Privacy policy
What leaves your machine, what never does, and why. Last updated: September 2026.
The installation scripts collect nothing
The install.ps1 and install.sh scripts are one-way: they download files and write them to the local Claude Code and Codex configuration directories. No information is sent back to Maleta.dev. There is no telemetry, installation identifier, or usage report. The scripts do not read API keys or session histories and do not upload any file from your disk. Before overwriting an existing configuration, they create a local backup with the .pre-install.bak extension.
The hosted installer downloads the project bundle from https://github.com/diego-ruas/maleta.dev/archive/refs/heads/main.tar.gz. That request goes to GitHub, which receives the caller's IP address and user agent; Maleta does not receive a copy of the downloaded files.
Cookies on app.maleta.dev
The workspace at app.maleta.dev sets two necessary cookies. better-auth.session_token holds the signed session: HttpOnly, SameSite=Lax, Secure with a __Secure- prefix in production, path=/, host-only on app.maleta.dev, and it expires after 7 days. better-auth.session_data is a necessary cache of the session written by Better Auth's session cookie cache; it is valid for 5 minutes (300 seconds) and appears as session_data.N when the payload is large. Neither cookie is used for advertising, profiling, or cross-site tracking, and signing out deletes both.
maleta.dev is a static site: it sets no cookie at all, and there is no way to sign in on that origin.
Optional measurement
Vercel Web Analytics and Speed Insights load only after you accept optional measurement. The choice is stored in this origin's localStorage under maleta-analytics-consent-v1; with no choice, with rejected, or with storage unavailable, no measuring script is loaded and no /_vercel/insights/* or speed-insights request is made. The workspace also sends the payload-free events “Maleta Started” and “App Error”, and those follow the same choice. They contain only their fixed names: Maleta does not add names, email addresses, account or session identifiers, selections, Maleta contents, commands, search terms, error messages, digests, stacks, or other user-provided content. Vercel records anonymous data points for aggregate statistics without advertising cookies or cross-site profiles.
The choice is per origin: accepting here does not turn measurement on in the workspace, and rejecting in one origin does not change the other.
GitHub and other direct connections
When you search for a public skill or request a summary, your browser queries GitHub directly: api.github.com for the API and raw.githubusercontent.com for raw content. GitHub receives your IP address and user agent for those requests under its own privacy policy. Maleta receives no copy of those searches, files, or tokens.
Optional account (app.maleta.dev only)
The account is optional and exists only in the app.maleta.dev workspace. Everything works without it. When you sign in with GitHub, the app stores the data GitHub provides in Maleta's database: your name, email, avatar address, and the numeric identifier of your GitHub account. maleta.dev has no database, does not process sign-in, and never receives this session.
Authorization also returns a GitHub access token, stored with the linked account as the credential for that link. It does not maintain the session — the session cookie described above does that — and the Maleta interface does not use it for any Maleta operation.
While you are signed in, every workspace page loads your avatar directly from the address GitHub provides (usually avatars.githubusercontent.com); the request goes from your browser to GitHub and does not pass through Maleta. The institutional pages /about, /contact, /privacy, and /terms do not load the avatar. To sign in, the browser also navigates to github.com/login/oauth/authorize, where GitHub receives your IP address and user agent before returning you to the app.
Each recorded session also stores the connection's IP address and user agent, information the server receives whenever it answers a request. Sign out deletes the cookie and the session. To delete the account and the identity data above, email contato@maleta.dev; account deletion is a manual request with no promised deadline and no self-service.
With an account you can also save a Maleta to it with Save to account. Only then does the server store the complete maleta.json document — name, slug, skill and plugin counts, revision number, and creation and update dates — linked to your account identifier. Nothing is sent when you sign in, create an account, or use the local list. Delete from account removes the record from the active database, immediately and with no trash; it does not reach backups, and a copy still stored in this browser stays here. There is no automatic time-based deletion: a Maleta remains in your account until you delete it or the account.
Device authorization and the CLI
maleta login prints a short code that you confirm at app.maleta.dev/device. The code expires after 10 minutes. The authorization request row is deleted by a bounded opportunistic sweep, not by a timer, so this policy promises no maximum retention: while no sweep runs, an expired request can remain in the table.
The CLI keeps its credential in ~/.maleta/credentials.json, written with mode 0600 inside a 0700 directory. That file holds the device token, the device name (the hostname by default), the platform, sha256 hashes of the device code and token and of the request IP, the last-activity time, and the Maleta bound to that computer. maleta watch also sends the conflict detail for a file it refuses to apply, so the account can show what the computer could not reconcile.
maleta logout removes this computer's credential and asks the server to revoke the computer. If that request fails, the credential is still removed locally and you must revoke the computer at app.maleta.dev under Account > Authorized computers. Revoked computers are kept as history and dropped from the active list.
The tray checks https://unpkg.com/maleta.dev@latest/native/update-manifest.json every 24 hours for a newer version. That request goes to unpkg.com, which may see the caller's IP address and user agent.
Who else receives data
Vercel hosts both origins and receives request data and access logs. Neon Postgres stores the account database. GitHub handles the OAuth round trip, serves the avatar your browser loads, and answers the direct API and raw content requests. unpkg.com serves the tray update manifest, and GitHub serves the installer archive. Maleta has no advertising or data-broker relationship with these providers. This list says who can receive the data; it does not assert a processing agreement or a transfer decision.
[TODO: confirm the retention windows and the data-processing terms of Vercel, Neon, GitHub, and unpkg.]
Local state and optional token
The site does not set tracking or advertising cookies. The workspace can store skill selections, plugins, external skills, the selected tool and system, saved Maletas, the Maleta being edited, the link to the account, recent searches, and the theme preference. This data is not sent to Maleta and is not shared between maleta.dev and app.maleta.dev.
The theme rides along with navigation between the two surfaces in the ?theme= URL parameter: links to the workspace carry the maleta.dev preference, and links back carry the workspace preference. On arrival, the parameter becomes that origin's stored theme preference (maleta-theme-v1) and is then removed from the URL. It is the only information in those links.
If you choose to save a GitHub Personal Access Token, it is stored as maleta-gh-token in this tab's browser session (sessionStorage), does not survive closing the tab, and is sent as an authorization header only for direct GitHub API requests that you initiate. It is not part of maleta.json and is not sent to Maleta. The maleta.json file is created and read on your device.
[TODO: confirm how long the workspace keeps its rate-limit and session tables, and whether a retention policy is enforced for them.]
The keys are aitoolkit-selected-skills, maleta-selected-plugins-v2, aitoolkit-custom-skills, aitoolkit-target-tool, aitoolkit-target-os, maleta-saved-maletas-v1, maleta-active-maleta-v1, maleta-cloud-links-v1, maleta-recent-scans, maleta-theme-v1, maleta-analytics-consent-v1, maleta-gh-token. Optional measurement records the choice in the last of them before any measuring script mounts, and no choice means nothing is measured.
Retention, deletion, and the questions still open
Deleting a local Maleta means clearing this origin's browser data. Deleting a Maleta saved to your account uses Delete from account in the app. Revoking an authorized computer is done under /account. maleta logout removes this computer's credential and asks the server to revoke it; if that request fails, remove the credential anyway and revoke the computer at app.maleta.dev.
Account deletion is requested by email and is manual; there is no self-service and no promised deadline. Deletion covers the active database rows for the user, the linked account, the sessions, and the Maletas saved to the account.
[TODO: confirm the backup and restore window of the database and the log retention of the hosting provider.]
[TODO: confirm the retention window for revoked computers and for authorization requests abandoned during idle periods.]
[TODO: confirm every third-party deletion mechanism and any export process.]
Your rights and contact
Without an account, Maleta has no profile for you to access, correct, or delete: Maletas remain in your browser. With an account, you can sign out at any time and request deletion of the identity data described above. For questions about data handling, content removal requests, or formal inquiries, email contato@maleta.dev. Other channels are listed on the contact page.