Project Machine is a personal control system for a builder’s projects — notes, tasks, decisions, and conversations with agents. This page explains what data we collect, why, and who else touches it. Plain language on purpose; the underlying practices match.
Who runs Project Machine
Project Machine is operated by Mechblocks (Jason Erickson). Contact: [email protected].
What we collect
- Account info. Username, email address, and a salted password hash (never the password itself). Optional profile display name.
- Content you create. Projects, notes, cards, tasks, decisions, canvas layouts, agents you configure, and chat messages you send. This is the substance of the product; without it there is nothing to store.
- Session cookies. A signed session cookie to keep you logged in.
- API keys and integration tokens you provide. If you supply an Anthropic (or other LLM provider) API key so agents can send prompts on your behalf, we store it encrypted at rest and use it only to make requests you initiate.
- Delivery-channel identifiers, only if you enable them. Phone number, Telegram chat ID, and Expo push tokens are stored only when you turn on the matching notification channel in Settings. Removing the channel removes the identifier.
- Push notification tokens (iOS app).When you install the iOS app and grant notification permission, the app sends its Expo push token to your account so we can deliver notifications you’ve opted into.
- Crash telemetry. If the app crashes, we capture the error stack trace, browser/device type, and the release version via Sentry. We do not capture session replays, form input, or request bodies.
How we use it
- To run the service you signed up for.
- To send notifications you’ve opted into (email digests, push, etc.).
- To debug crashes and improve reliability.
- To respond to you when you contact support.
What we don’t do
- We do not run advertising and we do not sell your data.
- We do not track you across other apps or websites.
- We do not use third-party product analytics (no Segment, Mixpanel, GA, etc.).
- We do not read your content to train models.
Third parties who touch your data
Project Machine relies on a small set of vendors. Each does one specific job and receives only what it needs.
- Anthropic (LLM API). When you use chat or agent features, the prompt content is sent to the LLM provider whose API key you configured (Anthropic by default). Their handling is governed by their API terms; we do not add data to their training set.
- Postmark. Transactional email delivery (password resets, magic links, invitations, morning digests).
- Sentry.Application crash / error telemetry. Errors only — no session replay, no request body capture.
- Expo Push Service. iOS push notification delivery, when you install the app and enable notifications.
- Backblaze B2. Encrypted off-site backup storage. Backups are encrypted on our server before upload; Backblaze sees ciphertext only.
- Cloudflare. DNS and edge network for the site.
Data retention and backups
Your content stays in Project Machine until you delete it or delete your account. The database is backed up nightly; local backups are pruned after 14 days, and client-side encrypted copies are retained off-site indefinitely for disaster recovery. When you delete an account, all associated content is removed from the live database on request; residual copies age out of encrypted backups on their normal rotation.
Your rights
You can request a copy of the data associated with your account, correct anything that’s wrong, or delete your account entirely. Email [email protected]. We’ll respond within a reasonable time frame.
Security
All traffic to the site is served over HTTPS. Passwords are stored as salted hashes. LLM API keys and other integration secrets are encrypted at rest with a server-side key. Backups are client-side encrypted before leaving our infrastructure.
Children
Project Machine is not directed to children under 13, and we do not knowingly collect data from them.
Changes to this policy
If we make material changes we’ll update the “Last updated” date at the top of this page and, for account holders, note the change in-app.
Contact
Questions, requests, or complaints: [email protected].