent: Withdraw consent for data processing at any time

To exercise these rights, please contact us at contact@mdedit.ai.