In short
- Your code does not reach us. Deck does not send files, prompts, agent replies or terminal contents to Maze Analytics.
- There is an account. We store your name, your email and the record that you accepted the terms.
- There are usage metrics. Operational events from the app, such as version, platform and open sessions. You can turn them off in Settings.
- The rest is yours. Session history, settings and projects stay on your disk.
The controller of this data is Maze Analytics, based in Blumenau, Santa Catarina, Brazil. The terms that govern use of the app are in Terms of use.
Your account data
To use Deck you sign in with an email and password or with your Google account. The account holds the minimum needed to identify you and to prove you accepted the terms:
| Data | What for |
|---|---|
| Name | Identify you in the app and in support |
| Sign in, reset your password and receive notices about the account | |
| Account identifier | Tie the app session to the account, without relying on the email |
| Terms acceptance | Record of the version accepted and the date, required by law |
| Creation and update dates | Upkeep of the account record |
The password is managed by Firebase Authentication, a Google service, and never reaches Maze Analytics in readable form. If you sign in with Google, authentication happens in the browser, with a one-time code, and we receive only your confirmed name and email.
When you create the account, you get a welcome email sent through Resend, which receives your address in order to deliver the message. Password reset emails come from Firebase. Notices about account security and about changes to the terms also go by email. We do not use your address for advertising.
The legal basis is performance of the contract for using the app, for the account record and the essential notices, and compliance with a legal obligation, for the acceptance record.
Usage metrics
Deck sends operational events to a Maze Analytics service. They show how the app is used, where it breaks and what is worth improving. They are on by default and can be turned off at any time in Settings, under Usage metrics. When you turn them off, sending stops immediately and the pending queue is discarded.
What is sent
- Deck version, operating system and platform.
- A random installation identifier, plus your system username and the machine name.
- Session lifecycle: session created, session ended, agent switched, status, failure to create.
- Which agent was used and whether the session ran in a worktree or in planning mode.
- The project name as you named it in Deck, plus a code derived from the folder path.
- Estimated cost for the day, computed from the data the agent itself reports.
- Screens opened and interface actions, to understand the path taken.
What is never sent
- Prompts, agent replies or any part of a conversation.
- Terminal contents, commands typed or keys pressed.
- Code, file names or full folder paths.
- Tokens, API keys or passwords.
The project name goes out exactly as you wrote it. If the project name is a client name, it goes along. Rename the project in Deck or turn the metrics off if that is a problem in your context.
The metrics do not carry your account identifier, and creating an account does not link earlier events to it. The legal basis is the legitimate interest in maintaining and improving the product, balanced by the narrow scope of the events and by the one-click opt-out.
What stays on your computer
Most of what Deck produces never leaves the disk. It lives in ~/Library/Application Support/Deck on macOS and in %APPDATA%\Deck on Windows:
- Projects, sessions, screen layout and preferences.
- Terminal history. On macOS the sessions live in tmux and survive closing the app.
- The scripts Deck uses to receive notices from the agents.
- Connection tokens, encrypted by the system keychain.
None of this is synced, and none of it has a copy on a server of ours. Deleting the app and that folder deletes everything. Because Deck works inside your repositories, what the agents write also stays where your project is.
Signing out does not erase that environment: projects, sessions and connections stay on the computer. Anyone with access to the same operating system account reaches these files, so separating people on the same machine means separating system accounts.
Agents and connections
Deck is where you use third-party tools with your own accounts. What goes to each of them is governed by the privacy policy of whoever provides it:
- Coding agents. The agent you open receives your prompts and the code you share with it, through the account you already use. Maze Analytics takes no part in that exchange and has no access to it.
- ClickUp. If you connect it, Deck talks straight to the ClickUp API using a token of yours, stored encrypted on your machine.
- GitHub. Deck uses the login already in the GitHub CLI on your computer. No GitHub token is stored by the app.
- Updates. To find out whether a new version exists, the app requests a public address on Google Cloud Storage and checks the integrity of the downloaded file. As with any download, the infrastructure provider logs the access.
- Interface fonts. On launch, the app loads two fonts from Google Fonts. It is a file request, with no data of yours attached.
This site
The Deck site uses no cookies, has no tracker, pixel or analytics tool, and stores nothing in your browser. The fonts are served by the domain itself, with no request to third parties. There is no form and no signup here.
Hosting is on Vercel, which keeps technical access logs, such as IP address and browser type, for as long as it takes to run and protect the infrastructure.
Where data lives and for how long
The account service and the metrics service run on Google Cloud infrastructure, in the São Paulo region, Brazil. Firebase Authentication, which handles sign-in, is a global Google service and may process data outside the country, under the safeguards the law sets for international transfers.
- Account data. Kept for as long as the account exists. When you ask for deletion, we erase the account record and the acceptance history stays only for the period the law requires.
- Usage metrics. Kept in aggregate form to follow how the product evolves, never to profile a person and never for automated decisions.
- Our account service does not store your IP address. Access logs kept by infrastructure providers follow the policy of each provider.
We do not sell data, we do not run advertising and we do not share your data with third parties for commercial purposes. We share only with the providers that operate the service, such as Google Cloud, for infrastructure, and Resend, for sending email, or when the law requires it.
Your rights
Under the Brazilian General Data Protection Law (LGPD), you can ask at any time for:
- Confirmation that we process data about you, and access to that data.
- Correction of incomplete or outdated data.
- Deletion of the account and the data, subject to what the law requires us to keep.
- Portability and information about who we share data with.
- Withdrawal of consent and objection to processing carried out under legitimate interest.
Just write to deck@mazeanalytics.com.br. We answer within 15 days. To turn the metrics off you do not need to talk to anyone: the switch is in Settings.
Changes to this policy
When something changes here, the date at the top changes with it. If the change affects what leaves your computer, we tell you inside the app or by the account email before it takes effect.
Data protection officer and contact
Requests about personal data, questions about this policy and contact with the officer in charge of data protection at Maze Analytics: deck@mazeanalytics.com.br.